Skip to content
ABCAC
Knowledge Center
Current Changes, Policy & Compliance

42 CFR Part 2 Is Now Enforceable: What Arizona SUD Providers Must Do

42 CFR Part 2's aligned rule is now enforceable. Here's what changed for SUD records — single consent, breach notification, new patient rights, and SUD counseling notes.

Editorial Team 7 min read Regulatory review recommended
Secure medical records folder with a lock icon representing patient confidentiality

For decades, substance use disorder (SUD) records lived under their own set of confidentiality rules — 42 CFR Part 2 — that were stricter, and often more confusing, than HIPAA. A major final rule reworked Part 2 to align it more closely with HIPAA, and the compliance clock has now run out. If your program touches SUD records, this is one compliance change you cannot afford to treat as optional.

Here's what changed and what your program should have in place.

The timeline you need to know

  • The final rule was effective April 16, 2024, giving providers a runway to prepare.
  • Compliance and enforcement began February 16, 2026.

That second date is the one that matters now. The grace period is over. Programs that haven't updated their consent forms, breach procedures, and patient-rights processes are out of compliance.

What actually changed

The rule's goal was to make Part 2 work more like HIPAA while preserving special protections for SUD records. The headline changes:

Previously, Part 2 could require a separate consent for essentially every disclosure. Now, a patient can sign one consent that covers all future uses and disclosures for treatment, payment, and health care operations (TPO). This is a significant workflow simplification — but only if your consent forms are updated to capture it correctly.

2. HIPAA-style breach notification — with real penalties

Part 2 now incorporates HIPAA's breach-notification requirements, and violations carry civil and criminal penalties (with civil penalties reaching into the seven figures — up to $2 million for certain violations). SUD records are no longer governed by a quieter, separate enforcement regime. If you have a breach involving Part 2 records, you notify the way HIPAA requires.

3. New patient rights

Patients gained HIPAA-like rights over their SUD records, including:

  • The right to an accounting of disclosures
  • The right to request restrictions on certain disclosures
  • The right to file complaints with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR)

Your notice of privacy practices and your patient-facing processes need to reflect these rights.

4. A new protected category: "SUD counseling notes"

This one is easy to miss and important to get right. The rule creates a distinct category of "SUD counseling notes," modeled on HIPAA's treatment of psychotherapy notes. These notes get heightened protection and generally require a separate, specific consent to disclose — they can't ride along on the standard TPO consent.

Practically, that means you should be documenting and storing SUD counseling notes in a way that keeps them separable from the rest of the record, so you can honor the higher consent bar.

5. Limited public-health flexibility

The rule permits certain de-identified disclosures for public-health purposes, giving programs a defined lane for public-health reporting that doesn't compromise individual confidentiality.

What Arizona SUD programs should have done by now

If you haven't already, treat this as your checklist:

  1. Update your consent forms to capture the single TPO consent — and to separately handle SUD counseling notes.
  2. Adopt HIPAA breach-notification procedures for Part 2 records, and make sure staff know a Part 2 breach now triggers HIPAA-style notice and penalties.
  3. Revise your notice of privacy practices to include the new patient rights (accounting of disclosures, restriction requests, OCR complaints).
  4. Segment SUD counseling notes in your documentation system so they can be protected at the higher standard.
  5. Train your staff. Front-desk, clinical, and billing staff all touch these records. Everyone who handles Part 2 information needs to understand what changed.
  6. Check your technology. Your EHR and any AI documentation tools need to correctly tag, segment, and protect Part 2 records — see the caution below.

A special warning about AI and other tools

If your program uses AI scribes, telehealth platforms, or any third-party tool that processes SUD records, verify that those tools correctly handle Part 2 data — including the SUD counseling-notes category and consent-revocation. A tool that's HIPAA-compliant in a general sense is not automatically Part 2-compliant. This is exactly the kind of blind spot that turns a helpful tool into a compliance liability.

The takeaway

42 CFR Part 2's aligned rule became effective in April 2024, and enforcement began February 16, 2026 — it's live now. SUD records now operate under a single TPO consent, HIPAA-style breach notification with penalties up to $2 million, expanded patient rights, and a new protected "SUD counseling notes" category. If your Arizona program hasn't updated its consent forms, breach procedures, patient-rights processes, and documentation systems, that work is overdue. Confidentiality has always been sacred in addiction treatment; now the rules for protecting it look a lot more like HIPAA.


Not sure your program is compliant?

Compliance details are nuanced, and this article is a summary, not a legal opinion. Have your consent forms, notice of privacy practices, and breach procedures reviewed by qualified healthcare-compliance counsel, and consult the official HHS resources on the Part 2 final rule.

This article is for general educational purposes and is not legal advice. Verify current requirements at hhs.gov and consult a qualified compliance professional before making changes to your program's privacy practices.

Verify current requirements before acting

Regulations, fees, and board processes can change. Confirm the latest requirements with ABCAC and the relevant licensing authority before making credentialing or compliance decisions.

Continue reading

Related guidance

View all articles