Legislative & Regulatory Foundation · 21st Century Cures Act · 45 CFR Parts 171 & 164
An Official Overview

The 21st Century Cures Act
and the Information Blocking Rules

What the law establishes, what it requires of Health Information Exchanges, and how Cures Gateway exists to fulfil it.

§ 1 · The Act

A patient's data belongs to the patient

The 21st Century Cures Act, Pub. L. 114-255, was signed into law on 13 December 2016 with overwhelming bipartisan support. Alongside its provisions on medical research and drug approval, Title IV of the Act confronted a quieter failure of American healthcare: patient data was technically digitised but practically trapped, held in incompatible systems and behind competitive walls.

The Act's answer was twofold. It required that electronic health information be made accessible through standardised, secure APIs "without special effort" on the part of the patient. And it created a new legal category of misconduct, information blocking: any practice by a regulated actor that is likely to interfere with the access, exchange or use of electronic health information, unless required by law or covered by a defined exception.

"The term 'information blocking' means a practice that... is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information."42 U.S.C. § 300jj-52(a) · 21st Century Cures Act, § 4004
§ 2 · The Rules

45 CFR Part 171: who is bound, and how

In 2020 the Office of the National Coordinator for Health IT (ONC, now ASTP) gave the statute operational force through the Information Blocking Rules, 45 CFR Part 171. The Rules bind three classes of "actors": healthcare providers, developers of certified health IT, and health information networks and health information exchanges. An HIE is therefore not an observer of this regime. It is a directly regulated actor.

A practice that interferes with access is unlawful unless it falls within one of the defined exceptions, each with strict conditions:

The architecture of the Rules is deliberate: openness is the default, and every deviation must be justified, documented and defensible.

§ 3 · Enforcement

Up to $1,000,000 per violation

Since 1 September 2023, the HHS Office of Inspector General has held authority to impose civil monetary penalties on HIEs, HINs and certified health IT developers of up to $1 million per violation. Each impeded request can constitute a separate violation. For healthcare providers, HHS has established separate "appropriate disincentives" through programme-level penalties.

$0
max penalty per violation
8
defined exceptions, strictly conditioned
0
audit trail retention required

Complementing enforcement, the individual right of access under HIPAA, 45 CFR § 164.524, entitles every patient to obtain their records, and to direct them to a designee of their choosing, within strict timeframes. A Personal Health Application acting at the patient's instruction stands in the patient's shoes. Declining, delaying or degrading that access is where regulatory exposure begins.

InstrumentCitationWhat it establishes
21st Century Cures ActPub. L. 114-255 (2016)Prohibition of information blocking; API access "without special effort"
Information Blocking Rules45 CFR Part 171Actor definitions, practice standard, eight exceptions
OIG Enforcement Rule88 FR 42820 (2023)CMPs up to $1M per violation for HIEs, HINs and developers
Individual Right of Access45 CFR § 164.524Patient access and designee direction within defined timeframes
TEFCACommon AgreementNational exchange framework incl. Individual Access Services
§ 4 · A Decade of Escalation

From statute to enforcement to scale

DEC 2016

The Act is signed

Pub. L. 114-255 establishes the prohibition of information blocking and the right to access "without special effort".

MAY 2020

The Rules take shape

ONC finalises 45 CFR Part 171: actors defined, exceptions codified, openness made the default.

SEP 2023

Enforcement begins

OIG gains authority to impose penalties of up to $1M per violation on HIEs, HINs and developers.

2024–2025

TEFCA goes live

Individual Access Services open a national lane for patient-directed exchange at scale.

2026 →

The wave arrives

Consumer platforms ship record access to hundreds of millions of users. Compliance becomes an infrastructure problem.

§ 5 · The Practical Problem

An unbounded obligation meets an unprecedented wave

The law places no ceiling on volume and provides no default compensation. As consumer platforms ship health record access to hundreds of millions of users, individual access requests against HIE endpoints are projected to grow from thousands to millions per day. Every one of those requests carries the same legal weight, the same identity assurance burden, the same consent complexity across fifty states, and the same audit obligation. An HIE cannot lawfully refuse the wave. The only question is how it is absorbed.

§ 6 · The Objective of Cures Gateway

Fulfil the obligation. Remove the burden. Return the value.

Cures Gateway is managed infrastructure operated by Agentic Healthcare that discharges the individual access obligation on behalf of connected HIEs, converting a regulatory liability into governed, compensated participation. In respect of every request, the Gateway undertakes to:

6.01

Vet every application

Each Personal Health Application is screened, contracted and continuously monitored before a single request reaches an HIE endpoint.

6.02

Prove every identity

Patients are identity-proofed to NIST IAL2 before any record moves, with consent captured under the applicable state regime across all fifty states.

6.03

Govern all traffic

Requests are buffered, queued and shaped to hourly rate limits the HIE controls, so lawful demand never becomes infrastructure saturation.

6.04

Document everything

Every request, response and timing metric is captured in ONC-defensible audit trails retained for six years or more.

6.05

Score every document

Each CCD is assessed for quality and completeness across 47 dimensions, with reporting the HIE owns.

6.06

Return the value

Participation costs the HIE nothing, and per-request earnings scale with volume, so compliance becomes income rather than expense.

§ 7 · In One Sentence

The law says patients must have their data.
We make sure they get it, safely, and that HIEs are stronger for it.

Cures Gateway

Aligned with TEFCA Individual Access Services · FHIR R4 · USCDI · HIPAA Business Associate framework · SOC 2 programme underway