Common signs include charging excessive fees for copies of records, restricting patients from accessing their own information, and relying on weak or inconsistent technology for data transfer. If patients cannot move records between providers smoothly, or if portals and exchange workflows lack clear security review, the organisation is likely creating practical barriers that undermine interoperability and patient access.
What poor information-blocking management looks like in practice
Poor management usually shows up as friction, inconsistency, and avoidable delay. If patients, clinicians, or partner organisations face repeat requests, unclear approval paths, inconsistent release rules, or technology that cannot reliably move records between systems, the organisation is not treating access as a governed process. The practical effect is that lawful sharing becomes harder than it should be.
A second sign is that policy and operations do not line up. Teams may say access is available while front-line staff still refuse, stall, or over-escalate routine requests. That gap often points to weak ownership, poor staff training, or tools that were never designed to support exchange at scale. When those conditions persist, information blocking becomes a workflow problem, not just a compliance issue.
Finally, poor management is visible when security review is treated as a blanket excuse rather than a bounded control. Good practice is to review the security of portals, interfaces, and exchange workflows without creating unnecessary barriers. ISO/IEC 27001:2022 Information Security Management provides the kind of control discipline that should prevent security from becoming an all-purpose reason to deny access.
Where the operational failures usually appear
The most common failure points are records release, patient access portals, and provider-to-provider exchange. Excessive fees, long turnaround times, poor status tracking, and repeated manual interventions suggest the organisation is optimising for internal convenience rather than interoperability. The same is true when different departments apply different rules to the same request type.
Weak technology is another signal. If data transfer depends on unstable interfaces, inconsistent interface ownership, or one-off workarounds, the organisation will struggle to support reliable movement of records. That does not just affect IT quality, it affects the usability of the entire exchange process. ISO/IEC 27002:2022 Information Security Controls is useful here because it links secure implementation discipline to operational control, including how access and technology choices are managed.
Another clue is poor visibility. If the organisation cannot explain who approves release, how exceptions are tracked, or why a request was denied, then it cannot prove that barriers are legitimate. That lack of traceability usually leads to repeat disputes, more manual handling, and greater risk that staff will apply rules unevenly.
How to tell the difference between legitimate protection and blocking
Not every refusal or delay is information blocking. Some limits are appropriate when they are specific, documented, and proportionate. The key test is whether the organisation can show that the restriction is tied to a clear, bounded reason and is applied consistently. If the answer changes from team to team, or if security review is so broad that it swallows ordinary exchange, the control is probably being misused.
Practical review should focus on whether the organisation can move information quickly without lowering core protections. For example, portals, APIs, and exchange workflows should support access decisions that are predictable and auditable rather than ad hoc. NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant because it reinforces the need for defined access control, authentication, auditability, and configuration discipline around those workflows.
In healthcare settings, poor management often shows up most clearly when the organisation cannot distinguish a control that protects data from a process that simply slows down release. The more the process depends on manual interpretation, the more likely it is that staff will create hidden barriers or inconsistent outcomes.
Risk and Threat Considerations
Poorly managed information blocking creates both operational and security exposure. It can push patients and partners toward slower, less reliable channels, increase the chance of incomplete records, and undermine trust in the organisation’s data-sharing processes. When barriers are inconsistent, staff may also work around controls in ways that reduce traceability.
Failure mechanism: Excessive restriction, weak workflow design, and inconsistent release decisions turn normal information sharing into a bottleneck, which encourages manual exceptions, duplicate handling, and untracked workarounds.
Impact: Patients may not get timely access, clinicians may make decisions with incomplete context, and the organisation may create avoidable privacy, integrity, and interoperability risk while appearing to be “protective.”
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | Controls who can access and share health information. |
| A.5.23 — Information security for use of cloud services | Covers secure exchange platforms and cloud-based record-sharing workflows. | |
| Recommendation — Define and enforce access rules that support lawful sharing without ad hoc barriers. Review cloud exchange services for controls that preserve secure interoperability. | ||
| NIST SP 800-53 Rev 5 | AC-3 — Access Enforcement | Applies to enforcement of who may view or release records. |
| AU-2 — Event Logging | Supports traceability for denials, exceptions, and transfer activity. | |
| Recommendation — Enforce release rules consistently so access decisions are predictable and auditable. Log record-access and exchange events so delays and denials can be explained. | ||
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication and Access Control | Supports controlled access to patient and provider information flows. |
| Recommendation — Apply access control governance so exchange paths are authorised and consistent. | ||
Practitioner Guidance
What to verify: Check whether the organisation can show a documented release path, a clear exception process, and consistent handling across portals, exchanges, and records requests. If staff cannot explain why a request was delayed or denied, the control environment is probably too weak to trust.
What to prioritise: Start with the highest-friction journeys, usually patient access and provider-to-provider exchange, because those are where poor governance becomes visible first. Fixing the workflow there gives you the clearest signal of whether the organisation is reducing barriers or just moving them around.
Common mistake: Treating every security concern as a reason to slow disclosure. Good organisations separate legitimate protection from process blockage, so they can preserve access without weakening safeguards.
Practitioner takeaway: The strongest indicator of poor management is not a single denial, it is a pattern of inconsistent decisions, weak ownership, and workflows that make lawful sharing harder than necessary.
Related resources from NHI Mgmt Group
- Who is accountable when a healthcare organisation uses a non compliant signature workflow for protected health information?
- What are the signs that human risk controls are not working in a healthcare organisation?
- What happens when a healthcare organisation lacks secure access controls for staff who need broad access to patient information?
- What are the signs that a healthcare organisation’s identity security controls are not keeping pace with HIPAA requirements?