Do you want more ideas about this?

Schedule a Consultation

Your EHR data is a strategic asset

Ask most healthcare CXOs who own their EHR data, and they will say, “we do.” Ask their legal team to produce the contract clause that establishes that ownership, and most rooms go quiet.

The data powering your clinical operations, your revenue cycle, and your AI strategy lives inside systems built, hosted, and contractually controlled by third-party EHR vendors. For most healthcare organizations, the terms governing what happens to that data when the relationship ends or when the vendor is acquired, raises prices, or changes direction were negotiated once, at go-live, and never revisited.

In 2026, that is no longer a risk you can defer. Three things have changed:

  • Regulators are penalizing providers for how their vendors handle data. Since September 2025, HHS has been actively enforcing information-blocking rules. The penalties come directly off your Medicare reimbursements, and if your EHR is the problem, the liability is still yours.[1]
  • Vendor acquisitions can change who controls your data overnight. When Oracle acquired Cerner, hospitals didn’t choose Oracle they inherited it. Without explicit contractual protections, your data rights are subject to decisions made in boardrooms you have no seat at.[2]
  • Your vendor is already building AI on your patients’ data. If your records are locked inside a proprietary system, your AI strategy runs on your vendor’s timeline. You end up paying for capabilities built on information your patients generated in your facility.

This guide is written for the healthcare leaders who own these decisions. It covers the legal landscape, the contract risk, the financial exposure, and the governance framework your organization needs before the next renewal conversation.

EHR data ownership vs. vendor control: where the risk actually lives

Your organization owns the patient data in your EHR. Your vendor owns the architecture it lives in, the format it is stored in, and the exit terms that determine whether you can actually move it. That gap is where most healthcare organizations are exposed.

As a covered entity under HIPAA, your organization is not just the owner of that data in a legal sense. You are its custodian. That means you are accountable for how it is collected, stored, accessed, and shared, regardless of which vendor’s system it sits in. If a vendor mishandles your patient data, the breach notification goes out under your name. The OCR investigation lands on your desk. The patient trust that erodes is yours to rebuild. Custodianship does not transfer when you sign a vendor contract. It stays with you.

In December 2025, the Texas Attorney General sued Epic Systems, alleging the company used its control over 325 million patient records both to restrict parents’ access to their children’s medical records and to impose punishing fees on hospitals that tried to bring in competing tools. The parental access claims made the headlines. [3] The market control claims are the ones that should worry every healthcare executive. This is not an isolated case. It is the clearest example yet of a dynamic that exists across the EHR market: vendors have zero legal ownership of your data, but they hold enormous practical leverage over your ability to access, export, and migrate it.

Three federal laws define the boundaries of this space:

Law What it does Who enforces it
HIPAA Sets privacy, security, and breach notification standards. Requires BAAs with all vendors handling patient data. HHS Office for Civil Rights. Penalties, adjusted annually for inflation, currently run $145 to $2,190,294 per violation.[4]
HITECH Act Extended HIPAA liability to Business Associates. Tied EHR use to CMS reimbursement through Promoting Interoperability programs[5] OCR and CMS jointly.
21st Century Cures Act Prohibits information blocking. Requires free electronic patient access to all health data. Mandates FHIR-based APIs. Nationwide enforcement since September 2025. OIG for vendors. CMS for providers through Medicare payment adjustments.

Information blocking: what it costs you

The financial consequences of information blocking violations are not abstract. They come off your Medicare reimbursements, your MIPS scores, and your program eligibility.

Entity Consequence
EHR Vendors Civil monetary penalties up to $1,000,000 per violation. ONC may revoke certification.[6]
Hospitals 75% reduction in the Medicare market basket increases.[7]
MIPS-Eligible Clinicians Zero score in Promoting Interoperability. Negative payment adjustment up to 9%. Effective July 31, 2024.[8]

Since September 2025, HHS has been publicly naming organizations under investigation. The reputational exposure compounds the financial one. These laws define what your vendor cannot do to your data. They do not, on their own, define what it costs you when they get close to the line.

Vendor lock-in: the trap hidden in your EHR contract

Most EHR contracts are negotiated once, at go-live, when the priority is getting the system live on time. The clauses that determine what happens when you want to leave get the least attention. That is not an accident. It is where vendors protect their revenue.

The numbers tell the story. Switching EHR systems costs between $25,000-$350,000+ depending on organization size and disrupts operations for six to eighteen months.[9] Nearly one in four medical group practice leaders expected to switch or significantly update their EHR within twelve months, per MGMA poll [10]. The dissatisfaction across the market is not a secret. The switching costs are what keep most organizations from acting on it.

That is lock-in. A financial one, built into your contract.

Contract clause What vendors often write What your contract should say
Data export format Export available in “vendor-supported formats,” which may mean proprietary, non-computable output Export must be provided in HL7 FHIR R4 and/or C-CDA format, covering all EHI, not just USCDI elements
Export fees Fees calculated on data volume, billed at termination, often large enough to make switching economically irrational Maximum export fee capped and defined upfront. Fees that make data portability prohibitive may constitute information blocking
Migration timeline Vendor will “reasonably cooperate” with migration, no defined timeline, no completion standard Full data export delivered within 30 to 60 days of written termination notice, with vendor-provided validation of completeness
API access after termination API access tied to active subscription, terminates immediately at contract end Patient-facing API access remains available for a minimum of 90 days post-termination
Secondary data use Vendor may use de-identified data for product improvement, benchmarking, and research with no limit and no notice Secondary use limited to explicitly agreed purposes. Vendor must notify before any new commercial use of data from your patient population
Data ownership language Contract silent on ownership, or uses “you retain rights to” rather than “you own” Explicit statement that all patient data remains the sole property of the organization. Vendor has no ownership rights

Source: EHR Source, EHR Data Exit and Vendor Lock-In: Contract Clauses That Actually Work (February 2026).[11]

These are not aggressive asks. They are the baseline terms that determine whether “you own your data” is a fact or a talking point.

Your vendor relationship is your biggest security risk

Every vendor with access to your patient data extends your attack surface, and your organization carries the consequences of a breach whether it originates inside your walls or theirs.

The 2025 Breach Barometer report found that business associates accounted for 77% of all healthcare records breached in 2024, out of more than 300 million records exposed that year.[12] The average breach cost $7.42 million. The average time to contain one was 241 days.

[13]

Your BAA is a risk-transfer instrument. If your vendor suffers a breach, your patients are notified under your name, Your OCR report is filed under your name, and your organization absorbs the reputational damage. The Change Healthcare attack in February 2024 exposed 192.7 million individuals’ records through a single third-party vendor relationship.[14]

The question is not whether your EHR is secure. It is whether every vendor touching your patient data is held to the same standard your organization is held to. If your BAA does not specify security requirements, audit rights, and breach notification timelines, it is not doing its job.

ONC certification and USCDI v3: what your vendor must deliver in 2026

Two certification requirements are directly relevant to your current operations and your reimbursement standing.

  • USCDI v3 is mandatory as of January 1, 2026. All ONC-certified EHR modules must now support the expanded United States Core Data for Interoperability standard, per ONC’s HTI-1 Final Rule.Β [15] If your vendor has not updated its certified modules accordingly, your Promoting Interoperability program status and the associated CMS reimbursement are at risk. Verify your vendor’s USCDI v3 certification status on the ONC Certified Health IT Product List at chpl.healthit.gov before your next reporting period.
  • FHIR API compliance is the portability standard. Since December 31, 2022, all ONC-certified EHRs have been required to support HL7 FHIR R4-based APIs enabling patients and providers to access complete health records without restriction. [16] This is the technical foundation for payer integrations, care coordination, population health tools, and AI-enabled clinical decision support. Vendors without functional FHIR API implementation are selling you an island.

How blueBriX approaches EHR data ownership

The challenges described in this guide, vendor lock-in, data portability barriers, governance gaps, interoperability limitations, are not abstract problems for the organizations we work with. They are the starting point of most conversations we have with healthcare executives looking to make a technology decision they can stand behind at the next board meeting, and long after it.

blueBriX treats data ownership as a structural commitment, not a talking point. It is built into the contract language, the platform architecture, the AI governance model, and the security baseline from the outset, so the organizations we work with negotiate from a position of leverage, not exposure.

That commitment plays out in five ways.

Contractual data ownership is explicit. Every blueBriX contract includes explicit language establishing that the healthcare organization retains sole ownership and administrative control of all patient data, during the relationship and after it. Export terms, formats, timelines, and fee structures are defined upfront, not negotiated under duress at the point of exit.

Interoperability is built on open standards. blueBriX supports both FHIR R4 and R5-based interoperability, keeping pace with the standard as it evolves, so your data exchange capabilities are not tied to yesterday’s specification. Our platform connects across systems, payers, labs, health information exchanges, and the TEFCA network, rather than creating proprietary dependencies.

The platform is designed for the highest-complexity care settings. Our specialization in Behavioral Health, Integrated Care, and PRTF management reflects a deliberate focus on the settings where data complexity, multi-provider care coordination, and regulatory specificity are highest, environments where getting data governance right directly determines care quality, billing accuracy, and regulatory standing. Our care coordination, risk stratification, advanced analytics, and revenue cycle management capabilities are built on a data foundation that serves both clinical and administrative leadership.

AI orchestration operates within clear data boundaries. As AI-powered clinical workflows become operationally central, who controls the underlying data and who benefits from it becomes a strategic question. blueBriX’s AI Orchestration capabilities never use your patient data to train external models without informed, documented consent. The AI works for your organization’s benefit, on your data, within your governance framework.

Security and compliance function as infrastructure. HIPAA-compliant data handling, signed BAAs, robust access controls, audit logging, and encryption standards are architectural defaults, the baseline we are able to demonstrate in an environment where the average healthcare breach costs $7.42 million and your vendor’s security posture is your liability as much as theirs.

The bottom line

Data is the underlying currency of every strategic initiative your organization is pursuing. Value-based care, AI adoption, population health management, revenue integrity. Your ability to execute on any of those depends on whether you actually control the data that powers them.

The legal framework is on your side. Information blocking is prohibited and enforced. Data portability is a right. The interoperability standards are mature enough to be written into contracts today. What most organizations are missing is not awareness of the problem. It is the translation of that awareness into enforceable terms, before the next renewal, before the next acquisition, before the next breach forces the conversation.

Your EHR vendor is not your partner by default. They are a counterparty. The organizations that understand that distinction, and negotiate accordingly, are the ones that will own their data in practice.

At blueBriX, that is the conversation we start with. If you are approaching a renewal, evaluating a new system, or simply want to understand where your current contract leaves you exposed, we are ready to have that conversation.

About the author

Basil P T

Basil P T is a Senior Technical Architect at blueBriX with over 10 years of experience in healthcare technology. He leads the technical design and scalability of the blueBriX EHR system, care coordination platform, and cloud infrastructure, working directly with FHIR R5, HL7, and open API standards to build systems that meet the interoperability and security demands of US healthcare. He built the initial prototype of blueBriX's proprietary EHR system, laying the technical foundation for what has since scaled into a core product. A contributor to the platform since its earliest stages, his work spans healthcare data security, HIPAA technical safeguards, system scalability, and the integration architecture that connects blueBriX with external EHRs, HIEs, and payer systems.

References

  1. https://www.hhs.gov/press-room/hhs-crackdown-health-data-blocking.html
  2. https://www.healthdatamanagement.com/articles/oracles-pending-purchase-of-cerner-raises-privacy-concerns?id=129357
  3. https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-sues-major-medical-record-database-gatekeeping-data-and-restricting
  4. https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
  5. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/factsheet/index.html
  6. https://www.federalregister.gov/documents/2023/07/03/2023-13851/grants-contracts-and-other-agreements-fraud-and-abuse-information-blocking-office-of-inspector
  7. https://www.aha.org/news/headline/2024-06-24-hhs-releases-final-rule-disincentivizing-health-care-providers-commit-information-blocking
  8. https://wyatthitechlaw.com/2024/07/03/hhs-adds-new-teeth-to-information-blocking-law-for-health-care-providers/
  9. https://www.ehrsource.com/articles/switching-ehr-systems/
  10. https://www.mgma.com/mgma-stat/building-a-robust-rfi-process-and-rfp-for-a-new-ehr-system
  11. https://www.ehrsource.com/articles/ehr-data-exit-and-vendor-lock-in-contract-clauses/
  12. https://databreaches.net/2025/02/26/business-associate-breaches-account-for-the-largest-percentage-of-breached-patient-records/
  13. https://www.bakerdonelson.com/webfiles/Publications/20250822_Cost-of-a-Data-Breach-Report-2025.pdf
  14. https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html
  15. https://healthit.gov/regulations/hti-rules/hti-1-final-rule/
  16. https://www.federalregister.gov/documents/2025/12/29/2025-23896/health-data-technology-and-interoperability-astponc-deregulatory-actions-to-unleash-prosperity

Frequently asked questions

Because lock-in operates at the contract level, not just the conduct level. Federal law prohibits active information blocking β€” deliberate interference with data access. It does not, by itself, specify export formats, cap exit fees, or require vendors to build easy migration pathways. A vendor that quotes you a legally permissible but economically prohibitive migration fee is not automatically an information blocker β€” but the result is the same. Your protection is the contract you negotiate before you sign, not the regulation you invoke after the fact.

Any party β€” patient, provider, developer, or competitor β€” can report suspected information blocking via the ASTP/ONC Information Blocking Portal (healthit.gov/information blocking). OIG investigates vendor violations; CMS administers provider disincentives through program participation requirements. Since September 2025, OIG has confirmed it is actively reviewing reports and expects early cases to be publicized as deterrence signals.

As of January 1, 2026, all ONC-certified health IT modules must support USCDI v3 as the baseline data set for certified functionalities, including the FHIR-based API criterion. USCDI v3 adds expanded demographic elements (sexual orientation, gender identity, pronouns) and social determinants of health data classes not required under v1. Verify your vendor’s USCDI v3 certification status at the ONC Certified Health IT Product List (CHPL) at chpl.healthit.gov.

AI contracts involving patient data require the same governance discipline as EHR contracts, with additional considerations specific to model training and inference. Key provisions: explicit prohibition on using your patient data to train models for the benefit of other customers; data residency and encryption standards; clear statement of what data is accessed, for what purpose, and with what retention; patient notification and consent protocols where applicable; and audit rights to verify compliance. Any AI vendor that cannot clearly answer these questions is a governance risk.

The Trusted Exchange Framework and Common Agreement (TEFCA) is the federal framework establishing the governance and technical standards for nationwide health information exchange. Qualified Health Information Networks (QHINs) under TEFCA serve as standardized exchange infrastructure that enables data sharing across disparate EHR systems, payers, and care settings β€” without proprietary API arrangements with every partner. For health systems, TEFCA participation through a QHIN-connected EHR is increasingly the baseline for participating in value-based care, care coordination, and population health program at scale.

Start with: (1) What is our complete data export process and timeline at contract termination? (2) What formats will that export be delivered in, and will it cover all EHI or just USCDI elements? (3) What is the maximum fee for data export and migration support? (4) Has your platform been updated to USCDI v3 certification, and can you provide the CHPL listing? (5) What secondary commercial uses do you make of de-identified data derived from our patient population? If your vendor cannot answer all five questions clearly and in writing, you have a governance gap.

If finalized, the proposed HIPAA Security Rule update will impose new security requirements on both covered entities and their Business Associates β€” including EHR vendors. Your BAA should already require vendors to maintain security standards equivalent to your own obligations. Review your current BAA against the proposed rule’s key requirements (MFA, network segmentation, asset inventory, 72-hour breach notification, annual encryption verification) and begin discussions with your vendor about their implementation roadmap. Vendors that cannot commit to meeting these standards are a future compliance liability.

Transitioning to a platform that treats compliance as infrastructureβ€”rather than an afterthoughtβ€”immediately reduces your administrative burden. Because blueBriX embeds HIPAA-compliant data handling, audit logging, and transparent security protocols as architectural defaults, you are no longer “managing” your vendor’s compliance failures. You are operating on a foundation built to meet 2026 standards, which helps you stay ahead of HHS/OCR requirements rather than perpetually reacting to them.

Yes. A core tenet of our AI Orchestration model is that the AI works for your organization, using your data, to achieve your outcomes. blueBriX’s approach ensures your data stays within your governance framework. You maintain control over how those insights are generated and, crucially, you are not inadvertently subsidizing your vendor’s AI product development with your own patients’ health information.