Back to All Articles

Blog

Substance Use Privacy Rights for Patients: What You Need to Know

August 4, 2026

Substance Use Privacy Rights for Patients: What You Need to Know

Woman reviewing substance use privacy documents at home

Federal law gives you specific, enforceable rights over your substance use disorder (SUD) treatment records. The two governing rules are 42 U.S.C. § 290dd-2 and its implementing regulation, 42 CFR Part 2 (universally called “Part 2”), which set the floor for confidentiality at federally assisted SUD programs. HIPAA’s Privacy Rule runs alongside Part 2 in many clinical settings, but it is the weaker of the two where SUD records are concerned. Understanding substance use privacy rights means knowing which law applies to your provider, what disclosures require your written consent, and exactly how to push back when a program gets it wrong.

Your core rights under Part 2, in plain terms:

  • Written consent required. Programs generally cannot share your SUD records without your signed, written consent that names the recipient, the purpose, and an expiration date.
  • Right to revoke. You can withdraw consent at any time, and the revocation takes effect for future disclosures.
  • Right to an accounting. You can ask the program for a record of who received your information and when.
  • Right to request restrictions. The 2024 Part 2 Final Rule added a new right, aligned with HIPAA, to ask a program to limit certain disclosures.
  • Law-enforcement protection. A standard subpoena or police request is generally not enough to access your records. Programs must refuse unless a Part 2-compliant court order is in hand.

Table of Contents

What is Part 2 and which programs and records does it cover?

Part 2 is the federal regulation that implements 42 U.S.C. § 290dd-2, the statute Congress passed specifically to protect SUD patient records from disclosure. The policy logic is straightforward: people who fear that seeking addiction treatment will expose them to criminal prosecution, job loss, or family-court consequences will avoid treatment. Part 2 removes that fear by creating confidentiality rules that are stricter than ordinary medical privacy law.

A “Part 2 record” is any information about a patient that would identify them as having or having had a substance use disorder, including their identity, diagnosis, prognosis, or treatment. The record does not have to say “substance use disorder” on its face. If it was created in connection with a Part 2 program and could be used to identify someone as a patient there, it qualifies.

What makes a program a “Part 2 program” is federal assistance. That includes opioid treatment programs (OTPs) registered with the DEA, federally funded residential and outpatient SUD programs, licensed methadone and buprenorphine providers that receive any federal funding (including Medicare or Medicaid reimbursement), and some digital health services that meet the federal-assistance threshold. The key word is any federal assistance — a single federal grant or a Medicare billing relationship can be enough to bring a program under Part 2.

Not every SUD-related service qualifies as a Part 2 program. A private-pay therapist who treats alcohol use disorder but receives no federal funding is likely covered only by HIPAA and state law, not Part 2. That distinction matters enormously in practice, so asking your provider directly is worth the 30 seconds it takes.

Infographic comparing HIPAA and Part 2 privacy protections

When a provider is both a Part 2 program and a HIPAA-covered entity

Many hospitals, integrated health systems, and large outpatient clinics are both Part 2 programs and HIPAA-covered entities. In those settings, a patient’s chart may contain a mix of general medical records (governed by HIPAA) and Part 2 records (governed by Part 2’s stricter rules). A HIPAA authorization alone does not unlock Part 2 records. The program must obtain a separate, Part 2-compliant authorization or a valid TPO consent under Part 2 rules before sharing SUD-specific information, even internally within the same health system.

Pro Tip: At your first appointment, ask two questions: “Is this program covered by 42 CFR Part 2?” and “Do you maintain Part 2 records separately from my general medical chart?” The answers tell you exactly which privacy framework protects your SUD information.

Two clinicians reviewing patient consent forms in office


What rights do you have under Part 2 as a patient?

Part 2 gives patients a defined set of rights, and programs are legally required to honor them. Here is what each right means in practice.

Written consent before disclosure. Before a Part 2 program shares your records with anyone outside the program, it must have your signed, written consent. A valid Part 2 consent must include:

  • The name or general designation of the program making the disclosure
  • The name or general designation of the recipient
  • The patient’s name
  • The purpose of the disclosure
  • How much and what kind of information will be shared
  • A statement that the patient may revoke consent at any time
  • The date, event, or condition upon which the consent expires
  • The patient’s signature and the date signed

A consent that authorizes disclosure for use in a civil or criminal legal proceeding requires a separate consent from any clinical-care consent. Programs cannot bundle those two purposes into one signature block and call it done.

Right to revoke consent. You can revoke any consent in writing at any time. Revocation stops future disclosures but does not undo disclosures that already occurred under the valid consent before you revoked it. To revoke, submit a written statement to the program, keep a dated copy, and follow up in writing if you do not receive confirmation.

Right to an accounting of disclosures. You can ask the program to tell you who received your Part 2 records, when, and for what purpose. Programs must respond within a reasonable timeframe. If a program cannot produce an accounting, that itself is a red flag worth documenting.

Right to request restrictions. The 2024 Part 2 Final Rule added this right, aligning Part 2 with HIPAA’s existing restriction-request mechanism. You can ask a program to limit disclosures beyond what Part 2 already requires. Programs are not always obligated to agree, but they must consider the request and document their response.

Right to a notice of privacy practices. Programs must give you a written notice explaining your rights, how your records may be used, and how to file a complaint. You should receive this at intake, not buried in a stack of forms you sign without reading.

Pro Tip: Keep a dated copy of every consent you sign and every revocation you submit. Note the name of the staff member you spoke with and the date. If a dispute arises later, this paper trail is your evidence.


How do HIPAA and Part 2 differ, and when does each apply?

HIPAA and Part 2 are not interchangeable, and the gap between them is where patients most often get hurt. HIPAA’s Privacy Rule governs protected health information (PHI) held by covered entities and permits a wide range of disclosures for treatment, payment, and health care operations (TPO) without patient authorization. Part 2 takes a different position: SUD records generally require written patient consent before disclosure, period.

The table below maps the key differences.

Dimension HIPAA Privacy Rule 42 CFR Part 2
Who it covers HIPAA-covered entities (providers, health plans, clearinghouses) Federally assisted SUD programs
Default consent for TPO Not required — permitted without authorization Written patient consent required (TPO consent option added by 2024 Final Rule)
Redisclosure by recipients Permitted under HIPAA rules Generally prohibited without patient consent or a Part 2-compliant court order
Law enforcement / subpoena Permitted in limited circumstances without authorization Standard subpoena generally insufficient; Part 2-compliant court order required
Patient right to accounting Yes, with exceptions Yes, strengthened by 2024 Final Rule
Patient right to request restrictions Yes Yes, added by 2024 Final Rule
Breach notification Required Required (added by 2024 Final Rule)
Notice of privacy practices Required Required; must be aligned with HIPAA notice for hybrid entities

How this plays out in real clinical settings

Consider three scenarios. A freestanding SUD specialty clinic that receives Medicaid reimbursement is a Part 2 program. Every disclosure of a patient’s SUD records requires written consent, and a routine insurance inquiry does not override that requirement. A hospital emergency room that treats an overdose patient is typically a HIPAA-covered entity but may not be a Part 2 program — so HIPAA’s TPO permissions may apply to the ER records, though any Part 2 records transferred in from a Part 2 program retain their Part 2 status. A primary-care provider who receives a patient’s Part 2 records under a valid TPO consent can use those records for treatment, but HIPAA redisclosure rules then govern what the primary-care provider does with them — with the critical limit that those records still cannot be used in legal proceedings against the patient without consent or a compliant court order.

That last point is where many providers get confused. Receiving Part 2 records under a TPO consent does not transform them into ordinary HIPAA records. The prohibition on using them against the patient in legal proceedings travels with the records. For a deeper look at how HIPAA applies specifically in rehab settings, Connected Recovery has published a plain-English breakdown of those protections.


What disclosures are permitted, and how does Part 2 protect you from law enforcement?

Part 2’s permitted disclosures are narrow by design. The law was written to give patients a credible assurance that seeking treatment would not hand prosecutors or police a roadmap to their lives.

Disclosures are permitted in these circumstances:

  • With valid written patient consent that meets all Part 2 requirements
  • Medical emergencies where disclosure is necessary to treat an immediate threat to the patient’s health
  • Research, audit, and evaluation under specific conditions, including data-use agreements and de-identification requirements
  • De-identified public health disclosures permitted under the 2024 Final Rule
  • Qualified Service Organization (QSO) agreements, where a contractor (a billing company, lab, or IT vendor) receives records only to perform services for the program and is contractually bound by Part 2 rules
  • TPO disclosures under a valid Part 2 TPO consent, allowing HIPAA-covered entities to receive and use records for treatment, payment, and operations

The law-enforcement protection in plain terms

A standard subpoena, search warrant, or routine legal request is generally not enough to access a patient’s Part 2 records. Programs are required to refuse such requests. To compel disclosure without patient consent, law enforcement or a court must obtain a Part 2-compliant court order — one that meets specific criteria set out in the regulation, including a finding that the public interest and the need for disclosure outweigh the potential injury to the patient and to the treatment relationship generally.

What does that look like in practice? If a police officer walks into a clinic and asks for a patient’s treatment records, staff must decline. If a prosecutor serves a standard subpoena, the program’s legal counsel should move to quash it unless it is accompanied by a Part 2-compliant court order. Part 2 continues to prohibit using SUD treatment records to investigate or prosecute a patient without written consent or a court order meeting those criteria.

Watch for this red flag: a program that treats a HIPAA-permissive disclosure as automatically satisfying Part 2 is wrong. HIPAA’s law-enforcement exceptions do not override Part 2’s stricter requirements. If a program tells you it shared your records with police “because HIPAA allows it,” that is worth documenting and potentially reporting.


What changed with the CARES Act and the 2024 Part 2 Final Rule?

Part 2 was largely unchanged for decades before Congress and HHS moved to modernize it. The changes that followed were significant, and patients who entered treatment before 2024 may be operating under outdated assumptions about their rights.

Event Date Practical effect for patients
CARES Act enacted March Directed HHS to align Part 2 with HIPAA; prohibited use of Part 2 records in criminal, civil, or administrative proceedings against patients without consent
Notice of Proposed Rulemaking (NPRM) December HHS published proposed changes and solicited public comment
2024 Part 2 Final Rule published February 16, 2024 Rule took effect; major patient-rights additions and HIPAA alignment provisions became operative
HHS guidance updates Ongoing post-February 2024 HHS and SAMHSA issued supplemental guidance clarifying implementation

The 2024 Final Rule made these concrete changes:

Single TPO consent option. Patients can now sign one consent covering treatment, payment, and health care operations, rather than separate consents for each purpose. This reduces paperwork without reducing protection — the TPO consent still carries Part 2’s redisclosure limits.

New patient rights. The Final Rule added the right to request restrictions on disclosures and the right to an accounting of disclosures, aligning those rights with HIPAA’s existing framework.

Breach notification. Programs must now notify patients when their Part 2 records are improperly disclosed, consistent with HIPAA’s breach-notification standards.

De-identified public health disclosures. The Final Rule created a limited pathway for programs to share de-identified SUD records with public health authorities, subject to specific conditions.

Core protections remain. The Federal Register preamble explicitly states that the rule’s provisions are severable, meaning that even if portions of the rule face legal challenge, the central prohibitions — written consent requirements and the ban on using records in legal proceedings without consent or a compliant court order — were intended to remain in force.

HHS’s stated goal was to make clinical coordination easier while keeping the high threshold for nonconsensual disclosure to courts and law enforcement. Whether that balance holds in practice depends partly on how well programs implement the new rules and how actively patients exercise their rights.


How is Part 2 enforced, and what should you do if your rights are violated?

Enforcement of Part 2 involves multiple federal actors, and the 2024 Final Rule strengthened the civil enforcement framework. Here is how to navigate it.

Who enforces what:

  • HHS Office for Civil Rights (OCR) — enforces HIPAA and, for the HIPAA-aligned provisions added by the 2024 Final Rule, may have enforcement authority over Part 2 aspects as well.

Step-by-step: how to file a complaint

  1. Consider contacting the Legal Action Center — The Legal Action Center is a nonprofit legal advocacy organization that specializes in privacy rights for people with SUD and can provide guidance on your specific situation.

What remedies are realistic: Corrective action plans are the most common outcome. Programs may be required to retrain staff, revise consent forms, or implement new record-security procedures. Civil penalties are possible for knowing violations. Injunctive relief is available in some circumstances. Timelines vary, but OCR typically acknowledges complaints within weeks and resolves them within months to years depending on complexity.


Close-up of hands writing legal complaint on patient rights

What should a compliant privacy notice from your program include?

Every Part 2 program must give patients a written notice of privacy practices at intake. This is not optional, and a program that cannot produce one on request is already out of compliance.

A compliant Part 2 patient notice should clearly state:

  • That the program is covered by 42 CFR Part 2 and that federal law protects the patient’s SUD records
  • A description of the types of disclosures the program may make and the circumstances under which each is permitted
  • The patient’s rights: to consent to or refuse disclosures, to revoke consent, to request restrictions, to request an accounting of disclosures, and to receive a breach notification if records are improperly disclosed
  • How to submit a request for restrictions or an accounting
  • The program’s breach-notification procedures
  • Contact information for filing a complaint, including the HHS/OCR complaint portal

For programs that are both Part 2 programs and HIPAA-covered entities, the notice must address both frameworks. HHS guidance provides model notice language that programs can adapt, and Connected Recovery’s HIPAA Notice of Privacy Practices is an example of how a compliant provider presents these disclosures to patients.

Broad blanket consents that authorize disclosure to any recipient for any purpose are not valid under Part 2. Each consent must name or describe specific recipients and purposes.

Bundled civil/criminal-use consents that fold authorization for legal proceedings into the same signature block as clinical-care consents are a serious problem. Those two purposes require separate consents.

Vague redisclosure language that says something like “we may share your records with our partners as permitted by law” without specifying Part 2’s limits on redisclosure should prompt questions before you sign.

If a notice or consent form reads more like a liability waiver than a patient-rights document, ask the program’s privacy officer to walk you through it line by line before you sign anything.


Practical steps to protect your records and exercise your rights

The gap between having rights and using them is usually information. These steps close that gap.

Questions to ask at intake

  • Is this program covered by 42 CFR Part 2?
  • Do you maintain Part 2 records separately from my general medical chart?
  • How do you handle TPO consents, and who can access my records under one?
  • What is your process for responding to law-enforcement requests for records?
  • How do I request an accounting of disclosures or revoke a consent I have already signed?

Sample request language you can adapt

To request your patient notice: “Please provide me with a copy of your 42 CFR Part 2 patient notice and your HIPAA Notice of Privacy Practices.”

To request an accounting of disclosures: “Pursuant to my rights under 42 CFR Part 2, I am requesting a written accounting of all disclosures of my substance use disorder records made by this program in the past [time period], including the date, recipient, and purpose of each disclosure.”

To revoke a consent: “I am revoking my consent dated [date] authorizing disclosure of my records to [recipient]. This revocation is effective immediately for all future disclosures. Please confirm receipt of this revocation in writing.”

To request a restriction: “Pursuant to my rights under 42 CFR Part 2 and the 2024 Final Rule, I am requesting that this program restrict disclosures of my records to [specific recipient or category] except as required by law.”

Protecting your records in practice

Keep copies of everything you sign at intake, including consent forms, the patient notice, and any authorization for insurance billing. Certified mail or email with read receipts creates a timestamp if you need to prove when you submitted a request or revocation. If you are concerned about third-party access through a Qualified Service Organization, you can ask the program for a copy of its QSO agreements to understand the scope of that access.

Understanding how rehab protects your professional reputation through operational confidentiality practices is also worth reviewing before you begin treatment, particularly if you have professional licensing or employment concerns.

Pro Tip: When signing intake forms, read every consent that mentions sharing with law enforcement, probation or parole officers, employers, or courts. Initial or sign next to each one separately, and keep a scanned copy. Bundled consents that lump clinical care and legal proceedings together are a red flag — ask for them to be separated before you sign.

One more practical note: if you are exploring insurance coverage for rehabilitation, understand that insurance billing itself involves some disclosure of diagnosis and treatment information. Ask your program specifically how it handles Part 2 records in the context of insurance claims and what consent it requires before billing your insurer.

For patients considering treatment and wanting to understand the confidential rehab admission process step by step, Connected Recovery has published a detailed walkthrough of what to expect from intake through discharge.


If you are ready to take the next step and want to speak with a team that treats confidentiality as a clinical priority, Connected Recovery’s residential treatment program in Van Nuys, California offers 24/7 medically supervised care in a 12-bed facility built around individualized attention. For patients who need to begin with detox, medical detox at Connected Recovery is available with full medical supervision and a clear transition plan into residential care.

Connected Recovery

This article provides general legal information about federal privacy laws and is not a substitute for legal advice. For guidance specific to your situation, consult a qualified attorney or contact the HHS Office for Civil Rights or the Legal Action Center.


Key Takeaways

Federal law under 42 U.S.C. § 290dd-2 and 42 CFR Part 2 gives SUD patients stronger confidentiality protections than HIPAA alone, requiring written consent for most disclosures and blocking standard law-enforcement requests without a Part 2-compliant court order.

Point Details
Primary governing law 42 U.S.C. § 290dd-2 and 42 CFR Part 2 protect SUD records at federally assisted programs; HIPAA applies alongside but is weaker.
Written consent is the default Programs must obtain signed, specific written consent before disclosing your records; blanket or bundled consents are not valid.
Law enforcement cannot use a standard subpoena Routine subpoenas and warrants are generally insufficient; a Part 2-compliant court order is required for nonconsensual disclosure.
2024 Final Rule added new rights Patients now have the right to request restrictions and accountings of disclosures, and programs must provide breach notifications.
Where to file a complaint Report HIPAA-related violations to HHS/OCR at hhs.gov/ocr/complaints; report Part 2 violations to SAMHSA; contact the Legal Action Center for advocacy support.

Why confidentiality is the foundation of effective treatment

Strict confidentiality is not a bureaucratic formality. It is the reason people walk through the door.

Every clinician who works in addiction medicine knows this: the patients who are most reluctant to seek help are often the ones who have the most to lose if their records surface in the wrong place. A professional license. A custody arrangement. A job that requires security clearance. Part 2 exists because Congress recognized that without a credible legal guarantee of confidentiality, the population most in need of treatment would simply avoid it.

At Connected Recovery, confidentiality is built into operations from the first phone call. Staff are trained on Part 2 and HIPAA requirements, records are maintained with access controls appropriate to a small, accredited facility, and Qualified Service Organization agreements with any third-party vendors are documented and scoped carefully. Patients receive a clear notice of privacy practices at intake, not buried in a stack of forms, and the team is available to walk through any consent before a patient signs it.

What patients should confirm at any facility, not just Connected Recovery: ask whether the program is a Part 2 program, ask to see the patient notice before intake paperwork is completed, and ask specifically how the program handles requests from law enforcement or courts. A program that cannot answer those questions clearly is a program that has not done the work.

Privacy under Part 2 is a civil right that reduces stigma and removes a concrete barrier to care. Treating it that way, operationally and not just on paper, is what separates facilities that take confidentiality seriously from those that treat it as a compliance checkbox.


Authoritative sources and further reading

The following primary and advocacy sources are the most reliable places to verify the rules described in this article, read the full regulatory text, or find complaint forms.

  • 42 CFR Part 2 — Full Regulatory Text (eCFR): The current, authoritative text of the regulation itself.
  • HHS: Understanding Confidentiality of SUD Patient Records (Part 2): HHS’s primary guidance page on Part 2 scope, patient rights, and model notice language.
  • HHS Fact Sheet: 2024 Part 2 Final Rule: Plain-language summary of every major change in the 2024 Final Rule.
  • Federal Register: Final Rule Modifying 42 CFR Part 2 (Feb. 16, 2024): The full regulatory preamble and rule text, including the severability discussion.
  • Legal Action Center: Fundamentals of 42 CFR Part 2: Advocacy-focused guidance on patient rights and how to use them; also a resource for finding legal assistance.
  • PubMed/NCBI: Privacy protection for patients with substance use problems: Peer-reviewed academic review of the policy rationale and clinical implications of SUD confidentiality law.
  • HHS Office for Civil Rights (OCR) complaint portal: hhs.gov/ocr/complaints — file HIPAA-related complaints here within 180 days of learning of a violation.
  • SAMHSA: samhsa.gov — contact for reporting Part 2-specific violations and for accessing SAMHSA guidance materials on SUD treatment confidentiality.
Connected Recovery Inc.

DHCS Licensed · Joint Commission Accredited

If you or a loved one is struggling with substance use, our admissions team is available to verify your insurance benefits and help you begin recovery. All calls are confidential.