Policy required document Healthcare
42 CFR Part 2 Consent and Redisclosure Policy
42 CFR Part 2 protects records that identify a person as having or having had a substance use disorder when the record comes from a federally assisted program.
The regulation is written around three documents: a written consent form with fixed content (2.31), a notice that travels with every disclosure made under consent (2.32), and formal written security policies and procedures for the records themselves (2.16).
Programs fold these into one policy that also covers the 2.22 patient notice, the exceptions that allow disclosure without consent, and breach notification.
The 2024 final rule moved Part 2 closer to HIPAA: one consent can now cover all future treatment, payment and operations uses, breach notification follows the HIPAA Breach Notification Rule, HIPAA-style penalties apply, and the Office for Civil Rights enforces. The compliance date was February 16, 2026. Programs that wrote their policy before 2024 need a rewrite, not an edit.
Obligation ledger
Who requires it, and what each one says.
| Source | Applies when | What it requires | Status |
|---|---|---|---|
| 42 CFR Part 2, consent requirements 42 CFR 2.31 | You disclose Part 2 records with patient consent | Written consent naming the patient, the discloser, the recipient, the purpose, how much and what kind of information, a revocation statement, an expiration event or date, a redisclosure statement, and the patient signature and date. A single consent for all future TPO uses is permitted. Legally required. | Mandatory |
| 42 CFR Part 2, notice to accompany disclosure 42 CFR 2.32 | Every disclosure made with written consent | Accompany the disclosure with a copy of the consent or a clear explanation of its scope, plus a statement that the record is protected by federal law and may not be redisclosed except as permitted. Legally required. | Mandatory |
| 42 CFR Part 2, security for records 42 CFR 2.16 | You are a Part 2 program or lawful holder | Formal policies and procedures to protect against unauthorized use and disclosure and reasonably anticipated threats, covering paper records (transfer, removal, destruction, secure storage) and electronic records (access, transmission, storage, sanitizing media). Legally required. | Mandatory |
| 42 CFR Part 2, patient notice 42 CFR 2.22 | You are a Part 2 program | Plain-language notice at admission of the program's legal duties and privacy practices. Legally required. | Mandatory |
| Part 2 final rule, breach notification 42 CFR 2.16(b), 89 FR 12472 | Breach of unsecured Part 2 records | Notify under the HIPAA Breach Notification Rule (45 CFR Part 164 Subpart D). Legally required from Feb 16, 2026. | Mandatory |
| CARF behavioral health standards CARF standards manual, Section 1 and program sections | You seek CARF accreditation for SUD programs | Written policies on confidentiality and records that surveyors verify against Part 2 and HIPAA. Accreditor expectation, contractual once you apply. | Implied |
Required sections
- Scope: which records and which staff are covered; definition of federally assisted program
- Patient notice procedure at admission (2.22) and how capacity is handled
- Consent form content and the nine elements of 2.31, including the TPO single-consent option and the SUD counseling notes exception
- Revocation handling and expiration events
- Redisclosure notice that accompanies every consented disclosure (2.32)
- Disclosures permitted without consent: medical emergency, research, audit and evaluation, court order under Subpart E, crimes on premises, child abuse reporting
- Prohibition on use in civil, criminal, administrative or legislative proceedings without consent or court order (2.12(d), 2.64, 2.65)
- Security policies and procedures for paper and electronic records, including destruction and media sanitization (2.16(a))
- Breach notification aligned to 45 CFR 164.400 to 164.414 (2.16(b))
- Qualified service organization agreements and business associate agreements
- Patient right to an accounting of disclosures made with TPO consent (from Feb 2026; single source: 2024 final rule)
- Complaint process and no-retaliation statement (2.26, single source)
- Staff training and sanctions cross-reference
What the examiner asks for
What changed
Change log.
Frameworks
Where this document is required.
Who looks at it
Where this document gets checked.
No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.
| Where it is looked at | Who looks at it |
|---|---|
| 42 CFR Part 2 | HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification |
| CARF | CARF surveyors, who are peer professionals employed in accredited or comparable organizations, trained and assigned by CARF. Surveys are scheduled and on site for two to three days |
| OIG 7-element program | No certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews |
Who helps write it
Consultants.
Firms that name these standards in their own material.
No firm has claimed a listing for this document yet. Claim yours →
Where it lives
Software.
Tools that hold documents like this one and record who has read them.
Need a hand implementing it?
Find a Consultant for 42 CFR Part 2 Consent and Redisclosure Policy
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Manage This Document in AllyMatter
Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.
Questions
What people ask.
We are HIPAA compliant. Are we covered?
No. Part 2 has stricter consent rules, a redisclosure notice HIPAA does not have, and a prohibition on use in proceedings. HIPAA compliance is the floor; the Part 2 policy sits on top.
What changed in the consent form?
One consent can now cover all future treatment, payment and operations uses by any HIPAA covered entity or business associate. The form still needs every 2.31 element, including a revocation statement, an expiration event, and the redisclosure statement.
Does the old 'prohibition on redisclosure' notice still work?
The 2.32 notice text changed with the 2024 rule. Forms and EHR templates written to the 2017 language need updating.
Who enforces Part 2 now?
HHS Office for Civil Rights, with HIPAA-style civil and criminal penalties, from the February 2026 compliance date.
Who owns this site?
AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.