Diagram showing electronic health information moving from a practice EHR to an authorised third-party application under the 21st Century Cures Act

21st Century Cures Act: Information Blocking and EHR API Fees

Bernard Mallala
Bernard Mallala
Founder & CTO, Hello

The rule stops vendors refusing access. It does not make the API free. Here is what a practice should budget and ask for in writing.

The short answer

The 21st Century Cures Act Final Rule requires that your electronic health information can be accessed, exchanged, and used without unreasonable interference. It does not make EHR and PMS vendor API access free. Vendors may charge a fee that recovers their reasonable costs, and in practice most price API access per provider or per practice rather than publishing a flat rate. Budget for that fee as part of any integration project.

If you are connecting an AI voice agent, a patient engagement tool, or a reporting platform to your practice management system, you will meet the Cures Act twice. First as leverage, because your vendor cannot simply refuse. Second as an invoice, because the same rule that prohibits blocking also permits recovering costs.

The 21st Century Cures Act Final Rule is the federal regulation that prohibits information blocking: practices likely to interfere with the access, exchange, or use of electronic health information. It was issued by the Office of the National Coordinator for Health Information Technology, now the Assistant Secretary for Technology Policy, and applies to health care providers, health IT developers of certified health IT, and health information networks and exchanges.

This guide is written for three audiences at once, because in most practices these are two or three people rather than a department. It is for practice owners and administrators deciding whether to approve an integration budget, for patients who want to know what they are entitled to, and for anyone on a sales or marketing team who has to answer "will my EHR vendor let you connect, and what will it cost?" without overpromising.

What does the 21st Century Cures Act actually require?

The Act was signed in December 2016. The Final Rule implementing its information blocking provisions was published in May 2020, with initial compliance from 5 April 2021 and the full scope of electronic health information applying from 6 October 2022.

Two obligations matter to a practice:

  • Patients get their records without unreasonable friction. Patients have a right of access to their electronic health information, including clinical notes and test results, in the form and format they request where it is readily producible, and without a fee for electronic access to records held in a certified system.
  • Data has to be able to move. Certified health IT must support standards-based application programming interfaces so that authorised third-party software can read and write data. A vendor cannot use the absence of an interface as a reason to keep you locked in.

What counts as information blocking?

Information blocking is a practice that is likely to interfere with the access, exchange, or use of electronic health information. For a health IT developer the standard is whether the actor knows or should know the practice is likely to interfere. For a health care provider the standard is knowledge that the practice is unreasonable.

Concrete examples that have drawn scrutiny:

  • Refusing to enable a standards-based API for a patient-authorised application.
  • Contract terms that forbid a practice from connecting approved third-party software.
  • Delays in provisioning access that have no technical justification.
  • Fees set so high, or structured so opaquely, that they function as a barrier rather than a cost recovery.

Does the Cures Act make EHR API access free?

No, and this is the most common misreading. The rule contains eight exceptions that describe conduct which is not information blocking. Two of them govern money and effort directly.

ExceptionWhat it permitsWhy it matters to your budget
FeesRecovering reasonable costs of providing access, exchange, or use of electronic health information.This is the basis on which vendors charge for API access. The fee must be based on objective, uniformly applied criteria, not on who is asking.
LicensingCharging a royalty for interoperability elements the vendor owns.Explains licence terms attached to developer programmes.
InfeasibilityDeclining a request that cannot reasonably be met.Sometimes legitimate, sometimes the label put on an unwillingness to build.
Preventing HarmWithholding data to prevent physical harm.Narrow and clinically grounded.
PrivacyDeclining where a privacy law or the patient's own choice requires it.Applies when consent is absent.
SecurityDeclining for genuine, consistently applied security reasons.Must be tailored, not a blanket refusal.
Content and MannerFulfilling a request in an alternative manner.Governs the format you receive.
Health IT PerformanceTaking a system offline for maintenance.Covers planned downtime.

The Fees exception is the one that shows up on your invoice. The rule permits a vendor to recover reasonable costs. It does not oblige a vendor to publish a price list, and it does not cap what "reasonable" means in any practical, pre-approved way.

How do EHR and PMS vendors actually price API access?

Pricing varies by vendor and, frequently, by customer. Across integration projects with systems including Nextech, PatientNow, ModMed, DrChrono, Dentrix, Eaglesoft, and Open Dental, the patterns fall into three groups:

ModelWhat it looks likeWhat to ask for
Custom, per providerA quote scoped to your practice, often scaling with the number of providers or locations. The most common pattern.A written quote that states whether the fee is one-time, annual, or per provider, and what happens when you add a provider.
Published developer programme ratesA standard fee to join a partner or developer programme, sometimes with tiers for additional endpoints.Which endpoints your integration needs, and whether they sit in the tier you are quoted.
BundledAPI access included in an existing contract or module you already pay for.Written confirmation that your current agreement covers the endpoints required.

Two practical notes. Fees are frequently quoted per provider rather than per practice, so a four-provider group can pay four times what a solo practice pays for the same interface. And the endpoints you need for scheduling, eligibility, and write-back are not always in the same tier, so a quote for "API access" can turn out to cover reads only.

Who pays the vendor's API fee?

The practice does. The fee is charged by your EHR or PMS vendor under a contract you hold with them, so it is your operating cost rather than something an integration partner absorbs. Treat it the way you treat a merchant processing rate: a pass-through cost of doing business electronically.

What a good integration partner should do is make the cost visible before you commit, help you scope the smallest set of endpoints that meets the requirement, and put the vendor's answer in writing. At Hello, integration engineering is part of every implementation: we request the vendor's API documentation, validate every operation against your live account before production, and deliver the validated field map as part of your written acceptance criteria. See how Hello connects to practice systems for the current directory.

How do you use the Cures Act when a vendor stalls?

Most vendors are cooperative. When one is not, the rule changes the conversation from a favour you are asking to an obligation they are managing. A workable sequence:

  • Put the request in writing and name the specific capability: standards-based API access for a patient-authorised or practice-authorised application, and the endpoints required.
  • Ask which exception applies if the answer is no. A vendor declining a request is expected to be able to say whether it relies on Fees, Licensing, Infeasibility, Security, or another exception.
  • Ask for the fee basis if the answer is a price. Under the Fees exception the charge should rest on objective and uniformly applied criteria, so it is reasonable to ask how the figure was derived.
  • Keep the correspondence. Complaints about information blocking can be submitted through the ASTP/ONC Information Blocking Portal, and enforcement for developers and networks sits with the Office of Inspector General.

Civil money penalties apply to health IT developers, networks, and exchanges. Health care providers are subject to appropriate disincentives set by the Department of Health and Human Services rather than the same penalty scheme.

What does this mean for patients?

If you are a patient, the rule is why you can pull your records into an app on your phone rather than waiting on a fax. You are entitled to electronic access to your health information, including clinical notes and test results, without a fee for electronic access, and in the format you asked for where the practice can readily produce it. If a practice or a portal makes that unreasonably difficult, that is what the information blocking rule exists to address.

Practices sometimes worry that faster access means more anxious phone calls about results. In our experience the opposite pressure is the real one: patients call because they cannot get an answer. Covering those calls reliably is an access problem before it is a technology problem, which is the subject of the callback trap in medical practices.

Cures Act compliance versus HIPAA compliance

HIPAA21st Century Cures Act
Core questionIs the data protected?Can the data move?
Primary obligationSafeguard protected health informationDo not interfere with access, exchange, or use
Typical failureA breach or an unsigned Business Associate AgreementA refusal, a delay, or a prohibitive fee
Applies toCovered entities and business associatesProviders, certified health IT developers, networks and exchanges

The two are complementary, not alternatives. An integration has to move data and protect it, which is why any vendor connecting to your systems should sign a Business Associate Agreement before touching protected health information. For the questions worth asking a vendor on the security side, see what to look for in a HIPAA-compliant AI answering service.

A practical checklist before you sign an integration

  • Ask your EHR or PMS vendor, in writing, what API access costs and whether the fee is one-time, annual, or per provider.
  • List the endpoints the integration needs, including write-back, and confirm they are inside the tier quoted.
  • Confirm who owns the developer account and what happens to it if you change partners.
  • Require validation against your live account before production, with the field map delivered in writing.
  • Confirm a Business Associate Agreement is signed before any protected health information is processed.
  • Budget the vendor fee as an operating cost alongside the integration work itself.

If you are scoping this now, the Hello pricing page shows what the work itself costs, and an AI implementation audit maps your systems and the access you will need before anything is committed.

Frequently asked questions

Does the 21st Century Cures Act require my EHR vendor to give me free API access?

No. The rule prohibits information blocking, but the Fees exception permits a vendor to recover reasonable costs of providing access, and the Licensing exception permits royalties on interoperability elements the vendor owns. Expect a fee, and expect it to be quoted per provider or per practice rather than published as a flat rate.

Who pays for EHR API access, the practice or the software vendor connecting to it?

The practice. The fee sits under your contract with your EHR or PMS vendor, so it is your operating cost. A good integration partner makes the cost visible before you commit and helps you scope the smallest set of endpoints that meets the requirement.

What are the eight information blocking exceptions?

Preventing Harm, Privacy, Security, Infeasibility, Health IT Performance, Content and Manner, Fees, and Licensing. The first five describe when withholding data is not blocking. The last three govern how a request is fulfilled and what may be charged.

What happens if a vendor refuses to enable an integration?

Ask which exception the refusal relies on and request the answer in writing. Complaints can be submitted through the ASTP/ONC Information Blocking Portal. Civil money penalties apply to health IT developers, networks, and exchanges, while providers face disincentives set by the Department of Health and Human Services.

Do patients pay to get their records electronically?

No fee applies to a patient's electronic access to their own health information held in a certified system. Patients are entitled to their electronic health information, including clinical notes and test results, in the form and format requested where it is readily producible.

The Cures Act does not remove the cost of connecting your systems. It removes the excuse for refusing to. Price the fee, get the answer in writing, and treat interoperability as a line item rather than a favour.

cures act interoperability compliance ehr integration
Bernard Mallala
Bernard Mallala
Founder & CTO, Hello

Bernard Mallala is the Founder and CTO of Hello, a HIPAA AI voice infrastructure for high-growth medical practices. He writes about patient access infrastructure, revenue capture, and front desk automation under real call volume.