Platform
Solutions
Company
Pricing
Register nowSign in

Compliance

42 CFR Part 2, explained for operators

What Part 2 requires beyond HIPAA, what a qualifying consent has to contain, and where treatment programs most often over-disclose without realising they have done it.

ProbityCare4 August 202611 min read
The short version
  • Part 2 protects substance use disorder treatment records more tightly than HIPAA, and it applies to programs, not to all providers.
  • Consent under Part 2 has required elements. A general HIPAA authorization does not satisfy it.
  • The 2024 alignment rule brought Part 2 closer to HIPAA in several respects — including permitting a single consent for future treatment, payment and operations uses — while also extending HIPAA-style penalties.
  • Most violations are not malicious. They are an export, a referral packet, or a records response that included more than the consent covered.

Part 2 exists for a reason worth stating plainly: people avoid substance use treatment when they believe the record can reach an employer, a court, a landlord, or a family member. The confidentiality is not administrative overhead layered on top of care. It is part of what makes the care possible.

That framing matters operationally, because the rule is easiest to comply with when staff understand why it is stricter, rather than experiencing it as HIPAA with extra paperwork.

Who it applies to

Part 2 applies to federally assisted programs that hold themselves out as providing, and do provide, substance use disorder diagnosis, treatment, or referral for treatment. “Federally assisted” is broad — it captures most programs, including those simply holding a DEA registration or receiving Medicaid.

Critically, it attaches to the program, not to every provider who might learn the same information. A general hospital that treats someone with a substance use disorder is usually not a Part 2 program. A treatment center is.

What a qualifying consent contains

This is the part most often got wrong, because a HIPAA authorization looks superficially similar. A Part 2 consent has to identify:

  1. Who is disclosing — the program name.
  2. Who receives it — the specific recipient, named. “Any treating provider” is not a name.
  3. What is disclosed — the amount and kind of information, defined narrowly enough to mean something.
  4. Why — the purpose of the disclosure.
  5. How long — an expiration date, event, or condition.
  6. The right to revoke, and how.
  7. Signature and date, by the patient or their authorised representative.

The 2024 final rule changed the shape of this in an important way: it permits a single consent covering all future uses and disclosures for treatment, payment, and health care operations, where the patient chooses that. That is a genuine simplification for care coordination — and it does not remove the requirement that the consent be specific about what it authorises.

The failure mode is almost never a consent that does not exist. It is a disclosure that went beyond the consent that did.

Where programs actually over-disclose

The referral packet

A patient is stepping down to outpatient and a coordinator sends “the chart” to the receiving provider. The consent covered a treatment summary. What went was the whole record, including group notes naming other participants.

The records response

A payer requests documentation. The program produces everything requested, which is correct for the claim — and includes Part 2 protected material that the payer's consent did not extend to.

The integration

A health information exchange connection or an API key that pulls the full record because nobody scoped it. Consent enforcement that lives in a policy rather than in the export path will eventually be bypassed by a system that does not read policies.

The subpoena

A subpoena alone does not authorise disclosure of Part 2 records. A court order meeting the regulation's requirements is a different instrument. Staff who do not know the difference will comply with the wrong one under pressure.

What good looks like operationally

Four things, and they are all structural rather than procedural:

  1. Protected records are designated at the record level, so the system knows which material is subject to Part 2 rather than relying on a person remembering.
  2. Consent is a record with fields, not a scanned PDF in a document folder — recipient, purpose, scope, and expiry all machine-readable.
  3. Every export path respects scope. Referrals, audit packets, API responses, and manual downloads all filter against the active consent, because the one that does not is the one that leaks.
  4. Disclosures are logged. Who received what, under which consent, on what date — producible when a disclosure is later questioned.
General information, not legal advice

Part 2 has changed materially in recent years and continues to be interpreted. Compliance dates, penalty structures, and the interaction with state law vary. Use this as orientation and your counsel or compliance officer for decisions.

The practical test

Pick a patient with an active release. Ask someone on your team to produce exactly what that consent authorises — no more — and time it. If the answer involves opening the full chart and deciding by hand what to remove, the control is a person's attention, and attention fails on the busy days.

ProbityCare

Written by the ProbityCare team — two founders, one of whom runs a treatment center, working alongside a clinic director with three decades in behavioral health and the founder of a revenue cycle management firm. More about us →

Get started

Start today, or take a look first.

Create an account in minutes. Or book a 30-minute walkthrough.

Register now