Arizona Substance Abuse Record Privacy Laws: What Patients and Providers Need to Know

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Arizona Substance Abuse Record Privacy Laws: What Patients and Providers Need to Know

Kevin Henry

Data Privacy

April 12, 2026

7 minutes read
Share this article
Arizona Substance Abuse Record Privacy Laws: What Patients and Providers Need to Know

Arizona substance abuse record privacy laws combine state statutes, federal rules, and administrative standards. If you create, store, or use substance use disorder (SUD) information in Arizona, you must reconcile Arizona Revised Statutes § 36-509, 42 U.S.C. § 290dd-2, 42 CFR Part 2, and Arizona Administrative Code R9-10-1410 with your day-to-day workflows.

This guide explains what those authorities require, how authorizations should be handled (including Arizona Department of Economic Security form DDD-2172A), and what special rules apply to the Arizona Prescription Monitoring Program and medical marijuana records under Arizona Revised Statutes § 36-2810.

Arizona Confidentiality of Substance Use Disorder Records

Arizona Revised Statutes § 36-509 protects behavioral health records, including SUD information. It restricts disclosure of patient-identifying details without proper authority and sets conditions for when sharing is allowed. These safeguards apply to providers, facilities, and others who maintain or access such records in Arizona.

What you may disclose under Arizona law

  • Treatment, payment, and health care operations permitted by law, when disclosure is necessary and appropriately limited.
  • With the patient’s written authorization that clearly describes what will be shared and with whom.
  • As required by law or court order, subject to strict relevance and privacy protections.
  • For oversight, licensing, audit, or quality review by authorized agencies, while maintaining patient confidentiality.

Arizona law works alongside federal protections. When both apply, follow the rule that provides the higher level of privacy for the specific record and purpose.

Federal Confidentiality Protections for Substance Use Disorder Records

Two federal authorities anchor SUD privacy: 42 U.S.C. § 290dd-2 and its implementing regulation, 42 CFR Part 2. These rules cover programs that diagnose, treat, or refer for SUD and receive federal assistance, and they focus on preventing unauthorized disclosure or re-disclosure of patient-identifying SUD information.

Core Part 2 requirements you must know

  • Written consent is the default path for disclosure; it must be specific about the recipient, purpose, and the information to be released.
  • Re-disclosure restrictions travel with the records; recipients are notified that further sharing is limited.
  • Narrow exceptions exist (for example, bona fide medical emergencies, qualified audits/evaluations, research under defined conditions, and certain court orders).
  • HIPAA still applies; you must satisfy both HIPAA and 42 CFR Part 2 when each governs the record or sharing scenario.

Because Part 2 is highly protective, build processes that default to the minimum necessary detail and maintain separate handling for SUD-designated data sets.

Authorization for Disclosure of Substance Use Disorder Records in Arizona

When disclosure is permitted by patient consent, your authorization must meet both Arizona and federal content standards. Use plain language and capture all required elements in a single, verifiable document.

Elements of a valid SUD authorization

  • Patient identity and, if applicable, a personal representative with legal authority.
  • The program/provider authorized to disclose and the specific person or organization to receive the information.
  • Purpose of the disclosure and a clear description of the SUD records to be shared.
  • Expiration date or event, and the patient’s right to revoke in writing.
  • Required 42 CFR Part 2 re-disclosure notice language.
  • Signature and date (electronic signatures are acceptable if your process can authenticate them).

Arizona providers often rely on standardized forms. For services coordinated with state agencies, the Arizona Department of Economic Security form DDD-2172A is widely used to document patient authorization in a manner consistent with 42 CFR Part 2 and state requirements.

Arizona Administrative Code on Medical Records

Arizona Administrative Code R9-10-1410 sets expectations for how licensed health care institutions create, secure, retain, and disclose medical records. These operational standards apply to behavioral health and SUD records you maintain within licensed settings.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Operational expectations for providers

  • Maintain complete, accurate, and timely records that support diagnosis, treatment, and continuity of care.
  • Implement administrative, physical, and technical safeguards that prevent unauthorized access or alteration.
  • Retain records according to required schedules and document every disclosure as part of your privacy accounting.
  • Provide patient access in a timely manner while screening and segregating SUD-designated data consistent with 42 CFR Part 2.

Arizona Prescription Monitoring Program Confidentiality

Arizona’s Controlled Substances Prescription Monitoring Program contains sensitive dispensing data that intersects with SUD care. Arizona Prescription Monitoring Program confidentiality rules limit who may query the database, the purposes for which data may be used, and how results may be stored.

Good practices for PMP data

  • Access only for legitimate clinical care or other authorized purposes, using unique credentials and multi-factor authentication when available.
  • Do not copy PMP data into general records unless necessary; if you must, include only relevant findings and avoid bulk downloads.
  • Follow your organization’s log-in, log-out, and audit procedures; immediately report suspected credential compromise.
  • When patients request their own PMP information, use approved processes that verify identity and preserve audit trails.

Arizona Medical Marijuana Confidentiality and Record Handling

Arizona Revised Statutes § 36-2810 safeguards the confidentiality of medical marijuana registry information. The statute restricts public access, limits verification to defined contexts, and requires secure handling by the Arizona Department of Health Services and parties that interact with registry data.

Practical implications for providers

  • Verify registry status only when necessary for treatment or compliance, and document the minimum information needed.
  • Do not disclose a patient’s cardholder status to third parties without the patient’s authorization or another clear legal basis.
  • Segregate registry identifiers from general clinical notes; avoid unnecessary duplication of card numbers in your EHR.
  • Train staff on handling and storage of any medical marijuana documents, including screenshots or printed verifications.

Medical Marijuana Data Linking and Destruction Requirements

Medical marijuana registry data should not be linked with unrelated databases or systems in ways that could expose a person’s status beyond authorized verification. Keep registry data siloed, restrict internal re-disclosure, and disable automated cross-population between modules unless a lawfully authorized purpose exists.

Retention and destruction

  • Retain only what you need to evidence a lawful verification or clinical decision; avoid storing full registry details when a simple “verified valid” notation suffices.
  • Adopt written destruction schedules for temporary verification artifacts (for example, printed lookups), using secure destruction methods.
  • Align destruction practices with Arizona Revised Statutes § 36-2810, your record-retention duties, and 42 CFR Part 2 when SUD information appears in the same record set.

Conclusion

To comply with Arizona substance abuse record privacy laws, map your data flows to Arizona Revised Statutes § 36-509 and § 36-2810, apply 42 U.S.C. § 290dd-2 and 42 CFR Part 2 to SUD-designated data, operationalize Arizona Administrative Code R9-10-1410, and harden access to PMP and registry information. Build least-necessary disclosures into every step.

FAQs

Arizona Revised Statutes § 36-509 protects behavioral health records at the state level, while 42 U.S.C. § 290dd-2 and 42 CFR Part 2 impose strict federal limits on disclosing and re-disclosing SUD information. In licensed settings, Arizona Administrative Code R9-10-1410 adds operational requirements for record creation, security, retention, and disclosure tracking. When more than one rule applies, follow the most protective standard for the specific disclosure.

How can patients authorize the release of their substance use disorder information?

Patients may sign a written authorization that names the disclosing provider, identifies the recipient, states the purpose, describes the SUD records to be shared, includes an expiration, explains the right to revoke, and contains the 42 CFR Part 2 re-disclosure notice. Providers often use standardized documents—such as the Arizona Department of Economic Security form DDD-2172A in applicable programs—to capture these elements clearly and consistently.

What confidentiality measures protect medical marijuana patient data?

Arizona Revised Statutes § 36-2810 makes medical marijuana registry information confidential, limits verification to defined purposes, and prohibits broad public disclosure. Providers should verify only when necessary, avoid storing full registry details in the chart, restrict internal access, and apply secure retention and destruction practices so that registry data is not linked or exposed beyond what the law allows.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles