The 21st Century Cures Act
and the Information Blocking Rules
What the law establishes, what it requires of Health Information Exchanges, and how Cures Gateway exists to fulfil it.
A patient's data belongs to the patient
The 21st Century Cures Act, Pub. L. 114-255, was signed into law on 13 December 2016 with overwhelming bipartisan support. Alongside its provisions on medical research and drug approval, Title IV of the Act confronted a quieter failure of American healthcare: patient data was technically digitised but practically trapped, held in incompatible systems and behind competitive walls.
The Act's answer was twofold. It required that electronic health information be made accessible through standardised, secure APIs "without special effort" on the part of the patient. And it created a new legal category of misconduct, information blocking: any practice by a regulated actor that is likely to interfere with the access, exchange or use of electronic health information, unless required by law or covered by a defined exception.
45 CFR Part 171: who is bound, and how
In 2020 the Office of the National Coordinator for Health IT (ONC, now ASTP) gave the statute operational force through the Information Blocking Rules, 45 CFR Part 171. The Rules bind three classes of "actors": healthcare providers, developers of certified health IT, and health information networks and health information exchanges. An HIE is therefore not an observer of this regime. It is a directly regulated actor.
A practice that interferes with access is unlawful unless it falls within one of the defined exceptions, each with strict conditions:
- Preventing Harm — withholding is permitted only to prevent defined harm to a patient or another person.
- Privacy — honouring a legal privacy precondition that has not been satisfied.
- Security — practices directly related to safeguarding the confidentiality, integrity and availability of EHI.
- Infeasibility — genuine impossibility, with a written explanation within ten business days.
- Health IT Performance — brief, necessary maintenance windows.
- Content and Manner — fulfilling a request in an agreed alternative manner under defined conditions.
- Fees — recovering reasonable costs, with express limits protecting patient access.
- Licensing — licensing interoperability elements on reasonable, non-discriminatory terms.
The architecture of the Rules is deliberate: openness is the default, and every deviation must be justified, documented and defensible.
Up to $1,000,000 per violation
Since 1 September 2023, the HHS Office of Inspector General has held authority to impose civil monetary penalties on HIEs, HINs and certified health IT developers of up to $1 million per violation. Each impeded request can constitute a separate violation. For healthcare providers, HHS has established separate "appropriate disincentives" through programme-level penalties.
Complementing enforcement, the individual right of access under HIPAA, 45 CFR § 164.524, entitles every patient to obtain their records, and to direct them to a designee of their choosing, within strict timeframes. A Personal Health Application acting at the patient's instruction stands in the patient's shoes. Declining, delaying or degrading that access is where regulatory exposure begins.
| Instrument | Citation | What it establishes |
|---|---|---|
| 21st Century Cures Act | Pub. L. 114-255 (2016) | Prohibition of information blocking; API access "without special effort" |
| Information Blocking Rules | 45 CFR Part 171 | Actor definitions, practice standard, eight exceptions |
| OIG Enforcement Rule | 88 FR 42820 (2023) | CMPs up to $1M per violation for HIEs, HINs and developers |
| Individual Right of Access | 45 CFR § 164.524 | Patient access and designee direction within defined timeframes |
| TEFCA | Common Agreement | National exchange framework incl. Individual Access Services |
From statute to enforcement to scale
The Act is signed
Pub. L. 114-255 establishes the prohibition of information blocking and the right to access "without special effort".
The Rules take shape
ONC finalises 45 CFR Part 171: actors defined, exceptions codified, openness made the default.
Enforcement begins
OIG gains authority to impose penalties of up to $1M per violation on HIEs, HINs and developers.
TEFCA goes live
Individual Access Services open a national lane for patient-directed exchange at scale.
The wave arrives
Consumer platforms ship record access to hundreds of millions of users. Compliance becomes an infrastructure problem.
An unbounded obligation meets an unprecedented wave
The law places no ceiling on volume and provides no default compensation. As consumer platforms ship health record access to hundreds of millions of users, individual access requests against HIE endpoints are projected to grow from thousands to millions per day. Every one of those requests carries the same legal weight, the same identity assurance burden, the same consent complexity across fifty states, and the same audit obligation. An HIE cannot lawfully refuse the wave. The only question is how it is absorbed.
Fulfil the obligation. Remove the burden. Return the value.
Cures Gateway is managed infrastructure operated by Agentic Healthcare that discharges the individual access obligation on behalf of connected HIEs, converting a regulatory liability into governed, compensated participation. In respect of every request, the Gateway undertakes to:
Vet every application
Each Personal Health Application is screened, contracted and continuously monitored before a single request reaches an HIE endpoint.
Prove every identity
Patients are identity-proofed to NIST IAL2 before any record moves, with consent captured under the applicable state regime across all fifty states.
Govern all traffic
Requests are buffered, queued and shaped to hourly rate limits the HIE controls, so lawful demand never becomes infrastructure saturation.
Document everything
Every request, response and timing metric is captured in ONC-defensible audit trails retained for six years or more.
Score every document
Each CCD is assessed for quality and completeness across 47 dimensions, with reporting the HIE owns.
Return the value
Participation costs the HIE nothing, and per-request earnings scale with volume, so compliance becomes income rather than expense.
The law says patients must have their data.
We make sure they get it, safely, and that HIEs are stronger for it.
Cures Gateway
Aligned with TEFCA Individual Access Services · FHIR R4 · USCDI · HIPAA Business Associate framework · SOC 2 programme underway