Information Blocking in Behavioral Health: What Your EHR Portal and Records Workflow Must Prove

,
Computer Splash

Most behavioral health operators we work with have a HIPAA right-of-access policy. Far fewer have checked whether their EHR’s note-release settings would hold up against an information blocking complaint. The two rules overlap, but they are not the same rule, and the gap between them usually lives in a configuration screen nobody on the compliance team has opened.

Below: what the rules expect, where programs drift, and what to pull this week. This is operational guidance, not legal advice; talk to health care counsel about your specific facts.

What information blocking means for a behavioral health provider

The 21st Century Cures Act made it a violation for health care providers, health IT developers, and health information networks to engage in practices likely to interfere with the access, exchange, or use of electronic health information (EHI). For providers, the standard turns on knowledge: a practice counts as information blocking when the provider knows it is unreasonable and likely to interfere. HHS maintains the regulations, exceptions and FAQs on its information blocking resource page.

The federal information blocking provisions became applicable to health care providers on April 5, 2021, and since October 6, 2022 the definition of electronic health information has covered all electronic protected health information in a provider’s designated record set, not just a limited standardized data set, with psychotherapy notes excluded. For a residential, PHP, IOP or outpatient behavioral health program, that means progress notes, treatment plans, assessments, medication records and discharge summaries are generally in scope, and any EHR setting that withholds them from a client by default has to fit a recognized exception.

HHS also finalized disincentives in 2024 for providers found to have committed information blocking, applied through certain CMS programs such as Medicare Promoting Interoperability and the Merit-based Incentive Payment System. Many free-standing behavioral health programs do not participate in those programs and assume the rule is somebody else’s problem. It is not. The obligation itself still applies, complaints can be filed through the federal reporting portal, and the same practices that create information blocking exposure usually create HIPAA right-of-access exposure as well.

Psychotherapy notes are narrower than most clinicians think

The most common misunderstanding we see in behavioral health record reviews is the belief that therapy progress notes are “psychotherapy notes” and therefore exempt from client access. Under HIPAA, psychotherapy notes are a narrow category: a mental health professional’s notes documenting or analyzing the contents of a counseling session that are kept separate from the rest of the medical record. The definition expressly excludes medication prescribing and monitoring, session start and stop times, treatment modalities and frequencies, clinical test results, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis and progress. HHS explains the distinction in its guidance on HIPAA and mental health.

In practice, a progress note written in the EHR’s standard note template, visible to the treatment team and used to support a claim, is not a psychotherapy note. If your clinicians believe it is, your access and information blocking decisions are being made on the wrong premise.

Why behavioral health programs drift into information blocking

When we review portal and records workflows, the problems rarely come from a deliberate decision to withhold. They come from defaults and workarounds set during implementation.

  • Blanket release delays: A portal rule that holds every behavioral health note for clinician sign-off, or for a fixed number of days, applied to every client, is not an individualized determination and is hard to fit inside the preventing harm exception.
  • Mislabeled note types: Progress notes built as a “confidential” or “psychotherapy” note type are hidden from the portal and from records requests even though they do not meet the HIPAA definition.
  • Undocumented harm decisions: A clinician decides a specific note should not be released but never records the reasoning, so nothing shows the decision was individualized and made by a licensed professional.
  • Commingled Part 2 records: Substance use disorder records protected under 42 CFR Part 2 sit in the same note stream as mental health notes, so the program either over-discloses Part 2 information to third parties or locks everything down to be safe.
  • Format and fee friction: Records staff insist on paper, charge fees that are not cost-based, or require clients to come on site for records that already exist electronically.

The exceptions that matter most in behavioral health

The information blocking regulations include a set of exceptions. A practice that meets every condition of an exception is not information blocking. Partial compliance does not count. Three exceptions come up constantly in behavioral health.

Preventing harm: This exception allows a provider to withhold or delay EHI to reduce a risk of harm, but only within tight conditions. When clients request their own information, the risk generally must be the kind HIPAA already recognizes as grounds for denying access, meaning a reasonable likelihood of endangering the life or physical safety of the client or another person, and it generally must rest on an individualized determination by a licensed health care professional. A program-wide hold on “all behavioral health notes” will rarely satisfy those conditions.

Privacy: When federal or state law requires a precondition, such as a written consent, before information can be disclosed, and that precondition has not been met, withholding is generally not information blocking if you apply the policy consistently. This is the exception that covers Part 2 records requested by a third party without a valid consent. HHS’s fact sheet on the 2024 Part 2 final rule summarizes how Part 2 consent now aligns more closely with HIPAA. Keep in mind that Part 2 does not bar clients from accessing their own records, so this exception is not a reason to withhold SUD documentation from the client it describes.

Infeasibility: If you cannot fulfill a request in the manner asked, for example because you cannot reliably segment protected data from the rest of the record, the exception requires a written response to the requester explaining why, within the timeframe the regulation sets. Programs that let portal requests they cannot fulfill sit unanswered lose that protection.

What a complaint or review actually turns on

When an access complaint lands, whether through the federal information blocking portal, an OCR right-of-access complaint, a payer inquiry or a surveyor’s client rights interview, the first thing anyone asks for is the record of what happened: when the request came in, what was released, when, in what format, and why anything was held. Programs that can produce a request log, the portal release settings in effect at the time, and the clinician’s documented harm determination are in a defensible position. Programs that can only say “the EHR does that automatically” are not. OCR’s right of access guidance sets out what clients are entitled to.

The inconvenient truth is that most EHR vendors ship behavioral health configurations designed to minimize clinician discomfort, not to satisfy information blocking exceptions. The vendor is not the provider of record. If the default is wrong, the program owns the consequence. If you are unsure how your configuration would read to a reviewer, call us at (888) 458-6619.

A one-week audit you can run now

  1. Export your portal release settings. List every note and document type, whether it releases to the client portal, and any delay. For each hold or delay, write down the exception it relies on. Anything you cannot map to an exception is a finding.
  2. Pull ten notes marked confidential or psychotherapy. Check each against the HIPAA definition. If the note lives in the main record or supports a claim, it is probably not a psychotherapy note.
  3. Review your last 90 days of records requests. For each, capture request date, release date, format, fee charged and any denial reason. Confirm every denial or delay has a documented, individualized determination by a licensed professional.
  4. Test Part 2 segmentation. Confirm your EHR can flag and separate SUD treatment records so a third-party disclosure without consent cannot include them by accident.
  5. Compare your paperwork to your system. Read your Notice of Privacy Practices and client handbook and confirm that what they say about access matches what the portal actually does.
  6. Add one policy line. “Any withholding or delay of electronic health information must identify the applicable information blocking exception and be documented in the client record.”

Where this fits in your compliance program

Information blocking spans HIPAA, Part 2, EHR configuration and client rights, so it tends to fall between departments. Assign one owner, usually the compliance officer or privacy officer, and add a portal settings review to your annual risk work rather than treating it as an IT project. Our HIPAA compliance checklist is a useful starting point for the privacy side, and programs without a dedicated compliance lead often use a fractional compliance officer to own reviews like this one.

Learn more about our behavioral health compliance services, or call (888) 458-6619 to schedule a records access review.