Policy · Patient access / health policy

What Information Blocking Means for You: Your Electronic Health Information Is Generally Expected to Move

For many patients, requesting medical information still feels like asking a favor. Federal law takes a different starting position: your electronic health information generally should be accessible, exchangeable, and usable for lawful purposes, and practices that improperly interfere with that movement may constitute “information blocking.” That does not mean every delay or denial is unlawful — information blocking is a defined legal concept that depends on specific facts, and this guide walks through what those facts are.

For many patients, requesting medical information still feels like asking for a favor. Federal law takes a different starting position. Electronic health information generally should be accessible, exchangeable, and usable for lawful purposes, and certain practices that improperly interfere with that movement may constitute “information blocking.”

That does not mean that every delay, technical problem, denial, or incomplete response violates federal law. Information blocking is a defined legal concept that depends on who engaged in the practice, what information was involved, whether the practice was likely to interfere with access, exchange, or use, what the actor knew, whether another law required the practice, and whether an exception applies.

This guide explains how the rules affect patients, how they interact with HIPAA and California law, and what steps may help when information is delayed or withheld. It is written for patients and family members, not for lawyers, and every claim here is stated with the qualifications the actual rule carries — because those qualifications are usually the difference between a real violation and a frustrating but lawful delay.

What Information Blocking Actually Means

The 21st Century Cures Act directed the federal government to address practices that interfere with the access, exchange, or use of electronic health information. Under 45 C.F.R. § 171.103, information blocking generally means a practice by an applicable “actor” that is likely to interfere with access, exchange, or use of electronic health information, unless the practice is required by law or covered by a regulatory exception.

The actors covered by the rules are health care providers; developers of certified health IT; health information exchanges (HIEs); and health information networks (HINs). If the organization withholding your information isn't one of these — a consumer app you downloaded yourself, for instance — the information-blocking rules simply don't apply to it, whatever else might.

The applicable knowledge standard also depends on the type of actor, and this distinction matters more than it sounds like it should. For a health care provider, a regulator generally must establish that the provider knew the practice was unreasonable and was likely to interfere with access, exchange, or use. For a certified-health-IT developer, HIE, or HIN, the standard is broader: whether the actor knew or should have known that the practice was likely to interfere.

A frustrating delay is not automatically a proven violation. A regulator evaluating a specific complaint would consider whether the organization was a covered actor; whether the information qualified as electronic health information; whether the practice interfered with access, exchange, or use; whether the required knowledge standard was met; whether another law required the practice; and whether an exception applied. Even when a practice does not satisfy every condition of a regulatory exception, it does not automatically become information blocking — the facts still have to be evaluated individually, which is the single most important qualifier in this entire area and the one most often left out of casual descriptions of the rule.

What Counts as Electronic Health Information

Electronic health information, or EHI, is defined more precisely than “anything in the computer.” In general, EHI is electronic protected health information that would be included in a HIPAA “designated record set,” regardless of whether the person or organization holding it is itself a HIPAA covered entity.

It generally includes electronic information used to make decisions about a person: visit and progress notes, laboratory and pathology results, radiology reports, medication and allergy information, problem lists, immunization information, discharge summaries, billing and claims records, and other electronically maintained decision-making records.

The definition excludes psychotherapy notes as specially defined under HIPAA, and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative proceeding. Records that exist only on paper generally are not EHI for information-blocking purposes — though they may still be accessible under HIPAA or California law, covered later in this guide.

Actual diagnostic images deserve a specific note, because they trip up more requests than any other category. A radiology report is different from the underlying CT, MRI, ultrasound, or X-ray image files. The files may be held in a separate imaging system and may require a different technical transfer process than the written report. That difference does not eliminate your access rights, but it can affect the manner in which the information can reasonably be provided — asking specifically for “the images, not just the report” is worth doing explicitly rather than assuming one request covers both.

Delays and Obstacles Can Matter — But Not Automatically

Information blocking is not limited to an explicit statement that records will never be provided. The regulatory definition of interference includes practices that prevent, materially discourage, or otherwise inhibit lawful access, exchange, or use, and a practice can be an act or an omission.

Potential examples include an unnecessary delay; disabling a download or export capability; imposing additional steps without a valid reason; refusing to use an available exchange method; charging impermissible or discriminatory fees; restricting a compatible application without adequate justification; or providing information in a form that cannot reasonably be used when another supported form was requested.

Whether a particular delay constitutes interference is fact-specific, and this is where the rule is most often misdescribed as broader than it is. Necessary delays — one needed to comply with another law, resolve a patient-matching problem, address a genuine security issue, or complete necessary technical steps — may not constitute information blocking when they last no longer than reasonably necessary. The rule targets unjustified interference, not every interval between a request and a response.

Sending Information to an App You Chose

Patients increasingly use apps to combine information from multiple health systems. A provider should not automatically reject a compatible app merely because the organization did not select, sponsor, or “approve” it. ASTP/ONC has stated that requiring third-party applications to undergo duplicative provider vetting before using certified standardized API technology may itself be an interference, when the certified API already incorporates required security standards.

That does not create an unlimited right to demand any transmission method, however. Under the Manner Exception, an actor generally should fulfill a request in the manner requested unless it is technically unable to do so or cannot reach agreeable terms with the requestor. When the requested manner cannot be used, the regulation establishes a process for providing access through an alternative manner without unnecessary delay — so a provider genuinely unable to support your specific app is not automatically blocking you, provided it offers a working alternative.

A practical app request should identify the name of the app; the account or connection details; the information requested; the relevant dates; and whether the app uses the provider's patient-facing API or another supported connection. A provider may also explain genuine privacy or security concerns — educating you about an app's risks is not the same as improperly preventing you from choosing it, and the two are worth telling apart when you're deciding how to respond.

HIPAA's separate third-party-transmission right has real limits worth knowing before you rely on it. HIPAA allows patients to obtain copies of protected health information and, in some circumstances, direct transmission to another person or entity. But a 2020 federal court decision (commonly referenced as the Ciox decision) vacated HHS guidance to the extent it had expanded the HITECH Act's third-party directive beyond an electronic copy of an electronic health record, and the same decision limited application of HIPAA's patient-access fee restrictions to certain third-party-directed requests. Your own right to obtain copies remains fully intact regardless. When direct app transmission is disputed, one practical alternative is to request the electronic records yourself and then transfer them to the app, when compatible and appropriate.

Privacy After Information Reaches a Consumer App

HIPAA protects information held by covered health care providers, health plans, clearinghouses, and their business associates. A consumer app you selected yourself may not be a HIPAA covered entity or business associate at all. Once information is transmitted to such an app at your direction, HIPAA protections may no longer govern the app's subsequent collection, use, sale, or disclosure of that data.

That does not necessarily mean the app answers to no law. Depending on the app and its functions, legal protections may include the Federal Trade Commission Act's prohibition on deceptive or unfair practices; the FTC's Health Breach Notification Rule; state consumer-privacy laws; state health-data laws; contractual privacy promises in the app's own terms; and app-store or platform requirements. The FTC's revised Health Breach Notification Rule expressly addresses many health apps, connected devices, and personal-health-record services that fall outside HIPAA specifically because they weren't designed to be covered by it.

Before connecting an app, it's worth actually checking: what information it collects; whether it combines information from multiple sources; whether it uses information for advertising; whether it sells or shares information; how account deletion works; whether exported data can be deleted; what happens after a security breach; and whether the privacy policy can change without your individual consent. Convenience and privacy are genuinely separate questions, and a compatible app is not automatically a safe one.

Why Test Results Sometimes Appear Before the Clinician Calls

Federal information-blocking regulations do not require every provider to proactively place every result into a portal the instant it becomes final. They do, however, prohibit certain unreasonable practices that interfere with lawful access once a request for access exists — and unnecessary delay after that point can implicate the rules.

ASTP/ONC has explained that patients may receive results in parallel with their availability to the ordering clinician. It has also stated directly that a blanket several-day delay covering a broad range of routine results does not qualify for the Preventing Harm Exception merely because a clinician would prefer to review every result first — preference is not the same as the individualized, documented risk assessment the exception actually requires.

An individualized delay may still be permissible when the applicable conditions are satisfied, including a reasonable belief that the practice will substantially reduce a recognized risk of harm and that the restriction is no broader than necessary. You can also ask that particular results be delayed until clinician review yourself: ASTP/ONC guidance recognizes that an actor can honor an agreed patient-requested delay when the agreed conditions and timeframe are followed without unnecessary extension. In California, Health and Safety Code § 123148 separately requires the health professional who requested a test to provide or arrange provision of the result when the patient requests it, subject to the statute's own terms.

Reading results safely matters as much as receiving them promptly. A value outside a laboratory reference range does not, by itself, establish disease or an emergency — reference ranges, clinical thresholds, trends, symptoms, medications, and the reason the test was ordered all affect interpretation. Radiology and pathology reports are written primarily for clinicians and often contain differential language, incidental observations, and recommendations that need clinical context to interpret correctly. A portal message requesting interpretation is the right move when the meaning or urgency is unclear; new severe symptoms, though, should be evaluated based on the symptoms themselves rather than by waiting for a portal response.

Legitimate Reasons Information May Be Limited

Current information-blocking regulations contain several detailed exceptions, addressing preventing harm; privacy; security; infeasibility; health IT performance; protecting access to lawful reproductive care; the manner of fulfilling a request; fees; licensing of interoperability elements; and specified TEFCA-related circumstances.

Each exception contains real conditions, and merely invoking words like “privacy,” “security,” or “patient safety” does not automatically establish compliance with any of them. Examples of potentially legitimate circumstances include a disclosure prohibited by federal or state law; required authorization that has not been completed; an individualized, professionally supported risk of recognized harm; inability to separate protected information about another person from your own record; a specific and documented cybersecurity risk; corrupted or mismatched data; a genuine system outage; inability to satisfy the request despite following the required alternative-manner process; and reasonable maintenance affecting system availability.

What does not qualify, on its own: a broad office preference, generalized discomfort with the request, unfamiliarity with how to fulfill it, or routine administrative convenience. If the explanation you're given sounds like one of those rather than one of the specific, documented circumstances above, that's worth naming directly when you ask for the reason in writing.

Your Separate HIPAA Access Right

Information blocking and HIPAA are related but genuinely distinct legal frameworks, and confusing them is one of the most common mistakes patients make when pursuing a records request.

The HIPAA Privacy Rule generally gives you the right to inspect or obtain a copy of protected health information maintained in one or more designated record sets by a covered entity or its business associate. A designated record set can include medical records; billing records; claims and payment records; enrollment records; case-management records; clinical laboratory reports; diagnostic images; and other records used to make decisions about you. Psychotherapy notes and information prepared for specified legal proceedings are generally excluded from this access right.

On timing: a covered entity ordinarily must act on a HIPAA access request within 30 calendar days. One extension of up to 30 additional calendar days is permitted when the entity gives you a written explanation within the original period and states the date by which it will act. These are outer limits, not recommended routine response times — many requests are fulfilled well before the 30-day mark, and a provider citing the full 30 days as though it were standard practice is not describing a legal requirement, just the maximum they're allowed to take.

On fees: for a copy provided directly to you, HIPAA generally permits only a reasonable, cost-based fee covering specified expenses such as labor for copying, requested electronic media, postage, and an agreed summary or explanation. Fees generally may not include searching for or retrieving the records, maintaining systems, verification, or general infrastructure expenses — if a quoted fee sounds like it's covering the organization's overhead rather than your specific copy, that's worth questioning directly.

On denials: when access is denied, HIPAA generally requires a written denial explaining the basis for the denial, any right to review, how to request review, and how to complain to the organization or the HHS Office for Civil Rights. Some grounds for denial are reviewable by another licensed health professional; others are not — the written denial should tell you which kind you're facing.

California Access Rights

California Health and Safety Code § 123110 provides a separate state-law access framework, and its timelines are more specific — and generally faster — than the federal HIPAA baseline.

Subject to statutory exceptions, an adult patient, an authorized minor patient, or a personal representative generally may inspect records during business hours within five working days after the provider receives the request, and obtain paper or electronic copies transmitted within 15 days after the provider receives a sufficiently specific request and any applicable fee.

When records are maintained electronically and you request an electronic copy, the provider must supply the requested electronic form and format when readily producible; otherwise, the provider and patient should agree on a readable electronic form and format. California now generally permits a reasonable, cost-based fee for paper or electronic copies, limited to specified copying labor, supplies, postage, and an agreed summary or explanation. Paper-copy charges may not exceed 25 cents per page, or 50 cents per page for records copied from microfilm. Special no-cost rules apply to certain records needed for specified public-benefit, immigration, or housing claims.

You also have a right to add your own statement to the record. Under Health and Safety Code § 123111, a patient who inspects the record under § 123110 may provide a written addendum concerning an item the patient believes is incomplete or incorrect. The addendum may contain up to 250 words for each disputed item, must clearly request inclusion in the record, must be attached to the record, and must accompany later disclosure of the disputed portion to a third party. This does not erase or replace the original clinical entry — it allows your own position to travel alongside the disputed information every time it's shared afterward. HIPAA separately provides its own right to request amendment under 45 C.F.R. § 164.526, which works differently and is worth asking about specifically if the California addendum route doesn't fit your situation.

Making a Request That Can Actually Be Processed

A written request generally produces a clearer record than an undocumented verbal conversation, and it's the difference between having proof of what you asked for and having only your memory of it. Use the provider's portal, designated records form, health information management process, or another method the organization accepts.

State your full identifying information; the records or categories requested; the date range; whether you want inspection or copies; the requested electronic or paper format; where the information should be sent; and whether the request is urgent for a scheduled clinical reason.

A useful initial request reads something like: “I am requesting access to and an electronic copy of the following records: [identify records and dates]. Please provide the records in [requested format] through [portal, secure email, download, supported app, or other method]. Please confirm the date received, the expected completion date, and any permitted cost before processing.”

For an app request specifically: “I am requesting access to my electronic health information through [name of app or service]. Please provide the steps required to connect the app through your supported patient API or another available electronic method. If the requested method cannot be used, please identify the reason and the alternative electronic methods available.”

And if you're facing a refusal or delay: “Please provide the specific reason for the denial or delay in writing. If the organization is relying on an information-blocking exception, HIPAA denial provision, or other law, please identify the applicable basis and any review or appeal process.”

One piece of advice worth taking seriously: avoid stating that the provider has “committed information blocking” before the facts have actually been evaluated. Asking for the precise basis is usually more useful than making a legal accusation — it gets you an answer faster, and it preserves your credibility if you do need to escalate later.

Helping a Family Member

A patient's records generally cannot be released to another person merely because that person is a spouse, adult child, sibling, caregiver, or emergency contact. Authority to access someone else's records has to come from somewhere specific: a valid patient authorization; status as a legally recognized personal representative; guardianship or conservatorship; parental authority; a health-care power of attorney; or another applicable state-law relationship.

The scope of that authority can vary in ways that surprise families. Parents do not always have unrestricted access to every part of an adolescent's record — federal and state laws may protect information relating to care the minor could consent to independently, and California law expressly limits parental or representative access in specified circumstances, particularly around reproductive, mental health, and substance-use care.

For an adult relative, the practical lesson is to obtain appropriate authorization or representative documentation before a crisis, whenever that's possible. Trying to establish authority in the middle of an emergency is far harder than setting it up in advance.

Complaints and Escalation

Before filing a formal complaint anywhere, it's worth trying internal escalation first: health information management; the medical-records department; the privacy officer; the compliance office; the patient-relations department; or the organization's information-blocking contact if it has one. Provide the original request, proof of submission, dates, responses received, what's still missing, and the resolution you're asking for — a specific, documented escalation often resolves things faster than any external complaint would.

For a suspected information-blocking practice specifically, you can submit a claim through the ASTP/ONC Information Blocking Portal. ASTP/ONC may review claims involving certified health IT, and the HHS Office of Inspector General has authority to investigate claims involving covered actors. OIG may impose civil monetary penalties of up to $1 million per violation against certified-health-IT developers, entities offering certified health IT, HIEs, and HINs; health care providers found to have committed information blocking may instead face program-specific federal disincentives rather than that same penalty structure. The Cures Act protects information received by ASTP/ONC that could identify the source from mandatory public disclosure under FOIA, subject to statutory provisions allowing use or disclosure when necessary to carry out the law — claims can also be submitted anonymously, though anonymity may limit follow-up and investigation, and this protection should not be treated as an absolute guarantee that identifying information can never be used during an investigation.

For a possible HIPAA access violation specifically, a complaint may be filed with the HHS Office for Civil Rights. OCR generally requires complaints to be submitted in writing, filed within 180 days of when you knew of the issue (subject to possible extension for good cause), and directed against a HIPAA covered entity or business associate.

For California providers, the appropriate complaint path depends on the organization and professional involved — it may include the Medical Board of California, the Dental Board of California, the Board of Registered Nursing, the California Department of Public Health, another professional licensing board, or a court remedy authorized by state law. A dispute involving a health plan, coverage determination, or plan conduct is a different matter from a provider-records request — depending on the plan, the appropriate regulator may instead be the California Department of Managed Health Care or the California Department of Insurance.

Closed Practices and Unavailable Records

A closed office does not automatically mean your records may be abandoned. California Health and Safety Code § 123145 requires specified licensed health-service providers that cease operations to preserve records for minimum periods, and treats leaving patients without access to records as abandonment. The exact retention rule and responsible custodian depend on the provider type, profession, facility, and other applicable regulations.

If you're trying to track down records from a closed practice, possible sources include the former practice's recorded message or website; the physician's or professional's licensing board; a successor practice; the hospital where the professional practiced; the malpractice insurer; a records-storage company; or the state agency that licensed the facility. One caution worth stating plainly: do not send sensitive identifying information to an unverified third party claiming to hold the records — verify who you're actually dealing with, through an independent channel like the licensing board's own public directory, before sharing anything as sensitive as a full medical history or identifying documents.

Keeping Your Own Useful Record

A personal record can reduce how much you depend on rapid transfer between organizations when it matters most. Consider securely retaining a current medication list with doses; allergies and reaction descriptions; major diagnoses; vaccination records; significant laboratory results; imaging reports; operative and procedure reports; pathology reports; specialist consultations; hospital discharge summaries; advance directives; and contact information for treating clinicians.

Store the information securely and keep a backup somewhere separate from the original. A concise medical summary like this is genuinely helpful in urgent care, but it's a supplement to the complete medical record, not a replacement for it — an emergency team will still want the full record from your actual providers when it's available.

When You Believe the Record Itself Is Wrong

Everything so far in this guide concerns access to a record — getting it, and getting it in a usable form. A separate, equally common problem is believing the record itself contains an error: a wrong medication, a misattributed diagnosis, a note that describes a visit inaccurately, or a result attached to the wrong date.

The correction mechanism is not information blocking, and it's not the same right as the access right described above — confusing the two leads to a request that asks the wrong question of the wrong office. Under California Health and Safety Code § 123111, once you've inspected your record under § 123110, you can submit a written addendum concerning any item you believe is incomplete or incorrect. As described earlier, that addendum can run up to 250 words per disputed item, must clearly request inclusion in the record, must be physically or electronically attached to the record, and must travel with the record every time the disputed portion is later disclosed to a third party. HIPAA's own amendment right under 45 C.F.R. § 164.526 works on a related but separate track, and a covered entity can grant, partially grant, or deny an amendment request — a denial itself must be explained in writing and generally includes your right to have a statement of disagreement included alongside the denial.

Neither mechanism erases the original entry. That surprises people who expect a correction request to function like fixing a typo, but the reasoning behind it is sound: the original entry reflects what a clinician actually observed, thought, or was told at the time, and preserving that — while adding your own account alongside it — protects the integrity of the clinical record as a historical document, not just a currently-accurate one. If the entry is a genuine factual error rather than a difference of interpretation — the wrong side of the body, a transposed date, a mismatched patient identifier — many practices will correct it outright rather than merely appending a statement, so it's worth first asking directly whether the office considers it a correctable factual error or a matter for the addendum process instead. Either way, put the request in writing and identify the specific entry, the specific error, and the specific correction or addition you're asking for — broad complaints about a note being 'inaccurate' without identifying what, specifically, is wrong are much harder for an office to act on.

A Note on the Rules Still Changing Underneath This Guide

Information-blocking regulation is not a settled, finished body of law — it has been amended multiple times since the original 2020 rule, and a further proposed rule (referred to in ASTP/ONC materials as HTI-5) was pending as of this guide's writing, with deregulatory changes to certification and information-blocking requirements under active consideration. As of this writing, that rule remains proposed rather than final, and nothing in it currently changes the obligations described throughout this guide — but it is a reminder that the specific mechanics here, more than most consumer-facing rules, are genuinely still moving.

That has a practical consequence worth naming directly: a specific dollar figure, a specific exception's exact conditions, or a specific timeline cited in this guide should be treated as accurate as of the date at the top of this article, not as a permanent fact. If a specific number matters to a decision you're making — a fee you're being charged, a penalty you're citing to an organization, a deadline you're relying on — confirming it against the current ASTP/ONC or HHS page cited in the sources below costs a few minutes and protects you against relying on a figure that has since been updated.

This is also why the most durable piece of advice in this entire guide is the one that doesn't depend on any specific number: ask for the reason in writing, and ask which specific rule or exception is being invoked. That question works the same way whether the applicable dollar figure is this year's or next year's.

A Worked Example: The Denied App Connection

It helps to see how the actual analysis runs in a specific case, rather than only in the abstract. Say a patient asks their clinic to connect a third-party medication-tracking app to their patient portal, and the clinic declines, citing “security concerns.” Is that information blocking?

The first question is whether the clinic is a covered actor — almost certainly yes, if it's a health care provider using certified health IT. The second is whether the app is requesting electronic health information as defined earlier in this guide — likely yes, if it's pulling medication and problem-list data through the clinic's patient-facing API. The third is whether declining the connection is likely to interfere with access, exchange, or use — on its face, yes, since the app cannot function without the connection.

The fourth question is where the analysis usually actually turns: does “security concerns” meet the Security Exception's actual conditions, or is it a generalized discomfort dressed up in the exception's language? The Security Exception requires the practice to be directly related to safeguarding EHI's confidentiality, integrity, and availability, implemented in a consistent and non-discriminatory manner, and tailored to the specific security risk being addressed — not simply invoked because the app is unfamiliar. A clinic that can point to a specific, documented risk (the app requests more data scopes than it needs, say, or has a known vulnerability) has a real basis. A clinic that simply prefers established, in-house-vetted apps and treats every new one with generic suspicion is much closer to the kind of blanket policy ASTP/ONC has specifically flagged as not qualifying for the exception.

Notice what the analysis does not turn on: whether the patient finds the refusal frustrating, whether the app is popular, or whether the clinic simply doesn't want to deal with it. It turns on whether a specific, applicable exception's specific conditions are actually met. That is the same four-question structure worth running through mentally any time a request is refused — covered actor, EHI, interference, and then the specific exception actually invoked — rather than accepting or rejecting the refusal on the strength of the word used to justify it.

What the Rules Do Not Guarantee

It's worth being honest about the limits here, because overstating what these rules promise sets people up for a frustrating surprise. Information-blocking and access laws do not guarantee that every medical record will be easy for a patient to interpret; that every requested format is technically supported; that every app will be secure or HIPAA covered; that every disagreement will result in alteration of the original record; that all your providers' records will automatically merge into one complete file; that a complaint will produce a particular enforcement outcome; or that every delay is unlawful.

What they do establish are real, specific rights and expectations concerning access, exchange, format, timing, fees, explanations, and complaint processes — rights that are genuinely more substantial than most patients realize, provided they're understood with the qualifications that actually apply. The most productive question to keep coming back to, in almost every situation this guide describes, is a simple one: what is the specific reason the information has not been provided, and can you give me that reason in writing? That single question, asked consistently and specifically, resolves more requests than any citation to a specific regulation ever will — because it forces the person on the other end of the request to actually locate a real basis, rather than reach for a vague, general-purpose “no.”

Patient Checklist

Make the request in writing, not just verbally.

Identify the records and date range specifically.

Request the form and format you actually need.

State clearly where the information should be sent.

Keep proof of submission.

Ask for the expected completion date up front.

Ask about cost before processing begins.

Request a written explanation for any denial or delay.

Ask specifically whether an alternative electronic method is available if your first request can't be fulfilled.

Escalate internally to records, privacy, compliance, or patient relations before filing an external complaint.

Use the ASTP/ONC Information Blocking Portal for suspected electronic-information interference specifically.

Use HHS OCR for a possible HIPAA access violation specifically.

Use the appropriate California regulator for state-law issues (Medical Board, DMHC, or CDI depending on who's involved).

Review an app's privacy practices before transferring your data to it.

Keep a secure personal copy of your important records.

The One Question Worth Asking Every Time

Across every scenario in this guide — a delayed result, a rejected app, a denied copy, a closed practice — one question does more work than any legal citation: what is the specific reason the information has not been provided, and can you get that reason in writing?

A specific, written reason does three things at once. It tells you whether the organization is relying on a real exception or just discomfort with the request. It creates a record you can escalate with, if escalation becomes necessary. And it very often resolves the request on its own, because an organization asked to put its reasoning in writing frequently discovers there isn't a good one — or finds the accommodation it should have offered from the start.

General educational information—not legal or medical advice

This guide provides general educational information. It is not medical advice, legal advice, or a determination that a particular organization has violated federal or state law. Information-blocking analysis is fact-specific, and HIPAA and California access rights contain exceptions and procedural requirements this guide summarizes but does not exhaustively cover. Patients with significant disputes should consider contacting the appropriate regulator listed above or obtaining individualized legal advice.

Questions Worth Asking Your Provider

What is the specific reason my request hasn't been fulfilled, and can I get that in writing?

If you're citing an information-blocking exception, which one, and what condition of it applies to my situation?

What is the expected completion date, and what would I be charged?

If my preferred app or format doesn't work, what alternative electronic method is available?

Who do I contact internally if this isn't resolved — privacy officer, compliance, or patient relations?

If I need to file an external complaint, is this an information-blocking issue, a HIPAA issue, or a California state-law issue?

Takeaway

Three separate legal frameworks govern your access to your own health information, and knowing which one applies to a given request — information blocking, HIPAA, or California’s own statute — changes both what you can expect and where you complain if it fails. Federal information-blocking rules mean your electronic health information generally should move when you ask — but “generally” is the operative word, and every real case depends on the specific actor, the specific information, the specific knowledge standard, and whether a real exception applies. HIPAA and California law separately guarantee access on their own timelines (30 days, extendable, for HIPAA; five working days for inspection and 15 days for copies under California law), regardless of whether information blocking is even in play. Consumer apps often fall outside all of this once you direct your data to them, though the FTC's rules may still reach them. The single most useful move in almost every scenario is the same: ask for the specific reason, in writing, before assuming either that you have no rights or that any delay is automatically unlawful. Keep the specific question — what is the reason, in writing — as your default response to any refusal, regardless of which of the three frameworks turns out to apply. That habit alone resolves more requests than any citation, in almost every setting this guide has walked through.

Sources and Authorities

The sources below are provided so readers can confirm the governing text and current agency guidance. Laws, regulations, agency pages, and implementation dates can change; time-sensitive requirements should be checked against the current official source.

CMS — Interoperability and Prior Authorization Final Rule CMS-0057-F — cms.gov

CMS — Interoperability Policies and Regulations — cms.gov

ASTP/ONC — Information Blocking — healthit.gov

45 C.F.R. Part 171 — ecfr.gov

HHS OCR — Right of Access — hhs.gov

www.healthit.gov — healthit.gov

www.healthit.gov — healthit.gov

www.healthit.gov — healthit.gov

www.federalregister.gov — federalregister.gov

www.hhs.gov — hhs.gov

www.hhs.gov — hhs.gov

www.ecfr.gov — ecfr.gov

www.ecfr.gov — ecfr.gov

www.hhs.gov — hhs.gov

leginfo.legislature.ca.gov — leginfo.legislature.ca.gov

leginfo.legislature.ca.gov — leginfo.legislature.ca.gov

leginfo.legislature.ca.gov — leginfo.legislature.ca.gov

leginfo.legislature.ca.gov — leginfo.legislature.ca.gov

www.ftc.gov — ftc.gov

www.dmhc.ca.gov — dmhc.ca.gov

www.insurance.ca.gov — insurance.ca.gov

Related Articles

Educational information notice: this article provides general educational information for physicians, medical staff, and policy audiences and is not legal or medical advice. It does not create an attorney-client or physician-patient relationship.

Approved for publication by Kanwar Partap Singh Gill, MD · Published August 6, 2026

You may be interested in

Pages that share this one’s legal or clinical territory, and a few that approach it from somewhere else entirely.

Or start from the whole collection: policy and regulation, patient education, what changed this week, or ask the library a question.