42 CFR Part 2: Substance Use Disorder Records Compliance Guide for US Healthcare Staff
What the 2024 update to 42 CFR Part 2 changed, who it applies to, and what staff training and policies should cover now the compliance date has passed.
42 CFR Part 2 is the US federal regulation that protects the confidentiality of records connected to substance use disorder (SUD) diagnosis, treatment and referral. It is often mentioned alongside HIPAA, but the two are not the same, and staff who handle SUD records need to know the difference. A final rule published in February 2024 aligned several parts of Part 2 with HIPAA, and the compliance date was February 16, 2026, so affected organisations should now be working to the updated requirements.
This guide explains who is covered, what changed and what training and policies should cover. It is general information, not legal advice. Your compliance officer or legal counsel should confirm how the rule applies to your organisation.
What Part 2 protects
Part 2 applies to many individuals and organisations that provide SUD diagnosis or treatment, or referral for SUD diagnosis or treatment. Its purpose is to make sure people are not deterred from seeking treatment because they fear their records could be disclosed. Some healthcare providers are subject to both HIPAA and Part 2, so they must meet both sets of requirements.
How Part 2 differs from HIPAA
HIPAA sets the general rules for protected health information. Part 2 adds a stricter layer of protection for SUD treatment records held by covered programs. Before the 2024 update, the two regimes differed significantly in how consent, disclosure and enforcement worked. The final rule brought them closer together, which is why many organisations needed to revise forms, policies and notices. For a refresher on the wider framework, see our guide to HIPAA training requirements.
Key changes under the 2024 final rule
- Enforcement. The Department of Health and Human Services Office for Civil Rights enforces Part 2, and HIPAA civil and criminal penalties apply to Part 2 violations.
- Patient rights. Organisations must update policies to include a patient's right to an accounting of disclosures and the right to request limits on the use and disclosure of Part 2 records.
- Notice of Privacy Practices. Organisations subject to Part 2 must create and distribute a Notice of Privacy Practices, either by updating an existing HIPAA notice or creating a new one.
- Breach procedures. Programs must draft and implement a policy and procedure for investigating and reporting a breach of Part 2 records.
- Consent forms. Forms patients use to consent to certain uses and disclosures of Part 2 records need to be revised.
The compliance date has passed
The compliance deadline for the final rule was February 16, 2026. As of October 2026, organisations that handle Part 2 records should have updated policies, consent forms, notices and breach procedures in place, and should have trained employees on the changes. If you are not sure that this has been done, raise it with your compliance lead now.
What staff should be able to do
- Recognise which records are SUD treatment records covered by Part 2.
- Know that these records have extra protection and not to disclose them without proper consent or another permitted basis.
- Know how to handle a patient's request for an accounting of disclosures or a request to limit disclosures, and who to pass it to.
- Know the organisation's breach reporting procedure and report suspected breaches immediately.
- Use the current consent forms and notice of privacy practices, not older versions.
Policies and documents to review
- Consent forms for uses and disclosures of Part 2 records
- Notice of Privacy Practices
- Procedure for patient requests (accounting of disclosures, restrictions)
- Breach investigation and reporting procedure
- Staff training records, showing who was trained on the changes and when
Security and data protection
Confidentiality rules are only as strong as the systems that enforce them. Access controls, audit trails and secure sharing between teams all matter. Our guide to the HITECH Act and HIPAA Security Rule training requirements covers related expectations for healthcare organisations.
Why training matters
Because HIPAA civil and criminal penalties now apply to Part 2 violations, mistakes carry real consequences. Short, regular training that covers what makes Part 2 records different, how to handle patient requests and how to report a breach is more effective than a one-off briefing. Browse our CPD courses to see training options for healthcare teams.
Key points to remember
- Part 2 protects records connected to SUD diagnosis, treatment and referral, and it is separate from HIPAA.
- The 2024 final rule aligned Part 2 more closely with HIPAA, including enforcement and penalties.
- The compliance date was February 16, 2026, so updated policies, notices and consent forms should now be in use.
- Staff need to know how to handle patient rights requests and report breaches.
- Confirm how the rule applies to your organisation with your compliance officer or legal counsel.
Sources
- Barnes & Thornburg LLP via Mondaq: Are you ready? The 42 CFR Part 2 final rule compliance date is almost here (mondaq.com), accessed October 2026
- Troutman Pepper: Final rule aligns 42 CFR Part 2 with HIPAA/HITECH, February 2024 (troutman.com), accessed October 2026
This page was last updated:
Learnsignal Healthcare Education Team
The Learnsignal Healthcare Education Team creates CPD and compliance training content for nurses, allied health professionals, and care providers, drawing on current regulatory guidance from bodies including NMBI and equivalent professional regulators.
View all posts by Learnsignal Healthcare Education Team


