The two-year compliance window for the 42 CFR Part 2 final rule closed on February 16, 2026. If your program updated its consents, patient notice, policies, and breach procedures before that date, this article is your audit checklist. If it didn't, you're not "preparing for" the rule anymore β you're out of compliance with it, under an enforcement regime that now carries HIPAA's civil penalty structure instead of the old, rarely-used criminal-only enforcement.
Here's what changed, what it means operationally, and where facilities are most commonly still exposed β written for owners, compliance officers, and clinical directors of SUD treatment programs.
42 CFR Part 2 β the federal confidentiality rule for substance use disorder treatment records β was written in an era when a single disclosure could destroy a life, and it protected records with consent requirements far stricter than HIPAA. The cost of that strictness was fragmentation: SUD records couldn't move with the patient through the care system, coordination suffered, and every disclosure needed its own consent.
Section 3221 of the CARES Act (2020) ordered HHS to align Part 2 with HIPAA. The implementing final rule was published February 16, 2024 (a joint effort of SAMHSA and the HHS Office for Civil Rights), took effect April 16, 2024, and gave programs until February 16, 2026 to comply.
1. Single consent for TPO. The old regime required consent disclosure by disclosure. Now a patient can sign one consent covering all future uses and disclosures for treatment, payment, and health care operations β and that consent stands until revoked. This is the biggest operational simplification in Part 2's history, and it's also where compliance details live: the consent document has specific content requirements, and revocation must actually work in your systems.
2. Redisclosure under HIPAA rules. Recipients who are HIPAA covered entities or business associates may redisclose Part 2 records they received under a TPO consent according to HIPAA's rules β ending the old "chain of consent" that made payers and health systems treat SUD records like radioactive material. Disclosures still carry notice requirements prohibiting use in proceedings against the patient.
3. HIPAA-aligned enforcement. Part 2 violations moved from the old criminal-only regime to HIPAA's civil and criminal enforcement structure β civil monetary penalties, OCR enforcement, and patient complaint rights. Practically: Part 2 went from a rule with almost no enforcement history to one enforceable exactly like HIPAA. Your Part 2 gaps now carry HIPAA-sized price tags.
4. Breach notification applies. The HIPAA Breach Notification Rule now applies to Part 2 records. A breach of SUD records triggers the same patient, HHS, and (where applicable) media notification obligations as any PHI breach β so your incident-response plan must treat Part 2 data as in-scope.
5. SUD counseling notes. The rule created a heightened category analogous to HIPAA's psychotherapy notes: SUD counseling notes maintained separately from the rest of the record require their own specific consent β the general TPO consent doesn't reach them. If your clinicians keep process-style counseling notes, your EMR needs to segment them.
6. New patient rights. Patients gained the right to an accounting of disclosures made with consent (phased in per the rule), the right to request restrictions, and the right to file complaints with HHS. The required Patient Notice was rewritten to parallel HIPAA's Notice of Privacy Practices.
7. What did not change. Part 2 records still cannot be used in civil, criminal, administrative, or legislative proceedings against the patient without specific consent or a court order. Law-enforcement restrictions remain tighter than HIPAA. And the CARES Act's anti-discrimination provisions prohibit using SUD records against individuals in employment, housing, court access, and social services. Part 2 aligned with HIPAA; it did not dissolve into it.
Walk your program through this. Every "no" is an open exposure item.
| # | Item | Where it lives |
|---|
| 1 | New TPO consent form meeting final-rule content requirements, in use for all admissions since Feb 2026 | Intake packet / EMR consent module |
| 2 | Revocation workflow that actually stops disclosures when a patient revokes | EMR + billing + HIE feeds |
| 3 | Updated Patient Notice (Part 2/NPP-aligned) posted and provided | Intake, website, facility |
| 4 | Redisclosure notice language attached to disclosures | EMR disclosure workflows, ROI templates |
| 5 | SUD counseling notes segmented with separate consent | EMR note types + access controls |
| 6 | Breach response plan explicitly covering Part 2 records | Incident response policy |
| 7 | Accounting-of-disclosures capability | EMR audit trail |
| 8 | BAAs and QSOAs reviewed against the new rule | Legal / vendor management |
| 9 | Workforce retrained on the new consent model | Training records |
| 10 | Policies & procedures manual updated and versioned | Compliance program |
Six months past the deadline, the same gaps show up repeatedly:
- The consent form got updated; the systems didn't. A compliant form feeding an EMR that can't track revocation or segment counseling notes is paper compliance.
- Counseling notes aren't actually segmented. If process notes live in the general record, the heightened protection isn't real β and neither is your compliance.
- Breach plans never added Part 2. Incident-response docs written pre-2024 rarely contemplate SUD-record breach notification.
- The accounting-of-disclosures right has no mechanism. When a patient asks, "who did you disclose my records to?", the answer has to come from an audit trail, not a shrug.
- Staff still operate on the old rules β either over-restricting (blocking legitimate TPO coordination the new rule permits) or under-restricting (treating alignment as if Part 2 disappeared).
Almost every checklist item above is a systems capability, not a policy paragraph: consent capture and revocation, note segmentation, disclosure tracking, audit trails, breach detection. This is exactly why we built Navix with 42 CFR Part 2 as a first-class concept β native consent management, Part 2-aware record handling, and complete audit logging β rather than a configuration project on top of a general medical EMR.
If your current system can't demonstrate items 1β7 in a live demo, that's a material compliance gap with an enforcement regime now attached. It's also, frankly, a sign the platform is aging out.
Run our free HIPAA + 42 CFR Part 2 self-audit to score your program, or book a demo and ask us to walk the checklist in the product.
This article is educational and not legal advice. The final rule contains provisions and phase-ins beyond this summary β review your program's obligations with qualified healthcare counsel.
β
- #42 cfr part 2
- #part 2 final rule
- #hipaa
- #sud confidentiality
- #compliance
- #consent management