Skip to main content
Category: De-identification and PHI Types

Substance Use Disorder Records

Also known as: SUD Records, SUD Patient Records, 42 CFR Part 2 Records, Part 2 Records, Alcohol and Drug Abuse Patient Records
Simply put

Substance use disorder (SUD) records are patient records related to treatment for alcohol or drug problems that receive special federal privacy protection. These protections come from a federal regulation commonly called 42 CFR Part 2, which generally applies to certain federally assisted treatment programs. In most cases these records cannot be used to investigate or prosecute the patient without the patient's written consent, and the confidentiality rules can be stricter than those under HIPAA alone.

Formal definition

Substance Use Disorder Records refers to patient records identifying, or protected under, the federal confidentiality regime at 42 CFR Part 2, which governs records related to SUD treatment created by or maintained within federally assisted SUD programs. Part 2 is a distinct federal framework administered under HHS and operates alongside, rather than as part of, the HIPAA Privacy Rule; where both apply, practitioners must reconcile Part 2's generally more restrictive consent and disclosure requirements with HIPAA obligations. A core Part 2 protection is that SUD treatment records generally cannot be used to investigate or prosecute the patient without the patient's written consent, subject to the specific exceptions in the regulation. Recent rulemaking has modernized certain Part 2 provisions and aligned some aspects with HIPAA, so the precise scope of covered programs, consent standards, permitted disclosures, and effective dates should be confirmed against the current text of 42 CFR Part 2 and applicable HHS guidance. Note also that HIPAA compliance alone does not establish Part 2 compliance, and state law may impose additional confidentiality requirements.

Why it matters

Substance use disorder records carry heightened confidentiality protections because the disclosure of a person's SUD treatment history can expose them to serious harm, including stigma, discrimination, and legal jeopardy. Under 42 CFR Part 2, these records generally cannot be used to investigate or prosecute the patient without the patient's written consent. This protection is stronger than what HIPAA alone provides, reflecting a longstanding federal policy of encouraging people to seek treatment without fear that their records will be turned against them.

For compliance professionals, the critical point is that HIPAA compliance alone does not establish Part 2 compliance. Where both frameworks apply, organizations must reconcile Part 2's generally more restrictive consent and disclosure requirements with their HIPAA obligations. Treating SUD records as ordinary PHI, or applying only HIPAA's minimum necessary and disclosure standards, can result in improper disclosures that violate a separate federal regulation. State law may also impose additional confidentiality requirements beyond either framework.

Recent HHS rulemaking has modernized certain Part 2 provisions and aligned some aspects with HIPAA, but the scope of covered programs, consent standards, permitted disclosures, and effective dates continue to evolve. Practitioners should confirm details against the current text of 42 CFR Part 2 and applicable HHS guidance rather than relying on prior versions of the rule, since the specific requirements have been the subject of active regulatory change.

Who it's relevant to

Federally Assisted SUD Treatment Programs
Programs that provide substance use disorder treatment and receive federal assistance are the core entities directly subject to 42 CFR Part 2. These organizations must apply Part 2's consent and disclosure protections to covered records and cannot rely on HIPAA compliance alone to satisfy their Part 2 obligations.
Privacy Officers and Compliance Staff
Privacy and compliance personnel at organizations that create, receive, or maintain SUD records must reconcile Part 2's generally more restrictive consent and disclosure requirements with HIPAA. They should track ongoing Part 2 rulemaking and confirm current requirements against the regulation and HHS guidance, and account for any additional state-law protections.
Legal Counsel and Auditors
Attorneys and auditors advising on healthcare privacy need to recognize that Part 2 is a separate federal framework with distinct rules, including the general prohibition on using SUD records to investigate or prosecute the patient without written consent. Because HIPAA compliance does not establish Part 2 compliance, assessments should evaluate both frameworks independently.
Providers and Care Coordinators Handling SUD Records
Clinicians, care coordinators, and other staff who handle SUD treatment records must understand that these records may carry stricter consent and disclosure requirements than other PHI, and should confirm the applicable consent standards before making disclosures.

Inside SUD Records

42 CFR Part 2 Records
Records relating to the identity, diagnosis, prognosis, or treatment of a patient that are maintained in connection with the provision of substance use disorder (SUD) services by a federally assisted program. These records are governed by 42 CFR Part 2, a separate federal regulatory framework distinct from HIPAA, and readers should verify the specific scope against the current regulatory text.
Part 2 Program
Generally, an individual or entity (or an identified unit within a general medical facility) that holds itself out as providing, and provides, SUD diagnosis, treatment, or referral for treatment, and that is federally assisted. Only records held by or on behalf of such a program typically fall within Part 2 protections.
Federally Assisted
A qualifying condition under Part 2 that generally includes programs receiving federal funding, licensure, certification, registration, or tax-exempt status related to SUD services. This is a defined regulatory concept that should be confirmed against the current rule rather than assumed from common usage.
Relationship to HIPAA
SUD records may also constitute protected health information (PHI) under HIPAA when held by a covered entity or business associate. Where both frameworks apply, Part 2 typically imposes more stringent consent and disclosure requirements, and compliance with HIPAA alone does not, in most cases, satisfy Part 2 obligations.
Consent and Disclosure Requirements
Part 2 generally requires specific patient consent for many disclosures that HIPAA might otherwise permit without authorization (such as certain treatment, payment, or operations uses). The exact consent content, exceptions, and redisclosure limitations should be verified against the current Part 2 regulatory text and any applicable HITECH Act amendments.
Redisclosure Restrictions
Information disclosed under Part 2 generally carries prohibitions on redisclosure, typically requiring a notice accompanying the disclosure. Recipients are generally limited in how they may further share the information beyond the scope of the original consent.

Common questions

Answers to the questions practitioners most commonly ask about SUD Records.

Are substance use disorder records just a type of PHI covered by the same HIPAA rules as everything else?
No. While substance use disorder (SUD) records maintained by certain federally assisted programs can also be protected health information under HIPAA, they are generally subject to a separate federal regulatory scheme (commonly referred to as Part 2) that imposes additional, and in many respects more stringent, protections. Treating these records as ordinary PHI can lead to unauthorized disclosures. Both frameworks may apply simultaneously, and where they differ, you generally must satisfy the more protective requirement. Readers should verify the specific obligations against the current regulatory text, because the interaction between HIPAA and Part 2 has been the subject of alignment efforts over time.
If we obtain a general HIPAA authorization from the patient, does that cover disclosure of their SUD records?
Not necessarily. A HIPAA-compliant authorization is not automatically sufficient for records protected under the Part 2 framework, which has historically imposed its own consent requirements with elements that differ from a standard HIPAA authorization. Relying on a general HIPAA authorization alone may leave you out of compliance with the SUD-specific rules. Confirm the current consent and redisclosure requirements against the applicable regulation, and note that state law may add further requirements beyond both HIPAA and the federal SUD rules.
How do we identify which of our records fall under the SUD-specific protections rather than general HIPAA rules?
Coverage generally turns on whether the record was created or maintained by a program that meets the regulatory definition of a covered SUD program, rather than simply on whether the record mentions substance use. Not every note referencing substance use in a general medical setting falls under the SUD-specific framework, and conversely records from a qualifying program generally do. Because these definitions have specific regulatory meanings that differ from common usage, work with privacy counsel to map which of your programs and record types qualify, and verify against the current regulatory text.
What should we consider when configuring our EHR or systems to handle SUD records?
In general, organizations consider whether they can segregate or flag SUD-protected records so that any consent, redisclosure notice, and access-control requirements are honored, and whether downstream disclosures can be tracked. Because the SUD framework has historically included restrictions on redisclosure, systems and workflows typically need a way to carry protective notices with the data. These are operational considerations, not a substitute for legal review; confirm the specific technical and consent requirements against the current regulation before finalizing configurations.
Do our business associate agreements adequately address SUD records?
A standard HIPAA business associate agreement addresses HIPAA obligations but does not by itself resolve requirements under the SUD-specific framework, which has its own contracting and downstream-recipient concepts. Where a vendor handles SUD-protected records, organizations generally review whether additional contractual terms are needed to bind that vendor to the SUD requirements. Have counsel confirm what agreement language is required under the current regulation, and remember that obligations attach through defined relationships rather than to any vendor that merely touches data.
How does obtaining HITRUST certification relate to compliance with SUD record requirements?
HITRUST certification, issued by a private organization against the HITRUST CSF, is not a legal requirement and does not by itself establish compliance with HIPAA or with the federal SUD record rules. A certification may support your broader security and privacy program, but it does not substitute for meeting the specific consent, redisclosure, and disclosure-tracking obligations that apply to SUD-protected records. Compliance with those requirements should be assessed directly against the applicable current regulatory text and any applicable state law.

Common misconceptions

SUD records are covered entirely by HIPAA, so following the HIPAA Privacy Rule is sufficient.
SUD records maintained by a federally assisted Part 2 program are governed by 42 CFR Part 2, a separate framework that generally imposes stricter consent and redisclosure requirements. Where both apply, compliance with HIPAA alone typically does not satisfy Part 2, and practitioners should apply both frameworks.
All records mentioning substance use are protected under Part 2.
Part 2 protections generally attach only to records held by or on behalf of a federally assisted Part 2 program meeting the regulatory definition. Substance use information recorded outside such a program may not fall under Part 2, though it may still be PHI under HIPAA. Scope should be confirmed against the current regulatory text.
Once SUD information is lawfully disclosed, the recipient can use and share it like any other health information.
Part 2 generally imposes redisclosure restrictions, typically requiring a prohibition-on-redisclosure notice. Recipients are usually limited to the purposes authorized by the original consent, and further sharing generally requires appropriate consent or an applicable exception.

Best practices

Determine whether records qualify as Part 2 records by assessing whether they are held by or on behalf of a federally assisted SUD program, rather than assuming HIPAA alone applies.
Where both HIPAA and Part 2 apply, follow the more stringent requirement for each disclosure, generally treating Part 2 consent and redisclosure rules as controlling for SUD records.
Use consent forms that meet the specific content requirements of the current Part 2 regulation for disclosures that Part 2 does not otherwise permit, and verify the required elements against the current regulatory text.
Include a prohibition-on-redisclosure notice with disclosures of Part 2 information and train staff on the limits recipients face on further sharing.
Confirm applicable requirements against the current 42 CFR Part 2 text and any HITECH Act amendments, and check for additional state law protections that may impose stricter obligations.
Document consent, disclosures, and the legal basis for each release so that Part 2 and HIPAA obligations can be demonstrated, recognizing that no single process guarantees compliance.