1. What does an EHR exit actually cost?
Six lines, and only two of them are usually unavoidable. The largest — the extraction quote — is the one with a federal rule attached.
| Cost line | Typical range | Avoidable? |
|---|---|---|
| Certified EHI export (the full electronic health information export a certified system must provide) | $0 | Not a cost. It is a capability the vendor certified to; see section 2. |
| “Data extraction” service — a vendor-run export delivered as files, usually with a contract addendum | Quotes we have seen run from the low four figures into five | Usually. Often the same data the certified export produces. Ask what it contains that the certified export does not, in writing. |
| Overlap subscription — paying both systems while you migrate and verify | 1–3 months of your current bill | No. Budget it. Cutting the overlap to zero is how practices discover a gap after the old system is gone. |
| Read-only archive access after termination | A monthly fee, sometimes indefinite | Often. If the export is complete and verified, you may not need it — but decide that before you cancel, not after. |
| Staff hours — reconciliation, verification, re-training | 20–60 hours for a small practice | No. This is the real cost of a migration and it is almost never in the quote. |
| Rebuild — templates, order sets, protocols, schedule rules, price lists | Days of clinical time | No. Structured content rarely transfers between systems in a usable form, whatever the export contains. |
The pattern worth internalising: the fee you are quoted is usually the avoidable line, and the work you are not quoted for is the unavoidable one. Practices negotiate hard on the extraction invoice and then lose three weekends to reconciliation nobody planned.
2. What is the EHI export right?
If your system is certified health IT, it had to build you a full export and let you run it yourself. The criterion is 45 CFR 170.315(b)(10), and certified modules that store electronic health information had to make the capability available to end users by 31 December 2023.
| What the criterion requires | The wording |
|---|---|
| A single-patient export | Enable a user to timely create an export file with all of a single patient’s electronic health information that can be stored at the time of certification by the product. |
| A whole-population export | Create an export of all the electronic health information that can be stored at the time of certification by the product. |
| In a usable form | Electronic and in a computable format, published with a publicly accessible hyperlink to the format’s documentation — so a receiving system can read it without asking permission. |
| On your schedule, not theirs | “A user must be able to execute this capability at any time the user chooses and without subsequent developer assistance to operate.” Timely means near real-time, reasonable and prudent in the circumstances. |
Read that last row again, because it is the one that settles most arguments. A capability you have to raise a ticket and pay for is not a capability you can execute at any time without developer assistance. If the only route your vendor offers is a paid service request, that is worth a direct question about how the product meets (b)(10).
3. When is a fee for your own data not allowed?
The information blocking rules include an exception that lets actors charge reasonable fees — and that exception specifically excludes two fees that show up on nearly every exit invoice. The citation is 45 CFR 171.302(b), and the two exclusions are these:
| Excluded fee | Citation | What it means at the table |
|---|---|---|
| A fee to perform an EHI export via the capability certified to 170.315(b)(10) for the purposes of switching health IT or to provide patients their EHI | 45 CFR 171.302(b)(3) | Charging for the certified export because you are leaving does not fit the fees exception. The vendor then needs a different exception, or the practice may implicate the information blocking definition. |
| A fee to export or convert data from an EHR technology that was not agreed to in writing at the time the technology was acquired | 45 CFR 171.302(b)(4) | A price invented at the exit is not protected. If the extraction fee is not in the contract you signed at the start, that is the question to ask first. |
| A fee based on an individual electronically accessing their own EHI | 45 CFR 171.302(b)(2) | Patient access is not a revenue line. |
The federal FAQ on this is explicit that where the technology is not certified to (b)(10), a fee agreed in writing when the technology was acquired can still be enforceable — but that if the fees were not agreed to in writing at the time of acquisition, the fees exception would not be available. So there are exactly two questions: is the system certified, and was the fee in the original contract?
What enforcement looks like in 2026. Developers of certified health IT, health information exchanges and networks face civil money penalties of up to $1 million per violation, an authority effective since 1 September 2023. Providers face disincentives through Medicare rather than penalties, effective 1 July 2024. The complaint portal has been open since 2021 and had taken on the order of 1,600 complaints by February 2026, with federal officials stating in 2026 that notices of investigation were going out to health IT developers. The practical value of knowing this is not that you will file — it is that the person quoting you knows it too.
4. How do you check whether the right applies to you?
Look your vendor up on the federal Certified Health IT Product List at chpl.healthit.gov before you argue about anything. It is public, it is searchable by product, and it tells you which criteria the product is certified to and whether the listing is active, retired or withdrawn.
| What you find | What follows |
|---|---|
| Active listing including (b)(10) | The export capability exists and you are entitled to run it yourself. Ask where it is in the interface before you ask what it costs. |
| Active listing without (b)(10) | Ask why. Modules that store EHI were required to make the capability available by 31 December 2023. |
| All listings retired or withdrawn | The developer is not a developer of certified health IT for these purposes, and the export right does not reach it. We have migrated a practice off exactly this situation — the lever did not apply, and the answer was the vendor’s own documented free export routes plus a database the practice already owned. |
| No listing at all | The same position. Your leverage is the contract you signed, so read the termination and data clauses closely. |
⚠️ Do not open with a threat. A complaint against a developer with no certification would be closed for want of jurisdiction, and leading with it tells the vendor you have not checked. Check first, then ask a specific question about a specific criterion.
5. What are the timing traps?
Every one of these is a date, and every one of them has ended a migration badly for somebody.
| Trap | What goes wrong |
|---|---|
| Auto-renew and notice period | Contracts commonly require 30, 60 or 90 days’ written notice before the renewal date. Miss it and you have paid for another year of a system you are leaving. Find this clause before you start looking at replacements. |
| Export production time | A practice-level export is not instant. One major cloud system takes up to 14 business days to produce one after the request is filed. |
| Download expiry | The same system makes the finished export available for 30 days and then deletes it permanently. Requesting early and downloading late is the same as not requesting. |
| Read-only ends | Post-termination read-only access often runs months, not years, and sometimes only while a fee is paid. It is not an archive strategy. |
| Your retention obligation does not end | State medical-record retention runs for years past the last visit, and losing access to the old system does not suspend it. Whatever you export is what you will have to answer with. |
🔑 The sequencing rule: request the export roughly four weeks before the contract lapses, download it the day it is ready, verify it against record counts, and only then give notice. Doing it in the other order is how a practice ends up negotiating from inside a 30-day window.
6. The order to do this in
Seven steps. The first three cost nothing and remove most of the leverage the vendor has.
| # | Step | Why here |
|---|---|---|
| 1 | Read the termination, notice and data clauses in your current contract | It sets every date that follows, and tells you whether any extraction fee was agreed in writing at acquisition. |
| 2 | Look the product up on the CHPL | Determines whether the export right applies at all. |
| 3 | Ask, in writing: where is the (b)(10) EHI export in the product, and what does it contain? | A written answer is the thing you can act on. It also usually reprices the quote. |
| 4 | Run the export yourself and open the files | Before you commit to anything. What is in there decides how much rebuilding the new system needs. |
| 5 | Reconcile counts — patients, encounters, documents, results | Against the numbers reported in the old system. This is the step practices skip and then regret. |
| 6 | Plan the overlap and the rebuild | Templates, protocols and price lists do not come across. Budget clinical time, not just admin time. |
| 7 | Give notice — last | Once you hold verified data. Notice is the moment the clock starts running against you. |
The mechanics of the move itself — what reconciles, what breaks and in what order — are in how to switch EHR without losing patient data, and there is a field-by-field example in switching from Cerbo.
7. Frequently asked questions
Can my EHR charge me to export my own data?
It depends on two things: whether the product is certified to 45 CFR 170.315(b)(10), and whether the fee was agreed in writing when you acquired the technology. The fees exception at 45 CFR 171.302(b) specifically excludes a fee to perform a certified EHI export for the purpose of switching systems, and excludes a fee to export or convert data that was not agreed in writing at acquisition. Outside those, a vendor can charge for genuine additional services.
What is the difference between an EHI export and a data extraction service?
The EHI export is a certification requirement: a self-serve capability producing all the electronic health information the product can store, in a computable format, executable without developer assistance. A data extraction service is a commercial offering — a person at the vendor running a process and delivering files. They frequently produce very similar data. Ask what the paid one contains that the free one does not, and get the answer in writing.
Does the export include my note templates and protocols?
Generally no. The export covers electronic health information about patients. Templates, order sets, protocol libraries, schedule rules and price lists are configuration, and they are almost never portable between systems. Budget time to rebuild them — it is the most consistently underestimated part of a migration.
What if my vendor is not certified at all?
Then the export right does not reach them and the information blocking provisions do not apply to them as a developer of certified health IT. Your leverage is your contract, plus whatever export routes the vendor documents for its own customers — which are often more generous than the sales conversation suggests. Check the CHPL before assuming either way.
How long should I keep the old system running?
Long enough to verify, which in practice means one to three months of overlap. Verify record counts and spot-check charts in the new system before you cancel, and confirm what happens to read-only access after termination — it is usually time-limited, sometimes fee-bearing, and never a substitute for an export you hold yourself.