42 CFR Part 2 for treatment centers: what it requires of your EHR
42 CFR Part 2 is the federal rule that gives substance-use-disorder treatment records stricter confidentiality than HIPAA alone. It governs when a Part 2 program may share those records, and a 2024 final rule reshaped consent with compliance required by February 16, 2026. Here is what it means for your program and your software.
What Part 2 is, and why it is stricter than HIPAA
42 CFR Part 2 is a federal regulation that protects the confidentiality of records identifying a person as having a substance-use disorder, when those records are held by a federally-assisted Part 2 program. It exists because the stakes of an SUD disclosure are unusually high: the same information that helps a clinician can, in the wrong hands, cost someone a job, a custody arrangement, or their freedom.
HIPAA generally permits sharing protected health information for treatment, payment, and health-care operations without specific authorization. Part 2 has historically been stricter: an SUD record could not be redisclosed without the patient’s written consent, and any disclosure had to travel with a notice prohibiting further redisclosure. That extra layer is the heart of Part 2.
Who it applies to
Part 2 applies to a "Part 2 program": a federally-assisted program, or an identified unit within a general medical facility, that holds itself out as providing and provides substance-use diagnosis, treatment, or referral for treatment. Many, though not all, behavioral-health and addiction-treatment providers meet that definition. If your program does, its SUD records carry Part 2 protections on top of HIPAA.
What the 2024 final rule changed
A 2024 final rule modernized Part 2 and moved it closer to HIPAA, with a compliance date of February 16, 2026. The headline change: a patient may now give a single consent for all future uses and disclosures for treatment, payment, and operations, rather than re-consenting for each one. The rule also aligned Part 2 with HIPAA on breach notification and on the penalty structure, and it strengthened patient rights around their records.
This is a real operational shift, not a footnote. Consent management, the notice of privacy practices, and the way redisclosure is tracked all have to reflect the new framework by the compliance date. This guide is educational, not legal advice; confirm the current requirements and dates with your compliance counsel.
What your EHR actually has to do
Compliance is not only a policy exercise. The software that holds the record has to enforce Part 2 structurally, because a rule that depends on every staff member remembering it will eventually be broken. At a minimum, an EHR handling Part 2 data should:
- Tag SUD records as Part 2-protected at the data level, so the protection travels with the data rather than living in a policy document.
- Gate disclosure on recorded consent, and attach the required redisclosure notice to anything that leaves the system.
- Keep an accounting of disclosures that can be produced on request, derived from an append-only audit trail rather than reconstructed by hand.
- Treat break-the-glass emergency access as a distinct, reason-captured, heavily-audited action, never a silent backdoor and never a hard block in a genuine emergency.
Practical next steps
Confirm whether your program is a Part 2 program. Inventory where SUD records live and how they leave the building. Update consent forms and your notice of privacy practices for the single-consent model. And pressure-test your EHR: ask your vendor to show you, in the product, how a Part 2 record is tagged, how consent gates a disclosure, and how an accounting of disclosures is generated. If those answers are policies rather than features, that is a gap worth closing before February 2026.