Skip to content
Behavioral Health Resource Solutionby The Vanguard Solution

Search the resource library

Search procedure codes, payer policies, state requirements and more

Compliance & Accreditation

42 CFR Part 2: Treatment Center Guide

Essential guide to 42 CFR Part 2 confidentiality requirements for substance use disorder treatment centers. Consent, re-disclosure, and compliance.

Quick Facts

Category
Federal Compliance
Last Verified
Mar 15, 2026
Published
Mar 6, 2026
Reading Time
14 min

Need compliance help?

For substance use disorder (SUD) treatment centers in the United States, few federal regulations are more operationally significant than 42 CFR Part 2. This regulation governs the confidentiality of patient records created by federally assisted programs that provide SUD treatment, and it imposes restrictions on information sharing that go well beyond what HIPAA requires. Understanding Part 2 is not optional for treatment center operators, clinical directors, and compliance officers — it directly shapes how your organization handles patient records, communicates with referral sources, coordinates care with other providers, and responds to legal demands for patient information.

This guide covers what 42 CFR Part 2 is, who it applies to, what it requires, how it differs from HIPAA, the significance of the 2024 rule changes, and the most common compliance pitfalls treatment centers encounter.

What Is 42 CFR Part 2?

42 CFR Part 2 is a federal regulation administered by the Substance Abuse and Mental Health Services Administration (SAMHSA) ↗ that protects the confidentiality of patient records maintained by federally assisted substance use disorder treatment programs. The regulation was originally enacted in the 1970s in response to a specific concern: individuals would avoid seeking addiction treatment if they feared their treatment records could be disclosed to employers, law enforcement, insurers, or others without their explicit consent.

The underlying policy rationale remains relevant today. Substance use disorders carry substantial social stigma, and the disclosure of SUD treatment records can have serious consequences for patients, including loss of employment, housing discrimination, child custody impacts, and criminal justice consequences. Part 2 exists to remove one barrier to treatment-seeking by providing patients with strong assurance that their treatment records will remain confidential unless they specifically authorize disclosure.

Part 2 applies specifically to records that identify an individual as having or having had a substance use disorder, or as having received SUD treatment or referral. It does not apply to all health records — only those created or maintained by programs that fall within its scope.

Who Does 42 CFR Part 2 Apply To?

Part 2 applies to federally assisted programs that hold themselves out as providing — and do provide — substance use disorder diagnosis, treatment, or referral for treatment. The definition of “federally assisted” is broad and encompasses most SUD treatment providers in the United States:

In practice, the “federally assisted” definition captures the vast majority of addiction treatment centers operating in the United States. If your organization accepts Medicaid or Medicare, holds tax-exempt status, or receives any form of federal funding, Part 2 almost certainly applies to your SUD treatment records.

Part 2 does not apply to programs that provide general medical or mental health care and do not hold themselves out as providing SUD treatment, even if individual patients within those programs happen to have substance use disorders. However, when a general healthcare provider receives SUD records from a Part 2 program, those specific records remain subject to Part 2 re-disclosure restrictions.

  • Direct federal funding: Programs that receive any federal funding, including SAMHSA grants, block grants, or direct appropriations
  • Medicare/Medicaid participation: Programs that accept Medicare or Medicaid reimbursement for SUD services
  • Tax-exempt status: Programs organized as tax-exempt nonprofit organizations under the Internal Revenue Code (501(c)(3) or similar)
  • Federal authorization: Programs authorized by federal law to provide SUD treatment, including methadone and buprenorphine programs operating under DEA registration
  • IHS or VA programs: Programs operated by or receiving funding from the Indian Health Service or the Department of Veterans Affairs

Key Provisions of 42 CFR Part 2

Patient Consent Requirements

The central mechanism of Part 2 is written patient consent as the prerequisite for most disclosures of SUD treatment records. Prior to the 2024 rule changes, Part 2 required a separate, specific written consent for each entity to which records would be disclosed. The consent form must include specific elements defined by the regulation:

(per 42 CFR § 2.31)

These consent requirements are more prescriptive than HIPAA’s general authorization requirements. Treatment centers must use consent forms that include all required elements; generic HIPAA authorization forms are typically insufficient for Part 2 compliance.

  • The name of the patient
  • The name of the program making the disclosure
  • The name or description of the entity receiving the disclosure
  • The purpose of the disclosure
  • A description of the information to be disclosed
  • A statement that the patient may revoke consent at any time
  • The date, event, or condition upon which the consent expires
  • The signature of the patient (and date)

The Re-Disclosure Prohibition

One of the most distinctive and operationally challenging features of Part 2 is the re-disclosure prohibition. When a Part 2 program discloses patient records to another entity with proper consent, that receiving entity is prohibited from further disclosing the information to any third party without obtaining a new, separate consent from the patient. The receiving entity must also provide the recipient with a written notice stating that the information is protected by federal law and cannot be further disclosed without patient consent.

This prohibition follows the information, not the entity. A hospital that receives SUD treatment records from a Part 2 program cannot share those specific records with another provider, insurer, or court without obtaining a new consent from the patient — even if the hospital could share its own records about the same patient under HIPAA.

The re-disclosure rule has historically created significant friction in care coordination, and is one of the primary reasons the 2024 rule changes were enacted.

Exceptions to Consent

Part 2 provides limited exceptions where disclosure is permitted without patient consent:

Notably, Part 2 historically did not include a general exception for treatment, payment, and healthcare operations (TPO) — the exception that forms the backbone of HIPAA’s information-sharing framework. This was the most significant operational difference between the two regulations and was a primary focus of the 2024 rule changes.

  • Medical emergencies: Disclosure to medical personnel who need the information to treat a condition that poses an immediate threat to the patient’s health
  • Audit and evaluation: Disclosure to entities conducting audits or evaluations of the program’s activities
  • Qualified Service Organization Agreements (QSOAs): Disclosure to organizations that provide services to the program (similar to HIPAA Business Associate Agreements)
  • Crime on program premises or against program personnel: Reports to law enforcement of crimes committed on program premises or against program staff
  • Court orders: Disclosure pursuant to a court order meeting specific Part 2 procedural requirements (which are more stringent than a standard subpoena)
  • Research: Disclosure for research purposes that meet Part 2’s specific research protections

The 2024 Rule Changes: What They Mean for Treatment Centers

In February 2024, the Department of Health and Human Services (HHS) finalized a major update to 42 CFR Part 2, implementing changes mandated by the CARES Act of 2020. These changes represent the most significant revision to Part 2 since the regulation was originally enacted and fundamentally alter how SUD treatment records can be shared.

Important: The compliance deadline for these changes was February 16, 2026. All Part 2 programs must now comply with the updated regulations, including the single-consent model for treatment, payment, and health care operations.

Single Consent for TPO

The most impactful change is the introduction of a single patient consent for treatment, payment, and healthcare operations (TPO) disclosures. Under the revised rule, a patient can sign a single consent form that authorizes all future disclosures for TPO purposes, rather than signing separate consents for each individual disclosure. Once a patient provides this TPO consent, their SUD records can flow between providers, payers, and healthcare operations entities in a manner similar to how other health information flows under HIPAA.

This change significantly reduces the administrative burden of Part 2 compliance and addresses longstanding concerns about care coordination barriers. Treatment centers that have struggled with obtaining individual consents for every disclosure to every entity can now operate with a single TPO consent, provided the consent form meets the regulation’s requirements.

HIPAA Enforcement Alignment

The 2024 rule brings Part 2 records under the HIPAA enforcement framework for certain purposes. This means that breaches of Part 2-protected information may now be investigated and penalized under HIPAA’s civil penalty structure, in addition to Part 2’s existing criminal penalty provisions. The alignment also means that Part 2 programs must comply with HIPAA’s breach notification requirements for unauthorized disclosures of SUD treatment records.

Anti-Discrimination Protections

The revised rule adds explicit anti-discrimination protections prohibiting the use of SUD treatment records in employment, housing, education, or other decisions that could disadvantage the patient. While the original regulation restricted disclosure, the 2024 rule goes further by restricting the use of disclosed information for discriminatory purposes.

What Hasn’t Changed

Despite the significant updates, several core Part 2 principles remain intact:

  • Part 2 records still receive greater protection than general health records under HIPAA
  • Court orders for Part 2 records still require a higher procedural standard than standard subpoenas
  • Patient consent is still required for disclosures (the change is that a single consent can cover multiple TPO disclosures)
  • Programs must still track disclosures and maintain records of consent

Common Compliance Violations

Treatment centers most frequently encounter Part 2 compliance issues in the following areas:

Inadequate Consent Forms

Using generic HIPAA authorization forms instead of Part 2-compliant consent forms is one of the most common violations. Part 2 consent forms have specific required elements that differ from HIPAA authorization requirements. Organizations should review their consent forms against the current regulatory requirements and update them to reflect the 2024 changes.

Improper Responses to Subpoenas

When a treatment center receives a subpoena for patient records, Part 2 does not permit disclosure based on the subpoena alone. A valid Part 2 court order — which requires a specific judicial finding that the public interest outweighs the patient’s privacy interest — is required. Treatment centers that produce records in response to standard subpoenas without a valid court order violate Part 2.

Failure to Include Re-Disclosure Notices

When disclosing records with patient consent, the treatment center must include a written notice to the recipient stating that the information is protected by federal law and cannot be further disclosed without patient consent. Omitting this notice is a common compliance gap.

Informal Disclosures

Staff discussions about patients in settings where they may be overheard, acknowledgment to third parties that an individual is a patient at the program, or responses to inquiries from family members without proper consent all constitute potential Part 2 violations. Staff training on the specific boundaries of Part 2 confidentiality is essential.

Electronic Health Record Configuration

EHR systems must be configured to properly segment SUD treatment records, apply appropriate access controls, and generate Part 2-compliant consent forms and re-disclosure notices. Systems that are not configured for Part 2 compliance create ongoing risk of unauthorized disclosures.

Penalties for Part 2 Violations

The 2024 final rule fundamentally changed the penalty landscape for 42 CFR Part 2 by aligning criminal penalties with HIPAA’s penalty structure. The previous penalties of $500 for a first offense and $5,000 for subsequent offenses have been replaced.

Criminal penalties (post-2024 alignment): Part 2 criminal penalties are now aligned with HIPAA under 42 U.S.C. § 1320d-6:

Civil penalties (post-2024): Unauthorized disclosures of Part 2-protected records are now subject to HIPAA civil monetary penalties, which range from $100 to $50,000 per violation, with annual maximums up to $1.5 million per violation category.

Note: These are the base statutory amounts. As of 2025, inflation-adjusted penalty amounts range from $145 to $73,011 per violation, with annual caps up to $2,190,294 per violation category.

Breach notification: Under the 2024 changes, breaches of Part 2-protected information trigger HIPAA’s breach notification requirements, including notification to affected individuals, HHS, and (for breaches affecting 500 or more individuals) the media.

The 2024 HIPAA enforcement alignment represents a dramatic increase in potential financial and criminal exposure for Part 2 violations compared to the prior penalty structure.

  • Knowing misuse of individually identifiable health information: up to $50,000 and 1 year imprisonment
  • Offenses committed under false pretenses: up to $100,000 and 5 years imprisonment
  • Offenses committed with intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm: up to $250,000 and 10 years imprisonment

Part 2 vs. HIPAA: Key Differences

Understanding how Part 2 differs from HIPAA is essential for treatment centers that must comply with both:

The practical implication: treatment centers must maintain dual compliance. HIPAA sets the floor for all health information privacy and security. Part 2 adds an additional, stricter layer specifically for SUD treatment records. Staff training must address both frameworks, and EHR systems must be configured to enforce the stricter Part 2 requirements for SUD records while maintaining standard HIPAA compliance for other health information.

For a practical, disclosure-level walkthrough of these differences — the two-tier note rule and a four-step check to run before any release — see 42 CFR Part 2 vs. HIPAA: What the Difference Means for SUD Disclosures.

Every facility’s compliance path is different. Talk to a Compliance Expert to get a customized Part 2 compliance assessment for your organization.

ElementHIPAA42 CFR Part 2 (Post-2024)
ScopeAll protected health information (PHI)SUD treatment records specifically
Consent for TPONot required (TPO exception)Required, but single consent now permitted
Re-disclosureNo special restrictionsReceiving entity may not re-disclose without new consent
Subpoena responsePermitted with certain conditionsRequires specific court order (higher standard)
Criminal penaltiesUp to $250,000 and/or 1-10 yearsNow aligned with HIPAA (up to $250,000 and/or 1-10 years)
Civil penaltiesUp to $1.5M per category per yearNow aligned with HIPAA civil penalties
Anti-discriminationLimited protectionsExplicit prohibition on discriminatory use
Breach notificationRequiredNow required (2024 alignment)

Implementing Part 2 Compliance

Effective Part 2 compliance requires attention to several operational areas:

Consent form updates. Review and update all consent forms to reflect the 2024 rule changes, including the option for single TPO consent. Ensure forms include all required elements specified in the regulation.

Staff training. All staff who handle patient information must understand Part 2 requirements, including the re-disclosure prohibition, consent requirements, exceptions, and the distinction between Part 2 and HIPAA. Training should include practical scenarios relevant to their roles.

EHR configuration. Your electronic health record system must support Part 2 compliance, including SUD record segmentation, access controls, consent tracking, and re-disclosure notice generation. A purpose-built behavioral health EHR can simplify Part 2 compliance by building these requirements into standard workflows.

Policy and procedure development. Written policies should address consent management, subpoena response procedures, re-disclosure notice requirements, breach response, and staff responsibilities under Part 2.

Legal counsel. Part 2 compliance questions, particularly regarding court orders, law enforcement requests, and the interaction between Part 2 and state privacy laws, should be addressed in consultation with legal counsel experienced in healthcare privacy law.

Get staff training on 42 CFR Part 2 compliance. Review HIPAA and Part 2 training topics to ensure your team understands these critical requirements.

Sources

  • 42 CFR Part 2 — eCFR ↗ — Official government resource
  • HHS — Understanding Confidentiality of Substance Use Disorder Patient Records ↗ — Official government resource
  • HHS HIPAA Information ↗ — Official government resource
  • SAMHSA ↗ — Official government resource

Frequently Asked Questions

This guide is provided for informational purposes only and does not constitute legal, regulatory, or professional advice. Regulations change frequently — always verify current requirements with the relevant state agency or accrediting body. is not a law firm or consulting firm.

  • What is 42 CFR Part 2?
  • Does 42 CFR Part 2 apply to all treatment centers?
  • What changed with the 2024 42 CFR Part 2 updates?
  • What are the penalties for 42 CFR Part 2 violations?
  • How is 42 CFR Part 2 different from HIPAA?

Get Staff Training

helps behavioral health organizations navigate compliance with confidence.

Reference tables

ElementHIPAA42 CFR Part 2 (Post-2024)
ScopeAll protected health information (PHI)SUD treatment records specifically
Consent for TPONot required (TPO exception)Required, but single consent now permitted
Re-disclosureNo special restrictionsReceiving entity may not re-disclose without new consent
Subpoena responsePermitted with certain conditionsRequires specific court order (higher standard)
Criminal penaltiesUp to $250,000 and/or 1-10 yearsNow aligned with HIPAA (up to $250,000 and/or 1-10 years)
Civil penaltiesUp to $1.5M per category per yearNow aligned with HIPAA civil penalties
Anti-discriminationLimited protectionsExplicit prohibition on discriminatory use
Breach notificationRequiredNow required (2024 alignment)

Common questions

Official sources

1,984 words · reviewed 2026-03-06
42 CFR Part 2: Treatment Center Guide — The Behavioral Health Resource Solution