If there’s one thing patients and healthcare professionals can agree on, it’s that the system runs best when information goes where it needs to go.

To help make that a reality, the information blocking rule from the 21st Century Cures Act was created to discourage healthcare providers, developers and networks from interfering with the access, exchange or use of electronic health information (EHI).

But being compliant with the information blocking rule isn’t as simple as saying “yes” to every request. There are privacy concerns, security risks and system access barriers to consider. That’s why the Office of the National Coordinator (ONC) released nine information blocking exceptions.

These exceptions cover the limited circumstances where restricting EHI access may be appropriate and information blocking might not apply. Think of these exceptions as guardrails to help you prioritize transparency alongside protecting patient privacy, maintaining security and managing real-world operational challenges.

In this article, we’ll break down all nine exceptions, explain when they apply and share practical considerations for ensuring compliance with the information blocking rule.

What Are Information Blocking Exceptions?

The goal of the information blocking rule is straightforward: remove unnecessary roadblocks so health information can flow more freely when it’s legally permitted and clinically appropriate. Still, regulators recognize that healthcare doesn’t operate in a perfect world. HIM teams regularly face situations where releasing information could create privacy concerns, introduce security risks or simply be impossible due to circumstances outside their control.

That’s where the information blocking exceptions come in.

But remember: these exceptions are guardrails, not get out of jail free cards! If your actions meet the requirements of an exception, you generally won’t be considered information blocking. However, if a situation doesn’t fit neatly into an exception, that doesn’t automatically mean information blocking occurred either. Regulators evaluate potential violations based on the specific facts and circumstances of each case.

Compliance tip: Information blocking exceptions aren’t loopholes. They’re narrowly defined protections designed to balance access, privacy, security and the operational realities of healthcare.

The 9 Information Blocking Exceptions

The nine information blocking exceptions fall into three categories.

Information Blocking Exceptions That May Allow an Organization to Not Fulfill a Request

This category of exceptions addresses situations where you may be justified in not fulfilling a request for EHI.

  • Preventing Harm
  • Privacy
  • Security
  • Infeasibility
  • Health IT Performance

Information Blocking Exceptions That Govern How Requests Are Fulfilled

This group considers the procedures at play for fulfilling requests to access, exchange or use EHI.

  • Manner
  • Fees
  • Licensing

Information Blocking Exceptions that Involve Participation within TEFCA

The final category characterizes information blocking exceptions specific to the Trusted Exchange Framework and Common Agreement (TEFCA).

  • TEFCA Manner

Exception #1: Preventing Harm

The information blocking rule is built around access, but not at the expense of safety. That’s where the preventing harm exception comes in.

If you reasonably believe releasing information could put a patient or another person at risk, you may be able to temporarily limit access. The important words here are “reasonably believe” and “patient.” These decisions must be based on the specifics of the situation – that patient – not a blanket policy or a “we always do it this way” approach.

Key considerations:

  • Individualized assessment is required
  • Restrictions must be narrowly tailored
  • Decisions should be documented
  • The goal is preventing harm, not preventing access

This exception is for defining reasonable practices that act as a seatbelt, not a roadblock.

Exception #2: Maintaining Privacy

One of the biggest priorities in healthcare as a whole (not just HIM) is protecting patient privacy – and for good reason. The privacy exception recognizes that there are times when privacy obligations may limit access to EHI.

This can include situations like:

  • Incomplete or invalid authorizations
  • Patient-requested privacy restrictions
  • State-specific privacy laws
  • Legally protected categories of information

However, you can’t simply reject a request because an authorization is incomplete. The regulation requires actors to use reasonable efforts to help the individual satisfy the authorization requirements, including providing a compliant authorization form or other reasonable assistance. This reinforces a key theme of the Information Blocking Rule: removing barriers to appropriate access whenever possible.

For release of information and HIM teams, this is familiar territory. The privacy exception simply provides a framework for balancing two equally important goals: protecting patient privacy and supporting appropriate access.

Exception #3: Upholding Security

You can’t improve trust in health information if hackers have access, too.

The security exception allows you to implement reasonable safeguards to protect the confidentiality, integrity and availability of EHI. That may mean pausing a request while verifying identity, investigating suspicious activity or responding to a cybersecurity threat.

Exception #4: Infeasibility

The infeasibility exception applies when fulfilling a request isn’t reasonably possible, despite good-faith efforts.

Examples might include:

  • Natural disasters limiting environmental safety and accessibility
  • Public emergencies
  • Significant system failures

The key here is documentation. When a request is truly infeasible, you need to be ready to explain why. That’s not just a best practice, it’s a regulatory requirement. Under 45 C.F.R. § 171.204, “the actor must, within ten business days of receipt of the request, provide to the requestor in writing the reason(s) why the request is infeasible.”

Exception #5: Health IT Performance

Every technology system eventually needs a tune-up. The health IT performance exception recognizes that maintenance, upgrades and repairs are a normal part of keeping systems running smoothly. This may include:

  • Planned maintenance windows
  • Software upgrades
  • Temporary downtime
  • System optimization efforts

The important distinction is intent. These activities should be reasonable and necessary and only for the time period needed to achieve the intended purpose, not used as a convenient way to restrict access.

Exception #6: Manner

Just because someone asks for EHI one way, that doesn’t mean it has to be provided that way.

The Manner exception allows organizations to provide EHI through a different format or delivery method when the requested option isn’t feasible or the parties can’t agree on how the information should be exchanged. For HIM teams, that’s often a practical reality.

The key is keeping information moving. You aren’t required to build new technology or create entirely new workflows to fulfill a request, but you are expected to provide access through a reasonable alternative whenever possible.

As with all of these exceptions, non-discrimination is key. If a request was fulfilled previously to another requestor using the exact same “manner,” it will be almost impossible to deny it to another requestor.

It’s also worth noting that newer exceptions, such as the Protecting Care Access Exception, recognize limited situations where restricting access to certain EHI may be appropriate. But the overall goal remains the same: support access to health information while applying exceptions only when specific requirements are met.

Exception #7: Fees

Let’s clear up one of the biggest myths around information blocking: fees are not automatically prohibited. Organizations may be able to charge certain fees if they’re reasonable, compliant and not designed to discourage access, and are uniformly applied. There is a difference between recovering reasonable costs and creating barriers to access.

When evaluating fees, you should ensure said fees are well-documented, consistently applied and aligned with applicable requirements.

(At HealthMark, we believe that patients should not have to pay to access their medical records and therefore do not charge patients to access their records.)

Exception #8: Licensing

The licensing exception may sound like something only lawyers and software vendors care about, but everyone in HIM should at least understand the basics.

As healthcare becomes more connected, organizations increasingly rely on:

  • Third-party APIs
  • Data exchange platforms
  • Interoperability solutions
  • Technology partnerships

This exception addresses how intellectual property protections and data sharing can coexist. While providers may not negotiate licensing agreements themselves, understanding the rules can help them better navigate the growing ecosystem of connected healthcare technologies.

Just like with the other exceptions, it’s important that any licensing terms are reasonable, narrowly tailored, non-discriminatory and not intended to deny or interfere with access or exchange of information.

Exception #9: TEFCA Manner

As TEFCA adoption grows, organizations may have the option to fulfill certain EHI requests through TEFCA only without being considered information blocking. The goal is to encourage secure, standardized and efficient information exchange through a common framework instead of maintaining multiple pathways for the same request.

This exception only applies when:

  • Both parties participate in TEFCA
  • The requested EHI can be exchanged through TEFCA
  • The request is not made through an ONC-certified API
  • Any applicable fees or licensing arrangements comply with existing requirements

Information Blocking Exceptions FAQs

Still have questions? You’re not alone. Information blocking rules often intersect with real-world operational and compliance challenges, so we’ve answered a few common questions you’re most likely to come across in your day to day responsibilities.

Does information blocking only apply to patient access requests?

No. Information blocking applies broadly to electronic health information, not solely patient right-of-access requests.

Can providers verify identity before releasing medical records?

Yes, provided verification requirements are reasonable and not used to create unnecessary barriers.

Can multi-facility organizations limit medical record releases to one location?

Not simply for convenience if records are available within the same system and no exception applies.

Can healthcare organizations exclude outside records when a medical record request is made?

Potentially, but providers should evaluate whether an exception applies before restricting access.

Building a Defensible Process Around Information Blocking Exceptions

When it comes to information blocking, good intentions are helpful. But good documentation is better. The HIM teams that navigate exceptions most successfully don’t rely on guesswork or crossed fingers; they rely on clear processes, procedures, and documentation that stand up to scrutiny.

Some best practices to follow include:

  • Creating written policies so staff aren’t making judgment calls on the fly
  • Training regularly (because regulations change and memories fade)
  • Documenting decisions and the reasoning behind them
  • Escalating gray areas instead of tackling it alone
  • Reviewing past decisions to avoid treating similar situations differently
  • Stay up to date as the rules continue to evolve

At HealthMark, we’ve found that structured workflows and thorough documentation are usually an organization’s strongest defense. When exception decisions are supported by clear policies, consistent processes and a documented rationale, compliance becomes much easier to demonstrate and defend.

Final Thoughts

The information blocking rule was created to improve access, not eliminate professional judgment. The nine information blocking exceptions recognize that HIM teams sometimes face situations where withholding, delaying or modifying access is reasonable and necessary – but that doesn’t mean you can withhold information whenever it’s inconvenient!

Understanding these exceptions, documenting your decisions and maintaining consistent processes better positions your team to support both patient access and regulatory compliance.

For more practical guidance on interoperability, release of information and regulatory compliance, subscribe to the HealthMark blog!

Sources:

  1. Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC). Information Blocking Exceptions Fact Sheet. U.S. Department of Health and Human Services. https://healthit.gov/wp-content/uploads/2024/04/IB_Exceptions_Fact_Sheet_508.pdf
  2. 21st Century Cures Act, Pub. L. No. 114-255. Referenced as the statutory foundation for the Information Blocking Rule. The introduction discusses the rule as originating from the 21st Century Cures Act. https://www.congress.gov/114/plaws/publ255/PLAW-114publ255.htm
  3. 45 C.F.R. § 171.204 (Infeasibility Exception). Establishes conditions under which fulfilling a request may be considered infeasible and requires actors to provide written notice within ten business days explaining why a request is infeasible. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-D/part-171/subpart-B/section-171.204
  4. 45 C.F.R. Part 171, Information Blocking. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-D/part-171
  5. Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP/ONC). Trusted Exchange Framework and Common Agreement (TEFCA). U.S. Department of Health and Human Services. https://healthit.gov/policy/tefca/
  6. 45 C.F.R. § 171.206 (Protecting Care Access Exception). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-D/part-171/subpart-B/section-171.206#p-171.206

Where do you want to start?

Tell us a little bit about yourself, and we’ll match you with the right expert to help you optimize your patient information.