Most Arizona practices that connect to a health information exchange design their consent workflow around HIPAA and stop there. That works fine for a primary-care record. It does not work for a substance use disorder (SUD) treatment record, because a second, older, and stricter federal rule — 42 CFR Part 2 — governs those specifically, and it does not simply defer to HIPAA. Practices that behave as if the two regimes are interchangeable are the ones that end up with a redisclosure violation nobody planned for.
Why SUD Records Get a Separate Rulebook
42 CFR Part 2 applies to any federally assisted program that provides SUD diagnosis, treatment, or referral for treatment. The rule exists because SUD information carries a distinct kind of harm if it leaks — employment consequences, custody disputes, criminal exposure — and Congress built Part 2 specifically to remove that fear as a barrier to people seeking treatment. The operating default is narrow: a Part 2 program generally cannot disclose any information that would identify someone as having, or having had, a substance use disorder, unless the disclosure fits a specific Part 2 exception (a medical emergency, for example) or the patient has signed a valid Part 2 consent. There is no general treatment-payment-operations carve-out the way there is under HIPAA.
What Belongs on a Valid 42 CFR Part 2 Consent Form
A HIPAA authorization and a Part 2 consent are not interchangeable documents, and a generic release-of-information form built for one will usually fail the other. A valid Part 2 consent needs to specify:
- The patient’s name and identifying information
- The name of the Part 2 program or person permitted to make the disclosure
- The name of the recipient, or a defined class of recipients
- The purpose of the disclosure — care coordination, payment, audit, or another stated reason
- A description of exactly what information may be released, limited to what is actually needed
- An expiration date or expiration event
- The patient’s signature and the date
Missing any one of these elements is enough to make the consent defective, which matters a great deal once that record is queried through an HIE rather than faxed between two offices that already know each other.
HIPAA vs. 42 CFR Part 2: Where the Two Regimes Diverge
The practical differences show up in three places: whether consent is required at all for routine care functions, what happens after the first disclosure, and what happens if the record is ever subpoenaed.
| Dimension | Standard HIPAA | 42 CFR Part 2 |
|---|---|---|
| Consent for treatment, payment, operations | Not required — implied as part of seeking care | Written consent required, even for treatment or payment, absent a defined exception |
| Redisclosure by the recipient | Permitted within HIPAA’s minimum-necessary standard | Prohibited by default unless the original consent or Part 2 itself permits it |
| Use in legal proceedings | Not specifically barred given a valid legal process | Sharply restricted — requires patient consent or a court order meeting Part 2’s heightened standard |
Where the two rules overlap and conflict, the stricter one controls. In practice, that means a practice cannot rely on its HIPAA notice-of-privacy-practices language to cover SUD data moving through an HIE — a separate, explicit Part 2 consent has to exist and has to travel with the record.
The 2024 “TPO Consent” Change and What It Means at the HIE Level
A recent update to Part 2 introduced a single consent — commonly called a TPO consent — that can cover future uses and disclosures of Part 2 records for treatment, payment, and healthcare operations, instead of requiring a fresh consent for every downstream party. Once a HIPAA-covered entity receives a Part 2 record under a valid TPO consent, it can generally redisclose that information the way HIPAA already allows it to redisclose any other record — with one significant carve-out that survives: the information still cannot be used against the patient in a legal proceeding without separately meeting Part 2’s consent or court-order standard. For an HIE-connected practice, this is the detail that actually changes workflow: the TPO consent simplifies routine care coordination, but it does not erase the redisclosure and legal-proceeding protections that made Part 2 stricter than HIPAA in the first place.
Practical Steps Before an SUD Record Touches an HIE
Before any substance use disorder record is queried or shared through a statewide exchange, a practice should be able to answer four questions: does a Part 2-compliant consent exist and is it current, does it name the right program and purpose, does the receiving party understand the redisclosure restriction that travels with the data, and is there a process for handling a subpoena that does not meet Part 2’s court-order standard. Behavioral health, EHR, and HIE-onboarding vendors vary widely in how well they actually build Part 2 segmentation into their consent workflows — some treat it as a checkbox, others build genuine data segmentation so Part 2-protected records are flagged and held to the stricter standard automatically. That distinction is worth vetting before a practice signs an integration agreement, not after the first audit finds a gap.