HIPAAFluent

Plain answers

HIPAA vs. 42 CFR Part 2: what recovery organizations need to know

If you run a rehab, outpatient program, or another substance use disorder treatment organization, you live under two federal confidentiality regimes at once: HIPAA, which covers health information generally, and 42 CFR Part 2, which protects substance use disorder treatment records specifically — and goes further. Most training vendors never mention the second one. Here is the honest picture.

What Part 2 is

42 CFR Part 2 — "Confidentiality of Substance Use Disorder Patient Records" — is a federal regulation, separate from HIPAA, that restricts how records identifying someone as having (or having had) a substance use disorder may be used and disclosed. Its stated purpose is striking in its clarity: to ensure that a person receiving treatment "is not made more vulnerable by reason of the availability of their record" than someone who never sought treatment at all. (42 CFR 2.2)

Who it applies to

Part 2 applies to "Part 2 programs": federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral for treatment. "Federally assisted" is broader than it sounds — it includes participating in Medicare, holding a DEA registration to dispense controlled substances used in SUD treatment, receiving federal funds in any form, and even tax-exempt status. The regulation's own examples of covered settings include treatment and rehabilitation programs, employee assistance programs, units within general hospitals, school-based programs, and private practitioners who hold themselves out as providing SUD treatment. (42 CFR 2.12(b), (e))

In practice: most rehabs, detox facilities, and outpatient SUD programs should assume Part 2 applies to them, and halfway houses or sober living homes that provide or hold themselves out as providing treatment or referral services may be covered too. Whether a specific organization is a Part 2 program is a legal determination for your compliance officer or counsel — not something a training course can decide for you.

How it differs from HIPAA

  • Consent-centric by default. HIPAA permits many disclosures without patient authorization — treatment, payment, and operations most of all. Part 2 starts from prohibition: uses and disclosures are barred unless a specific circumstance permits them, and the workhorse permission is the patient's written consent, with required elements spelled out in the rule. A 2024 update did allow a single written consent to cover all future treatment, payment, and health care operations uses — a significant alignment with how HIPAA works — but the consent itself is still the gate, and the patient can revoke it in writing. (42 CFR 2.31, 2.33)
  • A notice must travel with the records. Each disclosure made with consent has to be accompanied by a written statement that the record is protected by federal law — the short form is simply: "42 CFR part 2 prohibits unauthorized use or disclosure of these records." (42 CFR 2.32)
  • Protection against use in proceedings. Part 2 records generally cannot be used to investigate, prosecute, or otherwise proceed against the patient in civil, criminal, administrative, or legislative proceedings without patient consent or a special court order — a shield that reflects why people fear seeking treatment in the first place. (42 CFR 2.12(d))
  • Counseling notes get extra protection. Like HIPAA's psychotherapy notes, "SUD counseling notes" kept separate from the rest of the record require their own dedicated consent, and treatment can't be conditioned on signing one. (42 CFR 2.31(b))
  • State law interplay. Like HIPAA, Part 2 doesn't sweep state law aside: if a state law prohibits something Part 2 would permit, the state prohibition stands — but no state law can authorize what Part 2 prohibits. (42 CFR 2.20)

Where the 2024 update aligned Part 2 with HIPAA

A February 2024 final rule reworked Part 2 to work more like HIPAA where that helps care coordination, without giving up the consent model. Beyond the single consent for treatment, payment, and operations, the current rule imports HIPAA's definitions (breach, covered entity, business associate), applies HIPAA's Breach Notification Rule to Part 2 programs' unsecured records "in the same manner" as it applies to covered entities, and ties violations to the same civil and criminal penalty provisions and enforcement process as HIPAA. (42 CFR 2.11, 2.16(b), 2.3)

Why your staff need both kinds of awareness

The two rules share a foundation: recognizing protected information, the discipline of minimum disclosure, safeguarding records, and reporting incidents immediately. That foundation is what HIPAA training builds — and it's why HIPAA awareness is required for the workforce of covered entities and business associates in the first place. But in a recovery organization, staff also need your program's Part 2 policies: when written consent is required, what the redisclosure notice looks like, and who answers the phone-call question "is my son there?" Part 2 makes even confirming that someone is a patient a disclosure. (42 CFR 2.11, "Disclose")

What our course does — and doesn't — cover

Our eight-chapter course teaches HIPAA: the Privacy, Security, and Breach Notification Rules. It does not teach your program's 42 CFR Part 2 obligations — those consent forms, notices, and procedures belong with your compliance officer or counsel, applied to your specific program. This page, like the course, is educational material, not legal advice. Read the full disclaimer.

42 CFR 2.2 42 CFR 2.12 42 CFR 2.31 42 CFR 2.32 42 CFR 2.16(b) All our sources

Start with the HIPAA foundation

Eight short video chapters, quizzes, individual certificates, and exportable training records for your whole staff.