Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Behavioral health  ·  13 May 2026  ·  7 min

42 CFR Part 2 stopped being a paper rule in February

Civil enforcement began February 16, 2026. Almost no generalist IT provider has heard of it, and it sits on top of HIPAA rather than instead of it.

The full compliance deadline for the revised 42 CFR Part 2 hit on February 16, 2026, and OCR launched a Civil Enforcement Program the same month.

The significance is easy to miss if you have worked around Part 2 for years. It has always existed. It has always been strict. But it carried criminal penalties only, and criminal referral for a records-handling violation essentially never happened, so in practice it was unenforced. It now carries HIPAA-style civil monetary penalties, which are assessed by the same office that assesses them for HIPAA, on the same kind of investigation.

What Part 2 requires that HIPAA does not

Part 2 governs substance use disorder treatment records held by federally assisted programs. Three obligations sit on top of HIPAA rather than instead of it.

  • Consent management. Consent for disclosure, the scope of that consent, and the ability to revoke it โ€” all recorded and enforceable in the systems that actually hold the record. A general-purpose EHR configuration does not do this by default.
  • Redisclosure control. A Part 2 record that leaves your organization carries its restrictions with it. If your systems cannot mark, track, and prove that, the control does not exist regardless of what the policy binder says.
  • Disclosure accounting. Being able to say who saw what and when. This requires audit logging that was switched on before you needed it, and it is the single most common thing we find switched off in a behavioral health estate.

Why your IT provider has probably not mentioned it

Because Part 2 is genuinely obscure outside behavioral health, and because for two decades it made no practical difference. A generalist managed services provider with one behavioral health client among forty commercial ones has no reason to have encountered it.

That is not incompetence. It is specialization, or the absence of it. But the consequence is that a whole category of provider is now exposed to civil penalties on an obligation nobody in their supply chain is tracking.

Where to start

  1. Confirm whether you are a Part 2 program. Not every behavioral health provider is; it turns on federal assistance and on holding SUD treatment records.
  2. Inventory where those records live, including the places outside the EHR: the referral inbox, the scanned intake share, the telehealth platform's recordings.
  3. Verify that audit logging is on and retained. If it is not, turn it on today. You cannot retroactively log.
  4. Build the business associate register. Telehealth platforms, referral partners, and answering services are the usual gaps.
  5. Add Part 2 to role-based workforce training, with completion records retained six years.

The 42 CFR Part 2 module is included in Chartline Compliant at no additional cost. It is not available as a bolt-on, because the controls it documents have to be ones we operate.

Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific ยง164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.