Audit & compliance
Substance use records have their own rules.
Part 2 protects SUD treatment records more tightly than HIPAA, and it governs what you can disclose, to whom, and with which consent. That has to be built into the record, not bolted on as a policy memo.
Consent is a record, not a checkbox. Every disclosure ties back to the consent that permitted it.
The consent is the control
Part 2 asks who, for what, how much, and until when.
Under Part 2 a general HIPAA authorization is not enough. Consent has to name the recipient, state the purpose, define the scope, and carry an expiration — and the system has to actually enforce it, not just store it.
Why the rules are different
Part 2 exists so that seeking treatment cannot be used against you.
The regulation was written because people avoid substance use treatment when the record can reach an employer, a court, or a family member. The confidentiality is not administrative overhead — it is part of what makes the treatment possible.
What the system enforces
Consent-scoped everything
Exports, referrals, audit packets, and API access all respect the active consent. If a record is outside scope, it is not in the file that leaves.
- Segregated at the record level
- Enforced on every export path
- Expiration honoured automatically
- Revocation takes effect immediately
What you can still do
Coordinate care properly
Scoped consent is what lets you work with a primary care physician, a referring hospital, or a drug court without handing over the entire chart.
- Share a summary, not the file
- Different consents for different recipients
- Qualified service organization agreements
- Every disclosure logged and producible
Its own category of risk
A Part 2 violation is not simply a HIPAA breach with a different name.
Disclosing SUD treatment records without qualifying consent carries consequences distinct from a HIPAA incident, and the 2024 alignment rule tightened the penalties rather than loosening them. Which is why this belongs in the record, not in a policy binder.
Works with
It runs on the same record as the rest of the platform.
Audit & compliance
Roles & permissions
A tech, a biller, a clinical director, and an owner should not see the same chart.
Read more →Audit & compliance
Activity log
An immutable record of who did what and when, across the whole tenant.
Read more →Audit & compliance
Trust center
Where the data lives, who can reach it, how it is encrypted, and what happens if something goes wrong.
Read more →Get started
Start today, or take a look first.
Create an account in minutes. Or book a 30-minute walkthrough.
