42 CFR Part 2

42 CFR Part 2 and HIPAA: what the final rule changed, and what it means for the people doing the work

Questions a Part 2 review should answer

  • Whether your organization is a part 2 program, a lawful holder of part 2 records, or neither.
  • Which intake, counseling, billing, referral, and records workflows can identify a person as having a substance use disorder.
  • Which vendors, health information exchanges, and care-coordination partners receive part 2 records from you.
  • Whether your consent forms match the current section 2.31 element list rather than the pre-2024 form.
  • Who investigates and reports a breach of part 2 records now that the HIPAA breach rule applies to them.

Substance use disorder records have always carried a stricter federal confidentiality rule than the rest of healthcare. The 2024 final rule moved a large part of that rule toward HIPAA, and the compliance date landed on February 16, 2026. Three days before it, the HHS Office for Civil Rights announced a civil enforcement program for Part 2.

This guide walks the current regulation section by section, links every claim to a primary source, and separates what is in force today from what is still waiting on other rulemaking.

2026compliance dateFebruary 16, 2026 for the SAMHSA final rule published February 16, 2024
8structural changesconsent, redisclosure, counseling notes, notice, rights, breach, penalties, legal process
1new enforcement programOCR began accepting Part 2 complaints and breach reports on February 16, 2026

Where to start

Four steps that decide whether a Part 2 program is actually ready

Most of the work is not exotic. It is scope, consent paperwork, the patient notice, and a breach and enforcement path that did not exist before.
01

Confirm whether part 2 actually applies to you

Part 2 does not cover every behavioral health provider. It covers federally assisted programs that hold themselves out as providing, and do provide, substance use disorder diagnosis, treatment, or referral for treatment, plus the people and organizations that lawfully receive those records.

02

Rebuild consent on the current section 2.31 elements

The single consent for all future treatment, payment, and health care operations disclosures is the headline change. It only works if the written consent carries every required element and the separate consent rules for counseling notes and legal proceedings are respected.

03

Replace the old patient notice with the section 2.22 notice

The pre-2024 written summary of federal confidentiality law is gone. Section 2.22 now requires a plain-language notice built on the same shape as a HIPAA notice of privacy practices, including patient rights, program duties, complaint routes, and an effective date.

04

Wire breach response and enforcement exposure into the program

Section 2.16 applies the HIPAA breach notification framework to unsecured part 2 records, and section 2.3 applies the HIPAA enforcement machinery. Since February 16, 2026, OCR accepts part 2 complaints and breach reports and can investigate, negotiate corrective action, and impose penalties.

The final rule

Eight changes that reshaped Part 2

Each one has a section number behind it. If a vendor summary cannot point you to the section, treat the summary as marketing.

Consent

One consent can now cover future treatment, payment, and operations

Section 2.31 permits a single written consent covering all future uses and disclosures for treatment, payment, and health care operations, with recipients describable as a class rather than named one at a time.

Redisclosure

HIPAA recipients may redisclose within HIPAA limits

A HIPAA covered entity or business associate that receives part 2 records under that consent may redisclose them as HIPAA allows, with a standing carve-out barring use against the patient in legal proceedings.

Counseling notes

SUD counseling notes get psychotherapy-note style protection

Notes kept separate from the rest of the record and analyzing a counseling session require their own specific consent, which may not be bundled with consent for anything else.

Patient notice

The patient notice now mirrors a notice of privacy practices

Section 2.22 sets required content: permitted disclosures without consent, disclosures needing consent with at least one example, patient rights, program duties, complaint procedures, non-retaliation, contact details, and an effective date.

Patient rights

Accounting of disclosures and the right to request restrictions

Section 2.25 creates a three-year accounting right for consented disclosures, and section 2.26 lets patients request restrictions on disclosures for treatment, payment, and operations.

Breach notification

The HIPAA breach notification rule reaches part 2 records

Section 2.16 applies 45 CFR part 160 and subpart D of 45 CFR part 164 to breaches of unsecured part 2 records, so notification duties now look like HIPAA breach duties.

Enforcement

Civil money penalties replaced the old criminal-only exposure

Section 2.3 applies the penalties in sections 1176 and 1177 of the Social Security Act and applies 45 CFR part 160 subparts C, D, and E to part 2 noncompliance.

Legal process

Tighter limits on records and testimony in proceedings

Records and testimony generally may not be used in civil, criminal, administrative, or legislative proceedings against a patient without specific written consent or a qualifying court order.

Part 2 is a separate federal rule, not a stricter reading of HIPAA

The confidentiality of substance use disorder patient records is governed by its own statute, 42 U.S.C. 290dd-2, and its own regulation at 42 CFR Part 2. The rule exists because people avoid treatment when they believe a record of that treatment can follow them into a courtroom, a custody dispute, a job application, or a prosecution. HHS states the purpose plainly on its own Part 2 page: fear of discrimination or legal trouble can deter people from seeking care.

That history matters when you read the 2024 changes, because the direction of travel is not simply deregulation. Some provisions loosened, particularly around consent and care coordination. Others tightened, particularly around use of records against a patient in legal proceedings. And the enforcement side moved from a criminal-only backstop that was almost never used to the full HIPAA civil enforcement machinery, which is used constantly.

Who is actually covered

The single most common mistake in Part 2 discussions is assuming it covers all behavioral health. It does not. Part 2 reaches a part 2 program, which HHS describes as any federally assisted program that provides SUD diagnosis, treatment, or referral for treatment. Federal assistance is defined broadly in section 2.12 and includes far more than direct grant funding, which is why programs that think of themselves as privately funded often still fall inside the rule.

The rule also follows the records outward. Section 2.11 defines a lawful holder as a person bound by Part 2 because they received records under a section 2.31 consent with an accompanying notice of disclosure, or under one of the statutory exceptions. HHS lists other health care providers, qualified service organizations, HIPAA covered entities and business associates, intermediaries, and investigative agencies among those who can be bound. An intermediary is defined separately as a person other than a part 2 program, covered entity, or business associate that receives records under a general designation in a consent for distribution to member participants, which is the definition that captures many health information exchanges and care-coordination networks.

A general mental health practice with no SUD program, no federal assistance, and no receipt of Part 2 records is governed by HIPAA and state law, not by Part 2. A primary care clinic that receives a patient's SUD records from a Part 2 program under consent is in a different position, because it is now handling records that carry restrictions HIPAA alone would not impose.

What the CARES Act set in motion

Section 3221 of the Coronavirus Aid, Relief, and Economic Security Act directed HHS to align parts of the SUD confidentiality regime with HIPAA and HITECH. SAMHSA published the resulting final rule in the Federal Register on February 16, 2024. The rule took effect on April 16, 2024, and HHS set the compliance date two years out. Its own fact sheet states that persons subject to the regulation must comply with the applicable requirements of the final rule by February 16, 2026.

Two years is a long runway, and a lot of programs used it the way organizations usually use long runways. The deadline arrived anyway, and it arrived with teeth attached.

Consent: one signature can now carry treatment, payment, and operations

Under the old rule, a Part 2 program generally needed a consent that named the specific recipient and described the specific disclosure. That model was workable for a standalone clinic and close to unworkable inside an integrated delivery system. Section 2.31 now permits a single written consent covering all future uses and disclosures for treatment, payment, and health care operations, and it allows the recipient description to be written as a class, using language such as my treating providers, health plans, third-party payers, and people helping to operate this program.

The elements themselves still have to be right. The consent must include the patient's name, the identification of the persons or class of persons authorized to make the use or disclosure, a description of the information that identifies it in a specific and meaningful fashion, a description of each purpose, notice of the right to revoke in writing, an expiration date or expiration event, the patient's signature, and the date of signature, along with the required statements about redisclosure and about the consequences of refusing to sign. A consent form drafted before 2024 will usually fail this list in more than one place, which is why the form itself is the first document to pull in any Part 2 review.

There are two firm exceptions to bundling. A consent for the use or disclosure of SUD counseling notes may only be combined with another consent for SUD counseling notes. And a consent for use or disclosure in a civil, criminal, administrative, or legislative proceeding may not be combined with consent for anything else. Both exceptions exist for the same reason: those are the disclosures most likely to harm the patient, so the rule refuses to let them ride along inside a routine intake signature.

Redisclosure, and the line that does not move

Once a HIPAA covered entity or business associate receives Part 2 records under a treatment, payment, and operations consent, it may redisclose those records as HIPAA permits. HHS puts it directly: that entity can share the record again without consent in all the ways that HIPAA allows, except for using the information in legal proceedings against the patient.

That exception is the most important sentence in the entire alignment project. The practical effect is that Part 2 records can now flow through ordinary healthcare operations, but they carry a permanent restriction with them. Any organization that receives them needs a way to know that a given record came from a Part 2 source, because the restriction attaches to the information rather than to the original holder. Segmentation stopped being a universal requirement and started being an operational necessity in a narrower place: knowing which records you cannot hand to a subpoena without a court order.

SUD counseling notes

Section 2.11 defines SUD counseling notes as notes recorded in any medium by a Part 2 program provider who is a SUD or mental health professional, documenting or analyzing the contents of conversation during a private, group, joint, or family SUD counseling session, and separated from the rest of the patient's SUD and medical record. The definition excludes medication prescription and monitoring, session start and stop times, modalities and frequencies of treatment, results of clinical tests, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date.

Anyone who has worked with the HIPAA psychotherapy notes definition will recognize the structure, including the trap inside it. The protection depends on the separation. Notes that live inside the general record do not qualify, no matter how sensitive their content. If a program wants this protection, the workflow and the chart have to be built to keep those notes apart, and clinical staff have to understand which of their documentation lands on which side of the line.

The patient notice under section 2.22

The old requirement to give patients a written summary of federal confidentiality law has been replaced with something much closer to a HIPAA notice of privacy practices. Section 2.22 requires each Part 2 program to inform the patient that federal law protects the confidentiality of substance use disorder patient records, at the time of admission or, if the patient lacks capacity at admission, as soon afterward as capacity is attained.

The notice has a required content list: a header identifying it as the program's notice of privacy practices, a description of uses and disclosures permitted without written consent in sufficient detail, the types of disclosures that require written consent with at least one example, patient rights including access, requesting restrictions, and obtaining an accounting, a statement that records cannot be disclosed in legal proceedings without specific written consent or a court order, the program's duties regarding privacy and breach notification, complaint procedures with an assurance of non-retaliation, contact information, and an effective date. It must be in plain language and available in paper or electronic form on request.

A program that already maintains a HIPAA notice should not simply staple the two together. The section 2.22 notice has its own content list and its own trigger, and the two documents describe different legal regimes even where they overlap.

Patient rights: access, accounting, and restriction requests

Section 2.23 covers patient access and restrictions on use and disclosure. Section 2.26 gives patients the right to request privacy protection for records, which parallels the HIPAA right to request restrictions on disclosures for treatment, payment, and health care operations.

Section 2.25 is the one worth reading twice. It gives a patient the right to an accounting of all disclosures made with consent under section 2.31 in the three years before the request, and it provides that a program must account for treatment, payment, and operations disclosures only where those disclosures are made through an electronic health record. That second half carries a caveat most summaries skip: HHS tied the compliance date for the electronic health record accounting requirement to the effective date of any finalized HHS modifications to the HITECH accounting of disclosures requirements, and that HITECH rulemaking has not been finalized. So the three-year accounting for consented disclosures is a live duty today, while the broader treatment, payment, and operations accounting through an electronic health record waits on separate rulemaking. A program should build the accounting log now and should not claim the deferred piece is already required.

Security and breach notification under section 2.16

Section 2.16 requires Part 2 programs to have formal policies and procedures for both paper and electronic records. For paper, that means secure storage such as a locked room, cabinet, safe, or similar container when records are not in use, plus procedures for transfer, removal, and destruction through sanitization. For electronic records, it means policies covering creating, receiving, maintaining, and transmitting records, and secure destruction that renders patient information non-retrievable. De-identification is pointed at the HIPAA standard in 45 CFR 164.514(b), such that there is no reasonable basis to believe the information can be used to identify a particular patient.

The larger change is in the same section: 45 CFR part 160 and subpart D of 45 CFR part 164 now apply to Part 2 programs for breaches of unsecured records. In practice that means the HIPAA breach notification workflow is the Part 2 breach notification workflow: the same four-factor risk assessment, the same individual notification timing, the same media notice threshold, and the same reporting to the Secretary. A Part 2 program that is not also a HIPAA covered entity may be meeting these obligations for the first time, and that is the gap most likely to produce a bad first year.

Enforcement is the part that changed the risk calculation

Before the final rule, a Part 2 violation carried criminal fine exposure under the statute and very little else. Section 2.3 now provides that any person who violates 42 U.S.C. 290dd-2(a) through (d) is subject to the applicable penalties under sections 1176 and 1177 of the Social Security Act, the same civil money penalty and criminal provisions behind HIPAA enforcement. Section 2.3(c) goes further and applies 45 CFR part 160, subparts C, D, and E to noncompliance with Part 2 in the same manner as they apply to covered entities and business associates. Those subparts are the compliance and investigation procedures, the civil money penalty procedures, and the hearing procedures.

Section 2.3(b) also creates the limitation on liability for investigative agency personnel that HHS describes as a safe harbor. An agency that exercises reasonable diligence to determine whether Part 2 applies before requesting records, and that complies with the applicable provisions afterward, is protected from civil or criminal liability. The fact sheet notes that reasonable diligence includes checking the SAMHSA facility locator and provider notices.

On February 13, 2026 HHS announced a civil enforcement program for the confidentiality of SUD patient records, effective February 16, 2026. From that date OCR accepts complaints alleging Part 2 violations and notifications of breaches of SUD patient records, and penalties align with the HIPAA mechanisms: resolution agreements, monetary settlements, corrective action commitments, and civil money penalties. OCR Director Paula M. Stannard framed the program as a way to instill confidence in patients so they will seek treatment from covered providers.

The practical read is straightforward. Part 2 moved from a rule with strict requirements and weak consequences to a rule with slightly looser requirements and HIPAA-grade consequences. Complaint-driven enforcement is how most HIPAA cases begin, and Part 2 now has a complaint channel.

Records in legal proceedings

The 2024 rule tightened rather than relaxed the protection that gave Part 2 its original purpose. Part 2 records and testimony relaying their content generally may not be used in a civil, criminal, administrative, or legislative proceeding against the patient unless the patient gives specific written consent or a court issues an order that authorizes the use or disclosure, with the procedures in subpart E of Part 2 setting out how such an order is obtained. A subpoena on its own is not enough.

This is where a well-trained records clerk is worth more than a policy binder. The moment a subpoena arrives, someone has to recognize that these records are different, route the request correctly, and avoid the reflex of producing what was asked for. That recognition is a training outcome, not a documentation outcome.

What this means for workforce training

Part 2 does not publish a course syllabus, and no federal agency certifies individuals or organizations as Part 2 compliant, just as no federal agency issues an official HIPAA certificate. What the rule does is create a set of decisions that front-line staff have to get right in real time, most of which a general HIPAA course never mentions.

A reasonable training scope for a Part 2 program covers the HIPAA baseline first, because the breach rule, the security expectations, and the notice structure now come straight from HIPAA. On top of that it needs the Part 2 layer: what makes an organization a Part 2 program, why the fact of a person's presence is itself protected, what a valid section 2.31 consent looks like, which notes are SUD counseling notes, what the section 2.22 notice promises patients, how accounting and restriction requests are handled, what to do when a subpoena arrives, and how to report a suspected breach fast enough for someone to investigate it.

Keep the evidence retrievable. Under an enforcement regime that now includes compliance reviews and complaint investigations, the useful artifacts are the same ones HIPAA investigators ask for: who was trained, on what scope, on what date, with a record someone can produce without a search. A workforce training requirement is only as good as the file behind it.

One boundary is worth stating clearly, because vendors blur it constantly. Training proof and organizational compliance are different things. A certificate documents that a named person completed training covering a defined scope on a specific date. It does not establish that the program's consent forms are current, that the section 2.22 notice has been issued, that breach procedures work, or that the accounting log exists. Use the certificate as the workforce-training evidence inside a Part 2 program, and keep the rest of the program documentation where a compliance officer can retrieve it when OCR, a payer, or a partner asks.

A short reading list of primary sources

Work from the regulation and the agency, not from summaries. The regulation itself is at 42 CFR Part 2 on eCFR, with subpart B carrying the general provisions at sections 2.11 through 2.26 and subpart C carrying the consent rules at sections 2.31 through 2.36. The statute is 42 U.S.C. 290dd-2. The rulemaking record is the February 16, 2024 final rule. HHS maintains both a plain-language Part 2 overview and a final rule fact sheet. The enforcement announcement is the February 13, 2026 HHS press release.

None of this is legal advice, and a program with a genuinely hard question about federal assistance, segmentation, or a specific subpoena should get counsel. What the sources above do give you is a way to check any claim someone makes about Part 2 against the section number it supposedly comes from, which is usually enough to separate the accurate summaries from the confident ones.

Reality check

Alignment with HIPAA made Part 2 easier to operate and more expensive to ignore

The consent change is a genuine simplification. A single signature covering future treatment, payment, and operations disclosures removes a real barrier to coordinated care, and redisclosure inside HIPAA limits removes another.

The trade is that everything downstream of consent now looks like HIPAA, including breach notification, complaint intake, investigations, corrective action, and civil money penalties. A program that treated Part 2 as a paperwork rule is now inside an enforcement system built for volume.

  • Pull the consent form first. Most pre-2024 forms fail the current element list.
  • Issue the section 2.22 notice and give it an effective date.
  • Decide who investigates a suspected breach and how fast they hear about it.
  • Train intake, clinical, billing, and records staff on the Part 2 layer, not just HIPAA basics.

Part 2 review list

  • Whether your organization is a part 2 program, a lawful holder of part 2 records, or neither.
  • Which intake, counseling, billing, referral, and records workflows can identify a person as having a substance use disorder.
  • Which vendors, health information exchanges, and care-coordination partners receive part 2 records from you.
  • Whether your consent forms match the current section 2.31 element list rather than the pre-2024 form.
  • Who investigates and reports a breach of part 2 records now that the HIPAA breach rule applies to them.

Who feels it

The Part 2 layer shows up differently in each role

The rule is one document. The decisions it creates are spread across intake, clinical documentation, billing, records, security, and compliance.

Intake and front desk

The moment a person is registered with a part 2 program, the fact of their presence can identify them as having a substance use disorder. Verification scripts, waiting-room practices, voicemail rules, and family questions all need part 2 answers, not general HIPAA answers.

Counselors and clinicians

Clinical staff need to know which notes fall inside the SUD counseling notes definition, how those notes must be separated from the rest of the record, and why a bundled consent form cannot authorize their release.

Billing and revenue cycle

A single consent for treatment, payment, and operations makes payer workflows easier than the old disclosure-by-disclosure model, but only if the consent on file actually carries the current required elements.

Health information management

Records teams own the accounting of disclosures, restriction requests, patient access, and the notice itself. Those are new or expanded duties with documentation attached to each one.

IT, security, and vendors

Section 2.16 requires written policies for creating, receiving, maintaining, transmitting, sanitizing, and destroying both paper and electronic records, and it points de-identification at the HIPAA standard in 45 CFR 164.514(b).

Compliance and privacy officers

Complaint intake, breach investigation, non-retaliation, corrective action, and the evidence file all now sit under an enforcement regime that did not exist for part 2 before 2026.

What is 42 CFR Part 2?

42 CFR Part 2 is the federal regulation protecting the confidentiality of substance use disorder patient records held by federally assisted SUD programs. It implements 42 U.S.C. 290dd-2 and is stricter than HIPAA in several places, particularly around consent and the use of records in legal proceedings against a patient.

What changed on February 16, 2026?

February 16, 2026 was the compliance date for the final rule SAMHSA published on February 16, 2024, which aligned much of Part 2 with HIPAA and HITECH as required by section 3221 of the CARES Act. On February 13, 2026 the HHS Office for Civil Rights announced a civil enforcement program, and from February 16, 2026 OCR began accepting Part 2 complaints and breach notifications.

Does Part 2 apply to every mental health or behavioral health provider?

No. Part 2 applies to federally assisted programs that hold themselves out as providing, and that provide, substance use disorder diagnosis, treatment, or referral for treatment, and to lawful holders who receive Part 2 records. A general mental health practice that does not meet that definition is governed by HIPAA and applicable state law rather than Part 2.

Can one consent now cover treatment, payment, and health care operations?

Yes. Section 2.31 permits a single written consent covering all future uses and disclosures for treatment, payment, and health care operations, and it allows recipients to be described as a class. Consent for SUD counseling notes and consent for use in legal proceedings must each stand alone and cannot be combined with other consents.

Do the HIPAA breach notification rules apply to Part 2 records?

Yes. Section 2.16 applies 45 CFR part 160 and subpart D of 45 CFR part 164 to breaches of unsecured Part 2 records held by Part 2 programs, which is why OCR now accepts Part 2 breach notifications.

What penalties apply to a Part 2 violation now?

Section 2.3 applies the penalties in sections 1176 and 1177 of the Social Security Act, the same civil money penalty and criminal provisions that apply to HIPAA, and applies 45 CFR part 160 subparts C, D, and E to Part 2 noncompliance. That gives HHS compliance reviews, investigations, corrective action plans, resolution agreements, and civil money penalties.

Does HIPAA training cover Part 2?

Not automatically. A general HIPAA course teaches the Privacy, Security, and Breach Notification Rules. Part 2 adds a separate consent model, a separate patient notice, counseling-note protections, and restrictions on legal proceedings. Staff at a Part 2 program need the HIPAA baseline and the Part 2 layer on top of it.

Does completing training make an organization Part 2 compliant?

No. Training proof and organizational compliance are different things. A certificate documents that a named person completed training on a date. Part 2 compliance also requires current consent forms, the section 2.22 notice, security and breach policies, accounting and restriction workflows, and evidence that all of it is maintained.

Training a team that handles SUD records?

Start with a solid HIPAA baseline, then add the Part 2 layer on top

USA HIPAA provides online HIPAA training with verifiable certificates for individuals and organizations, so the workforce-training evidence inside your Part 2 program is easy to produce.

Building the wider program? Pair this guide with the HIPAA compliance program guide, the breach risk assessment page, and the HIPAA training log kit so consent, notice, breach response, and training proof stay connected in one evidence file.