Skip to main content

Free billing audit

Get audit →
Quick Answer

What Is 21st Century Cures Act?

The 21st Century Cures Act is a 2016 federal law whose information blocking provisions, implemented at 45 CFR part 171, prohibit health care providers, health IT developers of certified health IT, and health information networks and exchanges from interfering with the access, exchange or use of electronic health information.

  • Confirm API data-set requirements against the certification criteria currently in force rather than a version number quoted elsewhere.
Regulation

21st Century Cures Act

Also known as: Cures Act; Cures Act of 2016

The 21st Century Cures Act is a 2016 federal law whose information blocking provisions, implemented at 45 CFR part 171, prohibit health care providers, health IT developers of certified health IT, and health information networks and exchanges from interfering with the access, exchange or use of electronic health information.

Definition

Signed into law in December 2016, the Cures Act spans FDA and NIH matters, but its operational effect on practices is the information blocking regime at 45 CFR part 171. Section 171.103 defines information blocking as a practice that, except as required by law or covered by an exception in subparts B, C or D, is likely to interfere with the access, exchange or use of electronic health information — and the knowledge standard differs by actor. A health IT developer of certified health IT, a health information network or a health information exchange is reached where it “knows, or should know, that such practice is likely to interfere”; a health care provider only where the provider “knows that such practice is unreasonable and is likely to interfere”. That difference is why a delayed release is not automatically unlawful. Consequences also differ by actor: developers, networks and exchanges face civil money penalties of “not more than $1,000,000 per violation” under 42 CFR part 1003, subpart N, while health care providers are subject to disincentives applied through Medicare programs under subpart J of part 171. The Act also requires patient access to electronic health information through standards-based APIs, with the required data set fixed by the certification criteria in force at the time — those criteria are revised, so date any version reference rather than quoting one as permanent.

Example

A practice configures its portal to hold laboratory results until a clinician has reviewed them, or declines to release imaging reports to a patient’s app through the API. Either practice may be information blocking, and either may not. The analysis runs through the definition first — is the practice required by law, and does an exception in subpart B, C or D cover it — and then through the provider knowledge standard, which asks whether the provider knows the practice is unreasonable as well as likely to interfere with access, exchange or use. Document the basis for any delay at the time it is applied, because that contemporaneous record is what the analysis later runs on. Whether a specific configuration complies is a legal question on the facts and the current text of part 171.

Common Misconceptions

The information blocking rules do not override HIPAA — they sit on top of it. They are also no longer a list of eight exceptions. Part 171 now carries exceptions for preventing harm, privacy, security, infeasibility, health IT performance and protecting care access in subpart B; manner, fees and licensing in subpart C; and a TEFCA manner exception in subpart D (45 CFR part 171). Read the current part rather than a remembered list. An exception is also not the only lawful reason to limit access: the definition itself excludes practices required by law, and a health care provider is reached only where the provider knows the practice is unreasonable as well as likely to interfere. A delay is a question to analyze, not a conclusion.

Practical Application

Review release configurations against the current text of part 171 rather than against a policy written when the rule first took effect — exceptions have been added and the conditions inside them carry their own requirements. Where a practice delays or limits a release, record at the time which exception or legal requirement it relies on and the facts supporting it, and have the policy reviewed by counsel, because the provider standard turns on whether the practice is unreasonable and only the record can support that judgment. Confirm API data-set requirements against the certification criteria currently in force rather than a version number quoted elsewhere.

Where This Applies on MedPrecision

Free billing audit

Need help with billing?

If this term is showing up in your denials, EOBs, or A/R aging, we can help. Get a free billing audit and we will trace the issue to its root cause.

  • No contract
  • No setup fees
  • Reply within 1 business day
Call us Free audit