
HIPAA privacy compliance, state health information confidentiality laws, Wisconsin medical record privacy, mental health record protections, and 42 CFR Part 2 substance use disorder records
Wisconsin Health Lawyer John Fisher
HIPAA Privacy Compliance as the Baseline Framework
Executive summary: HIPAA privacy compliance establishes a federal baseline for the protection, use, and disclosure of protected health information; however, HIPAA is not invariably the most restrictive or controlling legal authority for every medical record disclosure or patient privacy decision. Covered entities, business associates, health care providers, administrators, legal counsel, and compliance officers must evaluate each proposed disclosure under all applicable federal and state health information confidentiality laws, including state medical record confidentiality statutes, Wisconsin patient health care record privacy requirements, mental health record protections, HIPAA preemption rules, and 42 CFR Part 2 substance use disorder treatment record requirements. The appropriate compliance analysis should identify the record type, the purpose of the disclosure, the recipient, the applicable consent or authorization standard, any redisclosure restriction, and the legal standard that governs the particular disclosure at issue.

This article explains how HIPAA privacy compliance interacts with state medical record confidentiality laws, Wisconsin health care record statutes, mental health record privacy protections, and 42 CFR Part 2 confidentiality rules for substance use disorder treatment records. It is intended to help health care providers, compliance officers, administrators, and legal counsel evaluate patient privacy disclosures, identify when HIPAA is only the baseline, and determine when a more specific federal or state privacy law may control the release of protected health information.
Summary: HIPAA, Part 2, and Health Information Confidentiality
This article addresses core health care privacy and compliance topics, including HIPAA privacy compliance, protected health information, state medical record confidentiality laws, Wisconsin health record privacy, mental health record confidentiality, 42 CFR Part 2 confidentiality rules, substance use disorder treatment records, SUD patient record confidentiality, HIPAA preemption, treatment-payment-health care operations disclosures, patient consent and authorization, redisclosure restrictions, and patient privacy disclosure workflows.
For compliance teams, the central issue is how HIPAA interacts with more protective state and federal confidentiality requirements. The analysis is especially important when patient information includes mental health records, substance use disorder records, Wisconsin patient health care records, or other specially protected health information that may require additional consent, documentation, breach-notification, redisclosure, or proceeding-use safeguards.
Why HIPAA Privacy Compliance Is Only the Starting Point
HIPAA, as a comprehensive federal regulatory framework governing the privacy and security of protected health information, has been effective in establishing broad institutional awareness within health care settings. Personnel generally understand that HIPAA prohibits unauthorized discussion of patient information outside the workplace and restricts disclosure of protected health information to third parties absent a valid regulatory basis, applicable exception, or patient authorization.
When a “HIPAA Issue” May Involve Other Privacy Laws
The prominence and institutional recognition of HIPAA are beneficial insofar as they reinforce regulatory awareness and promote the protection of patient confidentiality. From a legal and compliance perspective, however, such prominence may also create the mistaken assumption that any potential disclosure of patient information is solely a “HIPAA issue.” Although this assumption reflects an appropriate sensitivity to confidentiality concerns, it may obscure the applicability of other legal authorities that impose equal or greater restrictions in particular circumstances.
Medical Record Disclosure Compliance Under Federal and State Law
Accordingly, HIPAA should be understood as one component of a broader legal framework governing health information confidentiality and patient privacy compliance. While HIPAA establishes a national privacy floor, medical record disclosure compliance requires consideration of additional federal and state confidentiality laws that may impose more stringent limitations on access, use, redisclosure, consent, or authorization.
Beyond HIPAA: State and Federal Health Information Confidentiality Laws
State Medical Record Confidentiality and Specially Protected Health Information
Multiple legal authorities may afford confidentiality protections that exceed those provided under HIPAA. These include state-specific medical record confidentiality statutes, enhanced protections for mental health treatment records, and federal and state laws governing substance use disorder and alcohol treatment records. Characterizing all patient privacy and health information confidentiality matters as “HIPAA issues” risks disregarding these more nuanced and, in some instances, more protective requirements. In certain circumstances, such oversimplification may result in policies or practices that are legally deficient because they fail to identify and apply the controlling legal standard.
Mental Health Records, SUD Records, HIV/AIDS Information, and Genetic Information
In addition to HIPAA, health information confidentiality is governed by a complex intersection of state and federal law. Many states impose heightened privacy obligations or regulate categories of information not addressed with comparable specificity under HIPAA, including mental health information, HIV/AIDS-related information, and genetic information. Likewise, certain federal regulations, including 42 CFR Part 2, impose particularly stringent consent and disclosure requirements for substance use disorder treatment records. Health care providers, administrators, and compliance personnel must therefore identify overlapping legal obligations and apply the applicable standard that is most protective or otherwise legally controlling.
The following comparison summarizes the principal differences among the confidentiality regimes most relevant to this analysis.
HIPAA, Wisconsin Law, and 42 CFR Part 2 Comparison Table
| Legal authority | Primary scope | General disclosure standard | Consent or authorization considerations | Compliance significance |
| HIPAA Privacy Rule | Protected health information held by covered entities and business associates. | Establishes a federal privacy floor and permits uses and disclosures when authorized by HIPAA, including for treatment, payment, and health care operations. | Authorization is required for certain disclosures, but many routine health care disclosures may proceed without patient authorization when HIPAA permits them. | HIPAA is the baseline analysis, but it does not displace more stringent state privacy laws or specialized federal confidentiality rules. |
| Wis. Stat. § 146.82 | Wisconsin patient health care records generally. | Patient health care records are confidential and may be released only as designated by statute or with informed consent, subject to enumerated exceptions. | Informed consent may be required unless a statutory exception applies, including certain treatment, payment, operational, governmental, or court-ordered circumstances. | Requires Wisconsin-specific review and may impose obligations distinct from HIPAA for general patient health care records. |
| Wis. Stat. § 51.30 and Wis. Admin. Code ch. DHS 92 | Mental health, developmental disability, alcoholism, and drug-dependence treatment records in Wisconsin. | Imposes specialized confidentiality requirements for treatment records and limits disclosure except as authorized by statute, regulation, consent, or applicable exception. | Written informed consent must generally identify the recipient, subject individual, purpose or need for disclosure, specific information disclosed, effective period, date, and authorized signature. | Often requires a more restrictive analysis than general health-record confidentiality rules, particularly for mental health treatment records. |
| 42 CFR Part 2 | Substance use disorder patient records maintained by federally assisted Part 2 programs and certain recipients of Part 2 records. | Historically, Part 2 prohibited use or disclosure unless a regulatory permission applied, patient consent was obtained, or a qualifying court order or other legal basis permitted disclosure. Under the 2024 final rule, a single written consent may authorize future uses and disclosures for treatment, payment, and health care operations, while other uses remain subject to Part 2’s specific limitations. | Part 2 now more closely aligns consent content, patient notice, breach-notification, and enforcement provisions with HIPAA. It also permits certain HIPAA covered entities and business associates that receive Part 2 records under a treatment, payment, and health care operations consent to redisclose those records as HIPAA permits, subject to continuing limits on use in proceedings against the patient. | Part 2 remains a specialized and highly protective regime, but post-2016 amendments have reduced certain information-sharing barriers while expanding patient rights, breach obligations, and civil enforcement exposure. |
Key Compliance Differences for HIPAA, Mental Health Records, and Part 2
HIPAA Baseline Rules and More Protective State Privacy Standards
Several compliance distinctions follow from this HIPAA, Wisconsin law, and Part 2 comparison. HIPAA functions principally as a federal baseline for protected health information rather than as the exclusive or invariably controlling rule for every patient privacy disclosure. Although HIPAA permits many disclosures for treatment, payment, and health care operations, those permissions must be evaluated against any more protective state health information confidentiality law or specialized federal confidentiality requirement. Wisconsin’s general health-record statute requires a separate state-law analysis because patient health care records may be released only as authorized by statute or with informed consent, subject to enumerated exceptions.
Part 2 and Mental Health Record Disclosure Requirements
Third, Wisconsin’s mental health record confidentiality provisions impose a more specialized and often more protective framework than either HIPAA or the state’s general health-record law. Records governed by Wis. Stat. § 51.30 and Wis. Admin. Code ch. DHS 92 require careful review of consent content, disclosure purpose, recipient identity, and any applicable statutory or regulatory exception. Fourth, 42 CFR Part 2 continues to warrant separate analysis whenever substance use disorder treatment information or SUD patient records are implicated. Although post-2016 amendments—particularly the 2020 CARES Act and the 2024 final rule—align certain Part 2 requirements more closely with HIPAA, Part 2 continues to impose specialized consent, redisclosure, proceeding-use, patient-rights, breach-notification, and enforcement requirements that must be evaluated independently.
Patient Privacy Disclosure Triage Before Release
The practical compliance question, therefore, is not merely whether HIPAA permits a disclosure. Rather, the organization must determine the nature of the record, the purpose of the proposed disclosure, the identity and legal status of the recipient, the existence and sufficiency of any consent or authorization, and whether any redisclosure restriction applies. Effective confidentiality compliance accordingly requires a triage process that identifies the applicable legal regime before information is released.
Wisconsin Health Record Confidentiality and HIPAA Harmonization
Wisconsin provides a useful illustration of how this multi-layered analysis operates in practice.
Wisconsin Patient Health Care Records and Mental Health Treatment Records
Wisconsin law illustrates the need for jurisdiction-specific analysis. Wisconsin maintains its own confidentiality statute, codified at Wis. Stat. § 146.82, and also imposes specific requirements governing mental health treatment records under Wis. Stat. § 51.30 and Wis. Admin. Code ch. DHS 92. These provisions may impose requirements that are more restrictive than HIPAA and, in certain respects, more restrictive than Wisconsin’s general patient health care record confidentiality provisions. Historically, Wisconsin’s restrictions on mental health treatment records were sufficiently stringent that disclosure to another treating provider generally required the patient’s written consent.
HIPAA Harmonization Act and Wisconsin Disclosure Workflow
In response to operational challenges created by these heightened restrictions, Wisconsin enacted legislation commonly referred to as the “HIPAA Harmonization Act” in 2013. The legislation modified certain disclosure restrictions and required providers to evaluate, or “triage,” disclosure requests by determining whether HIPAA or more restrictive state confidentiality provisions govern the particular request. This analysis is especially significant when the information at issue consists of mental health treatment records.
Wisconsin HIPAA Harmonization Act: Disclosure Triage Process
Under the Wisconsin HIPAA Harmonization Act, HIPAA standards generally govern disclosures made for treatment, payment, or health care operations. Wisconsin subsequently expanded certain permissible disclosures to narrowly defined emergency circumstances, thereby allowing disclosures to other treating providers when consistent with HIPAA. For disclosures outside treatment, payment, health care operations, or specified emergency circumstances, more restrictive Wisconsin confidentiality requirements may control. Although Wisconsin law contains exceptions permitting disclosure in particular circumstances, those exceptions are generally narrower than the exceptions available under HIPAA.
HIPAA Preemption, More Stringent State Law, and Wisconsin Confidentiality Requirements
HIPAA Preemption and More Stringent State Privacy Law
HIPAA’s preemption framework generally provides that state law is preempted unless the state law is more stringent with respect to privacy protections. In that circumstance, the more stringent state law is not displaced and must be applied. The Wisconsin Harmonization Act, however, identifies categories of disclosures in which HIPAA standards govern notwithstanding otherwise applicable state-law restrictions. Where the Harmonization Act does not make HIPAA controlling, Wisconsin providers must determine whether state law or HIPAA imposes the more restrictive requirement and apply the governing standard.
How to Determine the Governing Confidentiality Standard
For purposes of compliance analysis, preemption should not be treated as a mechanical conclusion. Rather, providers should assess the nature of the record, the purpose of the proposed disclosure, the identity of the recipient, the existence and scope of any patient authorization or consent, and any state-law exception that may apply. This analysis is necessary to ensure that the applicable legal authority is correctly identified and that patient information receives the level of protection required by law.
42 CFR Part 2 Confidentiality Rules for Substance Use Disorder Records
Post-2016 Part 2 Regulatory Updates and the 2024 Final Rule
Among federal confidentiality regimes, 42 CFR Part 2, administered by the Substance Abuse and Mental Health Services Administration (SAMHSA) and enforced in coordination with the U.S. Department of Health and Human Services Office for Civil Rights, remains a specialized framework for substance use disorder treatment records and SUD patient record confidentiality. Since 2016, Part 2 has undergone significant modernization. The 2017 revisions updated terminology and structure, later amendments addressed disclosure mechanics and interoperability concerns, and the 2020 CARES Act directed HHS to align certain Part 2 requirements more closely with HIPAA. The 2024 final rule, effective April 16, 2024, implements that statutory direction, with covered persons required to comply by February 16, 2026.
Single Consent, Redisclosure, and HIPAA Alignment
As revised, Part 2 continues to protect records identifying a patient as having or having had a substance use disorder, but it now permits a single patient consent for all future uses and disclosures of Part 2 records for treatment, payment, and health care operations. When a HIPAA covered entity or business associate receives Part 2 records pursuant to such consent, the recipient may redisclose the information in accordance with HIPAA, subject to Part 2’s continuing prohibitions on use and disclosure in civil, criminal, administrative, and legislative proceedings against the patient absent patient consent or a qualifying court order. The 2024 Part 2 final rule also aligns Part 2 more closely with HIPAA regarding patient notices, breach notification, complaint processes, civil enforcement, and certain patient rights, including accounting-of-disclosure and restriction-request rights. It further recognizes special protections for SUD counseling notes and permits disclosure of de-identified Part 2 records to public health authorities.
Part 2 Compliance Analysis After the 2024 Final Rule
Accordingly, Part 2 compliance should be analyzed under its current framework rather than characterized as a categorical barrier to treatment, payment, or health care operations disclosures. The current substance use disorder record disclosure analysis is more nuanced: organizations must confirm whether the records are Part 2 records, whether a valid treatment, payment, and health care operations consent or another Part 2 permission applies, whether the recipient is a HIPAA covered entity or business associate, whether redisclosure is permitted, and whether any proceeding-use, counseling-note, breach-notification, state-law, or documentation requirement imposes an additional limitation.
Summary of Part 2 regulatory updates: Since 2016, Part 2 has shifted from a more rigid consent-and-disclosure framework toward a modernized structure that better accommodates coordinated care, interoperability, and HIPAA-aligned compliance processes while preserving heightened protections for substance use disorder treatment information. The 2017 revisions updated terminology and structure; subsequent amendments addressed disclosure mechanics and electronic information-sharing concerns; and the 2020 CARES Act directed HHS to align certain Part 2 requirements more closely with HIPAA.
The 2024 final rule implements that alignment by permitting a single written patient consent for future treatment, payment, and health care operations uses and disclosures, modifying redisclosure rules for HIPAA-regulated recipients, and aligning Part 2 more closely with HIPAA regarding patient notices, breach notification, complaint processes, civil enforcement, and certain patient rights. At the same time, Part 2 continues to impose independent restrictions on use or disclosure in civil, criminal, administrative, and legislative proceedings against the patient, absent patient consent or a qualifying court order. The current compliance inquiry therefore remains record-specific and recipient-specific, requiring organizations to determine whether Part 2 applies, whether consent or another permission authorizes the disclosure, whether HIPAA-based redisclosure is available, and whether any remaining Part 2, state-law, counseling-note, breach-notification, documentation, or proceeding-use limitation applies.
Avoiding an Overbroad HIPAA-Centered Compliance Approach
Why an Overbroad HIPAA-Only Approach Creates Compliance Risk
The operative compliance concern is that routine characterization of health information confidentiality issues as “HIPAA issues” may be incomplete from a legal and regulatory perspective. Reliance on generic HIPAA policies, without analysis of state-specific medical record privacy requirements and specialized federal confidentiality regimes, may institutionalize an overbroad HIPAA-centered compliance approach. That approach may expose an organization to compliance risk where applicable law requires a more protective consent, authorization, disclosure, documentation, or redisclosure standard than HIPAA alone would require.
Practical Compliance Recommendations for Patient Privacy Disclosures
Recommended HIPAA, Part 2, and State Privacy Compliance Controls
- Do not release patient information until the applicable patient privacy law or health information confidentiality regime has been identified and documented.
- Determine whether the information falls within a specially protected category, including mental health records, substance use disorder records, HIV/AIDS-related information, or genetic information.
- Identify all potentially applicable federal and state authorities and determine which standard governs the proposed disclosure.
- Implement consent, authorization, access-control, redisclosure, breach-notification, and proceeding-use safeguards when required by specialized laws, including the post-2024 version of 42 CFR Part 2.
- Review policies, training materials, and disclosure workflows periodically to ensure they do not reflect an overbroad “HIPAA-only” compliance framework.
Conclusion: Applying the Correct Patient Confidentiality Law
Effective patient confidentiality compliance requires a structured legal analysis that extends beyond HIPAA privacy compliance alone. Although HIPAA establishes an essential federal baseline for the use and disclosure of protected health information, it does not necessarily supply the controlling standard in every circumstance. State medical record confidentiality statutes, specialized mental health record protections, and 42 CFR Part 2 substance use disorder record rules may impose additional, more specific, or more protective requirements depending on the nature of the record, the purpose of the proposed disclosure, the recipient, and the legal authority supporting release. Accordingly, health care organizations should implement a structured confidentiality triage process that requires personnel to identify the applicable category of information, determine all potentially governing federal and state health information confidentiality laws, evaluate the sufficiency of any required consent, authorization, court order, or exception, and document the basis for disclosure before information is released. Policies, training materials, and operational workflows should likewise be reviewed and maintained to ensure that they require legal-regime identification and do not rely on an undifferentiated “HIPAA-only” approach. By embedding this analysis into routine patient privacy disclosure practices, organizations can reduce compliance risk, promote lawful information sharing, and preserve patient trust.
- The Physician Board Member – Meeting Your Responsibilities as a Director
- Concierge Medicine Agreements – Five Key Contract Clauses for Medical Practices
- Telehealth Membership Platforms: A Provider Compliance Guide
- Medicare Opt-Out – A Make-or-Break Decision for Concierge Physicians
- Hybrid Concierge Models – Why Popularity Comes With Compliance Risk
