42 CFR Part 2 is a federal regulation that governs the confidentiality of substance use disorder (SUD) patient records. Its purpose is to ensure that people seeking treatment for substance use disorders are protected from stigma, discrimination, and legal harm.
The rules changed substantially in 2024. A final rule published February 8, 2024, implementing section 3221 of the CARES Act, aligned much of Part 2 with HIPAA. Its compliance date - February 16, 2026 - has passed, so the aligned framework is now the one you are held to.
Even after alignment, Part 2 remains stricter than HIPAA in specific areas. And from a practical standpoint, it creates heightened access control, consent enforcement, and data segmentation requirements that must be supported by your IT systems - not just your policies.
The current framework rests on three moves the 2024 rule made:
What stayed stricter: records and testimony cannot be used in civil, criminal, administrative, or legislative proceedings against the patient without specific consent or a court order - and consent for legal proceedings cannot be combined with consent for anything else. The rule also created a new protected category, SUD counseling notes, which require their own specific consent and sit outside the general TPO authorization.
The legal test has two parts. Part 2 applies to federally assisted programs that hold themselves out as providing SUD diagnosis, treatment, or referral for treatment (42 CFR 2.11-2.12).
"Federally assisted" is broader than it sounds. Medicare certification, tax-exempt status, and DEA registration to dispense SUD medications all count - so most treatment providers qualify. But a behavioral health provider that is not federally assisted, or does not hold itself out as providing SUD services, is not a Part 2 program.
In practice, this covers:
If your organization touches SUD-related data from a Part 2 program, the restrictions likely follow the records to you.
Part 2 protects any information that identifies an individual as having or seeking treatment for a substance use disorder, when it is created by, received from, or relates to a Part 2 program.
This includes:
Importantly, even the fact that someone is a patient is protected information.
This is a critical distinction, and it is commonly stated wrong: Part 2 does not simply "take precedence" over HIPAA. Regulated entities must comply with both.
Where the two now align - single consent for TPO, breach notification, penalties - compliance work overlaps heavily. Where Part 2 is more protective, its stricter standard controls: chiefly the prohibition on using records in proceedings against the patient without specific consent or a court order (HHS final-rule fact sheet).
Being HIPAA compliant does not automatically make you Part 2 compliant. Part 2 also intersects with HITECH, ONC certification, EPCS in treatment environments that prescribe controlled substances, and state-level privacy and mental health laws. Approach it as part of a broader GRC strategy, not in isolation.
The regulation is privacy-focused, but compliance depends heavily on technical safeguards and operational controls.
Consent management, post-2024:
Granular access controls:
Data segmentation and segregation:
Audit logging and monitoring:
Security policies and breach readiness:
Since the 2024 rule, violations are subject to the same civil and criminal penalties as HIPAA violations - a significant escalation from the old criminal-only fine structure.
Beyond penalties, non-compliance brings enforcement actions, legal exposure, and loss of patient trust.
Most importantly, violations cause real harm to real people. Exposing someone's treatment history can cost them a job, custody, or their standing in a small community. That is the harm the regulation exists to prevent.
Part 2 compliance is a data governance problem wearing a privacy label. The organizations that handle it well know exactly where SUD data lives, who can touch it, and what their systems will and won't allow.
That is the same discipline a cyber risk management program builds for every sensitive data type - Part 2 just raises the stakes and narrows the tolerances.
Here's the key takeaway: most 42 CFR Part 2 failures are not intentional - they're technical.
Misconfigured EHRs, overly broad access, and unclear consent enforcement are the most common causes of violations.
Strong cybersecurity hygiene, paired with proper governance and configuration, dramatically reduces risk.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment maps where Part 2 data lives in your environment and tests whether your systems actually enforce the post-2024 consent, segmentation, and access rules - not just document them.
Document where SUD-related data exists, which systems store or process it, who has access, and which vendors are involved.
Move to the single TPO consent where appropriate, establish separate consent workflows for SUD counseling notes and legal proceedings, and align your Patient Notice with the HIPAA Notice of Privacy Practices requirements.
Confirm Part 2 data is restricted appropriately, role-based access is enforced, and no default or "open" access exists - especially in integrated EHRs.
Verify access to Part 2 data is logged, disclosures can be accounted for, logs are reviewed, and your incident response plan treats Part 2 records under the HIPAA Breach Notification Rule.
Staff must understand how HIPAA and Part 2 fit together after alignment, why Part 2 data still carries stricter handling - especially around legal proceedings - and how to handle, disclose, and report correctly.
Apply the two-part test: are you federally assisted, and do you hold yourself out as providing SUD diagnosis, treatment, or referral? Federally assisted is broad - Medicare certification, tax-exempt status, or DEA registration to dispense SUD medications all count. And if you receive Part 2 records from a covered program as a vendor or partner, the restrictions follow the records to you.
Since the 2024 final rule, Part 2 violations carry the same civil and criminal penalties as HIPAA violations, and breaches of Part 2 records are reportable under the HIPAA Breach Notification Rule. The human cost is just as real: exposed treatment records cause direct, lasting harm to patients.
The assessment phase runs 2 to 4 weeks. Remediation depends on your EHR's segmentation capabilities and how much consent workflow needs rebuilding - configuration fixes move fast, while EHR-level data segmentation can take longer. If your consents still reflect the pre-2024 rules, that update belongs at the top of the list.
It depends on how many systems hold SUD data and what the gaps are. You get a firm quote after the assessment; the conversation costs nothing.
Part 2 failures are usually configuration failures - access too broad, segmentation missing, consent limits unenforced. General IT support rarely audits for that. We review the environment independently and work co-managed with your existing provider to close what we find.
Both apply to a Part 2 program - one doesn't replace the other. Since 2024 they align on TPO consent, breach notification, and penalties. Part 2 stays stricter where it matters most: records can't be used in proceedings against the patient without specific consent or a court order, and SUD counseling notes need their own consent.
Policy updates, yes. The hard part is technical: verifying your EHR actually segments Part 2 data and enforces consent limitations. That takes someone who can test the system, not just read the manual. Our DIY-with-support tier keeps your team in the driver's seat with expert backup.
Start by finding every place SUD data lives - the violations happen in systems nobody thought to check. Our Cyber Risk & Compliance Gap Assessment maps your Part 2 exposure and tests enforcement against the current rule. No pressure. No jargon. Just clear insights and your best next steps.
Official source: eCFR - 42 CFR Part 2
Secondary source: SAMHSA - statutes, regulations & guidelines
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25