How SAMHSA’s 42 CFR Part 2 Regulations Interact with HIPAA: A Practical Compliance Guide
42 CFR Part 2 Overview
42 CFR Part 2 safeguards the confidentiality of patient records created by federally assisted programs that provide diagnosis, treatment, or referral for treatment of a Substance Use Disorder (SUD). Designed to reduce stigma and protect patients, the rule imposes strict legal disclosure restrictions on identifiable SUD information and applies to “Part 2 programs,” lawful holders of Part 2 records, and certain recipients such as Qualified Service Organizations (QSOs). ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
Under Part 2, records generally may not be used or disclosed without the patient’s written consent unless a specific exception applies. Key concepts include the program’s duty to warn against improper redisclosure and long-standing prohibitions on using SUD records to investigate or prosecute a patient absent consent or a court order meeting precise criteria. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
For Protected Health Information compliance across your enterprise, remember that Part 2 protects SUD “records,” which often sit alongside HIPAA-governed PHI. When both frameworks apply, you must honor Part 2’s stricter standards where they differ from HIPAA. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
HIPAA Overview
HIPAA establishes national rules for the privacy and security of PHI held by covered entities and their business associates. It permits uses and disclosures of PHI for treatment, payment, and health care operations (TPO) without patient authorization, subject to conditions like the minimum necessary standard for many non-treatment disclosures. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html?hl=en&utm_source=openai))
The HITECH Act supplements HIPAA by adding breach notification standards and strengthening enforcement. Together, HIPAA and HITECH set baseline breach notification standards—central to modern compliance programs—even when you also handle Part 2 records. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/laws-regulations/final-rule-update/hitech/index.html?utm_source=openai))
Interaction Between 42 CFR Part 2 and HIPAA
Many organizations hold data subject to both Part 2 and HIPAA. The 2024 final rule implementing CARES Act section 3221 aligns major areas of Part 2 with HIPAA and the HITECH Act, including allowing a single patient consent for all future TPO uses and disclosures and enabling downstream HIPAA covered entities and business associates to redisclose Part 2 records consistent with HIPAA. Still, Part 2 keeps stronger limits on legal uses—for example, records cannot be used in legal proceedings against a patient without specific consent or a qualifying court order. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
Operationally, this alignment reduces friction in care coordination while preserving heightened Substance Use Disorder confidentiality where it matters most. Your policies should reflect that when Part 2 and HIPAA differ, the more protective rule governs the Part 2 records at issue. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
Recent Updates to 42 CFR Part 2
On February 16, 2024, HHS issued a final rule updating Part 2; persons subject to the rule must comply by February 16, 2026. Highlights include: a single patient consent for all future TPO uses and disclosures; permission for HIPAA covered entities and business associates to redisclose records under HIPAA; public health disclosures of de-identified data; alignment with HIPAA/HITECH breach notification standards; replacement of prior criminal-only penalty structure with HIPAA-style civil and criminal enforcement; expanded patient rights; a model-aligned Patient Notice; explicit confirmation that segregating/segmenting Part 2 data is not required; and creation of “SUD counseling notes” with protections analogous to HIPAA psychotherapy notes. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
HHS also created a safe harbor for investigative agencies that, acting with reasonable diligence, mistakenly obtain Part 2 records, and it added the right to file complaints directly with the Secretary. Together these changes modernize Substance Use Disorder confidentiality while promoting HITECH Act alignment and Office for Civil Rights enforcement. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Patient Consent Requirements
Part 2 requires specific, written patient consent for most disclosures. The regulation lists mandatory elements (for example, patient name, description of information, who may disclose and who may receive it, purpose, expiration, and the right to revoke), and it now permits a single consent covering all future TPO uses and disclosures. Each disclosure made with consent must include a copy of, or a clear explanation of, the scope of that consent. ([ecfr.io](https://ecfr.io/Title-42/Section-2.31?utm_source=openai))
Special rules apply. You may not bundle consent for civil, criminal, administrative, or legislative proceedings with consent for other disclosures; and separate consent is required for SUD counseling notes. These Patient Consent Protocols are central to Substance Use Disorder confidentiality and should be embedded in intake workflows and your release-of-information processes. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
Disclosure Without Patient Consent
Part 2 permits limited disclosures without consent, including: medical emergencies (including certain declared-disaster situations when a program is closed and unable to obtain consent), reports of crimes on program premises or against program personnel, reporting suspected child abuse or neglect as required by state law, court orders meeting Subpart E criteria, research meeting specific protections, and audit or evaluation activities. Document the basis for each such disclosure and provide the required redisclosure warning when applicable. ([ecfr.io](https://ecfr.io/Title-42/Section-2.51?utm_source=openai))
The 2024 final rule added permission to disclose de-identified information to public health authorities consistent with HIPAA’s de-identification standards. Where HIPAA and Part 2 overlap, apply the stricter standard; for example, HIPAA’s broad TPO permissions cannot override Part 2’s legal disclosure restrictions. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
Enforcement and Penalties
Effective February 16, 2026, HHS’s Office for Civil Rights administers and enforces Part 2, bringing it under the same civil enforcement framework that applies to HIPAA. OCR can investigate complaints, conduct compliance reviews, and impose civil money penalties using the HIPAA Enforcement Rule structure. Organizations may file or face Part 2 complaints through OCR’s established intake channels. ([hhs.gov](https://www.hhs.gov/hipaa/part-2/index.html?utm_source=openai))
Breach Notification Standards now mirror HIPAA: notify affected individuals without unreasonable delay and no later than 60 days after discovery; report breaches to HHS (and for incidents affecting 500 or more individuals, follow the large-breach reporting timelines and public posting requirements). OCR maintains a dedicated portal for HIPAA and Part 2 breach reporting and publishes breaches affecting 500+ individuals. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))
In practice, you should treat SUD records as a high-sensitivity subset of PHI: build layered access controls, verify the legal basis before each disclosure, and maintain defensible logs that show how you applied Legal Disclosure Restrictions. Align training, policies, and your Notice content with the updated Patient Notice guidance to demonstrate Protected Health Information compliance across HIPAA and Part 2. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/privacy-practices-part-2/index.html?utm_source=openai))
FAQs.
How do 42 CFR Part 2 regulations differ from HIPAA?
HIPAA permits broad TPO uses and disclosures of PHI; Part 2 requires written consent for most SUD disclosures, even for coordination of care, unless a specific exception applies. After the 2024 final rule, a single consent can authorize TPO uses and downstream HIPAA redisclosures, but Part 2 still bars using SUD records against a patient in legal proceedings without consent or a qualifying court order. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html))
What are the patient consent requirements under 42 CFR Part 2?
Consent must include specific elements (patient, discloser, recipient, description of information, purpose, expiration, revocation, and more). The rule now allows a single, prospective TPO consent; prohibits combining litigation-related consent with other permissions; and requires separate consent for SUD counseling notes. Include a copy or clear explanation of the consent with each disclosure. ([ecfr.io](https://ecfr.io/Title-42/Section-2.31?utm_source=openai))
When can SUD information be disclosed without patient consent?
Permitted scenarios include bona fide medical emergencies (including certain declared-disaster closures), crimes on program premises or against staff, mandated child abuse or neglect reporting, court orders that meet Subpart E, qualified research, and audit/evaluation activities. Public health disclosures of de-identified data are also permitted. ([ecfr.io](https://ecfr.io/Title-42/Section-2.51?utm_source=openai))
What enforcement actions apply to noncompliance with 42 CFR Part 2?
HHS OCR enforces Part 2 using the HIPAA Enforcement Rule’s civil penalty framework and investigates complaints and breaches. Breach notification obligations follow HIPAA’s timelines and reporting mechanics, including HHS posting of breaches affecting 500 or more individuals. ([hhs.gov](https://www.hhs.gov/hipaa/part-2/index.html?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.