HIPAA governs the vast majority of health records nationwide, while 42 CFR Part 2 applies only to records from federally assisted substance use disorder programs. The 2024 Final Rule aligned breach notification and penalties across both frameworks, but Part 2 still bars using SUD records in legal proceedings without specific patient consent or a qualifying court order. If your organization touches both, the operational rule is simple: apply whichever standard protects the patient more.
TL;DR:
- Organizations handling both HIPAA and Part 2 records must apply the more protective standard at each disclosure decision to ensure compliance.
- The 2024 Final Rule simplifies consent by allowing a single prospective TPO consent for Part 2 records, but redisclosure still requires a written notice prohibiting further sharing.
- Staff must recognize Part 2 records on sight and understand stricter redisclosure and consent rules, with comprehensive training and clear workflows.
- Records involving both rules often require updating consent forms, privacy notices, and ensuring vendor contracts reflect redisclosure restrictions.
- Electronic health records do not need segmentation for Part 2, but access controls, audit trails, and metadata are vital to prevent unintentional redisclosure.
Table of Contents
- HIPAA Compliance Guidelines vs 42 CFR Part 2: The Quick Comparison
- Who Has to Comply: Part 2 Programs vs HIPAA Covered Entities
- Consent, Redisclosure, and What the 2024 Final Rule Still Forbids
- Enforcement, Breach Notification, and Patient Rights You Need to Update
- A Compliance Checklist for the Post-Final-Rule Deadline
- How EHRs and Documentation Should Handle Part 2 Records
- Governing Dual-Covered Situations Without Guessing
- Why PSCG Treats This as a Public Safety Issue, Not Just a Legal One
- Turning Compliance Into Operational Strength
- Where to Verify These Rules Yourself
- Sources
HIPAA Compliance Guidelines vs 42 CFR Part 2: The Quick Comparison
For a compliance officer triaging a new intake form or a records request, the differences boil down to five operational categories.
- Scope: HIPAA covers virtually all protected health information (PHI) held by covered entities and business associates. Part 2 covers only records of identity, diagnosis, prognosis, or treatment maintained by federally assisted SUD programs.
- Consent: HIPAA permits disclosure for treatment, payment, and operations (TPO) without patient authorization. Part 2 has historically required written consent for nearly every disclosure, though the Final Rule now allows a single prospective TPO consent for Part 2 records too.
- Redisclosure: HIPAA allows PHI to flow between covered entities under TPO with fewer restrictions. Part 2 still requires a prohibition-on-redisclosure notice and limits how far a record can travel once shared.
- Enforcement: Both are now enforced through aligned civil and criminal penalty structures, with the Office for Civil Rights handling Part 2 enforcement much like HIPAA complaints.
- Legal proceedings: HIPAA permits disclosure in response to a valid subpoena in many cases. Part 2 generally does not, absent specific consent or a court order meeting Part 2’s own criteria.
Default to the stricter rule whenever a record could plausibly fall under both, and you will rarely go wrong.
Who Has to Comply: Part 2 Programs vs HIPAA Covered Entities
Part 2’s authority traces back to a single statute, 42 U.S.C. 290dd-2, implemented through 42 CFR Part 2. HIPAA’s authority comes from 45 CFR parts 160 and 164. The populations they cover overlap less than most people realize.
- Part 2 programs: federally assisted SUD treatment programs, SAMHSA-grant-funded clinics, hospital-based SUD units that hold themselves out as providing SUD care, and any program that receives federal tax-exempt status or federal funding tied to SUD treatment.
- HIPAA covered entities: health plans, most health care providers who transmit claims electronically, health care clearinghouses, and their business associates.
- Hybrid cases: a hospital ER that treats an overdose and refers the patient to an in-house SUD program often holds Part 2 records and HIPAA PHI in the same chart. An EMS agency that transports a patient with a documented SUD diagnosis from a Part 2 program may inherit lawful-holder obligations the moment that record changes hands.
That last scenario trips up more agencies than any other. A run report referencing a Part 2 program by name can itself become a Part 2 record.
Consent, Redisclosure, and What the 2024 Final Rule Still Forbids
The single biggest operational shift in the Final Rule is consent simplification. Patients can now sign one prospective consent covering all future TPO-related disclosures of their Part 2 records, rather than authorizing each disclosure individually. That mirrors how HIPAA already treats TPO, and it meaningfully eases coordination between a treatment program, a hospital, and a health plan.
What has not changed is redisclosure. Once a Part 2 record moves to a new holder under a TPO consent, that record still needs a written notice prohibiting further disclosure without additional patient consent, unless another exception applies. HIPAA has no equivalent blanket redisclosure notice requirement for ordinary PHI.
- Written TPO consent now covers multiple future disclosures instead of requiring a signature every time.
- Every redisclosure of a Part 2 record must carry a prohibition-on-redisclosure statement.
- A subpoena alone typically does not authorize releasing Part 2 records; staff often assume it does, and that assumption is the single most common compliance failure in this space.
Pro Tip: Build a two-person sign-off into any workflow where legal counsel or a records custodian receives a request for SUD-related information. A quick second look catches the subpoena-versus-court-order confusion before it becomes a reportable breach.
Enforcement, Breach Notification, and Patient Rights You Need to Update
The Final Rule folded Part 2 breach notification and penalty structures into the same enforcement authorities that already govern HIPAA, which means your existing breach response plan is a solid foundation rather than a separate system to build from scratch.
Part 2 still layers on patient rights that HIPAA does not require in the same form: an accounting of certain disclosures, the right to request restrictions on how a record is used, and specific protections for SUD counseling notes that go beyond HIPAA’s psychotherapy notes carve-out.
- Add Part 2-specific accounting-of-disclosures language to your privacy notice.
- State patients’ right to request restrictions on SUD-related disclosures explicitly, not by cross-reference.
- Confirm your Notice of Privacy Practices and Part 2 patient notice can be combined but each requirement still shows up in plain language.
A Compliance Checklist for the Post-Final-Rule Deadline
Treat this as a sequence, not a menu. Each step depends on the one before it.
- Update consent forms first. Move to the single prospective TPO consent model and add prohibition-on-redisclosure language to every packet that could contain Part 2 information.
- Rebuild your combined notice. Merge your HIPAA Notice of Privacy Practices with Part 2’s required patient notice, but keep Part 2’s stricter language intact rather than diluting it into generic HIPAA phrasing.
- Train staff on the decision point, not just the policy. Front-line staff, revenue-cycle teams, and dispatch or records personnel need to recognize a Part 2 record on sight and know to apply the stricter rule by default. PSCG’s HIPAA compliance work with EMS agencies centers on exactly this kind of applied training.
- Audit your contracts. Review Qualified Service Organization Agreements, Business Associate Agreements, and vendor contracts to confirm every lawful holder of a Part 2 record understands its redisclosure limits.
- Rehearse your breach playbook. Run a tabletop exercise that includes a Part 2-specific breach scenario, not just a generic HIPAA breach, and document the outcome.
Pro Tip: Sequence matters. Agencies that jump straight to staff training before fixing their consent forms end up retraining everyone six months later when the paperwork catches up to the policy.
How EHRs and Documentation Should Handle Part 2 Records
The Final Rule does not require electronic health record segmentation, so you are not obligated to wall off SUD records into a separate system. That is a relief operationally, but it shifts the burden onto documentation and access controls instead.
Every disclosure involving a Part 2 record needs a retrievable copy of the consent (or a documented explanation when consent was not required), plus an accounting entry where Part 2 mandates one. On the technical side, role-based access controls, audit trails tied to individual users, and consent-linked metadata tags do more to prevent accidental redisclosure than any segmentation scheme would. A clinical data integrity approach that treats consent status as structured metadata, rather than a note buried in free text, makes audits considerably faster.
Governing Dual-Covered Situations Without Guessing
When both rules apply to the same record, the operational answer is consistent: apply the more protective standard at each disclosure decision, not just once at intake. That means training clinical staff, revenue-cycle teams, legal counsel, and IT administrators on a shared curriculum, refreshed at least annually and whenever the Final Rule’s guidance updates.
Audit checks should stay simple: confirm consent is on file before every disclosure, confirm redisclosure notices accompany every outbound record, and log every subpoena or court order request with the reviewer’s name attached.
Why PSCG Treats This as a Public Safety Issue, Not Just a Legal One
We have spent years inside EMS and public safety operations, and confidentiality failures rarely start with bad intent. They start with a records clerk or a field provider who never got clear guidance on which rule applies to the chart in front of them. Three priorities matter most right now: update your consent forms and notices, train staff at the actual decision point, and review vendor contracts for lawful-holder gaps. If your agency needs a structured assessment of where those gaps sit, PSCG’s system design resources are a reasonable place to start the conversation.
— Mike
Turning Compliance Into Operational Strength
Getting HIPAA and Part 2 alignment right is not a paperwork exercise. It is the difference between a records request that gets handled correctly in five minutes and one that turns into a reportable breach six months later. Consulting firms specialize in working with EMS agencies, fire departments, and public safety leaders to translate these federal requirements into practical policies, training curricula, and vendor contract language usable in the field.
Experienced EMS and public safety practitioners provide compliance recommendations that reflect operational realities, not just regulatory text. If your agency needs a structured system design assessment that folds in these confidentiality requirements from the ground up, review PSCG’s EMS system design examples and reach out through Thepscgroup to schedule an initial conversation about your agency’s specific gaps.
Where to Verify These Rules Yourself
- HHS’s Final Rule fact sheet for the plain-language summary of what changed.
- Govinfo for exact regulatory language.
- NIST SP 800-66 Rev. 2 for technical safeguards when records are stored electronically.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Hhs
- Hhs
- Govinfo
- SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide | CSRC







