# 42 CFR Part 2 vs HIPAA after the February 2026 deadline

> The compliance date for the rule aligning Part 2 with HIPAA passed on February 16, 2026. Alignment did not mean merger — Part 2 still goes further in specific, auditable ways. Here is what changed, what didn’t, and what a clinic should check now.

Source: https://www.curertech.com/resources/42-cfr-part-2-vs-hipaa
Author: CurerTech Editorial Team — Clinical & product editorial
Published: 2026-07-22

---

**Key takeaways**

- The deadline has passed — this is no longer a preparation question. A federally assisted SUD program that has not updated its consent workflow, privacy notice, and breach procedures is out of compliance today, with penalties now enforced on HIPAA's civil and criminal framework.
- The biggest operational win: one written consent can now cover all future uses and disclosures for TPO (treatment, payment, and health care operations), and HIPAA-covered recipients may redisclose under HIPAA's rules.
- The biggest new obligation: SUD counseling notes — a clinician's analysis of a counseling session — now need their own consent, outside the TPO consent, analogous to HIPAA psychotherapy notes.
- One patient right is not yet live: the accounting-of-disclosures requirement takes effect only when HHS revises the matching HIPAA provision — but the systems that will satisfy it are worth building now.

## What is the difference between 42 CFR Part 2 and HIPAA in 2026?

42 CFR Part 2 — the federal confidentiality rule for substance use disorder records — now aligns with HIPAA on consent mechanics, breach notification, and penalties; compliance was required by February 16, 2026. Part 2 remains stricter in three places: written consent for treatment, payment, and operations; separate consent for SUD counseling notes; and protection against use in legal proceedings.

## What changed on February 16, 2026?

Enforcement did. HHS announced the final rule modifying Part 2 on February 8, 2024 — implementing Section 3221 of the CARES Act — and gave the field two years to comply. February 16, 2026 was the day that transition ended: no new document was published, but the aligned framework stopped being a preparation target and became the enforceable standard. Since that date: Part 2 breaches are handled under the HIPAA Breach Notification Rule, Part 2 violations carry HIPAA's civil and criminal enforcement authorities (replacing Part 2's old criminal-only penalties), and the single-consent model is the operating standard. For a clinic, the question has flipped from “what do we need to change?” to “can we show we changed it?”

## Where does Part 2 and HIPAA now align?

Four places, and each one removes a workflow that used to exist only for SUD records. Consent: a patient can sign once for all future TPO uses and disclosures, instead of a new consent per disclosure. Redisclosure: a HIPAA-covered entity that receives records under that consent may redisclose them under HIPAA's standards — the old “no redisclosure” notice regime is gone for TPO. Breach notification: the same rule, the same clocks, the same reporting paths as any other PHI (protected health information). Penalties: the same enforcement structure, which cuts both ways — simpler to administer, and more expensive to ignore.

| Dimension | Under HIPAA | Under Part 2, as of 2026 |
| --- | --- | --- |
| Consent for treatment, payment & operations | No patient consent required — TPO uses are permitted by default | Written consent still required — but a single consent now covers all future TPO uses and disclosures |
| Counseling notes | Psychotherapy notes need separate authorization | New parallel category: SUD counseling notes need their own consent, excluded from the TPO consent |
| Legal proceedings | Records reachable by subpoena under HIPAA's conditions | Records cannot be used in proceedings against the patient without written consent or a court order — the protection follows the record after redisclosure |
| Who is covered | All covered entities and business associates | Federally assisted SUD programs — which includes nearly every OTP and most licensed SUD treatment providers |
| Accounting of disclosures | Right exists under the Privacy Rule | Right added on paper — compliance date deferred until HHS revises the matching HIPAA provision |

*Per the HHS fact sheet on the 42 CFR Part 2 final rule (announced 02/08/2024; compliance required by 02/16/2026), as of July 2026. This guide is informational, not legal advice — confirm specifics with counsel and your state’s rules, which can be stricter.*

## What should a clinic audit now that the deadline has passed?

Five questions, each answerable with evidence rather than intention:

- <blue>Is the single TPO consent actually in the workflow?</blue>  Not just a revised form — is it captured on the patient record at intake, retrievable per patient, and honored downstream when records move?
- <blue>Was the Notice of Privacy Practices updated?</blue> The aligned framework required updated patient notices by the compliance date; the old Part 2 notice language is now wrong.
- <blue>Are counseling notes separable?</blue> If a clinician’s session-analysis notes live undifferentiated in the general chart, the new separate-consent category cannot be honored. The record system has to know which notes are which.
- <blue>Does the breach plan cover SUD records?</blue> Same HIPAA clocks and reporting paths now apply — the breach-response procedure should no longer treat Part 2 records as a special case with no process.
- <blue>Could you produce a disclosure log if asked?</blue> The accounting-of-disclosures right is deferred, but a program that logs disclosures now will meet it by default — and disclosure logs are what make the legal-proceedings protection provable.

> Alignment simplified the paperwork. It did not simplify the promise — SUD records still carry protections that follow the record wherever it goes.

## Who does Part 2 actually apply to?

“Federally assisted” SUD programs — a definition broad enough to cover nearly every opioid treatment program (DEA registration alone qualifies a program as federally assisted) and most licensed or certified SUD treatment providers. A general behavioral health practice that does not hold itself out as providing SUD care may sit outside Part 2 while remaining fully under HIPAA — which is exactly why mixed programs need record systems that can tell the two populations apart. If in doubt, the determination is worth an hour of counsel’s time; the penalties now assume you knew.

## What does this ask of your software?

Every item on the audit list above is a data-capture question before it is a policy question: consent captured and connected to the record, notes categorized so counseling notes can carry their own consent, disclosures logged, and the two rule regimes distinguishable in one system. CurerTech — an all-in-one EMR, RCM (revenue cycle management — billing and collections), and CRM (patient engagement) platform — carries Part 2 consent and disclosure controls on the patient record itself, so consent status travels with the chart rather than living in a filing cabinet. How that works in an opioid treatment program is covered in the [MAT/OTP platform overview](/solutions/opioid-treatment-mat) and the [methadone clinic software guide](/solutions/opioid-treatment-mat); CurerTech's own privacy and security posture is at [/hipaa](/security-hipaa).
