By Fisher, JD, CHC, CCEP
Client Alert for Health Care Providers: Disclosure of Part 2 Records for Payment or Health Care Operations
Executive Summary. Recent amendments to 42 C.F.R. Part 2 continue the federal government’s effort to align substance use disorder record confidentiality rules more closely with HIPAA while preserving Part 2’s heightened privacy protections. For hospitals, health systems, physician groups, community health centers, behavioral health providers, and integrated delivery networks, the practical result is a more workable pathway for using and disclosing Part 2-protected information for payment and health care operations—but only if provider consent workflows, EHR configuration, vendor contracting, notice practices, and redisclosure controls are carefully managed.
This alert focuses on what health care providers should do when they create, receive, maintain, or transmit Part 2 records in connection with billing, claims submission, care management, quality reporting, utilization review, accreditation, credentialing, compliance, legal support, and other provider operations.
Background: Why Part 2 Matters for Providers. Part 2 protects records that identify an individual as having sought or received substance use disorder diagnosis, treatment, or referral for treatment from a federally assisted Part 2 program. Provider organizations should assess whether they operate a Part 2 program, an identified SUD treatment unit within a general medical facility, or medical personnel whose primary function is SUD diagnosis, treatment, or referral. Providers that are not themselves Part 2 programs may still become lawful holders when they receive Part 2 records from another program, such as through patient consent, referral, health information exchange, emergency treatment, or operational support arrangements.
SAMHSA’s 2018 regulations permitted a lawful holder of Part 2 records to further disclose those records to contractors, subcontractors, and legal representatives to carry out payment or health care operations on the lawful holder’s behalf. The 2024 final rule, issued by HHS through SAMHSA and the Office for Civil Rights, further aligns Part 2 with HIPAA by permitting a single patient consent for future uses and disclosures for treatment, payment, and health care operations, subject to Part 2-specific safeguards. The 2024 rule became effective April 16, 2024, and regulated entities generally must comply by February 16, 2026.
Provider Payment and Health Care Operations Use Cases. A provider that is a lawful holder may disclose Part 2 records to contractors, subcontractors, or legal representatives when the disclosure is necessary for payment or health care operations activities performed on the provider’s behalf. Provider-focused examples include revenue cycle management, coding and billing, prior authorization support, claims appeals, utilization review, quality assessment and improvement, patient safety activities, peer review, credentialing, accreditation, licensing, compliance audits, legal services, cybersecurity investigations, EHR hosting and support, health information exchange operations, population health analytics, and business planning.
Providers should distinguish operational disclosures from treatment disclosures. A disclosure to a billing vendor, coding consultant, outside counsel, accrediting body, or EHR support vendor may fit within payment or health care operations. By contrast, sharing Part 2 records with another treating clinician, affiliated practice, or care team member for diagnosis, treatment, or referral generally should be supported by a valid Part 2 consent or another Part 2-permitted basis.
Provider Contracting Requirements. Providers should review business associate agreements, qualified service organization agreements, EHR and revenue cycle contracts, managed services agreements, legal engagement letters, audit arrangements, and subcontractor flow-down provisions. These agreements should bind recipients to applicable Part 2 obligations, require appropriate safeguards for patient-identifying SUD information, restrict use and disclosure to the permitted provider purpose, require downstream subcontractors to accept comparable obligations, address breach and incident reporting, and preserve the provider’s ability to audit or obtain assurances of compliance.
Patient Consent and Redisclosure After the 2024 Final Rule. Under the 2024 amendments, a patient may provide a single consent authorizing all future uses and disclosures of Part 2 records for treatment, payment, and health care operations. Once Part 2 records are disclosed pursuant to such a consent to a HIPAA covered entity or business associate, that recipient may generally redisclose the records as permitted by HIPAA. However, Part 2 continues to prohibit use or disclosure of the records in civil, criminal, administrative, or legislative proceedings against the patient unless the patient provides specific consent or a Part 2 court order or comparable legal mandate applies.
Notice to Recipients. Disclosures of Part 2 records should be accompanied by the required notice explaining that the records are protected by federal confidentiality law and that redisclosure is restricted except as permitted by Part 2. For disclosures made under a broad treatment, payment, and health care operations consent, organizations should ensure the notice accurately describes the scope of the consent and any continuing limitations, including the prohibition on use in proceedings against the patient.
Operational Focus Areas for Providers. Provider compliance teams should pay particular attention to EHR flags and segmentation, intake and registration workflows, patient consent templates, referral processes, billing edits, claims attachments, portal releases, health information exchange participation, care management documentation, call center scripts, subpoenas and law enforcement requests, and release-of-information procedures. These workflows often determine whether Part 2 information is identified before it is disclosed and whether the required consent, notice, and redisclosure limitations are applied consistently.
Provider Compliance Checklist. Health care providers that create, receive, maintain, or transmit Part 2 records should take the following steps before disclosing records for payment or health care operations:
- Map where Part 2 records originate, including SUD clinics, medication-assisted treatment programs, embedded behavioral health teams, emergency departments, primary care practices, referral networks, health information exchanges, and scanned outside records.
- Determine whether the provider is acting as a Part 2 program, lawful holder, HIPAA covered entity, business associate, qualified service organization, or other recipient for each disclosure pathway.
- Identify the specific payment or health care operations purpose for the disclosure, such as billing, claims appeal, utilization review, accreditation, quality improvement, peer review, legal support, or EHR maintenance.
- Update patient consent forms to support single-consent treatment, payment, and health care operations disclosures while preserving revocation rights and any Part 2-specific limitations.
- Revise vendor and professional services contracts, including EHR, revenue cycle, coding, billing, audit, compliance, legal, and health information exchange agreements, to include Part 2 obligations and subcontractor flow-down terms.
- Configure EHR, release-of-information, and health information exchange workflows so Part 2 records can be identified, tracked, and accompanied by the appropriate notice to recipients.
- Train registration, HIM, billing, care management, compliance, legal, and clinical staff on the difference between HIPAA permissions and Part 2 restrictions, especially for redisclosures and subpoenas.
- Review incident response and breach notification procedures to ensure Part 2-related disclosures are escalated promptly and evaluated under both Part 2 and HIPAA-aligned standards.
Key Takeaways for Health Care Providers. The expanded pathway for payment and health care operations disclosures should help providers integrate Part 2 information into routine administrative and operational workflows, including revenue cycle, quality, compliance, and health IT functions. However, providers should not treat Part 2 records as ordinary HIPAA-protected information. The availability of a single treatment, payment, and health care operations consent does not eliminate the need to identify Part 2 records, manage patient revocations, provide required notices, control redisclosures, and prevent use of patient-identifying SUD records in proceedings against the patient.
Provider organizations should use the period before the February 16, 2026 compliance date to update consent workflows, EHR configuration, vendor contracting templates, notice practices, release-of-information procedures, subpoena response protocols, and workforce training. Providers that operate integrated SUD and non-SUD services should also test whether their systems can reliably distinguish Part 2 records from other behavioral health and general medical records before relying on broader payment or health care operations disclosures.
