
What 42 CFR Part 2 Protects
42 CFR Part 2 is a federal regulation that protects the confidentiality of patient records created by addiction treatment programs that receive federal assistance. It requires patient consent before a program discloses most information identifying someone as having sought or received treatment for a substance use disorder (SUD), and it applies on top of, not instead of, the HIPAA Security Rule. The regulation is codified at 42 CFR Part 2 and is jointly administered by the Substance Abuse and Mental Health Services Administration (SAMHSA) and the HHS Office for Civil Rights (OCR).
If you run an addiction treatment center, a methadone clinic, a detox facility, or an outpatient SUD program, Part 2 likely applies to you in addition to HIPAA. Getting consent language, redisclosure notices, and breach procedures wrong can expose a program to both federal penalties and patient complaints, so these rules deserve the same attention as clinical protocols.
Quick Answer
42 CFR Part 2 requires federally assisted addiction treatment programs to get patient consent before disclosing most substance use disorder (SUD) treatment records, applying stricter rules than HIPAA alone. A February 2024 final rule from HHS and SAMHSA aligned several Part 2 requirements with HIPAA, including breach notification and enforcement, with a compliance date of February 16, 2026, that has already passed. Programs that have not updated consent forms, their Notice of Privacy Practices, and breach procedures to match the 2024 rule should treat it as an active compliance gap, not a future deadline.
Who Counts as a "Part 2 Program"
A facility is a Part 2 program, and must comply, if it holds itself out as providing SUD diagnosis, treatment, or referral and is "federally assisted." According to SAMHSA's confidentiality regulations guidance, federal assistance includes receiving Medicare or Medicaid certification, federal grant funding, tax-exempt status, or a DEA registration that allows the program to dispense or prescribe controlled substances for SUD treatment. Most licensed addiction treatment centers meet at least one of these criteria, which means most are covered even without a direct federal grant.
A general medical practice that only incidentally treats patients with SUD, such as a primary care office prescribing buprenorphine as part of broader care, is not automatically a Part 2 program unless it meets the "holding out" test. That determination affects consent forms, breach obligations, and your HIPAA Notice of Privacy Practices, so it is worth confirming with legal counsel rather than guessing.
Compliance Deadline Already Passed
HHS and SAMHSA published a final rule updating 42 CFR Part 2 in the Federal Register on February 16, 2024, implementing Section 3221 of the CARES Act. Most provisions carried a two-year compliance date of February 16, 2026, which has now passed. If your program has not updated its consent forms, Notice of Privacy Practices, and breach procedures to match the 2024 final rule, you are currently outside the compliance window and should close the gap now.
What the 2024 Final Rule Changed
The 2024 final rule narrowed the gap between 42 CFR Part 2 and HIPAA, but it did not eliminate Part 2's extra protections. The key changes include:
- Single consent for treatment, payment, and operations. Patients can now sign one consent covering all future uses and disclosures of their SUD records for treatment, payment, and healthcare operations, instead of naming each recipient separately.
- HIPAA-aligned redisclosure. Once a HIPAA covered entity lawfully receives Part 2 records, it may redisclose them in accordance with the HIPAA Privacy Rule rather than obtaining a new Part 2 consent for every downstream disclosure.
- Breach notification now applies. The HIPAA Breach Notification Rule extends to Part 2 records, so a breach involving SUD treatment data triggers the same patient notification, HHS reporting, and in some cases media notification duties as a HIPAA breach.
- HIPAA-style enforcement and penalties. HHS OCR can now pursue civil money penalties for Part 2 violations using the HIPAA enforcement framework, in addition to the criminal penalties that already existed under Part 2.
- Updated Notice of Privacy Practices. Part 2 programs must give patients a notice describing their privacy rights, similar to the HIPAA Notice of Privacy Practices.
These changes make Part 2 compliance operationally closer to HIPAA, which means the technical safeguards you already use for electronic records, including HIPAA compliant email for healthcare providers, now carry more direct regulatory weight for SUD data too.
Part 2 Compliance Action Checklist
- Update consent forms to reflect the single-consent option for treatment, payment, and operations
- Revise or create a Notice of Privacy Practices that covers Part 2 patient rights
- Confirm your breach response plan treats SUD record incidents under the HIPAA Breach Notification Rule
- Review business associate and data-sharing agreements for Part 2-specific redisclosure language
- Train front-desk and clinical staff on the updated consent and redisclosure rules
- Confirm your EHR and messaging systems log and restrict SUD data access separately where required
How Part 2 Enforcement Works Alongside HIPAA
Part 2 and HIPAA now share an enforcement mechanism but remain separate rules, and a single incident can trigger obligations under both. If a ransomware attack exposes a database that includes SUD treatment records, you need to run breach analysis under HIPAA for the broader patient data while also confirming that the SUD-specific consent and redisclosure requirements under Part 2 were not independently violated before the incident occurred. Programs that already run HIPAA security awareness training and document their electronic health records security controls have a head start, because the technical safeguards expected under both rules largely overlap: access controls, audit logging, encryption, and a tested incident response plan.
Staff training matters as much as policy language here. Front-desk employees who scan an insurance card or clinicians who copy notes into a referral letter are the people most likely to trigger a redisclosure problem, so HIPAA employee training requirements should be extended to cover Part 2 consent and redisclosure rules specifically, not just general HIPAA awareness. Reviewing current healthcare cybersecurity threats in 2026 alongside your Part 2 update is also worth doing, since the same attacks that cause a HIPAA breach now trigger Part 2 breach notification too.
Key Takeaway
42 CFR Part 2 still requires stricter consent than HIPAA for most SUD treatment disclosures, and since the compliance date passed on February 16, 2026, Part 2 breaches now carry HIPAA-style penalties and notification duties. Treat a Part 2 update as both a documentation project and a technical safeguards review.
Where Managed Endpoint Security Fits
Neither 42 CFR Part 2 nor the HIPAA Security Rule names a specific product, but both expect documented technical safeguards that can prevent and detect unauthorized access to SUD treatment records. Bellator Core combines managed endpoint detection and response, remote monitoring, and Ransomware Rollback® for $33 per computer per month, built for practices that need monitored, managed protection rather than a one-time software license. If you only need core detection and response coverageBellator Shield starts at $19 per computer per month; compare both on the protection plans page before deciding which fits your program's size and risk.
Get a HIPAA and Part 2 Security Review
A short, no-pressure assessment of where your endpoint security, access controls, and breach response plan stand against current HIPAA and 42 CFR Part 2 expectations.
Frequently Asked Questions
Yes. Even after the 2024 alignment, Part 2 still generally requires patient consent before disclosing SUD treatment records, while HIPAA permits many treatment, payment, and operations disclosures without separate patient authorization. The 2024 rule simplified Part 2 consent to a single form covering future TPO uses, but it did not remove the underlying consent requirement.
You remain bound by whichever version of Part 2 consent rules your forms currently reflect, and operating with outdated forms after the February 16, 2026 compliance date is a documentation gap that HHS OCR could flag during a complaint investigation or audit. Update your forms and Notice of Privacy Practices promptly, and confirm current status with legal counsel.
If a telehealth program meets the "federally assisted" and "holding out" tests described by SAMHSA, it is a Part 2 program regardless of delivery method. Confirm this with counsel, since telehealth billing and funding arrangements can affect the federal assistance determination.
HHS OCR enforces Part 2 using HIPAA's civil money penalty framework following the 2024 final rule, while SAMHSA continues to provide program-level guidance and interpretation. Criminal penalties that existed under the original Part 2 statute still apply in applicable cases.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.



