Legislative & Regulatory Foundation

Patient Access · Information Blocking · 45 CFR Parts 171 & 164

The framework behind
patient-directed access

What federal policy establishes, what it means for Health Information Exchanges (HIEs), and how Cures Gateway helps HIEs support patient access through governed infrastructure.

Prepared by Agentic Healthcare, Inc. · Revised July 2026

Federal policy is expanding patient access

The 21st Century Cures Act was signed into law in December 2016 with broad bipartisan support. Among its many provisions, the Act advanced a national commitment to making electronic health information more accessible, exchangeable, and usable.

The Act called for secure, standards-based access to electronic health information without special effort by the patient. It also established the prohibition against information blocking: practices that are likely to interfere with the access, exchange, or use of electronic health information unless required by law or covered by a defined exception.

"The term 'information blocking' means a practice that… is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information."

42 U.S.C. § 300jj-52(a) · 21st Century Cures Act, § 4004

What the Information Blocking Rules mean for HIEs

In 2020, the Office of the National Coordinator for Health IT, now ASTP, implemented the Act's information-blocking provisions through 45 CFR Part 171.

The rules apply to three categories of regulated actors:

  • Healthcare providers
  • Developers of certified health IT
  • Health information networks and Health Information Exchanges

HIEs therefore play a central role in meeting federal expectations for access, exchange, and use of electronic health information.

A practice that interferes with access may be permissible only when it satisfies the conditions of a defined exception.

1 · Preventing Harm

Allows certain practices intended to prevent defined harm to a patient or another person.

2 · Privacy

Applies when a legal privacy requirement has not been satisfied.

3 · Security

Covers practices that protect the confidentiality, integrity, and availability of electronic health information.

4 · Infeasibility

Applies when fulfilling a request is genuinely infeasible and the required explanation is provided.

5 · Health IT Performance

Allows limited practices necessary to maintain or improve system performance.

6 · Content and Manner

Defines how requests may be fulfilled through an alternative content or technical method.

7 · Fees

Allows certain reasonable fees, subject to conditions and limitations.

8 · Licensing

Permits licensing of interoperability elements on reasonable and non-discriminatory terms.

The framework is designed to promote access while recognizing legitimate privacy, security, technical, and operational constraints.

Information-blocking requirements carry meaningful enforcement risk

Since September 2023, the HHS Office of Inspector General has had authority to impose civil monetary penalties on certain regulated actors, including HIEs, HINs, and certified health IT developers.

$1MMaximum civil monetary penalty per violation
8Exceptions, each subject to specific conditions
RequirementsImportant for demonstrating how requests are evaluated and fulfilled

HIPAA's individual right of access also gives patients the right to obtain copies of their health information and, in certain circumstances, direct that information to a designated third party.

Together, these requirements reinforce a clear direction: patients should be able to access and use their health information through secure and appropriate channels.

InstrumentCitationWhat it establishes
21st Century Cures ActPub. L. 114-255Prohibition of information blocking and support for API-based access
Information Blocking Rules45 CFR Part 171Regulated actors, practice standards, and eight exceptions
OIG Enforcement Rule88 FR 42820Civil monetary penalties for certain regulated actors
Individual Right of Access45 CFR § 164.524Patient access and certain third-party direction rights
TEFCACommon AgreementA national framework for trusted health information exchange

From policy to implementation

2016

2016

The Act is signed

The 21st Century Cures Act establishes the prohibition against information blocking and advances standards-based patient access.

2020

2020

The rules take effect

45 CFR Part 171 defines regulated actors, establishes the eight exceptions, and gives operational meaning to the statute.

2023

2023

Enforcement begins

The Office of Inspector General gains authority to impose civil monetary penalties on certain regulated actors.

2024

2024-2025

National exchange expands

TEFCA and other national initiatives increase the reach and scale of electronic health information exchange.

2026 and beyond

Patient demand continues to grow

More consumer health applications are enabling patients to request and use their health records directly.

Growing demand requires scalable infrastructure

As more applications offer direct health-record access, HIEs may receive a growing volume of patient-directed requests.

Each request can introduce requirements related to:

  • Application trust and vetting
  • Patient identity proofing
  • Consent and authorization
  • Request routing and traffic management
  • Response documentation
  • Data completeness and quality

Meeting those needs consistently can require significant operational, technical, and compliance resources.

Cures Gateway gives HIEs a governed way to manage patient-directed access without building and maintaining a separate access network.

Support patient access. Reduce the burden. Create new value.

Cures Gateway is managed infrastructure that helps participating HIEs support patient-directed requests through one governed connection.

6.01

Vet every application

Each Personal Health Application is reviewed for legal, technical, privacy, and security readiness before joining the network.

6.02

Verify every patient

Patients complete identity proofing to NIST IAL2 standards before a request reaches the HIE.

6.03

Apply consent requirements

Cures Gateway captures and applies relevant consent and authorization requirements for each request, including applicable state-specific rules.

6.04

Govern request traffic

Requests can be buffered, queued, and managed within operating limits established with the participating HIE.

6.05

Document each transaction

Request, response, and timing information is captured to support monitoring, reporting, and audit needs.

6.06

Evaluate response quality

Clinical documents can be assessed for completeness and quality before being delivered to the requesting application.

6.07

Expand participation without added cost

There is no participation fee for HIEs. As the network grows, participating organizations may also gain access to emerging revenue and partnership models.

Patients increasingly expect access to their records.
Cures Gateway helps HIEs provide it through infrastructure that is governed, scalable, and designed to strengthen their role in health data exchange.

Free to join Built for HIEs Live today TEFCA-compatible workflows FHIR R4 USCDI HIPAA safeguards NIST IAL2

Cures Gateway · Powered by Agentic Healthcare, Inc. · info@agentichealth.io