What It Is

The current framework rests on three moves the 2024 rule made:

  • Consent got simpler: patients may now give a single consent for all future uses and disclosures for treatment, payment, and health care operations (TPO). Once a HIPAA-covered entity receives records under that consent, it may redisclose them as HIPAA permits - with one carve-out below.
  • Breach notification now applies: the HIPAA Breach Notification Rule extends to breaches of Part 2 records. A breach of SUD records is reportable the same way a breach of any PHI is.
  • Penalties now match HIPAA: the old criminal-only fine structure was replaced with the same civil and criminal enforcement authorities that apply to HIPAA violations (42 U.S.C. 1320d-5 and 1320d-6).

What stayed stricter: records and testimony cannot be used in civil, criminal, administrative, or legislative proceedings against the patient without specific consent or a court order - and consent for legal proceedings cannot be combined with consent for anything else. The rule also created a new protected category, SUD counseling notes, which require their own specific consent and sit outside the general TPO authorization.

What Information Is Regulated

Part 2 protects any information that identifies an individual as having or seeking treatment for a substance use disorder, when it is created by, received from, or relates to a Part 2 program.

This includes:

  • Treatment records, diagnoses, and referrals
  • Medication-assisted treatment data
  • Appointment and billing records
  • Communications that could identify someone as an SUD patient
  • SUD counseling notes - the new category requiring separate, specific consent

Importantly, even the fact that someone is a patient is protected information.

IT Requirements

The regulation is privacy-focused, but compliance depends heavily on technical safeguards and operational controls.

Consent management, post-2024:

  • One TPO consent, correctly captured: systems must record the patient's single consent for treatment, payment, and operations - and honor its revocation.
  • Separate consent paths: SUD counseling notes and legal-proceedings disclosures each require their own specific consent, and the legal-proceedings consent cannot be bundled with anything else. IT systems must be able to enforce these limits, not just document them.

Granular access controls:

  • Role-based access and least privilege: with separation of Part 2 data from general PHI.
  • Immediate revocation: when roles change or staff depart.

Data segmentation and segregation:

  • Part 2 data segmented within EHRs where possible: clearly identifiable and protected.
  • Standard workflows blocked from unauthorized sharing: integrated EHRs are where this fails most often.

Audit logging and monitoring:

  • Track access and disclosures: who accessed Part 2 data, and where it went. The new patient right to an accounting of disclosures depends on this capability.
  • Investigate and retain: logs support both compliance and breach investigations.

Security policies and breach readiness:

  • Formal security policies and procedures: 42 CFR 2.16 requires documented policies and procedures to secure records - paper and electronic - against unauthorized access, and to govern their disposal. Encryption is not mandated by Part 2 itself, but it is the expected way to secure electronic records in practice, and it triggers HIPAA's breach-notification safe harbor.
  • Breach notification procedures: the HIPAA Breach Notification Rule now applies to Part 2 records, so your incident response plan must treat SUD records as reportable PHI.

How It Fits Into Cyber Risk Management

Part 2 compliance is a data governance problem wearing a privacy label. The organizations that handle it well know exactly where SUD data lives, who can touch it, and what their systems will and won't allow.

That is the same discipline a cyber risk management program builds for every sensitive data type - Part 2 just raises the stakes and narrows the tolerances.

How We Help With 42 CFR Part 2 Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps where Part 2 data lives in your environment and tests whether your systems actually enforce the post-2024 consent, segmentation, and access rules - not just document them.

How to Prepare

  1. Identify Part 2 data in your environment

    Document where SUD-related data exists, which systems store or process it, who has access, and which vendors are involved.

  2. Update consents and notices to the 2024 rule

    Move to the single TPO consent where appropriate, establish separate consent workflows for SUD counseling notes and legal proceedings, and align your Patient Notice with the HIPAA Notice of Privacy Practices requirements.

  3. Validate access controls and data segmentation

    Confirm Part 2 data is restricted appropriately, role-based access is enforced, and no default or "open" access exists - especially in integrated EHRs.

  4. Assess logging, monitoring, and breach response

    Verify access to Part 2 data is logged, disclosures can be accounted for, logs are reviewed, and your incident response plan treats Part 2 records under the HIPAA Breach Notification Rule.

  5. Train staff

    Staff must understand how HIPAA and Part 2 fit together after alignment, why Part 2 data still carries stricter handling - especially around legal proceedings - and how to handle, disclose, and report correctly.

Official source

Official source: eCFR - 42 CFR Part 2

Secondary source: SAMHSA - statutes, regulations & guidelines

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25