42 CFR Part 2 Compliance

Stricter than HIPAA.
Applies to more than you think.

42 CFR Part 2 protects substance use disorder records with privacy requirements that go significantly beyond HIPAA. If your practice treats or refers for SUD, it likely applies to you.

Join the Waitlist

What Is 42 CFR Part 2?

42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) is a federal regulation that imposes strict privacy protections on records relating to the identity, diagnosis, prognosis, or treatment of patients with substance use disorders. It is significantly more restrictive than HIPAA for covered records — requiring specific patient consent for most disclosures, prohibiting redisclosure by recipients, and severely limiting law enforcement access.

Does 42 CFR Part 2 Apply to Your Practice?

Part 2 applies to "Part 2 programs" — individuals or entities that hold themselves out as providing SUD diagnosis, treatment, or referral and receive federal assistance. Federal assistance is defined broadly to include Medicare or Medicaid certification, 501(c)(3) tax exemption, and federal licensure or certification. This means most practices that provide any SUD-related services and bill Medicare or Medicaid are likely subject to Part 2.

Common practice types subject to Part 2:

Key Differences from HIPAA

2024 Part 2 Amendments

Significant amendments effective in 2024 aligned Part 2 more closely with HIPAA while maintaining core protections. Key changes: patients can now provide a single general consent for treatment, payment, and healthcare operations disclosures; public health disclosure provisions similar to HIPAA now apply; breach notification requirements similar to HIPAA were added. The prohibition on use of Part 2 records in criminal and civil proceedings without patient consent remains in effect.

Documentation Requirements

AuditVault and 42 CFR Part 2

AuditVault includes 42 CFR Part 2 compliance documentation controls as a built-in module — consent form tracking, disclosure logs, staff training records, and security policies specific to SUD records. For practices subject to both HIPAA and Part 2, AuditVault manages both compliance frameworks in a single platform.

Learn more: What Is 42 CFR Part 2 and Does It Apply to Your Clinic?

HIPAA plus Part 2 — one platform.

AuditVault launches January 2028. Join the waitlist for early access.

Join the Waitlist