Information blocking rules and data trust: what the ONC final rule means for AI
Photo by Hanseul Kim on Unsplash
insight

Information blocking rules and data trust: what the ONC final rule means for AI

By Jason Alan Snyder·April 28, 2026

The ONC information blocking final rule forces health data to flow. But flowing data is not trustworthy data. Without a trust layer that scores provenance, consent, and quality before AI models consume health records, interoperability becomes a pipeline for unreliable inference.

The ONC information blocking final rule went into full effect on October 6, 2022. Since that date, every actor in healthcare IT that touches electronic health information (EHI) has been prohibited from practices that restrict the access, exchange, or use of that data. The stated goal is simple: make health data flow. The unstated consequence is more complicated. Data that flows freely is not data that flows safely, and it is certainly not data that an AI model should consume without verification.

What is the final rule of information blocking?

The 21st Century Cures Act directed the Office of the National Coordinator for Health IT (ONC) to define information blocking and establish rules against it. The ONC Final Rule, published in 2020 and phased in through 2022, does exactly that. It identifies three categories of actors subject to the rule: health IT developers of certified technology, health information networks and exchanges, and healthcare providers. Any practice by these actors that is likely to interfere with access, exchange, or use of EHI qualifies as information blocking unless it falls under one of eight recognized exceptions.

Those exceptions cover areas like preventing harm, protecting privacy, managing security, and addressing infeasibility. But the core mandate is clear. If you hold health data electronically, you cannot sit on it.

What is the purpose of the information blocking rule?

The rule exists because data silos kill patients. Fragmented records lead to duplicated tests, missed diagnoses, medication errors, and delayed care. ONC estimated that information blocking costs the U.S. healthcare system over $30 billion annually in redundant procedures alone. The Cures Act and the ONC Final Rule aim to dismantle the technical and contractual barriers that keep EHI locked inside proprietary systems.

For patients, this means faster access to their own records. For providers, it means fewer fax machines and more API calls. For AI developers, it means a dramatically larger supply of training data. That last point is where the trust problem begins.

What are the consequences of information blocking?

For health IT developers and health information networks, the consequences are financial. The HHS Office of Inspector General (OIG) can impose civil monetary penalties of up to $1 million per violation. For healthcare providers, enforcement is handled through existing mechanisms like conditions of participation and certification requirements. The OIG published its final enforcement rule in July 2023, making these penalties real rather than theoretical.

But there is a second set of consequences that the rule does not address. When data flows without trust scoring, AI models ingest records with unknown provenance, expired consent, poor concordance, and inconsistent quality. The cost of that failure shows up downstream: biased predictions, unreliable clinical decision support, and regulatory exposure that no information blocking exception can fix.

What rule helps avoid harm from AI?

The ONC's HTI-1 Final Rule, finalized in December 2023, represents the first federal attempt to regulate AI in health IT. It requires developers of certified health IT to provide transparency around predictive decision support interventions (DSIs). This includes disclosing the data used to train, test, and validate AI models, along with performance metrics and known limitations.

HTI-1 is a transparency rule, not a data quality rule. It tells you what data went into the model. It does not tell you whether that data was trustworthy. A model trained on EHR records with lapsed consent, outdated demographics, or unverified lab results can pass every HTI-1 disclosure requirement and still produce harmful outputs. As we have written before, explainability solves the wrong problem when the training data was never verified.

The gap between interoperability and trust

ONC interoperability rules, TEFCA, and the information blocking provisions all share a common assumption: that making data accessible is the primary barrier to better care and better AI. Accessibility is necessary. It is not sufficient.

Consider what happens when a health system receives EHI through a TEFCA-compliant exchange and feeds it into a predictive model for sepsis risk. The record arrives. It conforms to USCDI standards. It is not blocked. But was the patient's consent captured for secondary use? Is the record current, or was it last updated 18 months ago? Does the diagnosis code match the clinical notes? These are trust questions, not interoperability questions. TEFCA does not answer them. The information blocking rule does not answer them. HTI-1 does not answer them. For a deeper look at what TEFCA does and does not solve, see TEFCA and the interoperability imperative.

MedPageToday reported in August 2023 on a proposed rule that would let patients hide parts of their medical record with a provider's permission. That proposal highlights a tension the information blocking framework has not resolved: the right to data access and the right to data control are not the same thing, and AI systems downstream need to know which rights were exercised on which records.

Key statistics

DTI dimension weights: where information blocking exposure hits hardest
DTI dimension weights: where information blocking exposure hits hardest

  • The ONC information blocking rule applies to all electronic health information as of October 6, 2022, not just the USCDI subset.
  • Civil monetary penalties for information blocking violations can reach $1 million per violation under the OIG enforcement rule.
  • ONC estimates information blocking costs the healthcare system over $30 billion per year in redundant care.
  • SuperTruth's DTI Engine scores records across 8 dimensions, with Provenance weighted at 25% and Consent at 20%, the two dimensions most directly affected by information blocking and its exceptions.
  • In the imaware deployment, SuperTruth standardized 105,000 diagnostic records and reduced data preparation time from 3 weeks to 2 hours, a 95% reduction.
  • Why data trust scoring is the missing layer

    Data preparation time: before and after DTI scoring (imaware)
    Data preparation time: before and after DTI scoring (imaware)

    The information blocking rule created the pipe. TEFCA standardized the connections. HTI-1 added transparency labels. None of them score the data itself.

    The Data Trust Index (DTI) fills that gap. Every health record that enters an AI pipeline should carry a score from 0 to 100 across eight dimensions: Provenance, Consent, Recency, Quality, Concordance, Validation, Breadth, and Stability. A record that arrives through a TEFCA exchange with full USCDI compliance but expired consent and a 14-month-old problem list should not receive the same treatment as a record verified last week with active consent and concordant clinical notes.

    Without this layer, the information blocking rule achieves its goal of making data flow while creating a new problem: AI models that train on data no one has verified. As we detailed in our research published at Zenodo, the Data Trust Index provides the first formal framework for scoring health data integrity before it reaches a model.

    The question is no longer whether health data will be shared. The ONC settled that. The question is whether anyone will verify that shared data before an algorithm acts on it.

    The DTI Engine scores every health data record 0 to 100 across 8 trust dimensions before your AI model sees it. If your team is evaluating EHI for training, compliance, or clinical use under the new information blocking and HTI-1 frameworks, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.

    Further reading:

  • DTI™ Engine
  • Health systems solution
  • Why EHR data needs a trust score before any AI model trains on it
  • What HIPAA does not tell you about data trust
  • Siloed health data: the infrastructure problem nobody has solved yet
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    DTI scores the record, not the patient.

    8 dimensions. 0–100. Travels with every record permanently.

    See the DTI Engine
    Share