Consumer health data ownership: what the 21st Century Cures Act actually enables
Photo by 2H Media on Unsplash
insight

Consumer health data ownership: what the 21st Century Cures Act actually enables

By Jason Alan Snyder·May 6, 2026

The 21st Century Cures Act gave patients a legal right to access their electronic health data through standardized APIs. But access is not ownership. Without trust scoring, provenance tracking, and consent governance, the data patients receive is often incomplete, outdated, or unusable for the AI systems that need it most.

The 21st Century Cures Act, signed into law in December 2016, did something no previous health legislation had done. It made information blocking illegal and required that patients be able to access their electronic health information through standardized, API-based interfaces. That was a structural shift. But seven years into implementation, the gap between what the law enables and what patients actually experience remains enormous.

What does the 21st Century Cures Act actually provide?

The Cures Act is a sprawling piece of legislation covering drug development, medical device innovation, mental health funding, and health IT interoperability. For patient health data ownership, the critical provisions fall in Title IV, which directs the Office of the National Coordinator for Health IT (ONC) to establish rules around electronic health information (EHI) access.

The law requires that certified health IT systems support standardized APIs, specifically FHIR (Fast Healthcare Interoperability Resources), so patients and their authorized apps can pull clinical data from EHR systems. It also defines and prohibits information blocking: practices by healthcare providers, health IT developers, or health information networks that interfere with the access, exchange, or use of EHI.

The ONC Final Rule, published in 2020, operationalized these provisions. Since October 6, 2022, the information blocking provisions apply to all EHI, not just the limited United States Core Data for Interoperability (USCDI) dataset.

The three major pillars of the Cures Act

The legislation stands on three pillars. First, accelerated drug and device development through streamlined FDA pathways, including the Regenerative Medicine Advanced Therapy (RMAT) designation and expanded use of real-world evidence. Second, expanded funding for biomedical research, including $4.8 billion for the National Institutes of Health, with specific allocations to the BRAIN Initiative, the Precision Medicine Initiative, and the Cancer Moonshot. Third, health IT interoperability and patient data access, which is where FHIR patient data access requirements and information blocking prohibitions live.

Most coverage of the Cures Act focuses on the first two pillars. The third pillar is the one that directly affects every patient, every provider, and every AI system that touches health data.

What the Cures Act does not do

The Cures Act gives patients access. It does not give them ownership in any property-law sense. Patients can request their records, connect third-party apps to their provider's patient portal, and receive clinical notes, lab results, and medication lists via FHIR APIs. But the data they receive has no trust score. No provenance chain. No quality attestation.

A patient who downloads their records through a FHIR-enabled app gets a snapshot. That snapshot may be incomplete if they have seen providers across multiple health systems. It may be outdated if a lab result was amended after the initial release. It may lack context about how data was collected, who entered it, or whether it has been validated against external sources.

This is the difference between access and usable data. The Cures Act solved the access problem. It did not solve the trust problem. As we have written previously, HIPAA does not tell you about data trust, and the Cures Act does not either.

Key statistics

imaware diagnostic record processing: before and after DTI
imaware diagnostic record processing: before and after DTI

The numbers make the gap visible:

  • The ONC reported that as of 2023, over 80% of hospitals had adopted certified EHR technology capable of FHIR-based data exchange.
  • HHS has received over 400 complaints related to information blocking since the enforcement provisions took effect, but zero civil monetary penalties have been issued as of early 2025.
  • A 2023 ONC survey found that only 40% of individuals who accessed their health records online reported using a third-party app to do so.
  • SuperTruth's work with imaware standardized 105,000 diagnostic records, reducing processing time from 3 weeks to 2 hours, a 95% time reduction, and saved 200+ hours per month.
  • The DTI Engine scores every record across 8 trust dimensions. In practice, records that arrive via FHIR APIs frequently score below 50 on provenance and consent dimensions before remediation.
  • What are the criticisms of the Cures Act?

    The most common criticism is enforcement. Information blocking is illegal, but consequences have been minimal. The HHS Office of Inspector General can impose civil monetary penalties up to $1 million per violation against health IT developers and health information networks, but enforcement against providers is handled through "appropriate disincentives" that CMS has been slow to define.

    A second criticism: the law accelerated FDA approval pathways without proportionally strengthening post-market surveillance. A 2018 MedPage Today opinion piece noted that pharmaceutical companies increasingly concentrate on cancer and rare diseases partly because faster approval timelines and smaller trial populations reduce development risk. The Cures Act's expanded use of real-world evidence for regulatory decisions demands that the underlying data be trustworthy, and the law itself does not establish standards for data trust.

    Third, privacy gaps. The Cures Act encourages patients to share data with third-party apps, but those apps are often not covered by HIPAA. Once data leaves the clinical system through a FHIR API and lands in a consumer app, the patient's data may be subject to far weaker protections. This creates a consent problem that the law acknowledges but does not resolve. SuperTruth built ConsentOS specifically because five-tier consent governance is necessary when data moves across these boundaries.

    The 21st Century Cures Act for dummies

    The simplest explanation: Congress passed a law that says hospitals and health IT vendors cannot block you from getting your own health records electronically. They have to use standard data formats (FHIR) so apps can read the data. And anyone who deliberately makes it harder for you to access or share your data can face penalties.

    That is the floor. It is a necessary floor. But a floor is not a finished building.

    What the Cures Act authorizes regarding electronic health information

    The law authorizes patients to access all EHI maintained in certified health IT systems, with limited exceptions for safety, privacy, and feasibility. It authorizes ONC to establish the Trusted Exchange Framework and Common Agreement (TEFCA), which creates a national governance structure for health information exchange. And it authorizes the use of patient-generated data and real-world evidence in regulatory decision-making.

    Each of these authorizations depends on data quality that the law itself does not measure. TEFCA sets rules for exchange; it does not score the trustworthiness of what gets exchanged. Real-world evidence submissions to the FDA require provenance that most health systems cannot currently produce. As we have covered, the information blocking rules create new requirements for data trust that most organizations are still catching up to.

    From access to trust

    DTI trust dimensions and their scoring weights
    DTI trust dimensions and their scoring weights

    The Cures Act created the legal right. FHIR created the technical standard. What is still missing is the trust layer: a way to score every record for provenance, consent status, recency, quality, concordance, validation, breadth, and stability before that record enters an AI training pipeline, a clinical decision, or a research dataset.

    Patient health data ownership means little if the data a patient accesses cannot be verified, scored, and governed. The SuperTruth Data Trust Index exists because access without trust is access without value.

    The DTI Engine scores every health data record 0 to 100 across 8 trust dimensions before your AI model sees it. If your team is evaluating data for training, compliance, or clinical use, and needs to operationalize what the Cures Act makes possible, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.

    Further reading:

  • DTI™ Engine
  • Health systems solution
  • Information blocking rules and data trust: what the ONC final rule means for AI
  • TEFCA and the interoperability imperative: what health systems need to prepare
  • ConsentOS: what five-tier consent architecture looks like in practice
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    DTI scores the record, not the patient.

    8 dimensions. 0–100. Travels with every record permanently.

    See the DTI Engine
    Share