Skip to main content
[email protected]
Menu
Language
Appearance

42 CFR Part 2 vs. HIPAA: The Consent Gap Arizona Practices Miss at HIE Connection

ATAzHeC Technology Council
August 15, 2026
5min read
WhatsAppEmail

Most Arizona practices that connect to a health information exchange design their consent workflow around HIPAA and stop there. That works fine for a primary-care record. It does not work for a substance use disorder (SUD) treatment record, because a second, older, and stricter federal rule — 42 CFR Part 2 — governs those specifically, and it does not simply defer to HIPAA. Practices that behave as if the two regimes are interchangeable are the ones that end up with a redisclosure violation nobody planned for.

Why SUD Records Get a Separate Rulebook

42 CFR Part 2 applies to any federally assisted program that provides SUD diagnosis, treatment, or referral for treatment. The rule exists because SUD information carries a distinct kind of harm if it leaks — employment consequences, custody disputes, criminal exposure — and Congress built Part 2 specifically to remove that fear as a barrier to people seeking treatment. The operating default is narrow: a Part 2 program generally cannot disclose any information that would identify someone as having, or having had, a substance use disorder, unless the disclosure fits a specific Part 2 exception (a medical emergency, for example) or the patient has signed a valid Part 2 consent. There is no general treatment-payment-operations carve-out the way there is under HIPAA.

A HIPAA authorization and a Part 2 consent are not interchangeable documents, and a generic release-of-information form built for one will usually fail the other. A valid Part 2 consent needs to specify:

  1. The patient’s name and identifying information
  2. The name of the Part 2 program or person permitted to make the disclosure
  3. The name of the recipient, or a defined class of recipients
  4. The purpose of the disclosure — care coordination, payment, audit, or another stated reason
  5. A description of exactly what information may be released, limited to what is actually needed
  6. An expiration date or expiration event
  7. The patient’s signature and the date

Missing any one of these elements is enough to make the consent defective, which matters a great deal once that record is queried through an HIE rather than faxed between two offices that already know each other.

HIPAA vs. 42 CFR Part 2: Where the Two Regimes Diverge

The practical differences show up in three places: whether consent is required at all for routine care functions, what happens after the first disclosure, and what happens if the record is ever subpoenaed.

DimensionStandard HIPAA42 CFR Part 2
Consent for treatment, payment, operationsNot required — implied as part of seeking careWritten consent required, even for treatment or payment, absent a defined exception
Redisclosure by the recipientPermitted within HIPAA’s minimum-necessary standardProhibited by default unless the original consent or Part 2 itself permits it
Use in legal proceedingsNot specifically barred given a valid legal processSharply restricted — requires patient consent or a court order meeting Part 2’s heightened standard

Where the two rules overlap and conflict, the stricter one controls. In practice, that means a practice cannot rely on its HIPAA notice-of-privacy-practices language to cover SUD data moving through an HIE — a separate, explicit Part 2 consent has to exist and has to travel with the record.

The 2024 “TPO Consent” Change and What It Means at the HIE Level

A recent update to Part 2 introduced a single consent — commonly called a TPO consent — that can cover future uses and disclosures of Part 2 records for treatment, payment, and healthcare operations, instead of requiring a fresh consent for every downstream party. Once a HIPAA-covered entity receives a Part 2 record under a valid TPO consent, it can generally redisclose that information the way HIPAA already allows it to redisclose any other record — with one significant carve-out that survives: the information still cannot be used against the patient in a legal proceeding without separately meeting Part 2’s consent or court-order standard. For an HIE-connected practice, this is the detail that actually changes workflow: the TPO consent simplifies routine care coordination, but it does not erase the redisclosure and legal-proceeding protections that made Part 2 stricter than HIPAA in the first place.

Practical Steps Before an SUD Record Touches an HIE

Before any substance use disorder record is queried or shared through a statewide exchange, a practice should be able to answer four questions: does a Part 2-compliant consent exist and is it current, does it name the right program and purpose, does the receiving party understand the redisclosure restriction that travels with the data, and is there a process for handling a subpoena that does not meet Part 2’s court-order standard. Behavioral health, EHR, and HIE-onboarding vendors vary widely in how well they actually build Part 2 segmentation into their consent workflows — some treat it as a checkbox, others build genuine data segmentation so Part 2-protected records are flagged and held to the stricter standard automatically. That distinction is worth vetting before a practice signs an integration agreement, not after the first audit finds a gap.

AT

Written by

AzHeC Technology Council

Join Our Community

Connect with like-minded readers, share your thoughts, and engage in meaningful discussions.

Explore More Articles

Discover our extensive library of health research and evidence-based insights.

Comments

0

Sign in to join the discussion

Share your thoughts and engage with the community

No comments yet

Sign in to be the first to comment!