Aligning Substance Use Privacy Regs With HIPAA Isn’t Simple episode artwork

EPISODE · Jan 27, 2026

Aligning Substance Use Privacy Regs With HIPAA Isn’t Simple

from Info Risk Today Podcast · host InfoRiskToday.com

Revisions to 42 CFR Part 2 that go into effect soon to better align federal regulations for the confidentiality of substance use disorder records with HIPAA require entities to adjust their compliance programs. But the changes aren't easy, said attorney David Holtzman, founder of HITprivacy LLC.

Episode metadata supplied by the publisher feed · Published Jan 27, 2026

Embed this episode

NOW PLAYING

Aligning Substance Use Privacy Regs With HIPAA Isn’t Simple

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasak-Migee, Executive Editor at Information Security Media Group. Today I'm speaking with privacy attorney David Holzman, who is the retired founder of Consulting Firm HIT Privacy LLC. David is also a former senior advisor at the U.S. Department of Health and Human Services Office for Civil Rights, which administers and enforces HIPAA.

We're going to be discussing regulatory changes coming soon to HHS related to 42 CFR Part II, which pertains to the federal rules protecting the confidentiality of substance use disorder records. These changes are meant to better align 42 CFR Part II with HIPAA. So David, February 16th is the compliance date for changes to the confidentiality, security, and breach notification requirements for Part II substance use disorder records. For our listeners, could you briefly please describe what these changes mean for Part II substance use disorder treatment providers and HIPAA-regulated entities?

What types of entities fall under both categories of providers and who is affected by the changes? Let me start by saying that 42 CFR Part II and HIPAA are two different regulatory sets that are meant to apply to two different groups of folks. They're distinct, but overlapping, and the goal is to protect health information. HIPAA applies broadly across the healthcare sector, Part II provides stricter, specific protections for records of individuals seeking treatment for substance use disorders at federally assisted programs.

Those are magic words like the definition of a covered entity under HIPAA. So a federally assisted program is any provider that accepts Medicare, Medicaid, or is a federal equally qualified healthcare provider. Essentially any provider that is not a private provider is a federally assisted program. So the CARES Act enacted in 2020 required HHS to update Part II, as you said, to align it more closely with HIPAA and to allow for the greater sharing of information purposes for coordinating care of substance abuse disorder patients.

But what it doesn't do, it doesn't integrate the HIPAA privacy and security and breach notification rules into 42 Part II, or let's just call it Part II. It maintains Part II as a separate and distinct regulatory set that provides a mishmash, that's a technical term, a mishmash of new regulations or new provisions that seek to integrate parts of but not all of the HIPAA privacy and breach notification rules into Part II. So what are some of the changes? So to keep it simple, let's just go section by section here.

So when we talk about disclosures for treatment payment in healthcare operations, HIPAA permits disclosures for treatment payment in healthcare operations without a specific patient authorization. Updated Part II now permits programs to obtain a single prior consent for all future treatment payment in healthcare operations disclosures, allowing records to follow the patient through the healthcare system as well as lowering some barriers for healthcare claims and administrative oversight. As for redisclosures, HIPAA generally allows redisclosures of protected health information for specifying legitimate purposes. Part II will now allow treatment programs and their business associates that receive treatment records via the new TPO consent to now redisclothes protected information using the HIPAA standards, except for a prohibition on redisclosure for use in any legal proceeding.

So Part II continues its prohibition on redisclosure of personal information for use in any legal proceeding. Unlike HIPAA, Part II continues to strictly prohibit disclosure of substance abuse and treatment records for use against a patient in any civil criminal or administrative proceeding without a specific court order that meets the standards established in Part II or a separate written consent from the patient. The new Part II rule creates a category for substance abuse treatment records for counseling notes which are treated like HIPAA psychotherapy notes. The sub counseling notes must be kept separate from the rest of the medical record and requires a separate specific consent for disclosure.

A new provision of Part II will be like HIPAA. Health care providers are required to provide patients with a notice how the organization may use and disclose the PHI as well as how to file a complaint about privacy practices. Part II providers must now develop and provide a notice to inform patients other federal privacy rights and provide patients with a notice of the program's privacy practices. As for information and security standards, Part II does not integrate the HIPAA security rule into Part II.

Disclosures are going to be required to have appropriate policies and procedures to reasonably protect against unauthorized uses and disclosures and to protect against reasonably anticipated threats or hazards to the security of PII, whether it be in paper form or electronic form. For paper records, they must develop health care organizations, the programs, and lawful holders must create physical and technical safeguards in accordance with the standards set out in Part II. For electronic records, programs that are creating and receiving and maintaining in trans-many records, they must have appropriate safeguards in place, but there's no specific distinction for what those standards are. They're sort of how should we put it, Lucy, and Lucy.

There is a reasonable standard that probably aligns with the risk-based approach in the security management process standards other security rules. Again, Part II does not go into a great detail of what the expectations are and what the requirements are going to be. For the breach notification rule, the breach notification rule of HIPAA applies only to Part II programs. Part II programs will be responsible for notification of breaches by their qualified service organizations and BAs, but the QSOs and the BAs are not covered by the breach provisions.

SAMHSA in Part II advises that programs could include contractual language with their business associates and QSOs to require these contractors to notify programs in the case of a breach, but it's not required. This could prove to be a significant loophole in the breach notification requirements that apply to Part II programs. That is an overview of the significant changes in Part II to integrate with the HIPAA regulations. So, David, with that all said, what's your advice to these entities, these Part II entities that now need to comply with the changes?

What steps should they be taking if they haven't already taken them, especially because, again, as we said, the onset of compliance is on February 16th? I think the three key areas that organizations should be taking, both for programs and contractors to these programs, is to, first of all, update their consent forms. The consent forms now permit a single prior consent for disclosure of information, specifically for treatment payment and healthcare operations, and any other disclosure that would be permitted by the individual. Secondly, they should revise their organization's policies and procedures.

The Part II regulation is changing dramatically, but it's not changing in a way that's clear cut or easy to understand. As I said, it's now a mismatch of what was already existing in Part II, and provisions of the HIPAA rules that are being parachuted into this regulation, and the fit is not always clean or concise. And the third step that is fundamental to compliance with these new Part II regulations is for staff training. Different components of your staff will need to be provided different levels of training in order to ensure that they understand the rights and responsibilities of the both the program, a business associate, and a qualified service organization in regards to how they handle patient information and how they safeguard it in the complicated process by which disclosure and re-disclosure may occur.

There has not been a lot of guidance issued by HHS on how to comply with the requirements of the new Part II. SAMHSA has contracted with the Center for Excellence for PHI or coephi.org. This organization has developed a series of templates that can be used by organizations to comply with the new Part II. Templates for consent for uses and disclosures of Part II records, a patient notice of privacy practices for Part II programs.

They also have a very thorough webinar about implementing changes to sub-privacy rules. I highly recommend that organizations go to coephi.org for assistance on how to comply with the new Part II requirements. David, in terms of entities that must comply with Part II requirements and the changes and existing HIPAA regulated entities, is there a lot of overlap? Are there many Part II providers that are also already needing to comply with HIPAA because they do more than just the programs that fall under Part II?

And if so, what changes for them if anything? I think this goes into the evolution of the treatment for substance use disorders. Many years ago, when the original Part II was implemented, substance use disorder treatment was mostly inpatient. And it was not widely reimbursed through health insurance.

Over the decades, substance use disorder treatment has evolved through the introduction of pharmaceuticals and that are administered in the medical office or in a hospital, general hospital setting. And health insurance, in many cases, is now required to cover treatment for substance use disorder. That is how the interaction between the HIPAA covered entities and the Part II providers have sort of collided in the stringent requirements of Part II were hard for HIPAA covered entities who were providing substance use disorder treatment. It was difficult for them to handle this information through the segmented requirements under Part II and also to manage the treatment payment and health care operations that were now commonplace in the medical treatment of substance use disorders.

I think what we're seeing is that through the revised Part II covered entities and business associates with their recognition through definitional changes in Part II, they will have an easier time to manage the business and the treatment of substance use disorder and to better be able to manage these patients through the health care continuum. Because substance use disorder treatment is now commonly recognized as one piece of the larger health care treatment continuum of a patient. Part II now specifically recognizes the definition under HIPAA of a covered entity and a business associate and adopts the same definitions of treatment, payment, and health care operations. As we said earlier, the significant difference is that under Part II, the HIPAA covered entity must obtain a prior consent prior to disclosure of information even if it is for treatment payment and health care operations.

That will require some modification of how the HIPAA covered entity manages its consent process but it is certainly an easing of the requirements of Part II as it has been in place since 1987. Is there anything else besides the changes coming to Part II that you're keeping a close eye on right now when it comes to HIPAA related issues for this year? I am looking forward to hearing from OCR director Paula Standard, the upcoming HIPAA Summit where it should be given an opportunity to share with us her vision of what she sees coming forward in the next year with regard to proposed changes to the HIPAA security rule and the long proposed changes to the privacy rule. The unified agenda for regulatory changes put out by OMB still shows that there will be final rules issued for the HIPAA privacy rule, those proposed rules that were from the last Trump administration in their NPRM 2021, and also that there will be an upcoming final rule for modification to the security rule.

That proposed rule came out I believe in December of 2024. So we'll be looking to Paula to provide insight as to what she sees over the horizon with these proposed rule changes. We'd also like to hear about how OCR plans to enforce the new Part II. The new Part II regulations, OCR was delegated by HHS, the authority to enforce Part II, and we'll be looking forward to more information as to how Paula sees OCR taking on this new responsibility.

Well, thank you so much, David. I've been speaking to David Holzman. I'm Mary Ann Cobus-Suck McGee of Information Security Media Group. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 27, 2026.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!