What Is 21st Century Cures Act?
The 21st Century Cures Act is a 2016 federal law whose information blocking provisions, implemented at 45 CFR part 171, prohibit health care providers, health IT developers of certified health IT, and health information networks and exchanges from interfering with the access, exchange or use of electronic health information.
- Confirm API data-set requirements against the certification criteria currently in force rather than a version number quoted elsewhere.
21st Century Cures Act
Also known as: Cures Act; Cures Act of 2016
The 21st Century Cures Act is a 2016 federal law whose information blocking provisions, implemented at 45 CFR part 171, prohibit health care providers, health IT developers of certified health IT, and health information networks and exchanges from interfering with the access, exchange or use of electronic health information.
Definition
Signed into law in December 2016, the Cures Act spans FDA and NIH matters, but its operational effect on practices is the information blocking regime at 45 CFR part 171. Section 171.103 defines information blocking as a practice that, except as required by law or covered by an exception in subparts B, C or D, is likely to interfere with the access, exchange or use of electronic health information — and the knowledge standard differs by actor. A health IT developer of certified health IT, a health information network or a health information exchange is reached where it “knows, or should know, that such practice is likely to interfere”; a health care provider only where the provider “knows that such practice is unreasonable and is likely to interfere”. That difference is why a delayed release is not automatically unlawful. Consequences also differ by actor: developers, networks and exchanges face civil money penalties of “not more than $1,000,000 per violation” under 42 CFR part 1003, subpart N, while health care providers are subject to disincentives applied through Medicare programs under subpart J of part 171. The Act also requires patient access to electronic health information through standards-based APIs, with the required data set fixed by the certification criteria in force at the time — those criteria are revised, so date any version reference rather than quoting one as permanent.
Example
A practice configures its portal to hold laboratory results until a clinician has reviewed them, or declines to release imaging reports to a patient’s app through the API. Either practice may be information blocking, and either may not. The analysis runs through the definition first — is the practice required by law, and does an exception in subpart B, C or D cover it — and then through the provider knowledge standard, which asks whether the provider knows the practice is unreasonable as well as likely to interfere with access, exchange or use. Document the basis for any delay at the time it is applied, because that contemporaneous record is what the analysis later runs on. Whether a specific configuration complies is a legal question on the facts and the current text of part 171.
Common Misconceptions
The information blocking rules do not override HIPAA — they sit on top of it. They are also no longer a list of eight exceptions. Part 171 now carries exceptions for preventing harm, privacy, security, infeasibility, health IT performance and protecting care access in subpart B; manner, fees and licensing in subpart C; and a TEFCA manner exception in subpart D (45 CFR part 171). Read the current part rather than a remembered list. An exception is also not the only lawful reason to limit access: the definition itself excludes practices required by law, and a health care provider is reached only where the provider knows the practice is unreasonable as well as likely to interfere. A delay is a question to analyze, not a conclusion.
Practical Application
Review release configurations against the current text of part 171 rather than against a policy written when the rule first took effect — exceptions have been added and the conditions inside them carry their own requirements. Where a practice delays or limits a release, record at the time which exception or legal requirement it relies on and the facts supporting it, and have the policy reviewed by counsel, because the provider standard turns on whether the practice is unreasonable and only the record can support that judgment. Confirm API data-set requirements against the certification criteria currently in force rather than a version number quoted elsewhere.
Related Terms
Information Blocking Rule
The Information Blocking Rule, codified at 45 CFR Part 171 under the 21st Century Cures Act, prohibits health care providers, health IT developers, and health information networks from engaging in practices likely to interfere with access, exchange, or use of electronic health information (EHI), subject to ten regulatory exceptions.
Read definitionFHIR
FHIR (Fast Healthcare Interoperability Resources) is an HL7 standard for exchanging healthcare information using modern web technologies (RESTful APIs, JSON/XML, OAuth 2.0), used for clinical data exchange, patient access APIs, and increasingly for prior-authorization and quality reporting.
Read definitionEHR (Electronic Health Record)
An Electronic Health Record is a digital, longitudinal record of a patient's health information maintained by a healthcare organization, designed to be shared across providers and care settings, and to support clinical decisions, billing, and quality reporting.
Read definitionHIPAA
HIPAA is the 1996 federal law that establishes national standards for protecting the privacy and security of individually identifiable health information held by covered entities and their business associates.
Read definitionWhere This Applies on MedPrecision
Need help with billing?
If this term is showing up in your denials, EOBs, or A/R aging, we can help. Get a free billing audit and we will trace the issue to its root cause.
- No contract
- No setup fees
- Reply within 1 business day