Skip to main content
Guide

Privacy and 42 CFR Part 2, what changes in your charting

What 42 CFR Part 2 requires for SUD records: who it covers, consent, segregation, disclosure logs, and how it changes the workspace.

42 CFR Part 2 governs confidentiality of substance use disorder (SUD) treatment records. It predates HIPAA, applies on top of HIPAA, and in several ways is stricter. For practices that treat SUD as part of a broader panel, the rule shapes what goes in the chart, who can see it, and what has to happen before a record leaves the building.

What Part 2 covers and what it does not

Part 2 covers records of patients receiving SUD diagnosis, treatment, or referral from a “Part 2 program.” That definition is what trips practices up. It includes:

  • Federally-assisted programs whose primary function is SUD treatment (an OTP, a residential SUD facility, a buprenorphine clinic).
  • Identified units within general medical facilities where SUD diagnosis, treatment, or referral is the primary function.
  • Medical personnel within general medical facilities whose primary function is SUD diagnosis, treatment, or referral.

A general outpatient psychiatry practice that treats some SUD patients alongside everything else is typically not a Part 2 program in the strict definition. A clinician in that practice whose primary function is SUD treatment may be subject to Part 2 for the records they create. Most MAT programs are. Most outpatient psychiatry practices that include MAT services are partially.

If you are not certain whether Part 2 applies, ask compliance counsel before you assume either way.

The 2024 update brought Part 2 closer to HIPAA in several places (notably a single broad consent for treatment, payment, and operations) but kept the core protections and added new ones around segregation, redisclosure, and breach notification.

What stays the same in your charting

The substance of the SUD note does not change. Assessment, diagnosis, medication, monitoring plan, C-SSRS, toxicology: same documentation. Part 2 governs handling, not content.

Do not “thin” Part 2 records to reduce disclosure risk. A thin chart that fails medical necessity creates denial, audit, and malpractice exposure without solving the disclosure problem. Write the full clinical content. Handle it rigorously.

What changes in your charting

Tag the record as Part 2. Most platforms use that tag to trigger segregation, audit, and disclosure controls.

Document the consents. Part 2 records can only be disclosed with patient consent in a specific format, with limited exceptions. The chart should make obvious which consents are in place, what they cover, and when they expire.

Mark the redisclosure prohibition. When a Part 2 record is disclosed, the material must carry a notice prohibiting redisclosure without further consent. Most platforms apply the standard wording on a Part 2 export.

Log every disclosure: date, recipient, records disclosed, consent used, and the redisclosure-prohibition notice that went with it. The log is part of the patient’s record and available on request. A referral, a release to a PCP, and a carrier query are each a separate entry. Build the log into the release workflow. Practices that try to backfill it typically have an incomplete log.

What changes in your workspace setup

Four operational patterns distinguish a Part 2-aware workspace from a HIPAA-only one:

  • Segregation. Part 2 records are segregated so disclosures of non-Part 2 records do not include Part 2 content. That can be section-level or record-level.
  • Consent management. Consent forms sit with the patient record. An external disclosure does not go through without an active, in-scope consent.
  • Audit logging. Every access is logged: who, when, what they did.
  • Workforce training. Annual training, documented per workforce member, on top of HIPAA.

Default to tagging SUD-related encounters as Part 2 unless the clinician affirmatively declasses the encounter for a documented reason. Tie consents to disclosures so a release cannot leave the system without a consent record attached.

In Nextvisit, the usual pattern is encounter-level tagging plus a custom tag (e.g., “Part 2”) and export controls that exclude tagged content from default flows. Consents and disclosure logs live as documents at /patient/[uuid]/documents with structured fields for consent type, scope, and expiration.

If you are a dedicated SUD program (OTP, residential, embedded MAT clinic), talk to compliance counsel about a separate workspace or a more formal segregation architecture.

The “co-occurring” problem

A patient with a primary mood or anxiety disorder and a substance use disorder, treated by the same clinician in the same encounter:

  • Document the encounter in full, with the SUD content present and clinically complete.
  • Tag the encounter. If the clinician is functioning as a Part 2 provider for this patient (primary function is SUD treatment, or SUD treatment is integral to the encounter’s purpose), the encounter is Part 2. If not, the encounter is HIPAA-only and the SUD content still sits under HIPAA.
  • Make the tagging basis visible. A short assessment note (“encounter tagged as Part 2 record per primary purpose of SUD treatment today”) clarifies the call for a later reviewer.
  • Tell the patient the Part 2 protections in plain language.

If the practice is not certain on a per-encounter basis, the safer default is to apply Part 2 more broadly.

What changes in your AI documentation tooling

Part 2 records cannot be used to train AI models without specific patient consent in the Part 2 format. Nextvisit does not train AI on PHI, which includes Part 2 records. Nextvisit trains AI on other customer data by default, and customers can opt out. Confirm the same of any other tool and document the confirmation.

Longitudinal views (AI Timeline, Treatment Pulse, peer review) operate across the chart, including Part 2 content. Those views are access-controlled and audit-logged. If a clinician cannot read the underlying records, the derived view is also restricted.

AI Tasks that touch patient or encounter data may produce outputs with Part 2 content. The destination has to match the consents in place. A referral letter should not include Part 2 content unless the referral has Part 2-compliant consent.

MCP and OAuth are external disclosures. Part 2 records should not flow there unless the consent and the external party’s compliance posture support it.

Patient rights

Part 2 patients have the right to know how their records can be used, to consent to disclosures with clear scope and expiration, to revoke that consent, to access the disclosure log and their own records, and to a complaint process. Document acknowledgment at intake or at the first SUD-related encounter.

Where Nextvisit fits

The platform supports the handling: encounter tagging, custom tags for Part 2 cohorts, document storage for consents and the disclosure log, audit logging on every access, segregated export controls, workspace-scoped API and MCP access. Clinical content is unchanged.

See it on your workflow

Twenty minutes, one mock visit. You leave with a note in your template.

We run a mock session live, draft the note, and walk through what the downstream claim would look like. No slides. No sales deck.

Live in 2 weeks or less BAA signed by default