Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
5 client organizations

Part 2 stopped being a paper rule on February 16, 2026.

The full compliance deadline for the revised 42 CFR Part 2 hit February 16, 2026, and OCR launched a Civil Enforcement Program the same month. Part 2 previously carried criminal penalties only and was effectively unenforced. It now carries HIPAA-style civil monetary penalties. This is a brand-new, real liability for every behavioral health and substance use disorder provider, and virtually no generalist IT company has heard of it.

Part 2 previously carried criminal penalties only and was effectively unenforced. Since February 16, 2026 it carries HIPAA-style civil monetary penalties.

What is actually different here

The specifics a generalist has never had to learn.

These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.

01

Part 2 records need consent management HIPAA never asked for

Consent for disclosure, the scope of that consent, and the ability to revoke it all have to be recorded and enforceable in the systems that actually hold the record. A general-purpose EHR configuration does not do this by default.

02

Redisclosure is the control most often missing

A Part 2 record that leaves your organization carries its restrictions with it. If your systems cannot mark, track, and prove that, the control does not exist regardless of what the policy binder says.

03

Disclosure accounting has to be producible, not theoretical

Being able to say who saw what and when requires audit logging that was turned on before you needed it. This is the single most common thing we find switched off in a behavioral health estate.

04

Telehealth widened the estate faster than anyone documented it

Clinician home offices, personal devices, and a video platform that may or may not have a BAA. The vendor and business associate register is the deliverable that closes this, and almost nobody has one.

Systems we run

We already know what these need.

And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.

  • Kipu
  • Netsmart
  • Qualifacts / CareLogic
  • Valant
  • SimplePractice
  • TherapyNotes
  • Zoom for Healthcare
  • Doxy.me
What the evidence file contains for this segment
  • Part 2 consent, revocation, and redisclosure control documentation
  • Disclosure accounting evidence with audit log retention
  • Business associate register covering every telehealth and referral platform
  • Role-based workforce training records covering Part 2 specifically, retained six years

Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.

How the compliance program works
Where this segment usually lands

Most start at Compliant.

The 42 CFR Part 2 module is included in Compliant at no additional cost. It is not available as a bolt-on, because the controls it documents have to be ones we operate.

Chartline Core

Managed IT with a security baseline.

$135/ user / month

15-user minimum · 36-month term

Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.

What is in Core

Chartline Secure

Everything in Core, plus 24/7 detection and response.

$189/ user / month

15-user minimum · 36-month term

For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.

What is in Secure
Most multi-location groups land here

Chartline Compliant

Everything in Secure, plus the HIPAA program and the evidence file.

$255/ user / month

25-user minimum · 36-month term

The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.

What is in Compliant
Behavioral health and SUD providers

See where you stand in about eight minutes.

Fifteen questions mapped to Security Rule citations, scored, with the specific §164 requirement named behind every gap. Nothing is gated and no call is required to see the result.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.