Cybersecurity: 24/7/365

A behavioral health practice sends a patient summary to a referring physician. Routine, permitted under HIPAA, done a hundred times a week across the country.
If that practice is a Part 2 program and the summary identifies the patient as receiving substance use disorder treatment, it may have just made an unlawful disclosure. HIPAA allows it. Title 42 of the Code of Federal Regulations does not.
42 CFR Part 2 is the rule most behavioral health practices know exists and few have configured their systems around. The February 2024 final rule changed enough that even practices with a Part 2 programme built years ago need to look again.
Part 2 is formally the Confidentiality of Substance Use Disorder Patient Records regulation. It protects the identity, diagnosis, and treatment records of anyone receiving SUD treatment from a federally assisted programme.
It exists because of a specific harm. Records showing someone sought addiction treatment have been used against them in employment, housing, custody, and prosecution. Congress decided that fear of exposure should not deter people from treatment. So it built protections stronger than ordinary medical confidentiality.
That reasoning is a public health judgement, not just a privacy one. Substance use disorders are treatable, but treatment only works if people present for it. So the rule accepts friction in information sharing as the price of keeping patients in care.
The rule is administered by the Substance Abuse and Mental Health Services Administration, part of the Department of Health and Human Services. It sits alongside the Health Insurance Portability and Accountability Act rather than replacing it — a Part 2 programme complies with both, and where they differ, the stricter applies.
This is the question most practices get wrong, in both directions. Part 2 does not cover everyone who treats addiction, and it covers some who do not think of themselves as a treatment programme.
You are a Part 2 programme if you are federally assisted and you meet the programme definition. Federal assistance is broad — it includes Medicare or Medicaid participation, DEA registration to dispense controlled substances for SUD treatment, federal grant funding, and tax-exempt status. Almost every organisation touching addiction treatment meets it.
The programme definition is where the line actually falls:
So a family practice that occasionally treats a patient with an addiction is generally not a Part 2 programme. The same practice that opens an advertised medication-assisted treatment clinic with dedicated staff generally is. If you employ a prescriber whose identified role is addiction treatment, look carefully — that third category catches practices that assumed they were outside the rule.
Yes, in the ways that matter operationally.
HIPAA permits disclosure of protected health information for treatment, payment, and healthcare operations without patient consent. Part 2 historically did not. Under Part 2, disclosure of patient records generally requires the patient's written consent — including to another treating clinician.
Two further differences catch people out. Part 2 protects the fact of treatment itself, so even confirming that a named person is a patient is a disclosure. And a subpoena is not sufficient authority to release Part 2 records: absent consent, disclosure to a court generally requires a court order meeting specific criteria, after a hearing. Staff trained on HIPAA will hand over records on a subpoena, because under HIPAA that can be appropriate. Under Part 2 it is a violation.
The final rule published in February 2024 aligned Part 2 much more closely with HIPAA, with a compliance date of February 16, 2026. Four changes matter most.
Single consent for treatment, payment, and operations. A patient may now give one written consent covering all future uses and disclosures for TPO, rather than a separate consent form for each disclosure. This is the largest practical change and the reason many programmes rewrote their consent form.
HIPAA breach notification now applies to Part 2 records. Previously Part 2 had no breach notification requirement of its own. A data breach involving SUD treatment records now follows the same notification path as any other PHI breach.
Patient right to an accounting of disclosures, bringing Part 2 in line with HIPAA's individual rights.
Redisclosure rules relaxed for TPO where a single consent is in place. The prohibition on using records against the patient in legal proceedings stays, absent specific consent or a court order.
Alignment is not merger. Consent is still required where HIPAA would not require it, and the litigation protections remain distinctly stronger.
Everything above turns into one technical requirement. Your systems have to treat Part 2 records differently from the rest of the chart, and most electronic health record systems do this badly.
What a compliant setup needs:
Ask your EHR vendor directly whether the system supports Part 2 segmentation. Ask for a reference site running it. "We support behavioural health" is not the same answer. Where a system cannot segment, practices end up running the SUD programme in a separate instance — workable, but it fragments patient information and creates its own risks.
Health information exchanges deserve specific attention. If your practice participates in one, confirm what it does with Part 2 data. Sending protected records to an exchange without appropriate consent is a straightforward violation, and the default configuration is not always safe.
Anyone processing Part 2 records on your behalf needs the same scrutiny you give a business associate under HIPAA, plus the Part 2 specifics. Your business associate agreement should acknowledge Part 2 obligations explicitly rather than referencing HIPAA alone — our BAA guide covers the baseline that agreement has to meet.
Retention follows the same logic as the rest of your records programme. The added constraint is that Part 2 records stay protected for their whole life, backups and archives included. Fold them into the schedule described in our guide to HIPAA record retention, and make sure whoever destroys records knows these carry extra restrictions.
Telehealth adds a further layer, since much behavioral health care is now delivered remotely. The platform holding those sessions is handling Part 2 records — see our telehealth compliance guide for the baseline requirements.
Answer the threshold question first, in writing: is any part of this practice a Part 2 programme? Get that determination documented, because everything else depends on it and "we assumed not" is a poor position after the fact.
If the answer is yes, work through four things. Update the consent form to the single-consent model. Confirm your EHR can segment SUD treatment records and enforce consent at disclosure. Train staff specifically on subpoenas versus court orders, and on never confirming patient status by phone. Then add Part 2 to your risk assessment as its own line rather than folding it into general HIPAA compliance.
Behavioral health practices carry a heavier confidentiality burden than the rest of medicine. The patient privacy stakes are real: the whole point of the rule is that exposure keeps people out of treatment. Systems built only to HIPAA will not meet it.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.