Skip to content
Saint Health Group

42 CFR Part 2 Compliance in 2026: What Every SUD Program Needs to Know Now

As of February 16, 2026, the updated 42 CFR Part 2 regulations are in force and the HHS Office for Civil Rights is actively accepting complaints under its new civil enforcement program. If your program has not yet updated its consent forms, privacy notices, breach response procedures, and staff training, you are behind. Here is what changed and how to close the gap.

Saint Health Group·July 8, 2026 · 9 min read · Last updated October 7, 2026

Receding concrete columns along a waterfront in monochrome, representing confidentiality around SUD records
Receding concrete columns along a waterfront in monochrome, representing confidentiality around SUD records

The compliance deadline has already passed. As of February 16, 2026, the updated 42 CFR Part 2 regulations governing the confidentiality of substance use disorder patient records are in force, and the HHS Office for Civil Rights has been accepting Part 2 complaints since February 16, 2026 under its new civil enforcement program. If your program has not yet updated its consent forms, notice of privacy practices, breach response procedures, and staff training, you are not early to this. You are behind, and every day of continued gaps in 42 CFR Part 2 compliance is a day of exposure to a federal complaint, a payer audit finding, or a licensing deficiency.

This guide walks through what actually changed under the final rule, what OCR enforcement now looks like, and the concrete steps a treatment program, opioid treatment program, or addiction medicine practice needs to take to close the gap, whether you are just starting to catch up or want a second set of eyes on work you have already done.

A Quick Refresher: What Is 42 CFR Part 2?

42 CFR Part 2 is the federal regulation that protects the confidentiality of records created by "Part 2 programs," federally assisted providers that hold themselves out as providing substance use disorder diagnosis, treatment, or referral for treatment. It has historically been stricter than HIPAA, requiring specific written patient consent for nearly every disclosure of SUD treatment information, including disclosures to other treating providers, payers, and even within an integrated health system.

That strictness was rooted in a real concern: patients avoiding treatment for fear that seeking help for addiction could be used against them in custody disputes, employment decisions, or criminal proceedings. But it also created friction that HIPAA-covered providers do not face: segmented records, duplicate consent processes, and care coordination gaps that many in the field argued did not serve patients well in an era of integrated, value-based care.

What Changed Under the 2024 Final Rule

Acting on Section 3221 of the CARES Act, HHS announced a final rule through SAMHSA and OCR on February 8, 2024. The Federal Register published it on February 16, 2024, and it took effect on April 16, 2024. It aligns Part 2 more closely with the HIPAA Privacy Rule and adds HIPAA-style breach notification and civil enforcement for Part 2 records. The rule gave the field roughly two years to prepare, with a compliance date of February 16, 2026, a date that has now come and gone.

A Single Consent Now Covers Treatment, Payment, and Operations

The single biggest operational change is consent. Under the prior rule, many programs needed a new, disclosure-specific consent every time SUD records moved to a new recipient. Under the final rule, a patient can now sign one consent authorizing all future uses and disclosures of their SUD records for treatment, payment, and health care operations (TPO), similar to how HIPAA-covered entities already operate. Once that TPO consent is on file, records can flow to other treating providers, payers, and business associates without a new consent for every transaction.

This does not eliminate consent. It restructures it. Patients still have to affirmatively consent, and revocation rights, the right to request restrictions, and the right to an accounting of disclosures all still apply. Programs that read "single consent" as "consent no longer required" are setting themselves up for a serious compliance failure.

Redisclosure Is Now Permitted Within HIPAA's Framework

Previously, nearly every redisclosure of Part 2 information required its own consent trail, which made data flow into shared EHRs, health information exchanges, and integrated care networks genuinely difficult. Under the final rule, when a patient consents to disclosure for treatment, payment, or health care operations, a HIPAA covered entity or business associate that receives the records may redisclose them as the HIPAA regulations permit, without a fresh Part 2 consent at every step. That permission excludes uses and disclosures in civil, criminal, administrative, and legislative proceedings against the patient. A Part 2 program, covered entity, or business associate that receives records under a single consent for treatment, payment, and health care operations is not required to segregate or segment those records from the rest of its record. SUD counseling notes still have to be kept separate to qualify for their own protection.

SUD Counseling Notes Are Carved Out and Held to a Higher Standard

The rule creates a defined category of "SUD counselor's notes," a clinician's private analysis of an individual or group counseling session, maintained separately from the rest of the record. These notes cannot be covered by the single TPO consent. A Part 2 program needs a separate written consent for any use or disclosure of SUD counseling notes, with limited exceptions for the originator's own treatment use, supervised training, and defense of a legal action brought by the patient. That consent can be combined only with another consent for SUD counseling notes, and the program cannot condition treatment or payment on it. This mirrors how HIPAA treats psychotherapy notes. Programs that keep detailed clinical impressions inside the general chart, rather than in a genuinely separate file, should not assume this carve-out protects them by default. The separation has to be real and documented.

Notice of Privacy Practices Requirements Are Aligned

Part 2 programs must now provide patients a notice describing their privacy rights that mirrors the HIPAA Notice of Privacy Practices, and many organizations are combining their HIPAA NPP and Part 2 notice into a single document rather than maintaining two. Whatever approach a program takes, the notice needs to explicitly address SUD record protections and the restriction on using those records in criminal, civil, or administrative proceedings without a court order.

Patients Gained New Rights

Patients can ask a Part 2 program for an accounting of disclosures made with consent during the prior three years. For treatment, payment, and health care operations, the accounting covers only disclosures made through an electronic health record. Patients can also ask the program to restrict uses and disclosures for treatment, payment, and health care operations. The program does not have to agree, except that it must agree when the disclosure goes to a health plan for payment or operations and the patient paid for the service in full out of pocket. Programs need a documented process for receiving, evaluating, and responding to these requests, not an ad hoc one.

Breach Notification Now Follows the HIPAA Rule, Even When HIPAA Wouldn't Require It

This is the change catching the most programs off guard. As of the compliance date, Part 2 programs must report breaches of SUD patient records according to the HIPAA Breach Notification Rule's timelines and thresholds. In the preamble to the final rule, HHS stated that a breach includes the use or disclosure of Part 2 records in a manner that Part 2 does not permit. Because Part 2 is stricter than the HIPAA Privacy Rule in several areas, an incident can be reportable under 42 CFR 2.16(b) even where HIPAA alone would not require a report. Programs relying solely on their existing HIPAA breach response plan may not actually be covering this obligation correctly.

Enforcement Is Real, Not Theoretical

OCR formally launched its civil enforcement program for Part 2 confidentiality violations effective February 16, 2026, and is now accepting complaints. Its toolkit includes investigations, resolution agreements, corrective action plans, monetary settlements, and civil money penalties. Those penalties are tiered and adjusted annually for inflation. Under the amounts HHS published on January 28, 2026 in 45 CFR 102.3, they range from $145 per violation at the lowest tier (where the violator did not know and, by exercising reasonable diligence, would not have known of the violation) up to $2,190,294 per identical violation per year at the highest tier, for willful neglect that goes uncorrected. Knowing violations involving false pretenses or intent to sell SUD records can carry criminal penalties as well, including substantial fines and prison time.

For programs that have treated Part 2 as a background legal requirement handled once at intake, this is the moment that calculus changes. OCR has an active complaint intake process, a defined enforcement structure, and a public compliance date that has already passed, which means "we were still working on it" is a weaker position with each month that goes by. Bringing consent, notice and breach procedures current with the final rule is part of our addiction treatment center consulting.

What Programs Need to Do Now

If your program has not completed a full Part 2 update, the priority is a focused gap-closing effort, not a slow rebuild. The core workstreams look like this.

  • Consent forms. Replace disclosure-specific consent language with a compliant single TPO consent, while preserving a separate, clearly distinct consent process for SUD counseling notes.
  • Notice of privacy practices. Update or combine your HIPAA NPP and Part 2 notice so patients receive one clear, compliant document describing their rights, including the restriction on use in legal proceedings.
  • Policies and procedures. Formalize written procedures for consent management, subpoena and court order response, redisclosure notices, accounting-of-disclosures requests, restriction requests, and breach response specific to Part 2's broader definition of a reportable event.
  • Staff training. Train clinical, front desk, billing, and records staff on what the new consent actually authorizes, how to explain it to patients (particularly patients early in recovery who may be wary of any information sharing), and how to recognize a Part 2-reportable incident.
  • EHR and health information exchange configuration. Confirm your EHR consent management workflows actually reflect the new single-consent model, correctly segregate SUD counseling notes, and produce the audit trail needed to support an accounting-of-disclosures request. If your current system cannot do this cleanly, it may be time to revisit choosing a behavioral health EHR.
  • Business associate and data-sharing agreements. Review agreements with EHR vendors, billing partners, and any health information exchange participation to confirm redisclosure permissions and breach reporting obligations are current with the final rule, not the prior regulation.
  • A documented gap assessment. Before assuming you are compliant, run a structured review against each requirement above and document what was found and fixed. In an OCR investigation, a documented remediation history is worth far more than an informal assurance that "we handled it."

Common Mistakes Programs Are Still Making

A few misreadings of the final rule keep showing up across the field. Some programs believe the single TPO consent means consent is no longer required at all, which is incorrect and risks unauthorized disclosures. Others assume the SUD counseling notes carve-out applies automatically to any clinical documentation, when it only applies to notes that are genuinely and consistently kept separate from the rest of the record. Still others have updated their HIPAA breach response plan and assumed it now covers Part 2, without accounting for the broader trigger for what counts as a reportable event under Part 2 specifically. Each of these gaps looks small in a policy binder and becomes significant the moment OCR opens a file.

Compliance Doesn't Exist in Isolation

Part 2 compliance sits alongside, not instead of, your state licensing and accreditation obligations. Oregon and Washington programs are still operating under OHA and DOH behavioral health rules, CARF or Joint Commission standards if accredited, and payer-specific documentation requirements, all of which now need to reflect the same consent and disclosure framework. A Part 2 update done in isolation from your broader compliance and risk infrastructure, licensing and accreditation support, and revenue cycle and payer operations tends to create new inconsistencies rather than resolving the original ones. The programs handling this well are treating it as one coordinated update across policy, clinical documentation, technology, and billing, not four separate projects running on different timelines.

Frequently Asked Questions

What is 42 CFR Part 2?

Part 2 is the federal regulation protecting the confidentiality of records created by Part 2 programs, meaning federally assisted providers that hold themselves out as providing substance use disorder diagnosis, treatment, or referral for treatment. It has historically been stricter than HIPAA.

What changed under the 2024 Part 2 final rule?

Acting on Section 3221 of the CARES Act, HHS announced a final rule on February 8, 2024 and published it on February 16, 2024. It aligns Part 2 with the HIPAA Privacy Rule, applies the HIPAA Breach Notification Rule to Part 2 records, and applies HIPAA civil enforcement to Part 2 violations. The field was given roughly two years to prepare.

Is Part 2 being enforced?

Yes. OCR formally launched its civil enforcement program for Part 2 confidentiality violations effective February 16, 2026 and is now accepting complaints. Its toolkit includes investigations, resolution agreements, corrective action plans, monetary settlements, and civil money penalties.

What is the most common mistake programs make about the new rule?

Believing the single consent for treatment, payment, and health care operations means consent is no longer required at all. That reading is incorrect and risks unauthorized disclosures.

How Saint Health Group Helps Programs Close This Gap

Saint Health Group does not just hand a program a memo describing what changed in the final rule. We write the actual consent forms, notice of privacy practices language, and Part 2-specific policies and procedures your program needs, then implement them directly across intake, clinical, records, and billing workflows. We train your staff on the new consent model and the broadened breach-reporting trigger so the people handling records every day actually understand what changed and why. We build the documentation and audit-trail infrastructure needed to respond to an accounting-of-disclosures request or a restriction request without scrambling. And where it matters most, we run a full on-site readiness review of your Part 2 compliance posture (the same way we approach an accreditation mock survey) so your program can demonstrate a genuine, documented compliance program if OCR, a state licensing surveyor, or a payer ever comes asking.

If your program is still working through what the final rule means for your consent process, your EHR configuration, or your breach response plan, reach out to Saint Health Group. We will tell you exactly where the gaps are and then close them, so you have one accountable partner handling this end to end rather than a compliance project spread across your legal counsel, your EHR vendor, and your own team with no one owning the whole picture.

Ask about this article

Have a question this article did not answer? Send it to the team that wrote it and we will reply by email within two business days. Prefer to talk? 503-389-3239

Your name and email go only to our team, never a mailing list.

Licensing, payer, and compliance intelligence for behavioral health operators. One email, most Tuesdays.

No spam. Unsubscribe any time.

More from The Journal

Back to The Journal →
Saint Health GroupTypically replies in seconds
Saint Health said:
Hi, I'm here to help. Ask me anything about behavioral health licensing, revenue cycle, compliance, or how Saint Health works.