Back to All Articles

Blog

42 CFR Part 2 Rule Explained for Providers

August 10, 2026

42 CFR Part 2 Rule Explained for Providers

Hands placing confidential records in lockbox

42 CFR Part 2 is the federal regulation that protects the confidentiality of substance use disorder (SUD) diagnosis, treatment, and referral records maintained by federally assisted programs, and as of February 16, 2026, full compliance with the 2024 Final Rule updates is required. The Office for Civil Rights (OCR) now enforces Part 2 with civil and criminal penalties aligned to HIPAA standards.

Three things every provider and administrator should know right now:

  • Consent is the default. Disclosing SUD records without written patient consent is prohibited except in a narrow set of statutory exceptions. The 2024 Final Rule adds a single TPO (treatment, payment, and health care operations) consent option, but that consent does not unlock use in legal proceedings.
  • Redisclosure limits survive the TPO consent. A covered entity that receives Part 2 records under a valid TPO consent still cannot redisclose those records for civil, criminal, administrative, or legislative proceedings without a separate patient consent or a qualifying court order.
  • HIPAA and Part 2 now share an enforcement framework, but Part 2 remains the stricter standard. Where the two regimes conflict, Part 2 controls.

Key Takeaways

42 CFR Part 2 requires written patient consent for most SUD record disclosures, and as of February 16, 2026, OCR enforces compliance with civil and criminal penalties aligned to HIPAA.

Point Details
Consent is the default rule Written consent is required for nearly all Part 2 disclosures; the 2024 Final Rule adds a single TPO consent option but does not eliminate consent as the baseline.
Redisclosure limits remain strict Recipients of Part 2 records under a TPO consent cannot redisclose those records for legal proceedings without a separate consent or qualifying court order.
OCR now enforces Part 2 As of the February 16, 2026 compliance deadline, OCR handles Part 2 complaints and investigations with HIPAA-aligned civil and criminal penalties.
Breach notification now applies Part 2 programs must follow HIPAA’s Breach Notification Rule for unsecured SUD records, including the 60-day notification window.
Update NPPs, consents, and QSOAs Programs that have not revised their Notices of Privacy Practices, consent forms, and QSOA templates since the 2024 Final Rule are currently out of compliance.

Table of Contents

What does 42 CFR Part 2 cover, and who does it apply to?

The regulation protects any information that could identify a person as having or having had a SUD, including records of diagnosis, treatment, or referral for treatment. That scope is deliberately broad. A scheduling note that reveals a patient attends a methadone clinic is a Part 2 record. So is a billing code that flags a residential detox admission.

The statutory authority sits at 42 U.S.C. 290dd-2, and the implementing regulation is 42 CFR part 2. Under 42 CFR §2.12, the rules apply to any Part 2 program: a federally assisted program that holds itself out as providing, and actually provides, SUD diagnosis, treatment, or referral for treatment. Federal assistance includes receiving federal funds, being licensed under federal law, or operating on federal property.

Lawful holders are entities that receive Part 2 records from a program and are therefore bound by the same confidentiality obligations. That category includes:

  • Covered entities (hospitals, health systems, payers) that receive SUD records under a valid consent
  • Qualified Service Organizations (QSOs) that provide services to a Part 2 program under a written Qualified Service Organization Agreement (QSOA)
  • Business associates of those covered entities when the records involve SUD information

Real-world examples: a hospital emergency department that receives a referral note from a residential detox program is a lawful holder. A billing company under a QSOA with a Part 2 clinic is a lawful holder. A health information exchange that routes SUD records is a lawful holder.

Key regulatory anchor: 42 CFR §2.12 restricts use and disclosure of any information that “would identify a patient as having or having had a substance use disorder.” The protection attaches to the information, not just the formal record — meaning verbal disclosures and electronic flags are covered just as much as a signed intake form.

For providers like Connected Recovery, whose residential treatment programs serve adults with both SUD and co-occurring mental health disorders, understanding exactly where the Part 2 boundary sits is not optional. Every admission, every referral note, and every coordination call with a payer operates inside this framework.


Written consent is the primary mechanism for lawful disclosure under Part 2. The regulation specifies exactly what a valid consent must contain. Under the official regulatory text, a compliant consent form must include:

  • The name or general designation of the program making the disclosure
  • The name or general designation of the person or organization receiving the information
  • The name of the patient
  • The purpose of the disclosure (specific enough to limit scope)
  • How much and what kind of information will be disclosed
  • The patient’s signature and date
  • A statement that the consent is subject to revocation at any time, and the procedure for revocation
  • The date, event, or condition upon which the consent expires

The 2024 Final Rule added one significant option: a single written consent covering all future disclosures for treatment, payment, and health care operations (TPO). Before this change, a program needed a separate consent for each disclosure or category of disclosure. The TPO consent option reduces administrative friction for programs that coordinate care across multiple providers and payers.

That said, the TPO consent is permissive, not mandatory. Many programs may choose to retain more granular, purpose-specific consents to limit redisclosure risk in sensitive cases, particularly when a patient’s records could be drawn into legal proceedings. The HHS overview of Part 2 makes clear that even under a valid TPO consent, the receiving entity cannot redisclose SUD records for civil, criminal, administrative, or legislative proceedings without a separate patient consent or a qualifying court order.

A practical example: a residential program issues a TPO consent at admission. The patient’s insurer receives treatment records for billing. The insurer’s internal fraud-investigation unit cannot then use those records in a coverage dispute proceeding — the TPO consent does not extend that far. The program should document the consent, the receiving entity, and the permitted purposes, and flag the record to make clear that redisclosure for legal proceedings is prohibited.

For billing workflows, the intersection of insurance claims and Part 2 consent is a common compliance gap. The insurance billing and rehab privacy discussion at Connected Recovery covers how these consents interact with claims processing in practice.

Pro Tip: Draft TPO consent language that names the specific categories of recipients (e.g., “treating physicians, payers, and their business associates”) rather than using open-ended language like “any healthcare provider.” Narrower recipient language reduces the risk that a downstream recipient treats the consent as broader than it is.


Part 2 allows disclosure without patient consent only in a defined, narrow set of circumstances. Each exception carries its own procedural requirements, and none of them are as permissive as HIPAA’s comparable provisions.

The main exceptions under 42 CFR part 2 are:

Medical emergencies. A program may disclose records to medical personnel to the extent necessary to meet a bona fide medical emergency. The program must document the disclosure, the name of the medical personnel, and the nature of the emergency.

Hands applying oxygen mask in emergency

Research. Disclosure to qualified researchers is permitted when the researcher provides written assurances that the records will be used only for the stated research purpose, will not be redisclosed, and will be destroyed or returned when no longer needed. IRB oversight is typically expected.

Audits and evaluations. Federal, state, and local government agencies conducting audits or evaluations of Part 2 programs may receive records, but only under written assurances that the information will not be used for any other purpose and will not be redisclosed.

De-identified public health reporting. The 2024 Final Rule expanded the ability to share de-identified SUD information for public health purposes, consistent with HIPAA’s de-identification standards. The information must be stripped of all identifiers that could link it back to a specific patient.

Vital statistics. Disclosure to public health authorities for the purpose of reporting deaths is permitted.

Operational note: State law may impose stricter confidentiality requirements than Part 2. When state law is more protective, it controls. Programs operating in states with their own SUD confidentiality statutes should map those requirements against Part 2 and apply whichever standard is more restrictive. The NCSACW Fact Sheet on the 2024 Final Rule provides useful guidance on permitted disclosures for research, audits, and public health reporting under the updated framework.

One exception that does not exist under Part 2: routine law-enforcement disclosure. Unlike HIPAA, Part 2 does not permit disclosure to law enforcement simply because a government agency requests it. That distinction matters enormously in practice, and it is covered in the next section.


How do subpoenas and court orders work under Part 2?

Part 2’s protections against use in legal proceedings are among its most distinctive features. The regulation bars use or disclosure of SUD patient records in any criminal prosecution or investigation of a patient without explicit written consent or an authorizing court order. That prohibition applies even when law enforcement presents a valid subpoena.

The HHS Fact Sheet on the 2024 Final Rule confirms that the Final Rule added a safe-harbor for investigative agencies that act with reasonable diligence in determining whether records are subject to Part 2 before seeking disclosure. Providers should document any improper demand and the steps taken to protect records.

When your program receives a subpoena, court order, or law-enforcement request involving SUD records, follow this sequence:

  1. Verify Part 2 applicability. Confirm the records at issue are Part 2 records (they identify a person as having or having had a SUD and were created by or for a Part 2 program).
  2. Do not disclose pending legal review. A subpoena alone does not authorize disclosure under Part 2. Stop the process and escalate.
  3. Notify legal counsel immediately. Route the request to your program’s attorney or records custodian before any response is prepared.
  4. Confirm notice and opportunity to be heard. Part 2 requires that the patient and the program receive notice and an opportunity to be heard before a court order compelling disclosure is issued. Confirm this procedural protection is in place.
  5. Assess whether a qualifying court order exists. A court order authorizing disclosure under Part 2 must meet specific criteria beyond a standard subpoena, including a finding that the public interest and the need for disclosure outweigh the potential injury to the patient.
  6. Redact non-pertinent information. If disclosure is ultimately compelled, disclose only the minimum necessary information responsive to the order.
  7. Document everything. Record the request, the date received, the legal review process, the decision made, and the basis for that decision.

When referring a request to counsel, a short written response to the requesting party works well: “The records you have requested may be subject to the confidentiality protections of 42 CFR Part 2. We are unable to confirm or deny the existence of such records or produce them without a court order meeting the requirements of 42 CFR §2.61 or a valid patient consent. Please direct further inquiries to [program legal counsel / records custodian].”


How does Part 2 compare to HIPAA, and where do the rules diverge?

The 2024 Final Rule brought Part 2 and HIPAA closer together on enforcement and breach notification, but Part 2 remains the stricter standard wherever the two overlap. Legal experts view the alignment as reducing administrative friction without eliminating the core protections that make Part 2 distinct. For a deeper look at how HIPAA operates in rehab settings specifically, the HIPAA protections in rehab programs overview at Connected Recovery is a useful companion read.

Dimension 42 CFR Part 2 HIPAA
Consent for disclosure Written consent required for most disclosures; TPO single consent now permitted Authorization required for most disclosures; TPO disclosures generally permitted without authorization
Redisclosure by recipient Strictly limited; recipient bound by same restrictions; legal proceedings require separate consent or court order Permitted for treatment, payment, operations; minimum-necessary standard applies
Breach notification Now aligned with HIPAA Breach Notification Rule (post-2024 Final Rule) Breach Notification Rule under HITECH; 60-day notification window
Enforcement authority OCR (post-2024 Final Rule); civil and criminal penalties aligned with HIPAA OCR; civil monetary penalties and criminal prosecution
Law-enforcement disclosure Prohibited without consent or qualifying court order Permitted in limited circumstances without patient authorization

The enforcement shift is significant. Before the 2024 Final Rule, Part 2 had its own separate penalty structure enforced through the Department of Justice. Now OCR handles complaints and investigations, and the penalty framework mirrors HIPAA. That means organizations already operating HIPAA compliance programs can integrate Part 2 into the same infrastructure, but they must not assume HIPAA compliance equals Part 2 compliance. The consent and redisclosure rules are still more restrictive.

On breach notification: as of the February 16, 2026 compliance date, Part 2 programs must follow HIPAA breach-notification procedures for unsecured SUD records. Smaller SUD clinics that historically operated outside HIPAA’s breach-reporting requirements now need incident-response playbooks and updated vendor contracts. The Mondaq guidance on practical compliance steps is worth reviewing for clinics building these workflows from scratch.


What changed in the 2024 Final Rule, and why does February 16, 2026 matter?

HHS published the 2024 Final Rule to modernize Part 2 and reduce friction between it and HIPAA, while preserving the core protections that distinguish SUD records from general medical records. The HHS overview of the Final Rule summarizes the changes and their rationale.

The major operational changes are:

Single TPO consent option. Programs may now obtain one written consent at admission covering all future disclosures for treatment, payment, and health care operations. This replaces the prior requirement for separate consents for each disclosure or category.

De-identified public health disclosures. The Final Rule expanded the ability to share de-identified SUD data for public health purposes, consistent with HIPAA’s de-identification standards.

Breach notification alignment. Part 2 programs are now subject to HIPAA’s Breach Notification Rule for unsecured SUD records, including the 60-day notification window and the requirement to notify affected individuals, HHS, and (for large breaches) the media.

OCR enforcement and penalty alignment. OCR now enforces Part 2 with the same civil and criminal penalty tiers as HIPAA. Individuals may file complaints directly with OCR.

Safe-harbor for investigative agencies. Agencies that act with reasonable diligence to determine whether records are subject to Part 2 before seeking disclosure receive a safe-harbor from certain penalty provisions.

Compliance timeline: The Final Rule was published in 2024. The compliance deadline for all covered entities and Part 2 programs was February 16, 2026. As of that date, programs that have not updated their Notices of Privacy Practices, consent forms, QSOA templates, and breach-notification procedures are out of compliance and subject to OCR enforcement. The Snell & Wilmer compliance guidance flagged these specific documents as the priority update targets ahead of the deadline.

The distinction between the rule’s effective date and the compliance deadline matters for audit purposes. The rule was effective before February 2026, but programs had a grace period to implement operational changes. That grace period is now closed.


What changed in the 2024 Final Rule, and why does February 16, 2026 matter? — overview diagram

A practical compliance checklist for Part 2 programs and lawful holders

The February 16, 2026 deadline has passed. If your program has not completed these steps, they are overdue. Work through them in priority order.

  1. Update your Notice of Privacy Practices (NPP). Under 42 CFR §2.22, programs must give patients a written notice at admission describing permitted uses and disclosures and patient rights. Your NPP must now include the non-delegable Part 2 language alongside any HIPAA NPP language. A combined NPP is permissible, but the Part 2-specific disclosures cannot be omitted or buried. The Connected Recovery HIPAA Notice illustrates how these notices can be structured for a residential SUD program.
  2. Revise consent forms to reflect the TPO option. Decide whether your program will adopt the single TPO consent or retain purpose-specific consents. Document that decision and the rationale. Update all consent templates accordingly, and train intake staff on the new forms.
  3. Revise QSOA templates. Every Qualified Service Organization Agreement must reflect the updated Part 2 obligations, including breach-notification responsibilities and the prohibition on redisclosure for legal proceedings.
  4. Implement breach-notification protocols. Build or update an incident-response playbook that covers: identification of a potential breach of unsecured SUD records, internal escalation, the 60-day notification window, notification to affected individuals, HHS reporting, and media notification for breaches affecting 500 or more individuals in a state.
  5. Update EHR segmentation and flags. Flag Part 2 records in your electronic health record system to prevent inadvertent disclosure. Many EHR platforms support record segmentation; confirm your configuration restricts access and export of SUD records consistent with Part 2.
  6. Document redisclosure handling. Create a written policy specifying that recipients of Part 2 records under a TPO consent may not redisclose those records for legal proceedings. Include this restriction in outgoing disclosure cover sheets and in QSOA language.
  7. Maintain audit logs. Log every disclosure of Part 2 records: date, recipient, purpose, consent or exception relied upon, and the name of the staff member who authorized the disclosure. Retention periods should align with your state’s medical records retention requirements, at minimum.
  8. Train staff. Training should cover: who is a Part 2 program and what records are covered; consent requirements and the TPO option; the prohibition on law-enforcement disclosure without consent or court order; breach-notification obligations; and how to respond to subpoenas and legal demands. Train all clinical, administrative, and billing staff at onboarding and at least annually thereafter.
  9. Review vendor contracts. Confirm that all business associates and QSOs have signed updated agreements that reflect Part 2 obligations, including breach notification and redisclosure limits.
  10. Schedule a periodic compliance review. Set a calendar reminder for an annual Part 2 compliance review, including a check of any OCR guidance updates, state law changes, and any complaints or incidents from the prior year.

Pro Tip: When updating your NPP, include a plain-language header that specifically identifies the document as a combined HIPAA and Part 2 notice. Practitioners who skip this step often produce a HIPAA-compliant NPP that fails the non-delegable Part 2 language requirement under §2.22, which is one of the most common compliance gaps OCR is likely to flag.

For programs coordinating medication-assisted treatment alongside residential care, the intersection of MAT records, billing disclosures, and Part 2 consent is a particularly high-risk area. Confirm that MAT-related records are flagged and that consent forms explicitly address their disclosure to prescribing physicians and payers.


Why strict confidentiality is central to Connected Recovery’s practice

At Connected Recovery, the confidentiality protections in 42 CFR Part 2 are not just a compliance obligation. They are foundational to the trust that makes treatment possible. Patients entering our residential treatment program in Van Nuys need to know that their records will not surface in a criminal proceeding, a custody dispute, or an employer background check. That assurance is what the regulation was designed to provide, and it is what we work to deliver operationally every day.

The 2024 Final Rule updates required us to revisit consent forms, QSOA agreements, and breach-notification workflows, and those updates are now in place. For providers still working through their own compliance gap analysis, or for legal counsel advising SUD programs on the operational implications of Part 2, Connected Recovery’s clinical leadership is available to discuss program-level implementation questions.

Connected Recovery

If you are evaluating treatment options for yourself or a family member and want to understand exactly how your records are protected, our confidential admissions process explains the steps from first contact through admission.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

These are the primary sources to share with legal counsel or use when confirming regulatory language:


Connected Recovery Inc.

DHCS Licensed · Joint Commission Accredited

If you or a loved one is struggling with substance use, our admissions team is available to verify your insurance benefits and help you begin recovery. All calls are confidential.