Comparison of six requirements under HIPAA and under 42 CFR Part 2, covering scope, consent, legal proceedings, privacy notices, breach notification, and enforcement

Where 42 CFR Part 2 goes further than HIPAA for substance use disorder records.

42 CFR Part 2 protects substance use disorder treatment records more strictly than HIPAA does. The biggest practical difference is that Part 2 records cannot be used against a patient in civil, criminal, administrative, or legislative proceedings without written consent or a qualifying court order. HIPAA has no equivalent bar. Part 2 also carries its own consent rules and its own privacy notice requirements. A 2024 final rule brought Part 2 closer into line with HIPAA, with a compliance date of February 16, 2026, and the Office for Civil Rights began accepting Part 2 complaints that same day.

If your clinicians diagnose, treat, or refer for substance use disorder, this almost certainly applies to you, and it now has an enforcement program behind it.

One note before we go further. This article is general information, not legal advice. Part 2 is a genuinely complicated regulation and we are an IT company, not a law firm. Use this to understand the shape of the obligation, then talk to counsel.

Does Part 2 Apply to Your Practice?

Part 2 applies to federally assisted programs that provide substance use disorder diagnosis, treatment, or referral for treatment. Two points catch people out.

First, federally assisted is broader than it sounds. It is not only about receiving grant money. Holding a DEA registration to dispense controlled substances for SUD treatment, or being tax exempt, can be enough. Most behavioral health organizations offering SUD services meet the definition.

Second, and this is the part that changed, obligations now reach beyond Part 2 programs themselves. A HIPAA covered entity that receives or maintains Part 2 records has its own requirements, including updating its notice of privacy practices, even if it is not a Part 2 program. If a counseling practice receives records from an SUD program for care coordination, that practice is now in scope for part of this.

If you are genuinely unsure whether your practice qualifies, that is a question for counsel, not for your IT provider. But assume you are in scope until told otherwise.

Six Places Part 2 Goes Further Than HIPAA

Requirement Under HIPAA Under 42 CFR Part 2
Who is covered Covered entities and business associates generally Part 2 programs, plus lawful holders of Part 2 records
Consent to share Generally not required for treatment, payment, and operations Consent governs. A single consent covering treatment, payment, and operations is now permitted, but consent is still the mechanism
Use in legal proceedings No specific prohibition Cannot be used against the patient in civil, criminal, administrative, or legislative proceedings without consent or a court order
Notice of privacy practices Standard HIPAA notice Must include Part 2 elements, including for covered entities that hold Part 2 records without being Part 2 programs
Breach notification Required Now required under Part 2 as well, aligned with the HIPAA approach
Enforcement Long established OCR enforcement OCR began accepting Part 2 complaints on February 16, 2026

The row worth reading twice is the third. That protection is the historical heart of Part 2, and it is why the rule exists: people will not seek treatment for addiction if the records can be used against them later. It survived the 2024 alignment intact.

What Changed on February 16, 2026

The 2024 final rule, issued jointly by SAMHSA and the Office for Civil Rights under a CARES Act mandate, was designed to reduce barriers to care coordination while keeping Part 2's heightened protections. Compliance was required by February 16, 2026.

The practical changes for a practice:

  • A single patient consent can now cover treatment, payment, and health care operations, rather than requiring separate consents. This is a genuine simplification.
  • Breach notification requirements now apply under Part 2, aligned with the HIPAA approach.
  • Notices of privacy practices had to be updated to carry Part 2 elements, including at covered entities that merely hold Part 2 records.
  • Patients gained a right to opt out of fundraising communications.
  • The prohibition on using SUD records against the patient in legal proceedings was preserved without weakening.

The Office for Civil Rights announced its Civil Enforcement Program for these records on February 13, 2026 and began accepting complaints, including breach notification complaints, three days later. Part 2 penalties follow the figures set in the HITECH Act rather than the annually adjusted HIPAA amounts, so they are lower, but the exposure is real and the complaint channel is open.

What This Means for Your Systems

Most Part 2 discussion is legal and clinical. Here is the technology side, which is where a practice's IT provider actually has to do something.

Consent has to be tracked, not just collected

If sharing turns on consent, your systems need to record what each patient consented to, when, and to whom disclosure is permitted. Behavioral health records platforms generally support this. The question is whether yours is configured to, and whether staff are using it consistently.

Disclosure tracking has to be real

You need to be able to show what was disclosed, to whom, and under what authority. That is an audit logging question, and it is worth confirming your platform captures it rather than assuming.

Segmentation matters more than in general healthcare

If SUD records live in the same system as everything else, and everyone can see everything, you have a problem that is harder to fix after an incident than before. Role based access inside the records platform is the control that does the work here.

Your notice of privacy practices is a document, and documents live somewhere

Updated notices need to be published on your website, available at intake, and version controlled so you can show what was in effect on a given date.

Vendor agreements have to account for it

Any vendor touching these records, including your IT provider, should understand that Part 2 applies. A Business Associate Agreement is the baseline, not the whole answer.

Five Things to Check This Month

  1. Has your notice of privacy practices been updated to carry Part 2 elements, and is the current version published and dated?
  2. Can your records platform show, for any patient, what they consented to and when?
  3. Can you produce a disclosure log if asked?
  4. Do staff who do not need access to SUD records have it anyway, simply because nobody restricted it?
  5. Does your breach response plan account for Part 2, or does it only reference HIPAA?

Why Most IT Providers Have Never Heard of This

Ask a general managed services provider about 42 CFR Part 2 and most will not recognize the citation. That is not incompetence. It is that Part 2 only touches a narrow slice of healthcare, and an IT company serving dentists, law firms, and manufacturers has had no reason to encounter it.

It matters for your practice because the controls Part 2 implies, consent tracking, disclosure logging, and access segmentation inside the records platform, are configuration decisions someone has to actually make. A provider who does not know the rule exists will not make them, and will not flag it when your configuration drifts.

We have supported behavioral health organizations delivering the full spectrum of mental health and drug and alcohol services for ten years. This is not a regulation we read about when it hit the news.

About Big U Computers

Big U Computers is a family owned IT provider in Macungie, Pennsylvania, serving practices and small businesses from Allentown and Bethlehem through Danville, Bloomsburg, and Lewisburg.

Not sure whether your systems support what Part 2 now requires? Call 570.340.0800 or book a free consult. We will walk the technology side with you, no charge.

This article is general information and not legal advice. 42 CFR Part 2 is complex and fact specific. Consult qualified counsel about your practice's obligations.

Big U Computers | P.O. Box 523, Macungie, PA 18062 | 570.340.0800 | bigucomputers.com