Skip to content
    August 23, 2026| Top Floor Team| 12 min read

    42 CFR Part 2 vs HIPAA: What the Alignment Rule Changed

    If your systems hold substance use disorder treatment records from a federally assisted program, HIPAA is not the only federal confidentiality rule you are under, and the overhaul of the second one has been mandatory since February 16, 2026. The final rule at 89 FR 12472 was published on February 16, 2024, took effect on April 16, 2024, and states in its DATES block that "Persons subject to this regulation must comply with the applicable requirements of this final rule by February 16, 2026." The headline change is real relief: a patient can now give a single written consent covering all future uses and disclosures for treatment, payment, and health care operations, which ends the per-disclosure consent treadmill that made Part 2 records unusable in ordinary care coordination. The contrarian half, and the reason "Part 2 is aligned with HIPAA now" is a dangerous summary: the alignment rule kept the provision that makes Part 2 genuinely different, which is that these records may not be used in proceedings against the patient without consent or a court order, and that restriction follows the record to whoever holds it.

    Below: how to tell whether Part 2 applies to you at all, what the rule changed, what it deliberately did not, and what any of it means for the systems you build.

    Key takeaways

    • Part 2 applies to a narrow set of holders and a broad set of records. The gate is whether the record came from a federally assisted program whose function is substance use disorder diagnosis, treatment, or referral.
    • Since February 16, 2026, a single patient consent can cover all future treatment, payment, and health care operations disclosures until the patient revokes it in writing.
    • Part 2 breaches now run through HIPAA's Breach Notification Rule, and Part 2 violations now carry HIPAA's civil and criminal penalty structure rather than a separate one.
    • The restriction that survived alignment is the one that matters most: records cannot be used in civil, criminal, administrative, or legislative proceedings against the patient without consent or a court order, and that restriction binds anyone who obtains the record.
    • A covered entity or business associate that receives records under a single treatment, payment, and health care operations consent is not required to segregate or segment them, which is the change your engineering roadmap actually cares about.

    First question: does Part 2 apply to you?

    Most health tech companies that ask this question do not fall under Part 2, and the ones that do often did not realize it. The test at 42 CFR 2.12 has two parts and both must be satisfied.

    The record has to identify a patient as having or having had a substance use disorder, directly or by reference to publicly available information, and it has to contain substance use disorder information obtained by a federally assisted program for the purpose of treating that disorder, diagnosing it for treatment, or referring the patient for treatment.

    "Federally assisted" is much broader than a federal grant. The regulation lists, among others, participation as a provider in the Medicare program, authorization to conduct maintenance treatment or withdrawal management, registration to dispense a controlled substance under the Controlled Substances Act to the extent it is used in treating substance use disorders, receipt of federal financial assistance "in any form, including financial assistance which does not directly pay for the substance use disorder diagnosis, treatment, or referral for treatment," and assistance from the IRS "through the granting of tax exempt status to the program." A tax-exempt clinic is federally assisted. So is a practice that holds a DEA registration for buprenorphine.

    The program half is what narrows it back down. The regulation's own explanation says coverage includes "treatment or rehabilitation programs, employee assistance programs, programs within general hospitals, school-based programs, and private practitioners who hold themselves out as providing, and provide substance use disorder diagnosis, treatment, or referral for treatment," and then gives the counterexample that matters: the rules would not apply "to emergency room personnel who refer a patient to the intensive care unit for an apparent overdose, unless the primary function of such personnel is the provision of substance use disorder diagnosis, treatment, or referral for treatment."

    There is a second counterexample worth quoting because it settles a question founders ask constantly. Under 42 CFR 2.12(d)(2)(ii), a treating provider who is not subject to Part 2 "may record information about a SUD and its treatment that identifies a patient," and the act of recording it "does not by itself render a medical record which is created by a treating provider who is not subject to this part, subject to the restrictions of this part." A primary care note mentioning a patient's substance use disorder is not automatically a Part 2 record. A record obtained from a Part 2 program is.

    What the alignment rule changed

    Single consent for treatment, payment, and health care operations. This is the operational headline. 42 CFR 2.33(a)(2) provides that when the consent given is "a single consent for all future uses and disclosures for treatment, payment, and health care operations, a part 2 program, covered entity, or business associate may use and disclose those records for treatment, payment, and health care operations as permitted by the HIPAA regulations, until such time as the patient revokes such consent in writing." Before this, each disclosure needed its own consent naming its own recipient, which is why Part 2 data historically sat in a walled-off system nobody integrated.

    No segmentation requirement for records received under that consent. 42 CFR 2.12(d)(2)(i)(C) closes with a sentence that reads like a footnote and is worth a quarter of your architecture budget: "A part 2 program, covered entity, or business associate that receives records based on a single consent for all treatment, payment, and health care operations is not required to segregate or segment such records." The data-tagging project many organizations scoped for Part 2 is, in that specific case, not required.

    Breach notification runs through HIPAA. 42 CFR 2.16(b) now provides that "the provisions of 45 CFR part 160 and subpart D of 45 CFR part 164 shall apply to part 2 programs with respect to breaches of unsecured records in the same manner as those provisions apply to a covered entity with respect to breaches of unsecured protected health information." Practically: the same presumption, the same four factors, the same clocks. If you already run a HIPAA breach determination process, that process now covers your Part 2 records, and the notification deadlines are the same ones.

    Security policies are now explicit. 42 CFR 2.16(a) requires formal written policies and procedures covering paper records (transfer, destruction with media sanitization, secure storage, workstation access, de-identification per 45 CFR 164.514(b)) and electronic records (creating, receiving, maintaining and transmitting; destruction with media sanitization; access; de-identification, again by cross-reference to the HIPAA standard). Note that cross-reference: Part 2's idea of de-identified is HIPAA's idea of de-identified, so the two lawful de-identification methods are the two lawful methods here too.

    Penalties moved onto the HIPAA structure. 42 CFR 2.3(a) now provides that any person who violates 42 U.S.C. 290dd-2(a) through (d) "shall be subject to the applicable penalties under sections 1176 and 1177 of the Social Security Act," which are the HIPAA civil and criminal penalty provisions. The four culpability tiers, from "did not know" through uncorrected willful neglect, are the same tiers. We are deliberately not printing dollar figures: the amounts are inflation-adjusted annually and there is more than one official set in circulation, so read the current table at 45 CFR 102.3 rather than any number in a blog post, including ours.

    What deliberately did not change

    Alignment is not merger, and the single largest difference survived intact.

    Under 42 CFR 2.12(d)(1), the restriction on using a Part 2 record "to initiate or substantiate criminal charges against a patient or to conduct any criminal investigation of a patient, or to use in any civil, criminal, administrative, or legislative proceedings against a patient, applies to any person who obtains the record from a part 2 program, covered entity, business associate, intermediary, or other lawful holder, regardless of the status of the person obtaining the record." The regulation then spells out what that bars: introducing the record or testimony into evidence in any federal or state criminal prosecution or civil action, relying on it to inform a decision in any federal, state, or local agency proceeding, using it for a law enforcement purpose or investigation, and using it in a warrant application, absent patient consent or a court order under subpart E.

    Nothing in HIPAA does that. This is the provision that makes Part 2 a substantively different regime rather than a stricter dialect of HIPAA, and it travels with the record. A downstream recipient who received the data legitimately, under consent, for treatment, is still bound by it.

    Two other survivals worth knowing. Redisclosure notice under 42 CFR 2.32 still has to accompany disclosures, so downstream recipients are told the data carries restrictions. And 42 CFR 2.33(b)(1) permits a covered entity or business associate that received records for treatment, payment, and health care operations to further disclose them per the HIPAA rules, "except for uses and disclosures for civil, criminal, administrative, and legislative proceedings against the patient." The exception is carved into the permission itself.

    What this means for the system you are building

    If you are a covered entity or business associate that will receive Part 2 records under a single treatment, payment, and health care operations consent, the engineering work is smaller than the pre-2024 guidance implied, because segmentation is not required in that case. What you do need: the ability to capture and store the consent, honor a written revocation prospectively, attach the 2.32 notice to onward disclosures, and, most importantly, prevent a subpoena response or a routine legal hold from sweeping these records into a proceeding against the patient. That last one is a legal-workflow control, not a database control, and it is the one nobody scopes.

    If you are a Part 2 program yourself and already run a HIPAA Security Rule program, the security policy work at 2.16(a) is largely the same list written more prescriptively. The genuinely new operational surface is breach notification, which you may never have had to run before.

    If you are a general provider who is not a Part 2 program, your obligation is to recognize records you receive from one and honor the redisclosure notice.

    The honest caveat

    Most companies asking us about Part 2 do not need a Part 2 project. They need forty-five minutes to establish that they are not a federally assisted substance use disorder program, do not receive records from one, and are therefore under HIPAA alone. That determination is free, it is in the regulation, and the section above is enough to run it yourself. If the answer comes back no, stop reading about Part 2 and spend the budget on the HIPAA risk analysis that is actually required of you.

    Even when Part 2 does apply, the parts that need an outside firm are narrow. Consent forms and the legal-proceedings workflow are counsel's work, not ours, and a health system with an experienced privacy office has usually already built both. Where we are genuinely useful is the technical layer: mapping which of your systems can hold a Part 2 record, proving the 2.16(a) policies are implemented rather than merely written, and folding the breach determination into a process you already run for HIPAA rather than standing up a second one. If someone quotes you a large segmentation and data-tagging program without first asking whether your consents are single treatment, payment, and health care operations consents, they are selling architecture the 2024 rule made optional.

    Where Top Floor fits

    We handle the applicability assessment, the data-flow mapping, and the 2.16(a) security policy and evidence work under our HIPAA practice, the ongoing program and vendor management under Compliance as a Service, and independent assessment and reporting under audit and assurance. We are not your lawyers. Consent forms, court-order responses, and anything touching the legal-proceedings restriction should go to counsel, and we will tell you that before you pay us.

    How to decide this week

    Answer the applicability question in writing, with the regulation open, and file the answer. Two sentences naming which limb of 42 CFR 2.12(b) you do or do not satisfy, and whether any of your data sources is a Part 2 program, is a durable artifact that saves the next person the same week of reading.

    If the answer is yes, look at your consent forms next. If they still name individual recipients per disclosure, you are running the pre-2024 model and carrying operational cost the current rule removed.

    Then check one thing that has nothing to do with your database: ask whoever handles subpoenas and legal holds whether they can identify a Part 2 record before it goes out the door. If the answer is no, that is your highest-severity gap, and it is a process fix rather than a project.

    Frequently asked questions

    Is 42 CFR Part 2 now the same as HIPAA?

    No. The February 2024 final rule aligned many mechanics, including a single consent covering all future treatment, payment, and health care operations disclosures, breach notification through HIPAA's Breach Notification Rule, and HIPAA's civil and criminal penalty structure. It did not merge the two regimes. The core Part 2 protection survived: under 42 CFR 2.12(d)(1), records may not be used to initiate or substantiate criminal charges against a patient or in any civil, criminal, administrative, or legislative proceeding against the patient without consent or a court order, and that restriction binds any person who obtains the record regardless of how they got it. HIPAA has no equivalent.

    When did the new Part 2 requirements become mandatory?

    The final rule at 89 FR 12472 was published on February 16, 2024 and took effect on April 16, 2024, but its DATES block set a later compliance date: persons subject to the regulation must comply with the applicable requirements by February 16, 2026. That date has passed, so as of August 2026 the requirements are live rather than upcoming. If your consent forms, security policies, or breach process still reflect the pre-2024 rule, you are behind rather than early.

    Do we still have to segment substance use disorder data in our systems?

    Not in the case the rule was written to fix. 42 CFR 2.12(d)(2)(i)(C) states that a part 2 program, covered entity, or business associate that receives records based on a single consent for all treatment, payment, and health care operations is not required to segregate or segment those records. That removes the data-tagging project many organizations had scoped. What you still need is the ability to identify these records when a subpoena, legal hold, or proceeding-related request arrives, because the restriction on using them against the patient did not go away.

    Does Part 2 apply to a primary care note that mentions addiction treatment?

    Generally no, and the regulation says so directly. Under 42 CFR 2.12(d)(2)(ii), a treating provider who is not subject to Part 2 may record information about a substance use disorder and its treatment that identifies a patient, and the act of recording it does not by itself make that medical record subject to Part 2. What does carry the restriction is a record obtained from a Part 2 program. So the question is never "does this note mention a substance use disorder", it is "where did this record come from".

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.