Skip to main content
Category: Regulatory Framework

Confidentiality of Substance Use Disorder Patient Records

Also known as: 42 CFR Part 2, 42 CFR Part 2, Part 2, Confidentiality of Alcohol and Drug Abuse Patient Records, Substance Use Disorder Confidentiality Regulations
Simply put

This is a federal law, commonly known as 42 CFR Part 2, that protects the privacy of patient records created by certain substance use disorder treatment programs that receive federal assistance. It generally requires patient consent before these sensitive records can be shared, offering protections that in many respects are stricter than those under HIPAA. These rules exist because information about substance use treatment carries a heightened risk of stigma and harm if disclosed.

Formal definition

42 CFR Part 2 is a federal regulation issued by the U.S. Department of Health and Human Services (HHS) governing the confidentiality of substance use disorder (SUD) patient records maintained by federally assisted programs that provide SUD diagnosis, treatment, or referral. It operates separately from, and in some respects more restrictively than, the HIPAA Privacy Rule, and applies specifically to records held by covered Part 2 programs rather than to all PHI. Following HHS final rulemaking intended to more closely align Part 2 with HIPAA, provisions address consent-based use and disclosure of Part 2 records; per the evidence, the rule prohibits combining patient consent for use and disclosure of records for civil, criminal, administrative, or legislative proceedings with other consents, and HIPAA-regulated entities receiving such records must ensure each disclosure is accompanied by a copy of the patient's consent. Practitioners should note that the applicability of Part 2 depends on whether a program meets the regulatory definition of a covered program, and that specific consent, redisclosure, and effective-date requirements should be verified against the current text of 42 CFR Part 2 and applicable HHS guidance. State law and other frameworks may impose additional obligations beyond Part 2.

Why it matters

Substance use disorder treatment information carries a heightened risk of stigma and harm if disclosed, which is why federal law provides protections that in many respects are stricter than those under the HIPAA Privacy Rule. Unlike HIPAA, which permits many uses and disclosures of PHI for treatment, payment, and health care operations without specific patient authorization, 42 CFR Part 2 generally requires patient consent before records held by covered Part 2 programs can be shared. For compliance professionals, this means that records touched by a federally assisted SUD program cannot be treated the same as ordinary PHI, even when the organization is otherwise operating under a HIPAA-compliant framework.

Who it's relevant to

Substance use disorder treatment programs
Programs that provide SUD diagnosis, treatment, or referral and receive federal assistance should determine whether they meet the regulatory definition of a covered Part 2 program. If they do, they are generally subject to Part 2's consent-based use and disclosure requirements, which apply in addition to any HIPAA obligations and can be more restrictive.
Privacy and compliance officers at HIPAA-regulated entities
Covered entities and business associates that receive Part 2 records must account for the requirement that each disclosure be accompanied by a copy of the patient's consent, and must recognize that Part 2 records cannot be treated identically to ordinary PHI. Compliance programs should verify current consent and redisclosure requirements against the text of 42 CFR Part 2 and applicable HHS guidance.
Legal counsel and litigation-facing staff
Because the rule prohibits combining consent for the use and disclosure of records for civil, criminal, administrative, or legislative proceedings with other consents, counsel handling subpoenas, discovery, or proceedings involving SUD records should confirm that the specific consent requirements are met before records are used or disclosed.
Health information management and EHR teams
Staff responsible for records systems and disclosure workflows may need to segregate or specially flag Part 2 records and build processes to attach the patient's consent to each disclosure. Confirm implementation details against the current regulatory text, since specific effective-date and technical requirements can change.

Inside 42 CFR Part 2

42 CFR Part 2
The federal regulation governing the confidentiality of substance use disorder (SUD) patient records, administered by the Substance Abuse and Mental Health Services Administration (SAMHSA) within HHS. It applies specifically to records from federally assisted SUD treatment programs and generally imposes stricter protections than the HIPAA Privacy Rule. Readers should verify current requirements against the applicable regulatory text, as Part 2 has been the subject of alignment efforts with HIPAA.
Part 2 Program
The entity or individual, or an identified unit within a general medical facility, that is federally assisted and holds itself out as providing SUD diagnosis, treatment, or referral. The regulation's protections attach based on whether a provider meets this definition; not every provider that encounters SUD information is a Part 2 program.
Covered Records
Records of the identity, diagnosis, prognosis, or treatment of a patient that are maintained in connection with a federally assisted SUD program and that would identify the patient as having or having had a substance use disorder. The scope is generally narrower and more specific than the broad category of PHI under HIPAA.
Patient Consent Requirements
Part 2 generally requires patient consent for disclosures that is more specific than a HIPAA authorization, typically including named recipients and defined purposes. Certain limited exceptions (such as medical emergencies and specified circumstances) may permit disclosure without consent; the precise conditions should be confirmed against the current regulation.
Relationship to HIPAA
Part 2 and HIPAA can apply concurrently to the same records. Where both apply, the more stringent protection generally governs. Compliance with HIPAA does not by itself establish compliance with Part 2, and Part 2 may impose additional restrictions on redisclosure beyond those in the HIPAA Privacy Rule.
Redisclosure Restrictions
Part 2 has historically limited how recipients of protected SUD records may further disclose them, often requiring a prohibition-on-redisclosure notice accompanying permitted disclosures. Specific notice language and conditions should be verified against the current regulatory text, as these provisions have been revised over time.

Common questions

Answers to the questions practitioners most commonly ask about 42 CFR Part 2.

Is Part 2 just a stricter version of HIPAA that applies to the same records?
No. Part 2 is a separate federal regulation (42 CFR Part 2) that is distinct from the HIPAA Privacy Rule, though both may apply to the same information. Part 2 applies specifically to records from federally assisted programs that meet its definition of a Part 2 program, and it has historically imposed disclosure and consent requirements that differ from HIPAA. A record can be subject to both frameworks at once, and in general the more protective requirement governs a given disclosure. Readers should verify the current text of 42 CFR Part 2 and how recent alignment efforts with HIPAA affect specific obligations, because the relationship between the two frameworks has changed over time.
Does obtaining a standard HIPAA authorization automatically satisfy Part 2 consent requirements?
Not necessarily. Part 2 has historically had its own consent requirements with content elements that may differ from a HIPAA authorization, and satisfying one does not by itself guarantee compliance with the other. The specific consent content, permitted redisclosure conditions, and applicable notices should be confirmed against the current version of 42 CFR Part 2, because these requirements have been the subject of regulatory changes intended to better align Part 2 with HIPAA. Where the two frameworks impose different requirements, organizations generally need to meet the applicable requirements of each that applies to the disclosure.
How do we determine whether our organization qualifies as a Part 2 program?
Whether an entity is a Part 2 program depends on the regulatory definition, which generally turns on whether the individual or entity is federally assisted and holds itself out as providing, or provides, substance use disorder diagnosis, treatment, or referral for treatment. General medical facilities and their personnel can fall within scope in certain circumstances. Because the definition is fact-specific and out of scope for a simple checklist, organizations should evaluate their programs against the current definition in 42 CFR Part 2 and, where the analysis is uncertain, consult legal counsel.
What should we do when Part 2 and HIPAA appear to conflict for a particular disclosure?
When both frameworks apply to the same disclosure, organizations generally need to comply with the requirements of each that applies, and in most cases the more protective or more restrictive requirement effectively governs whether and how the information may be disclosed. This analysis should be documented and applied at the level of the specific disclosure rather than as a blanket policy. Because the interaction between the two frameworks is nuanced and has been affected by regulatory changes, verify the current requirements and consider legal review for recurring or high-risk disclosure scenarios.
How should Part 2 requirements be reflected in agreements with vendors and other third parties?
Part 2 has historically included obligations addressing redisclosure and, for certain arrangements, agreements governing how contractors and others handle protected records. These are conceptually distinct from HIPAA business associate agreements, so a HIPAA business associate agreement alone does not necessarily address Part 2 obligations. Organizations should identify which vendors receive Part 2 records, determine the applicable Part 2 requirements against the current regulation, and ensure contractual terms and redisclosure limitations are addressed appropriately, coordinating with counsel where the requirements overlap or differ from HIPAA.
How does Part 2 affect breach handling and prohibitions on redisclosure?
Part 2 has historically restricted redisclosure of protected records and required accompanying notices limiting further disclosure, which may impose obligations beyond the HIPAA Breach Notification Rule administered by HHS OCR. Breach notification obligations for Part 2 records may involve multiple authorities and frameworks depending on the facts, and Part 2, HIPAA, the HITECH Act, and applicable state laws can each impose separate requirements. Because thresholds, timelines, and enforcement roles vary by framework and change over time, organizations should confirm current requirements under 42 CFR Part 2 and coordinate their breach response with counsel rather than assuming HIPAA processes alone are sufficient.

Common misconceptions

If an organization complies with the HIPAA Privacy Rule, it is automatically compliant with 42 CFR Part 2.
HIPAA and Part 2 are separate authorities. Part 2 generally imposes stricter, more specific requirements for SUD records, particularly around consent and redisclosure. Where both apply, the more protective standard typically governs, so HIPAA compliance alone does not establish Part 2 compliance.
A standard HIPAA authorization is sufficient to disclose SUD records under Part 2.
Part 2 has historically required consent that is more specific than a HIPAA authorization, generally including elements such as named recipients and defined purposes. Practitioners should confirm the current consent requirements against the applicable regulatory text before relying on a HIPAA-style authorization.
Part 2 applies to any provider or record that mentions substance use.
Part 2's protections generally attach to records held by federally assisted programs that meet the regulatory definition of a Part 2 program. Not every provider that encounters SUD information is covered, though HIPAA may still apply to that information independently.

Best practices

Determine whether your organization or a specific unit meets the regulatory definition of a Part 2 program before assuming or ruling out its applicability, and document that analysis.
Where both Part 2 and HIPAA apply to the same records, apply the more stringent protection and confirm your consent, disclosure, and redisclosure processes meet the stricter Part 2 requirements.
Use consent forms that satisfy the specific elements Part 2 requires rather than defaulting to a standard HIPAA authorization, and verify required elements against the current regulatory text.
Include appropriate prohibition-on-redisclosure notices with permitted disclosures of protected SUD records, confirming current notice requirements against the applicable regulation.
Train staff who handle SUD records on the differences between HIPAA and Part 2, particularly the narrower disclosure exceptions and stricter consent rules under Part 2.
Verify current requirements against the applicable regulatory text and account for any additional obligations from state law or other frameworks that may exceed the federal baseline.