The Real Time Medical Systems v. PointClickCare Casebook
A consistently updated post on healthcare’s first major information blocking case
Details
Core Issue: Information blocking via technical restrictions preventing third-party access and extraction of data
Plaintiff: Real Time Medical Systems (Analytics Application)
Defendant: PointClickCare (EHR for skilled nursing facilities)
Courts: District Court of Maryland, appealed to Fourth Circuit Court of Appeals
Dates: January 21, 2024 - Present
Why: Providers aren’t always able to choose the applications they want and third party apps feel blocked as EHR use technology to allegedly self-preference their products
Type: Information Blocking
Subtype: RPA
Important Links:
Summary
Automated data access has always been a gray area in healthcare. Real Time Medical Systems (RTMS), which provides analytics to skilled nursing facilities, depended on automated collection of EHR data from its customers’ systems. When PointClickCare (PCC) introduced unsolvable CAPTCHAs that blocked those automations but allegedly did not offer APIs of equivalent functionality, RTMS filed suit, arguing that such technical barriers constituted information blocking under the 21st Century Cures Act.
Because the Cures Act does not provide a private right of action, RTMS brought its claims under Maryland’s unfair-competition law, using information blocking as the predicate wrongful act. While IntusCare v. RTZ had established some minor precedent of a path of private action using unfair competition law, this case thus became the first serious test of whether private litigants could use state law to enforce federal interoperability rules.
In July 2024, Judge Paula Xinis ruled that PCC’s CAPTCHAs did constitute information blocking, rejecting its “performance,” “security,” and “manner” exception defenses and issuing a preliminary injunction against the restrictions.
On March 12, 2025, the Fourth Circuit affirmed that ruling, establishing the first appellate precedent that:
Private plaintiffs can incorporate Cures Act violations into state unfair-competition or tortious-interference claims (reaffirming the earlier decision in IntusCare v. RTZ). This solidifies a new private enforcement pathway. Even though the Cures Act itself does not allow private lawsuits, plaintiffs can now use state laws as a back door to enforce federal interoperability rules. That means EHR vendors and health data gatekeepers are no longer just facing regulators - they are now exposed to potentially unlimited litigation from competitors, startups, and even providers.
Screen scraping and RPA can qualify as lawful access methods under the Cures Act. This was largely unexpected by the industry - in terms of the three ways one can integrate, most expected that RPA and direct-to-database access would be considered illegitimate workarounds rather than authorized methods of data exchange.
The burden to prove an exception lies with the actor in this case, PointClickCare. This shifts the playing field: EHR vendors are now presumed to be blocking unless they can prove otherwise, making it far easier for plaintiffs to win and much harder for vendors to rely on broad, hand-wavy defenses.
Following the appellate win, PCC’s en banc petition was denied on April 28, 2025, and the case returned to District Court for continued proceedings on the merits.
Potential Outcomes
The outcome of RTMS v. PointClickCare will shape how courts interpret and enforce the 21st Century Cures Act’s information blocking provisions for years to come. The case sits at the crossroads of interoperability policy, product design, and competitive dynamics within the EHR ecosystem.
If RTMS ultimately prevails as they have with the injunction, the decision could cement a private enforcement pathway for information blocking through state unfair competition and tortious interference claims. That would expand accountability beyond HHS and OIG enforcement, inviting more lawsuits when APIs or integration programs are seen as exclusionary.
In that way, such a shift could also undermine regulatory enforcement. Vendors (and EHRs) dissatisfied with OIG or ASTP outcomes might increasingly push disputes into the courts, using litigation to reinterpret or preempt administrative findings.
The die seems cast here, at least in states with flexible unfair competition laws like California and even middle ground states like Maryland. RTMS v. PCC, IntusCare v. RTZ, and similar cases have shown that pairing state tort law with federal information blocking rules is a viable path for private enforcement. Once courts recognize that theory, it’s difficult to see how the industry—or the regulators—can put that genie back in the bottle.
A win for RTMS would also validate several automated extraction methods, including screen scraping and RPA, as lawful data access approaches when standardized APIs are insufficient, forcing EHR vendors to justify any technical or contractual restrictions with detailed documentation. RPA is skyrocketing as an integration technique. This would also add tremendous incentive for EHRs to build robust APIs or other “controlled” integration pathways in order to have alternative manners to offer, effectively channeling third-party demand back into vendor-managed ecosystems rather than unregulated automation. At a minimum, why not allow RPA in a controlled fashion to mitigate risk while still observing and monetizing, if you’re an EHR?
A loss for RTMS, or a later narrowing of the precedent, would have the opposite effect: affirming vendors’ discretion to define “secure and reasonable” interoperability on their own terms. That outcome would preserve the historic model, where EHR actors have large discretion over third-party access outside of a small number of standards-based APIs, and courts defer heavily to security and performance exceptions.
Right now, RTMS is exploring uncharted territory, but it’s clear PCC is on the defensive. There’s a reason the EHR Association has weighed in twice with amicus briefs - they recognize the implications with a full loss. PCC will need strong expert witnesses and much stronger documentation of the exceptions they have tried to claim - specifics on the security threats implicit with the RTMS approach, logs and data showing the performance impact, or documentation of their communications showing they negotiated to find an alternate manner and that RTMS walked away.
Either way, RTMS v. PointClickCare will define the boundaries of what “reasonable and necessary” really means in the Cures Act era and determine whether robotic process automation, not just APIs, belongs in the future of interoperability.
Case Events
Relevant Articles
Super Integration Fighter III: Desperate applications that lack “sanctioned interfaces” like APIs will try to find ways into systems of record via other means, such as RPA or direct to database. While not directly related, it is thematically tied to the court case - RTMS was using screenscraping and felt APIs offered couldn’t meet their needs.
There Will Be Bundling: Systems of record are drawn to build all functionalities their customers need, leading them into competition and conflict with point solutions. While not directly related, it is thematically tied to the court case - RTMS has accused PCC of only blocking their access once they released a competing analytics product.
Posts:
Real Time Medical’s Response: RTMS focused on procedural arguments against PointClickCare’s motion to dismiss, arguing injunctions have higher bars than dismissals and that PCC is inappropriately fact-injecting at the 12(b)(6) stage. They avoid substantive debates, confident in procedural grounds while Count I (Maryland’s Nursing Home Records Act) remains a wild card.
PointClickCare’s “Unclean Hands” Defense: PCC’s new motion to dismiss in the RTMS case added an “unclean hands” argument, claiming RTMS engaged in wrongful conduct (violating customer contracts via bots, refusing reasonable fees) while seeking equitable relief. This represents a shift from purely defensive regulatory compliance arguments to offensive misconduct claims, alongside highlighting tensions with Maryland’s Nursing Homes Act requirements.
Takings Clause Implications for Healthcare: Apple’s potential appeal on App Store policies raises Fifth Amendment takings questions that could impact healthcare. PointClickCare already included takings arguments in their information blocking appeal, suggesting that judges forcing EHRs to provide RPA access without compensation could violate constitutional property rights.
The Fourth Circuit Denies PointClickCare’s En Banc Petition: The long shot from PCC, the EHR Association and AHA fails. The preliminary injunction (and associated precedent) stands and we continue back to the district court for the fuller trial.
EHR Association’s Second Amicus Brief: The EHRA, joined by the American Hospital Association, filed a brief supporting PCC’s en banc petition. They argue the appellate decision creates an unreasonable negotiation burden for healthcare organizations receiving countless information requests annually. Their position on the Manner Exception claims it was specifically designed to allow standardized alternatives rather than custom solutions, though this interpretation conveniently sidesteps the “missing 70%” of data not covered by standards like USCDI.
PointClickCare’s En Banc Request: PCC petitioned for the full Fourth Circuit to review their case, arguing the panel misinterpreted the Manner Exception, improperly allowed private enforcement of the Cures Act, and incorrectly placed the burden of proof. While a procedurally appropriate step, the petition appears to be a long shot as it largely rehashes arguments already addressed in the appeal decision. The request focuses on the case’s significance as the first major information blocking litigation, potentially affecting all Americans’ health record access.
A Layer Deeper on Implications of RTMS v. PCC: The court’s opinion reinforces several key points about information blocking: the burden of proof falls unequally on EHR vendors; once information blocking is proven (which is fairly trivial given the broad definition), the burden shifts to defendants to prove an exception applies; and exceptions like the manner exception will be difficult to use, requiring documented negotiation efforts rather than simply abandoning talks.
RTMS’s Big Win: A significant appeals win for Real Time Medical Systems in their case against PointClickCare. The court found RTMS is likely to succeed on its unfair competition claim, determining that PointClickCare’s actions likely violated the 21st Century Cures Act’s information-blocking provisions. None of PointClickCare’s claimed exceptions (manner, performance, security) were supported by evidence. This establishes that violations of the Cures Act can support state law unfair competition claims despite the Act lacking a private right of action.
RTMS v. PCC Arguments: New appellate court oral arguments suggested significant skepticism of RTMS’s position in this information blocking case. Judge Heytens focused on contractual issues - since RTMS accesses data through facilities that agreed not to use bots, he questioned how this wasn’t a breach “every single time.” While judges showed concern for data sharing goals, their questions highlighted tension between contractual rights and information blocking rules.
Information Blocking Litigation Precedent: Initial court decisions in RTMS v. PointClickCare and IntusCare v. RTZ establish that, while the Cures Act lacks a private right of action, EHRs remain vulnerable to litigation through alternative legal theories. Courts have ruled that information blocking can serve as an “independently wrongful act” for tortious interference claims or as evidence of unfair competition, even when the underlying regulation can only be enforced administratively. If this stands, this creates a viable pathway for future private litigation against EHRs over information blocking, though the EHR Association’s amicus brief in the PCC appeal seeks to overturn this interpretation.
Real Time Medical Systems v. PointClickCare Update: RTMS submitted their response brief to the appeals case that started this summer. I want to point out (again) that this case is infinitely more important to the industry than the sexier and more well-known Particle v. Epic case. The shape of information blocking interpretation and enforcement is taking form, currently setting an extremely broad aperture for what might be blocking and allowing for private action (lawsuits) in addition to administrative complaints. Every EHR and digital health company should be paying attention.
AHA and EHRA Step In: The American Hospital Association and EHR Association jointly filed an amicus brief supporting PointClickCare, arguing that Maryland’s common law unfair competition claims improperly intrude on federal authority under the Cures Act. Their stance, if accepted, could limit state-level private enforcement and restrict “information blocking” to HHS’s administrative domain, potentially shutting down the emerging wave of private litigation that uses these rules as a basis for tort and competition claims
PointClickCare’s Opening Brief: In its 82-page appellate brief, PointClickCare argues the Maryland court erred in finding its anti-bot measures unlawful. The company centers its defense on privacy, security, and contract enforcement, asserting that information blocking shouldn’t override customer agreements. It leans heavily on the Manner Exception, claiming it offered compliant alternatives, while challenging how the lower court assigned burden of proof for security and performance. The brief previews how courts will weigh contractual and technical defenses against the Cures Act’s broad access mandate
PointClickCare’s Appeal and Injunction Fallout: The initial Real Time Medical Systems v. PointClickCare ruling found that PointClickCare’s use of unsolvable CAPTCHAs to block data access constituted information blocking, rejecting their claimed performance, security, and manner exceptions. The injunction (if upheld) legitimizes screen scraping as a valid data exchange method and sets early precedent for how courts interpret the Cures Act’s blocking provisions. PointClickCare’s appeal to the Fourth Circuit marks the first major judicial test of those rules
CAPTCHAs Found to Be Blocking in Preliminary Injunction: Judge Paula Xinis ruled that PointClickCare’s use of unsolvable CAPTCHAs to block RTMS access constituted information blocking, rejecting claims under the performance, security, and manner exceptions. The injunction prohibits further blocking, marking the first major judicial finding that screen scraping can qualify as lawful interoperability. The decision weakens common vendor defenses and could accelerate new API development or normalize scraping as an accepted access path
Hearing Delay and Settlement Window: The PointClickCare hearing was postponed from early July to July 19, with parties given until the 26th to negotiate settlement. The dispute centers on a $125-per-facility fee for data connections - low by industry standards, yet enough to trigger litigation over fairness and access. The delay underscored both the practical tension in API economics and how thin the margins can be for third party point solutions.
Judge Signals Early Win for Real Time Medical Systems: In RTMS v. PointClickCare, a July 3 ruling was delayed, but the judge appeared poised to block PointClickCare’s use of CAPTCHAs that prevented automated data access. The case hinges on whether restricting screen scraping or RPA constitutes information blocking under the Cures Act. The outcome could validate automated extraction as a lawful data-sharing method—potentially extending to direct database access if the same logic holds





Thanks for sharing your great reporting on such an important, precedent-setting case pertaining, as you say, “interoperability policy, product design, and competitive dynamics within the EHR ecosystem”.
I’ve been on many occasions on RTMS’s position, and experienced systematic information blocking attempts from EHR vendors (to be precise, the foot-dragging and political posturing was actually channelled in most cases through the provider’s CIO, acting as an unofficial representative of that vendor and presumably mainly seeking to simplify his/her life).
I know little about US legislation (enough to appreciate that it seems to be moving in what I consider a positive direction regarding the “burden of proof” you mention as well as people’s rights over their medical data) but that shouldn’t affect my observations on your post, the main one being: How come this legal dispute is between two technology vendors? Where is the common customer, the one paying for all this software and related services, which I must assume has not given up in its technology purchasing agreements the right to decide which system can access and use which data within their technology ecosystem?
In my own experience the blocking was ultimately unsuccessful precisely because the customer (a department within the hospital) fought for our solution’s deployment and couldn’t be denied a minimum level of data sharing (ADT and lab tests fundamentally), which we were always happy to participate in to show our value add to the enterprise beyond our natural scope of operation.
In my view most EHR vendors are on the wrong side of (digital health) history as they try to “capture” the customer in the hope of being the sole provider of technology solutions. This has devastating systemic consequences for the health system (in which care providers are but one component, estimated to account for no more than 20% of health outcomes) far beyond their commercial interests.
One hopes market forces and legislation will force their hand with respect to legitimate and purposeful data sharing; in fact, I think their EHR should be essentially “headless” and API-rich (even if they also provide user-facing clinical support), and very much concentrated on what I deem to be their essential mission: to support the management functions (resource management & payer billing) of a complex, multiple service lines business, all of which is essentially orthogonal to the longitudinal dimension of the patient/customer’s health journey (the main source of the proverbial fragmentation in this industry) and mostly oblivious to population health processes and goals which, beyond emergencies response, have one essential, strategic goal: prevention.