42 CFR Part 2

42 CFR Part 2, and how we handle it

Last updated 23 July 2026

Substance use disorder treatment records carry protections that go beyond HIPAA. This page explains what that means in practice and exactly how HopeConnect enforces it, so you can judge whether our handling meets your standard.

What Part 2 covers

42 CFR Part 2 is the federal regulation governing the confidentiality of substance use disorder patient records held by federally assisted programs. Its central principle is that these records generally cannot be disclosed without the patient's specific written consent, and that consent identifies who the information may go to and for what purpose.

The reason for the stricter standard is practical rather than bureaucratic. People avoid treatment when they fear that seeking help will expose them to employment, custody, housing, or criminal consequences. The regulation exists so that seeking treatment is safer.

Why it is stricter than HIPAA

HIPAA permits many disclosures for treatment, payment, and healthcare operations without separate patient authorization. Part 2 does not work that way for the records it covers. Consent is generally required, it is specific rather than general, and redisclosure by the recipient is itself restricted.

For referral coordination this matters enormously, because a referral is by definition a disclosure from one organization to another. A coordination system that treats a substance use referral like any other referral is not a convenience problem, it is a compliance failure with real consequences for a patient.

How HopeConnect enforces it

These are specific behaviors in the software, not policy statements:

What we do not claim

This page is an explanation, not legal advice

Part 2 has been amended over time, including through alignment efforts with HIPAA, and how it applies depends on your program, your funding, and your circumstances. Nothing here is legal advice, and we are not going to tell you that using HopeConnect makes your organization compliant. Compliance is a property of your organization and its practices, not of a vendor's software. What we can tell you is precisely what our system does and does not do, so your compliance and legal teams can evaluate it against your own obligations. Ask us the detailed version and you will get a direct answer.