A practice configures its patient portal to hold lab results for 72 hours "so the doctor can call first." A patient calls on day two asking why the result is not visible. The front desk says HIPAA gives the practice 30 days. That is true. It is also beside the point, because a second federal rule applies to the same result, and it does not have a 30-day grace period.
HIPAA's Privacy Rule, at 45 CFR Parts 160 and 164, is a permission structure: it says when a covered entity may share P.H.I. (Protected Health Information) and gives patients a right of access with a deadline. The information blocking regulations at 45 CFR Part 171, issued under the 21st Century Cures Act, are a prohibition: they say a health care provider may not engage in practices likely to interfere with access to electronic health information unless a law requires it or an exception applies. This article quotes both, puts them side by side, shows where they meet, and gives a small practice the checklist for the places where its habits are compliant under one rule and exposed under the other.
HIPAA vs Information Blocking: What Each Rule Actually Says
What HIPAA Requires
Under 164.524(b)(2)(i), a covered entity "must act on a request for access no later than 30 days after receipt of the request," with one extension of up to 30 days on written notice. Denials are limited to the grounds in 164.524(a)(2) and (a)(3). Fees are cost-based. Beyond the right of access, most of the Privacy Rule describes disclosures the practice is permitted, not required, to make. That is the whole design: HIPAA sets a privacy floor and then tells the practice what it may do above it. The access rule in detail is in HIPAA right of access.
What Part 171 Says
45 CFR 171.103 defines the offense: "Information blocking means a practice that except as required by law or covered by an exception set forth in subparts B, C, or D of this part, is likely to interfere with access, exchange, or use of electronic health information; and (b) If conducted by: ... (2) A health care provider, such provider knows that such practice is unreasonable and is likely to interfere with access, exchange, or use of electronic health information."
Three definitions from 171.102 fill that in. "Interfere with or interference means to prevent, materially discourage, or otherwise inhibit." The regulated parties, called actors, are "a health care provider, health IT developer of certified health IT, health information network or health information exchange," and 171.101(b) says they have been subject to the part "on and after April 5, 2021." And the protected information, electronic health information or EHI, "means electronic protected health information as defined in 45 CFR 160.103 to the extent that it would be included in a designated record set as defined in 45 CFR 164.501," excluding psychotherapy notes and information compiled for a legal proceeding.
The ONC page on information blocking restates the knowledge standard in plain terms: for developers and networks, the test is whether they "know, or should know," that a practice is likely to interfere; for health care providers, "the law applies the standard of whether they know that the practice is unreasonable and is likely to interfere with the access, exchange, or use of EHI." A provider has to know the practice is unreasonable. A three-day hold on every result, with no clinical judgment involved, is the kind of blanket practice that standard was written for.
Side by Side
| HIPAA Privacy Rule | Information blocking (45 CFR Part 171) | |
|---|---|---|
| Who it binds | Covered entities and business associates (160.103) | Actors: health care providers, developers of certified health IT, health information networks and exchanges (171.102) |
| What it covers | PHI in any form: paper, oral, electronic | EHI: electronic PHI in the designated record set, minus psychotherapy notes and litigation material |
| Core obligation | Use and disclose only as permitted; honor the right of access | Do not engage in practices likely to interfere with access, exchange, or use of EHI |
| Deadline | 30 days to act on an access request, one 30-day extension (164.524(b)(2)) | No fixed deadline; the test is whether a practice is "likely to interfere" |
| Knowledge standard | None for the access duty; penalty tier depends on culpability (160.404) | Provider must know the practice is unreasonable and likely to interfere (171.103(b)(2)) |
| Who enforces | HHS Office for Civil Rights | HHS Office of Inspector General investigates; ONC reviews claims against certified developers |
| Consequence for a provider | Civil money penalties and resolution agreements | Disincentives under 171.1001 (CMS program status), public posting under 171.1101 |
The enforcement row deserves one more sentence. Under 171.1001, CMS may treat a hospital or a MIPS-eligible clinician found to have committed information blocking as "not a meaningful EHR user," and may remove an accountable care organization or its participants from the Medicare Shared Savings Program "for at least 1 year." Under 171.1101, ONC will post the provider's name, business address, and the practice found to be information blocking on its public website once the disincentive is applied. That is the small-practice exposure: payment program status and a public listing.
Where the Two Rules Meet
ONC has addressed the overlap directly. Its own guidance on how the information blocking regulations work with the HIPAA Rules makes three points, each grounded in the regulation text.
First, a HIPAA prohibition is not information blocking. 171.103 excludes practices "required by law." As ONC puts it, if another law "prohibits sharing EHI in a particular circumstance, such as for a particular purpose, then not sharing EHI in the particular circumstance is not information blocking." A practice that refuses a disclosure the Privacy Rule forbids is not blocking anything.
Second, a HIPAA precondition is handled by the privacy exception. Most of the Privacy Rule does not forbid disclosures; it permits them once a condition is met, such as a valid authorization. 171.202(b), the "precondition not satisfied" sub-exception, protects a practice that declines to share because a required precondition has not been met, provided the practice's approach is "tailored to the applicable precondition," is "implemented in a consistent and non-discriminatory manner," and either follows written policies that "specify the criteria to be used by the actor to determine when the precondition would be satisfied" and are implemented "including by providing training," or is documented case by case. There is a catch that trips up practices: if the authorization on file is defective, 171.202(b)(2) requires the practice to "use reasonable efforts within its control to provide the individual with a consent or authorization form that satisfies all required elements" and not to "improperly encourage or induce the individual to withhold the consent or authorization." Rejecting the bad form and going silent is not enough.
Third, a valid HIPAA denial is a valid Part 171 denial. 171.202(d) covers the case where a patient requests EHI under the right of access and the actor's practice "must be consistent with 45 CFR 164.524(a)(2)," the unreviewable denial grounds. Deny access for a reason HIPAA recognizes, in the way HIPAA requires, and the privacy exception applies.
Where They Do Not Meet: The 30-Day Question
HIPAA's 30-day clock is not adopted anywhere in Part 171. Taking 30 days to fulfill an access request is compliant under 164.524. Whether a routine delay is a practice "likely to interfere" with access is a separate question under 171.103, and nothing in the regulation text says the HIPAA deadline answers it. The exceptions that could cover a delay are specific: the preventing harm exception in 171.201 requires, among other conditions, a risk "determined on an individualized basis in the exercise of professional judgment by a licensed health care professional" with a relationship to the patient, or a data-quality problem, and the harm must be of a type that would justify a HIPAA denial under 164.524(a)(3). A blanket 72-hour hold on all results is not individualized. The manner, fees, and infeasibility exceptions in subpart C have their own conditions. ONC's page adds that the exceptions "are voluntary and offer actors certainty," and that a practice outside every exception "does not automatically mean that information blocking has occurred"; it is evaluated case by case. That is not the same as a safe harbor.
Enforcement on Both Sides
OCR's Right of Access enforcement is well established and reaches small providers: a $70,000 civil monetary penalty against Gums Dental Care for failure to provide timely access to patient records (October 17, 2024), a $200,000 penalty against Oregon Health & Science University on the same ground (March 6, 2025), and a Right of Access settlement with Azul Vision, Inc. (August 27, 2026). Information blocking claims are submitted through ONC's portal, and ONC's page states that the HHS Office of Inspector General "has authority to investigate claims of possible information blocking across all types of actors." A patient who waited too long for a portal result can file with both.
The Small-Practice Checklist
- Result release settings. Find every automatic delay in the portal and the EHR. Either remove it or document the individualized clinical basis the preventing harm exception requires, per patient, per result.
- Written access policy. The 164.524 workflow (intake log, 30-day date, fee sheet, denial letter) plus a paragraph stating that requests are fulfilled as soon as practicable, not held to the deadline.
- Precondition procedures. Written criteria for when an authorization is valid, the steps staff take to help a patient fix a defective one, and training records showing staff learned them, so 171.202(b)(1)(i) is satisfied.
- Denial discipline. Deny only on 164.524(a)(2) or (a)(3) grounds, in writing, with review rights where required, so 171.202(d) applies.
- Patient opt-outs. A documented process for a patient's request not to share their EHI, meeting 171.202(e).
- Fees. The HIPAA cost-based fee schedule, applied consistently; the Part 171 fees exception in 171.302 has its own conditions, and a fee that fails HIPAA will not pass it.
- Vendors. The EHR and portal vendors are actors in their own right; the practice's B.A.A. (Business Associate Agreement) and service agreement should require them to support access, exchange, and use rather than obstruct it. The vendor side is in the business associate agreement guide.
- Staff script. "HIPAA gives us 30 days" is retired. The replacement is "you will have it as soon as it is ready, and no later than 30 days."
What to Write Into the Policy
One document can serve both rules. Title it the records access and information sharing policy. State the HIPAA right of access and its deadlines; state that the practice is a health care provider actor under 45 CFR 171.101 and does not engage in practices likely to interfere with access, exchange, or use of EHI; list the specific circumstances in which the practice declines or delays (a HIPAA prohibition, an unmet precondition, an individualized harm determination, a patient's own request) and cite the paragraph each one rests on; and assign one owner, usually the privacy officer, for both HIPAA complaints under 164.530(d) and information blocking questions. The rest of the patient-facing rights are collected in the provider guide to patient rights, and the Privacy Rule structure the policy sits inside is in the Privacy Rule requirements guide.
The 72-hour hold at the top of this article is the whole lesson: a HIPAA-compliant practice that a second federal rule may treat as interference. The fix is to release the result and let the call happen after.
---
FAQ
Does HIPAA's 30-day deadline protect a practice from information blocking claims?
No. 45 CFR Part 171 does not adopt the 30-day clock. Taking 30 days is compliant under 164.524, but whether a routine delay is a practice likely to interfere with access is a separate question under 171.103, judged against the Part 171 exceptions.
Is a small medical practice an actor under the information blocking rule?
Yes. 171.102 defines actors to include health care providers, and 171.101(b) makes them subject to the part on and after April 5, 2021.
If HIPAA prohibits a disclosure, can it be information blocking to refuse it?
No. 171.103 excludes practices required by law, and ONC's guidance states that not sharing EHI where another law prohibits it is not information blocking.
What happens to a provider found to have committed information blocking?
Under 171.1001, CMS may treat the provider as not a meaningful EHR user for hospital or MIPS purposes, or remove it from the Medicare Shared Savings Program for at least one year, and under 171.1101 ONC posts the provider's name and the practice on its website.
Can we delay releasing test results so the physician can call first?
Only with an exception. The preventing harm exception in 171.201 requires an individualized determination by a licensed professional with a relationship to the patient, tied to a harm that would justify a HIPAA access denial. A blanket delay on all results does not meet that.
Conclusion
Most small practices already comply with HIPAA's access rule and have never read Part 171, which is the gap this article is about. One Guy Consulting's Full-Scope plan includes the policy set that covers records access and release of information, and consulting time to walk the practice's actual delay and denial practices against both rules. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR Part 171 (information blocking)
- 45 CFR 171.103 (information blocking definition)
- 45 CFR 171.202 (privacy exception)
- 45 CFR 171.1001 (disincentives for health care providers)
- ONC: Information Blocking
- ONC: Information Blocking Regulations Work in Concert with HIPAA Rules (April 12, 2023)
- 45 CFR 164.524 (right of access)
Related Reading