The Office of the National Coordinator for Health IT (ONC) has spent the past year supporting public health agencies in responding to the COVID-19 pandemic, while advancing health equity, increasing adoption of electronic health record standards, and continuing to handle information blocking regulations. Currently, complaints about information blocking from providers and health IT vendors are pouring in.

Information blocking enforcement has begun, and ONC has received hundreds of complaints, most from patients, alleging that parties are hindering the free flow of health data. However, the U.S. Department of Health and Human Services (HHS) has not yet finalized penalties for non-compliant providers and vendors, which remains one of the last obstacles to implementing the information blocking provisions of the 2016 21st Century Cures Act.

In an interview, ONC head Micky Tripathi shared his views on information blocking complaints, providers' concerns about compliance, and HHS's slow progress in defining penalties—a significant gap in the enforcement rule.

Complaints accelerate, but future numbers uncertain

In the 11 months from April 2021 to February 2022, ONC received about 300 information blocking complaints. In the subsequent 8 months (March to October), ONC received another 240, showing a slight acceleration trend. But Tripathi said that since interoperability complaints are still in early stages, ONC cannot determine future complaint volume or pace.

"This is 'uncharted territory,' lacking a clear frame of reference." For example, 540 complaints are "insignificant" compared to HIPAA complaints, which can reach tens of thousands annually.

"What surprises me more is the current composition of complaints," Tripathi said. Complaints against providers remain the clear majority, continuing a trend since March. The vast majority of complaints are submitted by patients and patient advocates.

Given that information blocking "is still a relatively specialized concept," this phenomenon is unexpected. Ordinary patients find it harder to learn about the complaint process, while vendors are highly focused because violations could lead to hefty fines. Tripathi said that as awareness increases and enforcement begins, the visibility of information blocking regulations may rise, and complaint numbers could increase accordingly.

"There is already awareness at the patient level, which surprises me," Tripathi said, "but we will observe. It is still early, and complaints against other types of actors may emerge in the future."

Enforcement complexity causes HHS delay

After ONC receives a complaint, it conducts an initial screening to determine if it may constitute an information blocking violation. If so, ONC refers the complaint to the HHS Office of Inspector General (OIG) for investigation.

OIG has statutory authority to impose civil monetary penalties of up to $1 million on non-compliant health IT vendors. However, regulators have not yet finalized the rule proposed in 2020, which specifies investigation procedures and penalty amounts.

This could lead to a backlog of complaints because OIG has not yet begun investigations—they cannot start until the rule is finalized.

"Generally, you don't enforce things in a rule until the final rule is issued," Tripathi said, "We hope it can be completed this year, but I can't promise on their behalf."

Additionally, HHS has not yet defined penalties for providers. Tripathi declined to give a specific timeline but said "we are working very hard to move forward."

Regulators face many difficulties in crafting the rule. The 21st Century Cures Act separates penalties for providers from other actors and authorizes the HHS Secretary to determine "appropriate disincentives," but does not define specifics or grant HHS additional authority to implement them.

"Regulators lack clear guidance," Tripathi said.

Therefore, HHS must identify powers available in existing agencies or programs that could serve as appropriate disincentives. This may involve CMS or other agencies with funding programs. At the same time, regulators must navigate the federal bureaucracy, which tends to be conservative in interpreting statutory authority.

"This is truly frustrating—the complexity is too high," Tripathi said, "That's why the timeline has extended. Despite our efforts, we face inherently complex issues that need to be sorted out step by step."

Will disincentives be lenient?

Some provider groups have lobbied HHS to issue warnings and corrective letters before penalties. Tripathi emphasized that ONC is not involved in deciding the severity of disincentives; OIG and other agencies responsible for "appropriate disincentives" will have full authority over enforcement.

The ONC head declined to comment on whether HHS is considering a warning phase. But Tripathi said penalties may vary based on the degree of violation by the actor.

"OIG is responsible for enforcement, and agencies will implement appropriate disincentives through existing programs. They may define penalty ranges based on the severity of violations and follow a set of criteria. It's conceivable this will be part of the process," Tripathi said.

"Definition as clear as possible"

The scope of electronic health information that providers and health IT vendors must share expanded significantly in October. Initially, the definition of "electronic health information" in the information blocking rule was limited to data elements in the USCDI dataset. But since October 6, the definition has expanded to all electronic health information that meets the definition of HIPAA protected health information.

Provider groups such as the American Hospital Association asked ONC in September to delay the change by one year. Providers argued that due to confusion about implementation and enforcement requirements, including unclear EHI definitions and lack of technical support, they could not meet the requirements on time.

Tripathi acknowledged providers' concerns are legitimate but noted that the 21st Century Cures Act has been passed for six years. ONC also provided an 18-month transition period from USCDI sharing to comprehensive EHI sharing.

"No one ever feels ready, right?" Tripathi said, "If we delay 12 months, would everyone suddenly be ready? That doesn't make sense. I don't think the world works that way. We have no reason to delay further."

The ONC head also mentioned eight information blocking exceptions, providing actors more operational leeway. For example, if an organization cannot electronically provide emergency records to a patient, the infeasibility exception may apply.

In defining EHI, regulators adopted a structure that providers should already understand. The EHI providers must now share is essentially the electronic portion of HIPAA designated record sets, which providers have handled for decades.

"I think the definition is as clear as possible," Tripathi said, "I understand there may be some ambiguity, but it traces back to HIPAA. You should have done this 20 years ago. Just continue building on existing requirements."