Skip to main content
Category: Regulatory Framework

42 CFR Part 2

Also known as: Part 2, Confidentiality of Substance Use Disorder Patient Records
Simply put

42 CFR Part 2, commonly called 'Part 2', is a federal regulation that protects the confidentiality of substance use disorder (SUD) treatment records. It generally restricts when these records can be used or disclosed, including limits on their use in legal proceedings against patients. It is a separate legal framework from HIPAA, though both can apply to the same information in many cases.

Formal definition

42 CFR Part 2 is a federal regulation governing the confidentiality of substance use disorder (SUD) treatment records created by federally assisted Part 2 programs. It generally prohibits the use and disclosure of such records unless specific circumstances exist, including consent-based or otherwise permitted disclosures for purposes such as treatment and payment as defined in the regulation. Part 2 also restricts the use of records and testimony in civil, criminal, administrative, and legislative proceedings against patients, absent appropriate patient authorization or another applicable exception, and provides heightened protection against disclosures to law enforcement and outside the Part 2 program. Part 2 operates independently of the HIPAA Privacy Rule and, where both apply, entities should evaluate obligations under each framework; readers should confirm current requirements against the applicable regulatory text, as provisions have been revised over time.

Why it matters

42 CFR Part 2 addresses a category of health information that carries unusually high stakes for patients: records related to substance use disorder (SUD) treatment. Because disclosure of SUD treatment can expose individuals to stigma, discrimination, and legal jeopardy, Part 2 generally imposes stricter limits on use and disclosure than the HIPAA Privacy Rule alone. In particular, it restricts the use of records and testimony in civil, criminal, administrative, and legislative proceedings against patients, absent appropriate patient authorization or another applicable exception. This protection against use in legal proceedings is a defining feature that sets Part 2 apart from the general HIPAA framework.

For compliance professionals, the practical significance is that Part 2 and HIPAA are separate legal frameworks that can both apply to the same information. An organization that is fully compliant with the HIPAA Privacy Rule is not automatically compliant with Part 2, and the reverse is also true. Where both frameworks apply, entities should evaluate their obligations under each and, where they differ, generally follow the more protective requirement. Missteps can create both regulatory exposure and real harm to patients whose SUD records receive heightened protection under the regulation.

Because Part 2 has been revised over time, including through rulemaking intended to better align aspects of it with HIPAA, organizations should not rely on outdated understandings of its requirements. Readers should confirm current obligations against the applicable regulatory text and relevant HHS guidance, and should be aware that state law may impose additional confidentiality requirements beyond both Part 2 and HIPAA.

Who it's relevant to

SUD Treatment Programs and Their Compliance Staff
Federally assisted programs that provide substance use disorder treatment are directly subject to Part 2's restrictions on the use and disclosure of SUD records. Compliance and privacy staff at these programs must understand when consent is required, which disclosures are permitted, and how Part 2 restricts use of records in legal proceedings, in addition to any HIPAA obligations that may apply.
Privacy and Compliance Officers at Healthcare Organizations
Organizations that receive, hold, or exchange SUD records may need to comply with Part 2 in addition to the HIPAA Privacy Rule. Privacy officers should evaluate obligations under both frameworks where they overlap, since HIPAA compliance alone does not establish Part 2 compliance, and should confirm current requirements against the applicable regulatory text.
Legal and Litigation Support Professionals
Because Part 2 restricts the use of records and testimony in civil, criminal, administrative, and legislative proceedings against patients, attorneys and litigation support staff handling matters involving SUD records need to account for its limits on disclosure to law enforcement and on use of protected records in proceedings, absent appropriate patient authorization or another applicable exception.
Health Information Exchange and IT Teams
Teams responsible for exchanging or integrating patient records should be aware that SUD records covered by Part 2 may carry heightened protections against disclosure outside the Part 2 program. Systems and data-sharing arrangements should be evaluated to ensure Part 2-protected information is handled consistent with the regulation and with any additional state law requirements.

Inside 42 CFR Part 2

Scope of Protected Records
42 CFR Part 2 governs the confidentiality of substance use disorder (SUD) treatment records that are created by federally assisted programs meeting the regulatory definition of a 'program.' Its protections are generally narrower and more specific than HIPAA's, applying to a defined category of SUD treatment information rather than to PHI broadly. Readers should verify the current definition of a covered 'program' against the applicable regulatory text.
Consent Requirements
Part 2 has historically imposed consent requirements for disclosure of covered SUD records that are generally more stringent than the HIPAA Privacy Rule's permitted uses and disclosures. The specific content, form, and permissible scope of consent are set by the regulation and have been subject to change; practitioners should confirm the current consent standards against the current regulatory text.
Relationship to HIPAA
Part 2 operates alongside HIPAA rather than replacing it. Where both apply, an entity may need to satisfy both frameworks, and Part 2's restrictions may impose additional obligations beyond those of the HIPAA Privacy Rule. Part 2 is administered separately from the HIPAA rules enforced by HHS OCR, and readers should not assume HIPAA compliance alone satisfies Part 2.
Redisclosure Limitations
Part 2 has traditionally restricted redisclosure of covered records by recipients, typically requiring accompanying notice that limits further use or disclosure. The precise redisclosure notice language and requirements should be confirmed against the current regulatory text, as these provisions have been revised over time.

Common questions

Answers to the questions practitioners most commonly ask about 42 CFR Part 2.

Is 42 CFR Part 2 just another name for HIPAA, or the same set of rules?
No. 42 CFR Part 2 is a separate federal regulation from HIPAA. While both address the confidentiality of health information, Part 2 is distinct in its origins, scope, and enforcement authority, and it applies specifically to records from federally assisted programs that meet its definition of a substance use disorder treatment program. HIPAA's Privacy, Security, Breach Notification, and Enforcement Rules operate independently, and a covered entity or business associate can be subject to HIPAA without being subject to Part 2. Where both apply, an organization generally must comply with each, and readers should verify the current text of both frameworks.
Does complying with HIPAA automatically mean I am compliant with 42 CFR Part 2?
Not necessarily. HIPAA compliance does not by itself establish compliance with 42 CFR Part 2, because Part 2 has historically imposed its own requirements that can differ from HIPAA's. An organization that handles records covered by Part 2 generally needs to evaluate both frameworks separately. Where the two frameworks address the same activity differently, organizations typically must reconcile the requirements rather than assume one satisfies the other. Because these rules have been the subject of regulatory alignment efforts over time, readers should confirm the current requirements of each against the applicable regulatory text.
How do I determine whether records I hold are actually covered by 42 CFR Part 2?
Coverage generally turns on whether the records identify a patient as having a substance use disorder and originate from a program that meets Part 2's definition of a federally assisted program providing substance use disorder diagnosis, treatment, or referral for treatment. Not every record mentioning substance use is automatically within scope, and not every provider is a Part 2 program. Organizations typically should assess the source of the records, the nature of the program, and how the federal-assistance and program criteria apply. Because these definitions have specific regulatory meaning that differs from common usage, verify the applicable definitions against the current regulatory text and consider legal review for close cases.
How should consent for disclosing Part 2 records be handled in practice?
Part 2 has historically relied on patient consent as a central mechanism for disclosures, with specific content and format expectations for a valid consent. In practice, organizations generally should build consent workflows that capture the required elements, track the scope of what the patient authorized, and avoid disclosing beyond that scope. Because the consent requirements and any permitted disclosure exceptions are defined in the regulation and have been subject to change, confirm the current requirements against the applicable regulatory text before designing or updating consent processes.
How does Part 2 affect information sharing between covered entities and business associates?
Where Part 2 applies, its restrictions generally travel with the records and can limit re-disclosure even to parties an organization would otherwise share with under HIPAA. This means that arrangements structured solely around HIPAA business associate agreements may not address Part 2's separate requirements. In practice, organizations typically should identify which data flows involve Part 2 records and evaluate whether additional restrictions, notices, or agreement terms are needed. Verify the specific re-disclosure rules against the current regulatory text, and note that state law may impose further requirements.
What operational steps help an organization stay aligned with Part 2 alongside HIPAA?
Common practical steps include identifying and segregating or labeling records that fall within Part 2 scope, mapping data flows to see where those records travel, aligning consent and disclosure procedures with Part 2's requirements, and training staff on how Part 2 differs from HIPAA. Organizations generally should also coordinate their Part 2 practices with their HIPAA Privacy and Security Rule programs rather than treating them in isolation. Because Part 2 requirements have evolved and may interact with HITECH, state law, and other frameworks, confirm current obligations against the applicable regulatory text and consult qualified counsel where scope is uncertain.

Common misconceptions

HIPAA compliance automatically means 42 CFR Part 2 compliance.
Part 2 is a distinct framework focused on federally assisted SUD treatment records and generally imposes requirements, particularly around consent and redisclosure, that go beyond the HIPAA Privacy Rule. An entity handling covered SUD records may need to satisfy both frameworks separately.
Part 2 applies to all substance use disorder information wherever it is held.
Part 2's protections generally attach to records created by federally assisted programs meeting the regulatory definition of a 'program.' Its scope is defined by that relationship rather than applying to every mention of SUD information in any setting. The precise scope should be verified against the current regulatory text.
Consent for disclosure under Part 2 works the same way as HIPAA authorizations.
Part 2 consent requirements have historically been more stringent and specific than HIPAA's permitted uses, disclosures, and authorizations. The exact requirements have changed over time and should be confirmed against the current regulatory text rather than assumed equivalent to HIPAA.

Best practices

Determine whether your organization or a specific record set meets the regulatory definition of a Part 2 'program' and covered SUD record before assuming HIPAA alone governs the information; verify the current definition against the applicable regulatory text.
Maintain distinct consent processes for covered SUD records, and confirm current Part 2 consent content and form requirements against the current regulatory text rather than relying on HIPAA authorization templates.
Include appropriate redisclosure notice with covered records when disclosing them, and confirm the current required notice language against the current regulatory text.
Where both HIPAA and Part 2 apply, design workflows to satisfy both frameworks, recognizing that Part 2 may impose additional obligations beyond the HIPAA Privacy Rule.
Coordinate with legal counsel to confirm current Part 2 requirements, since these provisions have been revised over time and may interact with HIPAA, the HITECH Act, and applicable state law.
Train staff who handle SUD treatment records on the distinction between Part 2 and HIPAA so that more protective Part 2 requirements are not overlooked in day-to-day disclosures.