42 CFR Part 2 and HIPAA for Addiction Counseling: A Practical Compliance Guide
42 CFR Part 2 Overview
Purpose and scope
42 CFR Part 2 establishes federal rules for Substance Use Disorder Confidentiality. It protects any information that identifies a person as having sought, received, or been referred for substance use disorder (SUD) services from a federally assisted program. The goal is to reduce stigma and deter harmful uses of sensitive information while enabling appropriate care.
How Part 2 relates to HIPAA
HIPAA sets baseline privacy and security standards for protected health information (PHI). Part 2 adds an extra layer for SUD records. When both apply, you must meet the more protective requirement. In practice, that means tighter consent rules, specific redisclosure limits, and careful handling of SUD data inside shared systems such as integrated electronic records.
Core compliance principles
- Disclose only with valid consent or a specific regulatory exception.
- Limit access on a “need-to-know” basis and document rationale.
- Tag and track SUD data to support Electronic Health Record Segmentation and auditability.
Applicability of Part 2
What counts as a Part 2 program
A Part 2 program is any person, unit, or entity that provides SUD diagnosis, treatment, or referral for treatment and holds itself out as doing so. Within a general medical facility, a specifically identified SUD component (for example, an outpatient MAT clinic or inpatient detox unit) is typically covered even if the rest of the facility is not.
Federally Assisted Programs
“Federally assisted” is interpreted broadly. It generally includes programs that receive federal funding directly or indirectly (such as Medicaid or federal grants), operate under federal authorization (such as a DEA registration to dispense controlled substances), are tax‑exempt, or are administered by a federal department. If you meet Part 2’s program definition and any of these assistance criteria, assume the rules apply.
Common edge cases
- Individual practitioners: If you publicly represent SUD services and meet federal assistance criteria, you may be a Part 2 program even in private practice.
- General medical practices: Routine screening or brief intervention alone does not always create a Part 2 program, but a dedicated SUD track or clinic likely does.
- Contractors and partners: Vendors or referral partners that receive SUD data must be bound by appropriate agreements and redisclosure limits.
Consent Requirements
Elements of a valid Written Disclosure Consent
A compliant consent should be specific and purposeful. Ensure it includes: patient name; what information will be disclosed; the recipient (person or organization); the purpose of the disclosure; how long the consent lasts (expiration date or event); the patient’s signature and date; and a statement that consent can be revoked at any time, except to the extent already relied upon.
Format, signatures, and workflow
Written consent may be captured on paper or electronically if you can verify the signer and maintain integrity of the record. Train staff to explain scope and duration in plain terms, verify identity, and record consent in the EHR where it is easy to find during care transitions.
Managing revocation and special situations
- Revocation: Treat revocations as prospective. Time‑stamp, communicate to downstream users as appropriate, and update access controls.
- Minors and incapacity: Follow state law for personal representatives while honoring any stricter protections that apply to SUD data.
- Treatment, payment, and health care operations: If you rely on a general consent for these activities, confirm it is permitted in your jurisdiction and clearly reflects the patient’s intent.
Redisclosure Limitations
The prohibition on redisclosure notice
When you disclose Part 2 information, include the required warning that the information is protected by federal law and may not be redisclosed unless permitted by Part 2 or other applicable law and patient consent. Add the notice to cover sheets, secure messages, and CCD/HL7 payloads to travel with the data.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Permitted redisclosures and exceptions
- Medical emergencies: Limited disclosures are allowed to address an immediate threat to health or safety; document the facts and rationale.
- Audit and evaluation: Disclosures to qualified auditors, payors, and oversight bodies are permitted with safeguards.
- Research: De‑identified data or disclosures under applicable approvals may be allowed.
- Court orders and required reports: Only as authorized by law and narrowly tailored.
Operational controls
- Embed the redisclosure notice in all outbound SUD documents and interfaces.
- Use data use agreements or qualified service organization/business associate agreements to bind recipients.
- Monitor outbound transmissions and maintain logs for Patient Disclosure Accounting.
Counseling Notes Management
Psychotherapy notes vs. progress notes
Psychotherapy notes (a clinician’s separate, personal notes analyzing conversation during a counseling session) are distinct from the medical record and require a higher bar for disclosure. Progress notes, medication records, scheduling, and billing belong in the clinical record and are subject to Part 2 and HIPAA rules.
Electronic Health Record Segmentation
Segment SUD data so authorized team members can access what they need without exposing unnecessary details. Practical steps include structured fields to tag SUD content, separate document types for therapy notes, restricted folders for sensitive attachments, and rules that prevent auto‑sharing of SUD items through portals or HIEs unless consent allows.
Minimum necessary and access control
- Apply role‑based access and break‑glass controls for crisis scenarios.
- Design note templates to capture clinical essentials without over‑identifying SUD status when not necessary.
- Audit access routinely to detect and correct over‑exposure.
Patient Rights Under Part 2 and HIPAA
Access and copies
Patients generally have the right to access and obtain copies of their records. Provide information in the requested format when feasible, verify identity before release, and deliver promptly. If you deny access to a narrow subset (for example, psychotherapy notes), explain the basis and offer alternative summaries when appropriate.
Patient Disclosure Accounting
Maintain a log of disclosures of Part 2 information, including date, recipient, description of what was shared, and purpose or legal basis. Be prepared to produce an accounting on request for the required retention period under applicable rules.
Amendments and restrictions
Enable patients to request amendments to inaccurate or incomplete information and to ask for restrictions on certain disclosures. Evaluate each request, document decisions, and implement approved restrictions across your systems and partners.
Breach Notification and Enforcement
Breach Notification Requirements
When SUD data is impermissibly accessed, used, or disclosed, conduct a prompt risk assessment, mitigate harm, and determine if notification is required. If notification is required, inform affected individuals without unreasonable delay and follow applicable federal and state timelines. Where HIPAA applies, follow its breach notification framework, and coordinate notices to regulators and, when threshold criteria are met, the media.
Incident response workflow
- Secure systems, preserve evidence, and contain exposure.
- Assess what was involved (types of data, scope, identities, and likelihood of misuse).
- Decide on notification, tailor letters to Part 2 sensitivities, and offer support such as credit monitoring when appropriate.
- Document actions, lessons learned, and control improvements.
Compliance Enforcement Penalties
Enforcement can include corrective action plans, civil monetary penalties, and—where intentional, wrongful disclosures occur—criminal exposure. Penalties escalate with factors such as willful neglect, failure to correct, and repeated violations. Strong policies, workforce training, vendor oversight, and auditing are your best protection.
Conclusion
To manage 42 CFR Part 2 alongside HIPAA, clearly define when Part 2 applies, obtain and track precise consents, control redisclosure, segment sensitive notes in the EHR, honor patient rights, and respond decisively to incidents. Build these safeguards into daily workflows so confidentiality strengthens, rather than impedes, safe and coordinated addiction care.
FAQs
What records are protected under 42 CFR Part 2?
Part 2 protects any information that identifies a person as seeking, receiving, or being referred for SUD services from a federally assisted program. It covers clinical notes, diagnoses, medications, lab results, appointment logs, billing entries, and even verbal confirmations if they would reveal SUD status. De‑identified data and information not created or received by a Part 2 program are generally outside the rule.
How does HIPAA complement 42 CFR Part 2 in addiction counseling?
HIPAA provides the baseline privacy, security, and breach notification framework for PHI. Part 2 overlays stricter confidentiality for SUD records, especially around consent and redisclosure. Together, they require you to secure data, limit access, document disclosures, and use the most protective rule where they differ.
When is written patient consent required for disclosures?
Written consent is required for most disclosures outside the program, including many care coordination and payment scenarios, unless a specific exception applies (such as a bona fide medical emergency, qualified audit/evaluation activities, approved research, mandated reports, or a valid court order). Obtain consent that clearly states what will be shared, with whom, for what purpose, and for how long.
How must breaches of Part 2 protected information be reported?
First, contain and investigate the incident. If the event meets breach criteria, notify affected individuals without unreasonable delay and follow applicable Breach Notification Requirements, including those that apply under HIPAA where relevant and any stricter state timelines. Document the assessment, notifications, and remediation steps, and strengthen controls to prevent recurrence.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.