42 CFR Part 2 Compliance: What SUD and Behavioral Health Providers Actually Need to Know in 2026
Mental & Behavioral Health

42 CFR Part 2 Compliance: What SUD and Behavioral Health Providers Actually Need to Know in 2026

Shivani Jain
Certified Healthcare Trainer, Mindbowser
TL;DR

42 CFR Part 2 protects substance use disorder (SUD) patient records, and it’s stricter than HIPAA in ways that trip up organizations that assume HIPAA compliance covers them. The 2024 final rule (effective April 16, 2024, enforcement live since February 16, 2026) closed some of that gap by allowing a single blanket consent for treatment, payment, and operations, but Part 2 still requires consent for disclosures HIPAA wouldn’t blink at. The two questions that matter most: are you actually a “Part 2 program” under the federal test, and does your records system enforce the redisclosure rule the way §2.32 requires. Getting those two right doesn’t cover everything below (duty to warn, valid consent forms, and legal process each carry their own traps), but it’s the starting point most organizations get wrong first.

The Question That Trips Up the Most People

In the HIPAA and Part 2 trainings I’ve run for behavioral health staff over the past two years, the question that comes up most isn’t “what counts as a violation.” It’s “does this even apply to us.” And the confident wrong answers I hear almost always go the same direction: staff assume Part 2 only covers dedicated addiction treatment centers, methadone clinics, the places with “recovery” or “SUD” in the name.

That assumption is wrong often enough to matter. A general hospital with an identified SUD unit is a Part 2 program for that unit. A primary care practice that takes Medicaid and has a nurse who “holds herself out” as providing SUD counseling, even informally, can trip the federal test. I’ve sat across from compliance officers who ran a full HIPAA risk assessment, felt good about their privacy posture, and had no idea Part 2 applied to them at all until an EHR vendor asked about it during implementation.

Enforcement is no longer theoretical. The Office for Civil Rights’ compliance deadline for the 2024 final rule was February 16, 2026, five months ago as of this writing, and Part 2 violations now carry the same penalty structure as a HIPAA breach: up to $2.1 million per violation category, not the flat $500 the old rule used to cap at. So the “does this apply to us” question isn’t academic anymore. Let’s start there.

42 CFR Part 2 enforcement penalties, OCR compliance deadline, and policy gaps.
Fig 1: 42 CFR Part 2 enforcement penalties, OCR compliance deadline, and policy gaps.

Who Is Actually a “Part 2 Program”? The Two-Part Test Most Organizations Get Wrong

The federal definition (42 CFR §2.11) runs on a two-part test, and an organization has to fail both parts to be safely outside Part 2’s reach.

Part one: federally assisted. This is broader than most people expect. It’s not just “receives a SAMHSA grant.” Federal assistance includes Medicare or Medicaid participation, tax-exempt status, and DEA registration to dispense controlled substances for SUD treatment. If your organization takes Medicaid, that box is almost certainly checked, regardless of how you’d describe your funding.

Part two: “holds itself out as providing” SUD diagnosis, treatment, or referral for treatment. This is the part that actually decides most cases, and it’s a behavior test, not a name test. The regulation doesn’t care what’s on your letterhead. It asks whether a reasonable person, looking at what the entity actually does, would conclude it offers SUD services. An identified SUD unit inside a general medical facility counts. A telehealth medication-assisted treatment (MAT) provider counts, obviously, but so does a primary care group where one clinician routinely handles buprenorphine inductions even if that’s not the practice’s stated specialty.

Two worked examples I use in training, because they’re the ones that actually change minds:

A 200-bed community hospital with a dedicated 12-bed detox unit is a Part 2 program for that unit, even though the rest of the hospital operates under HIPAA only. The records system has to be able to draw that line, which is a real technical requirement, not just a policy one.

A behavioral health group that bills Medicaid and has one physician regularly prescribing buprenorphine, without a formal “SUD program” designation anywhere in its org chart, can still meet the holds-itself-out test once that prescribing pattern becomes how the practice actually operates, there’s no specific patient-count threshold in the regulation itself, it’s a facts-and-circumstances test. I’ve watched compliance officers argue this point and lose.

If either test fails, honestly, you’re likely not a Part 2 program, and HIPAA’s rules govern instead. But given how broad the federally-assisted prong is, most SUD-adjacent organizations end up covered.

Flowchart explaining how to determine if an organization is covered by 42 CFR Part 2.
Fig 2: Flowchart explaining how to determine if an organization is covered by 42 CFR Part 2.

What Changed in 2024, and What Didn’t

The 2024 final rule (89 FR 12472, effective April 16, 2024) narrowed the gap between Part 2 and HIPAA, but it didn’t close it, and the distinction matters for how you configure consent workflows.

Before 2024, Part 2 had no treatment/payment/operations (TPO) exception at all. Every single disclosure, even routine care coordination between a patient’s SUD counselor and their primary care doctor, needed specific patient consent. HIPAA never required this for TPO. That gap was the single biggest operational headache Part 2 created for integrated care teams.

The 2024 rule fixed part of it: providers can now get one blanket consent that covers all future TPO uses and disclosures, instead of a new consent every time. That’s the change most compliance summaries lead with, and it’s real. But here’s the part that gets glossed over: Part 2 still requires that consent exist in the first place. HIPAA doesn’t require any consent for TPO. So the rule made Part 2 more workable, not equivalent to HIPAA. If your system logic treats “we got blanket consent once” as “now this patient’s data behaves like any other patient’s data,” that’s wrong, and it’s the kind of wrong that shows up in an audit.

Three other 2024 changes worth knowing: patients gained a HIPAA-parallel right to an accounting of disclosures and a right to restrict disclosure to health plans for self-pay services. Breach notification now follows HIPAA’s Breach Notification Rule timeline, generally 60 days. And one thing the rule explicitly does not require: data segmentation. I want to be direct about this because I’ve heard vendors imply otherwise. Nothing in the 2024 final rule mandates that Part 2 data live in a technically separated system from the rest of a patient’s record. Segmentation is a design choice some organizations make to simplify consent enforcement, not a federal requirement.

Comparison of 2024 Part 2 Final Rule changes and unchanged compliance requirements.
Fig 3: Comparison of 2024 Part 2 Final Rule changes and unchanged compliance requirements.

The Redisclosure Rule Is Where Most Violations Actually Happen

If I had to name the single provision that causes the most real-world violations, it’s not the consent requirement. It’s redisclosure, governed by 42 CFR §2.32.

Once a recipient legitimately receives Part 2-protected records, with consent, they generally can’t turn around and redisclose that information further without a separate, specific consent covering that redisclosure, unless a distinct exception applies. Every disclosure of Part 2 data has to carry a notice telling the recipient this. The rule updated the required notice language in 2024 to a shorter standard form: “42 CFR Part 2 prohibits unauthorized use or disclosure of these records.”

Here’s the 2024 change that matters most for HIPAA-covered organizations working alongside Part 2 programs: if a HIPAA-covered entity or business associate lawfully received SUD records through a valid Part 2 consent, it can now redisclose that information for TPO purposes the same way HIPAA would permit, without needing a fresh Part 2 consent for every downstream disclosure. That’s a genuine simplification, and it’s the piece of the 2024 rule I’d argue actually reduces administrative burden rather than just documenting it differently.

But the failure mode I see most often in practice: a records system passes SUD data to a downstream provider correctly, with consent, and then that provider’s own system redisclose it again, to a specialist, a lab, a billing vendor, without checking whether the original consent covered that further step, and without attaching the required notice. “We didn’t realize it was Part 2 data” is not a defense the regulation recognizes. If your system can’t flag Part 2-origin data as it moves downstream, that’s the gap that actually generates enforcement exposure, not the initial consent step everyone focuses on.

Diagram showing unauthorized redisclosure risks under 42 CFR Part 2 Section 2.32.
Fig 4: Diagram showing unauthorized redisclosure risks under 42 CFR Part 2 Section 2.32.

Preparing Your Organization For 42 CFR Part 2 Requirements?

Duty to Warn Under Part 2 Isn’t What Most People Think

This is worth its own section because it’s the single most consistently misunderstood point I run into in training, and it’s a real search question people bring to Google, not a hypothetical.

Many clinicians assume Part 2 has a Tarasoff-style duty to warn: if a patient poses a serious threat to someone, you can identify them and alert the intended target or authorities, the same latitude most state laws give clinicians outside the SUD context. That’s not quite what Part 2 permits.

Part 2 does allow disclosure to prevent or lessen a serious and imminent threat to health or safety, including contacting law enforcement or other authorities. But the disclosure cannot identify the person as a patient receiving SUD treatment. You can act to prevent the harm. You generally cannot, in that same act, reveal that the person is in SUD treatment, because that disclosure isn’t covered by the exception, it’s a separate Part 2-protected fact.

In practice, this means a clinician can call 911 and say a specific threat exists at a specific location, but has to be careful about how much of the clinical context, specifically the SUD treatment relationship, gets volunteered in that call. It’s a narrower exception than most training materials present it as, and I’ve watched experienced clinicians get this wrong in role-play exercises because the instinct to just explain everything, including why they know what they know, is strong under pressure.

Allowed and prohibited disclosures under 42 CFR Part 2 duty-to-warn exceptions.
Fig 5: Allowed and prohibited disclosures under 42 CFR Part 2 duty-to-warn exceptions.

Court Order vs. Subpoena: Why the Difference Matters When Someone Comes Asking

Legal process is another area where the mechanics matter more than the general rule.

A Part 2 court order, issued under §2.61 through §2.65, only authorizes disclosure of Part 2 records. It does not, by itself, compel anyone to produce them. A subpoena, by contrast, is a compulsory legal instrument, but a subpoena alone, without a matching Part 2 court order, cannot force disclosure of Part 2-protected records. You generally need both: a valid court order that specifically meets Part 2’s procedural requirements (which include a hearing and specific findings a judge must make) AND a subpoena or other compulsory process.

The practical upshot: if your organization receives a subpoena for Part 2 records with no accompanying court order that meets §2.61’s standards, the correct answer is usually to decline, not comply. That’s a legal determination your counsel should make, not a front-desk or medical-records-staff judgment call, but staff need to know enough to route the request correctly instead of producing records under pressure because “it’s a subpoena, it looks official.”

What a Valid Consent Form Actually Has to Include

Section 2.31 spells out required elements, and I’ve reviewed enough consent forms in audits to know where organizations cut corners.

A compliant Part 2 consent needs: the patient’s name; who or what class of entity is authorized to disclose; a specific description of the information being disclosed, not a blanket “all records”; the name or class of the recipient; the purpose of the disclosure; an expiration date or event; and a clear statement of the patient’s right to revoke the consent in writing, along with how to do so. Since the 2024 rule, “treatment, payment, and healthcare operations” is now an acceptable purpose description for the new blanket consent option, which used to require narrower purpose language. If a disclosure involves fundraising, the form needs an explicit opt-out statement.

The most common mistake I see isn’t a missing signature. It’s vague information description, forms that say “SUD treatment records” without specifying what that covers, which creates ambiguity about whether a given disclosure was actually authorized when it’s reviewed later.

Seven required elements of a valid 42 CFR Part 2 patient consent form.
Fig 6: Seven required elements of a valid 42 CFR Part 2 patient consent form.

What This Means for the Systems Behind Your Records

Everything above is a legal and operational requirement. None of it enforces itself. A records system that’s technically HIPAA-compliant doesn’t automatically do the things Part 2 actually requires: flagging which patients and which data originated under Part 2 consent, tracking what a specific consent actually authorizes and for how long, attaching the redisclosure notice automatically whenever Part 2-origin data moves to a new recipient, and applying the 60-day breach-notification clock consistently with everything else in the record.

This is also where the RCM side of this intersects, since billing and coding for behavioral health services touches the same consent boundaries. If your billing workflows aren’t accounting for Part 2 consent scope, that’s worth reviewing alongside the clinical documentation side; Mindbowser’s behavioral health RCM guide covers the billing-specific mechanics that sit next to this.

None of this is exotic engineering. It’s closer to a well-defined access-control and audit-logging problem layered on top of whatever EHR or practice-management system a program already runs. But it does need to be built deliberately, because most off-the-shelf behavioral health software treats consent as a checkbox rather than a scoped, expiring, auditable authorization tied to specific data and specific recipients.

How Mindbowser Helps

We’ve built PHI de-identification tooling through PHISecure that strips all 18 HIPAA identifiers from clinical data, including DICOM imaging, video, and document formats. That covers the technical de-identification piece a program needs if it wants to contribute data to a research effort under §2.52’s exception, a real, existing capability, not a custom build from scratch, though the exception itself has other conditions (IRB review, safeguards against re-identification for law enforcement purposes) that de-identification tooling alone doesn’t satisfy.

Let me be specific about where that accelerator’s reach actually ends, though. PHISecure handles de-identification. It does not, on its own, track which patient records carry live Part 2 consent, enforce redisclosure notices as data moves between systems, or manage consent expiration. Those are consent-tracking and audit-trail problems specific to how a given organization’s records flow, and there’s no off-the-shelf accelerator that covers that whole problem, because the correct architecture depends on which EHR, which referral partners, and which billing systems a program already has in place. That’s genuinely custom integration work: mapping consent scope to data access rules inside the specific systems a program runs, building the redisclosure-notice logic into the data-sharing points that actually exist in that program’s workflow, and setting up audit logging that can answer “was this specific disclosure authorized” months after the fact.

If you’re evaluating whether your current systems handle this correctly, or building new SUD-specific software from the ground up, that’s a conversation worth having before a gap turns into an OCR finding.

Closing

Part 2 compliance mostly fails in the gap between what a policy document says and what the underlying systems actually enforce. Getting the “are we even covered” question right, and building consent, redisclosure, and audit logic into the systems your staff use every day rather than into a binder nobody reads during an audit, is what actually reduces exposure. If that gap sounds familiar in your organization, request an assessment and we’ll walk through where your current systems stand against it.

What is 42 CFR Part 2?

A federal regulation protecting the confidentiality of substance use disorder patient records held by federally assisted programs. It generally requires patient consent for disclosure in situations where HIPAA alone would not, and it restricts how recipients of that data can redisclose it further.

How is 42 CFR Part 2 different from HIPAA?

The core difference is consent. HIPAA permits disclosure for treatment, payment, and healthcare operations without patient authorization. Part 2 has always required consent for these disclosures; the 2024 final rule made that easier by allowing one blanket consent instead of repeated ones, but it didn’t remove the consent requirement itself. Part 2 also imposes a redisclosure prohibition that HIPAA doesn’t have in the same form.

Who is required to comply with 42 CFR Part 2?

Organizations that meet a two-part federal test: they receive federal assistance (which includes Medicare/Medicaid participation, tax-exempt status, or DEA registration for controlled substances), and they hold themselves out as providing SUD diagnosis, treatment, or referral for treatment. This can include a specific unit inside a larger organization that is otherwise governed only by HIPAA.

Does 42 CFR Part 2 have a duty-to-warn exception?

A narrow one. Part 2 permits disclosure to prevent or lessen a serious, imminent threat to health or safety, but the disclosure cannot identify the person as receiving SUD treatment. It is not the same latitude many state duty-to-warn laws provide outside the SUD context.

Does 42 CFR Part 2 require data segmentation?

No. The 2024 final rule does not mandate that Part 2-protected data be technically segmented from the rest of a patient’s record. Segmentation is an implementation choice some organizations use to simplify consent enforcement, not a federal requirement.

Frequently Asked Questions

A federal regulation protecting the confidentiality of substance use disorder patient records held by federally assisted programs. It generally requires patient consent for disclosure in situations where HIPAA alone would not, and it restricts how recipients of that data can redisclose it further.

The core difference is consent. HIPAA permits disclosure for treatment, payment, and healthcare operations without patient authorization. Part 2 has always required consent for these disclosures; the 2024 final rule made that easier by allowing one blanket consent instead of repeated ones, but it didn’t remove the consent requirement itself. Part 2 also imposes a redisclosure prohibition that HIPAA doesn’t have in the same form.

Organizations that meet a two-part federal test: they receive federal assistance (which includes Medicare/Medicaid participation, tax-exempt status, or DEA registration for controlled substances), and they hold themselves out as providing SUD diagnosis, treatment, or referral for treatment. This can include a specific unit inside a larger organization that is otherwise governed only by HIPAA.

A narrow one. Part 2 permits disclosure to prevent or lessen a serious, imminent threat to health or safety, but the disclosure cannot identify the person as receiving SUD treatment. It is not the same latitude many state duty-to-warn laws provide outside the SUD context.

No. The 2024 final rule does not mandate that Part 2-protected data be technically segmented from the rest of a patient’s record. Segmentation is an implementation choice some organizations use to simplify consent enforcement, not a federal requirement.

Shivani Jain

Shivani Jain

Certified Healthcare Trainer, Mindbowser

Connect Now

Shivani Jain is a Certified Healthcare Trainer at Mindbowser. She has 15+ years of experience in healthcare operations and learning and development, with deep expertise in HIPAA compliance training, clinical workflow design, and NABH accreditation.
She has built and delivered training frameworks for US healthcare workflows, led clinical quality control initiatives, and serves as Mindbowser’s domain authority on healthcare compliance and patient safety education.

Share This Blog

Read More Similar Blogs

Let’s #Transform Healthcare,# Together.

Partner with us to design, build, and scale digital solutions that drive better outcomes.

Location

Global Tech Teams LLC, 525 Washington Blvd, Industrious at Newport Tower, Jersey City, NJ 07310, United States.

Contact

+1 408 786 5974
contact@mindbowser.com
BOOK A QUICK CONSULTATION

Have a Healthcare Project in Mind?

Let’s discuss your goals, workflows, and next steps in a focused consultation call.

Calendar icon Schedule a Call

Contact form