What Is 42 CFR Part 2 and Why It Matters

42 CFR Part 2 is a federal regulation that governs the confidentiality of substance use disorder (SUD) patient records. Its purpose is to ensure that people seeking treatment for substance use disorders are protected from stigma, discrimination, and legal harm.

The rules changed substantially in 2024. A final rule published February 8, 2024, implementing section 3221 of the CARES Act, aligned much of Part 2 with HIPAA. Its compliance date - February 16, 2026 - has passed, so the aligned framework is now the one you are held to.

Even after alignment, Part 2 remains stricter than HIPAA in specific areas. And from a practical standpoint, it creates heightened access control, consent enforcement, and data segmentation requirements that must be supported by your IT systems - not just your policies.

What It Is

The current framework rests on three moves the 2024 rule made:

  • Consent got simpler: patients may now give a single consent for all future uses and disclosures for treatment, payment, and health care operations (TPO). Once a HIPAA-covered entity receives records under that consent, it may redisclose them as HIPAA permits - with one carve-out below.
  • Breach notification now applies: the HIPAA Breach Notification Rule extends to breaches of Part 2 records. A breach of SUD records is reportable the same way a breach of any PHI is.
  • Penalties now match HIPAA: the old criminal-only fine structure was replaced with the same civil and criminal enforcement authorities that apply to HIPAA violations (42 U.S.C. 1320d-5 and 1320d-6).

What stayed stricter: records and testimony cannot be used in civil, criminal, administrative, or legislative proceedings against the patient without specific consent or a court order - and consent for legal proceedings cannot be combined with consent for anything else. The rule also created a new protected category, SUD counseling notes, which require their own specific consent and sit outside the general TPO authorization.

Who It Applies To

The legal test has two parts. Part 2 applies to federally assisted programs that hold themselves out as providing SUD diagnosis, treatment, or referral for treatment (42 CFR 2.11-2.12).

"Federally assisted" is broader than it sounds. Medicare certification, tax-exempt status, and DEA registration to dispense SUD medications all count - so most treatment providers qualify. But a behavioral health provider that is not federally assisted, or does not hold itself out as providing SUD services, is not a Part 2 program.

In practice, this covers:

  • SUD treatment programs and opioid treatment programs (OTPs): the core case.
  • Behavioral health and addiction treatment providers: when they meet the two-part test above.
  • Integrated care organizations: for the SUD units or providers within them that meet the test.
  • Everyone downstream who receives Part 2 records: lawful holders, qualified service organizations, and vendors - EHR and health IT vendors, cloud and SaaS providers, IT and MSP providers, billing and analytics vendors, and consultants with access to SUD records.

If your organization touches SUD-related data from a Part 2 program, the restrictions likely follow the records to you.

What Information Is Regulated

Part 2 protects any information that identifies an individual as having or seeking treatment for a substance use disorder, when it is created by, received from, or relates to a Part 2 program.

This includes:

  • Treatment records, diagnoses, and referrals
  • Medication-assisted treatment data
  • Appointment and billing records
  • Communications that could identify someone as an SUD patient
  • SUD counseling notes - the new category requiring separate, specific consent

Importantly, even the fact that someone is a patient is protected information.

Relation to Other Frameworks

This is a critical distinction, and it is commonly stated wrong: Part 2 does not simply "take precedence" over HIPAA. Regulated entities must comply with both.

Where the two now align - single consent for TPO, breach notification, penalties - compliance work overlaps heavily. Where Part 2 is more protective, its stricter standard controls: chiefly the prohibition on using records in proceedings against the patient without specific consent or a court order (HHS final-rule fact sheet).

Being HIPAA compliant does not automatically make you Part 2 compliant. Part 2 also intersects with HITECH, ONC certification, EPCS in treatment environments that prescribe controlled substances, and state-level privacy and mental health laws. Approach it as part of a broader GRC strategy, not in isolation.

IT Requirements

The regulation is privacy-focused, but compliance depends heavily on technical safeguards and operational controls.

Consent management, post-2024:

  • One TPO consent, correctly captured: systems must record the patient's single consent for treatment, payment, and operations - and honor its revocation.
  • Separate consent paths: SUD counseling notes and legal-proceedings disclosures each require their own specific consent, and the legal-proceedings consent cannot be bundled with anything else. IT systems must be able to enforce these limits, not just document them.

Granular access controls:

  • Role-based access and least privilege: with separation of Part 2 data from general PHI.
  • Immediate revocation: when roles change or staff depart.

Data segmentation and segregation:

  • Part 2 data segmented within EHRs where possible: clearly identifiable and protected.
  • Standard workflows blocked from unauthorized sharing: integrated EHRs are where this fails most often.

Audit logging and monitoring:

  • Track access and disclosures: who accessed Part 2 data, and where it went. The new patient right to an accounting of disclosures depends on this capability.
  • Investigate and retain: logs support both compliance and breach investigations.

Security policies and breach readiness:

  • Formal security policies and procedures: 42 CFR 2.16 requires documented policies and procedures to secure records - paper and electronic - against unauthorized access, and to govern their disposal. Encryption is not mandated by Part 2 itself, but it is the expected way to secure electronic records in practice, and it triggers HIPAA's breach-notification safe harbor.
  • Breach notification procedures: the HIPAA Breach Notification Rule now applies to Part 2 records, so your incident response plan must treat SUD records as reportable PHI.

Why It Matters

Since the 2024 rule, violations are subject to the same civil and criminal penalties as HIPAA violations - a significant escalation from the old criminal-only fine structure.

Beyond penalties, non-compliance brings enforcement actions, legal exposure, and loss of patient trust.

Most importantly, violations cause real harm to real people. Exposing someone's treatment history can cost them a job, custody, or their standing in a small community. That is the harm the regulation exists to prevent.

How It Fits Into Cyber Risk Management

Part 2 compliance is a data governance problem wearing a privacy label. The organizations that handle it well know exactly where SUD data lives, who can touch it, and what their systems will and won't allow.

That is the same discipline a cyber risk management program builds for every sensitive data type - Part 2 just raises the stakes and narrows the tolerances.

How We Help With 42 CFR Part 2 Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps where Part 2 data lives in your environment and tests whether your systems actually enforce the post-2024 consent, segmentation, and access rules - not just document them.

How to Prepare

  1. 01Identify Part 2 data in your environment

    Document where SUD-related data exists, which systems store or process it, who has access, and which vendors are involved.

  2. 02Update consents and notices to the 2024 rule

    Move to the single TPO consent where appropriate, establish separate consent workflows for SUD counseling notes and legal proceedings, and align your Patient Notice with the HIPAA Notice of Privacy Practices requirements.

  3. 03Validate access controls and data segmentation

    Confirm Part 2 data is restricted appropriately, role-based access is enforced, and no default or "open" access exists - especially in integrated EHRs.

  4. 04Assess logging, monitoring, and breach response

    Verify access to Part 2 data is logged, disclosures can be accounted for, logs are reviewed, and your incident response plan treats Part 2 records under the HIPAA Breach Notification Rule.

  5. 05Train staff

    Staff must understand how HIPAA and Part 2 fit together after alignment, why Part 2 data still carries stricter handling - especially around legal proceedings - and how to handle, disclose, and report correctly.

Frequently Asked Questions

Does 42 CFR Part 2 apply to my organization?

Apply the two-part test: are you federally assisted, and do you hold yourself out as providing SUD diagnosis, treatment, or referral? Federally assisted is broad - Medicare certification, tax-exempt status, or DEA registration to dispense SUD medications all count. And if you receive Part 2 records from a covered program as a vendor or partner, the restrictions follow the records to you.

What happens if we're not compliant?

Since the 2024 final rule, Part 2 violations carry the same civil and criminal penalties as HIPAA violations, and breaches of Part 2 records are reportable under the HIPAA Breach Notification Rule. The human cost is just as real: exposed treatment records cause direct, lasting harm to patients.

How long does it take to become compliant?

The assessment phase runs 2 to 4 weeks. Remediation depends on your EHR's segmentation capabilities and how much consent workflow needs rebuilding - configuration fixes move fast, while EHR-level data segmentation can take longer. If your consents still reflect the pre-2024 rules, that update belongs at the top of the list.

What does compliance cost?

It depends on how many systems hold SUD data and what the gaps are. You get a firm quote after the assessment; the conversation costs nothing.

We already have an IT provider. Do we still need this?

Part 2 failures are usually configuration failures - access too broad, segmentation missing, consent limits unenforced. General IT support rarely audits for that. We review the environment independently and work co-managed with your existing provider to close what we find.

What's the difference between 42 CFR Part 2 and HIPAA?

Both apply to a Part 2 program - one doesn't replace the other. Since 2024 they align on TPO consent, breach notification, and penalties. Part 2 stays stricter where it matters most: records can't be used in proceedings against the patient without specific consent or a court order, and SUD counseling notes need their own consent.

Can we handle this ourselves?

Policy updates, yes. The hard part is technical: verifying your EHR actually segments Part 2 data and enforces consent limitations. That takes someone who can test the system, not just read the manual. Our DIY-with-support tier keeps your team in the driver's seat with expert backup.

Where do we start?

Start by finding every place SUD data lives - the violations happen in systems nobody thought to check. Our Cyber Risk & Compliance Gap Assessment maps your Part 2 exposure and tests enforcement against the current rule. No pressure. No jargon. Just clear insights and your best next steps.

Official source

Official source: eCFR - 42 CFR Part 2

Secondary source: SAMHSA - statutes, regulations & guidelines

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25