Data blocking is any practice that unreasonably limits the availability, disclosure, or use of electronic health information. In healthcare, it prevents records from moving safely between providers and can also restrict patients from accessing their own information. It is both a governance problem and an interoperability failure.
What Data Blocking Means in Practice
Data blocking is not just a technical delay; it is a governance failure that impairs the lawful exchange and use of electronic health information. In practice, it shows up when records are unnecessarily withheld, interfaces are obstructed, or patients cannot get timely access to their own data.
Because the harm is tied to information movement, the issue often sits at the boundary of policy, interoperability, and operational control. A system can be technically capable of sharing data while still behaving in a way that functions as blocking if business rules, vendor workflows, or institutional practices create unreasonable friction.
How Data Blocking Disrupts Interoperability
Interoperability depends on more than a working API or exchange connection. It also requires that organizations allow data to be requested, disclosed, and reused in ways that support care coordination, continuity, and patient access.
Data blocking can arise when a system fragments access across portals, prevents export in usable formats, or applies asymmetric rules to outside providers and patients. The practical result is that information becomes trapped inside one workflow, even when sharing would be clinically and operationally appropriate.
This is why data blocking is often discussed alongside broader interoperability policy: the core issue is not simply whether systems can connect, but whether they can exchange information without unreasonable constraints. NIST Privacy Framework is useful here because it treats data governance and controlled sharing as part of managing privacy risk, not as an afterthought.
Why Data Blocking Matters for Patients and Providers
For patients, the most direct impact is delayed or denied access to their own health information, which weakens transparency, portability, and informed decision-making. For providers, blocked data can lead to incomplete records, duplicated tests, slower referrals, and avoidable safety issues.
When exchange is restricted, the problem becomes systemic rather than local. One organization’s restrictive practice can propagate through referrals, care networks, and downstream systems, making the entire information flow less reliable.
NIST Cybersecurity Framework 2.0 is a helpful lens for this kind of cross-functional control problem because governance, protection, and recovery all depend on trustworthy information availability. EU General Data Protection Regulation (GDPR) also provides a relevant privacy model where lawful access, design choices, and processing controls matter when personal data subjects need meaningful access to their information.
What Makes Data Blocking a Governance Problem
Data blocking usually reflects a decision structure, not a single software defect. It can stem from unclear ownership of exchange policy, conflicting incentives, poor vendor configuration, or operational choices that prioritize control over legitimate access.
That governance layer is what makes the term broader than interoperability alone. A platform may expose interfaces, yet still be governed in a way that limits who can retrieve information, how quickly, and under what conditions.
For that reason, organizations need to treat data blocking as a control and accountability issue across health information exchange, patient access, and record portability. NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant because access control, auditability, and system integrity all shape whether information can be disclosed appropriately.
Risk and Threat Considerations
Data blocking creates exposure when information is unnecessarily withheld from clinicians, patients, or approved exchange partners. The risk is not only inconvenience, but also clinical blind spots, delayed treatment, and control failures that are hard to spot until they affect care delivery.
Failure mechanism: Restrictive policies, fragmented interfaces, or vendor-driven workflow constraints prevent lawful disclosure or practical reuse of electronic health information, even when the organization appears to have exchange capability.
Impact: Patients lose timely access to their own records, providers make decisions with incomplete information, and the organization increases operational, compliance, and trust risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Data blocking reflects how health data sharing fits organizational duties and stakeholders. |
| ID.AM-01 — Physical Devices and Systems Inventory | Interoperability problems depend on knowing what systems hold and move the records. | |
| PR.AA-01 — Identity Management, Authentication and Access Control | Blocking often results from access control decisions that restrict legitimate disclosure or retrieval. | |
| Recommendation — Define health-information sharing responsibilities and ownership for exchange and patient access. Inventory systems and data paths that govern exchange and patient record availability. Ensure authorized users and patients can reach permitted health information without unreasonable barriers. | ||
| GDPR | Article 15 — Right of Access by the Data Subject | Patient access limitations make the access-rights dimension materially relevant. |
| Article 25 — Data Protection by Design and by Default | Exchange design choices affect whether access and disclosure are built in or blocked. | |
| Recommendation — Ensure people can obtain their personal data in a usable form without undue restriction. Build exchange and patient-access paths into systems by design, not as exceptions. | ||
| NIST SP 800-53 Rev 5 | AC-4 — Information Flow Enforcement | Data blocking concerns whether information flows are enforced or obstructed appropriately. |
| AU-2 — Event Logging | Exchange denial and access friction need traceability to diagnose blocking behavior. | |
| CM-8 — System Component Inventory | Interoperability issues depend on accurate knowledge of components that store or transmit records. | |
| Recommendation — Control information flows so legitimate health data exchange is allowed and unjustified blocking is prevented. Log disclosure, access, and exchange events that reveal unjustified restrictions on data movement. Maintain an accurate inventory of components that store, transform, or transmit health information. | ||
Practitioner Guidance
Why practitioners should care: Data blocking is often misdiagnosed as a technical integration issue when the real problem is usually policy, governance, or product behavior. Treating it as an interoperability and accountability issue helps clarify where the control failure actually lives.
Practitioner takeaway: The key test is whether information is being withheld unreasonably, not whether the system can technically connect.
Related resources from NHI Mgmt Group
- When does data tokenization create more value than blocking AI use?
- How can organisations reduce developer AI data leakage without blocking adoption?
- What is the difference between blocking access and enabling data protection?
- Should organisations prioritise inline blocking or forensic visibility for AI data risk?