1.2 Specialized Federal Privacy Laws: 42 CFR Part 2, GINA, FERPA, and Cures Act Information Blocking
Key Takeaways
- 42 CFR Part 2 applies exclusively to federally assisted specialized Substance Use Disorder (SUD) programs, enforcing strict consent rules and a mandatory written prohibition on re-disclosure notice (42 CFR § 2.32).
- The 2024 SAMHSA/HHS Part 2 Final Rule aligned SUD privacy with HIPAA by permitting single broad consent for all future Treatment, Payment, and Operations (TPO), applying the HIPAA Breach Notification Rule, and aligning civil penalty structures.
- Under GINA (Public Law 110-233) and 45 CFR § 164.502(a)(5)(i), genetic information is classified as PHI, and health plans are strictly prohibited from utilizing genetic data (including family medical history) for underwriting purposes.
- Student health and immunization records maintained by educational institutions subject to FERPA (34 CFR Part 99) are classified as 'education records' or 'treatment records' and are expressly excluded from the definition of PHI under HIPAA (45 CFR § 160.103).
- The 21st Century Cures Act Information Blocking Rule (45 CFR Part 171) prohibits healthcare providers, health IT developers, and health information exchanges from interfering with the access, exchange, or use of Electronic Health Information (EHI), subject to eight narrow regulatory exceptions.
Specialized Federal Privacy Laws: 42 CFR Part 2, GINA, FERPA, and Cures Act Information Blocking
While HIPAA establishes the general federal baseline for health information privacy and data security, it does not operate in a vacuum. A complex matrix of specialized federal statutes imposes heightened protections on specific categories of sensitive health data—including substance use disorder treatment, human genomics, and education-linked clinical records. Furthermore, modern federal policy actively penalizes the unreasonable withholding of electronic health data under interoperability mandates.
Health privacy and security officers must master these specialized statutes to prevent severe regulatory conflicts, discriminatory data use, and significant administrative penalties.
42 CFR Part 2: Confidentiality of Substance Use Disorder (SUD) Patient Records
Codified under the statutory authority of Section 543 of the Public Health Service Act (42 U.S.C. § 290dd-2), 42 CFR Part 2 safeguards the privacy of individuals seeking diagnosis, treatment, or referral for Substance Use Disorder (SUD). Enacted during the 1970s amid intense social stigma and fear of criminal prosecution, Part 2 provides protections that are substantially more restrictive than general HIPAA standards.
Applicability and Scope: What Qualifies as a Part 2 Program?
Part 2 does not apply to every healthcare entity that treats a patient with an addiction. It applies exclusively to federally assisted programs that hold themselves out as providing SUD services:
- Federally Assisted: Broadly construed to include any entity that receives federal funds (Medicare/Medicaid reimbursement, federal grants), is authorized to conduct business by the federal government (DEA registration to dispense controlled substances like buprenorphine or methadone), or operates with tax-exempt non-profit status.
- Part 2 'Program': An individual or entity (other than a general medical facility) that holds itself out as providing, and provides, SUD diagnosis, treatment, or referral for treatment; OR an identified unit within a general medical facility that holds itself out as providing SUD services; OR medical personnel or other staff in a general medical facility whose primary function is the provision of SUD services.
Critical Distinction: An emergency department physician in a general acute care hospital who stabilizes an acute opioid overdose is not a Part 2 program. However, a specialized inpatient addiction recovery unit operated within that same hospital is a Part 2 program.
SUD Patient Consent Requirements
Historically, Part 2 prohibited any disclosure of SUD records without specific patient consent, even for routine medical treatment, except in bona fide medical emergencies (§ 2.51) or pursuant to specialized court orders (§§ 2.61–2.67). Disclosures made with consent were required to include the mandatory statutory Notice to Accompany Disclosure (42 CFR § 2.32):
"This record which has been disclosed to you is protected by federal confidentiality rules (42 CFR Part 2). The federal rules prohibit you from making any further disclosure of this information unless further disclosure is expressly permitted by the written consent of the person to whom it pertains..."
The CARES Act of 2020 and the 2024 Final Rule Modernization
Section 3221 of the Coronavirus Aid, Relief, and Economic Security (CARES) Act of 2020 directed HHS and SAMHSA to align 42 CFR Part 2 with HIPAA. The 2024 SAMHSA/HHS Final Rule modernized Part 2 while retaining core anti-discrimination and criminal justice protections:
- Single Broad Consent for Future TPO: Patients may now execute a single, universal consent permitting the Part 2 program to disclose their SUD records for all future Treatment, Payment, and Health Care Operations (TPO) in alignment with HIPAA. Once disclosed to a HIPAA covered entity or business associate, those records may be re-disclosed in accordance with the HIPAA Privacy Rule (except in legal proceedings against the patient).
- Alignment of Breach Notification: The HIPAA Breach Notification Rule (45 CFR Part 164 Subpart D) now formally applies to unauthorized breaches of Part 2 records.
- Enforcement Alignment: Historic criminal misdemeanor fines were replaced with direct Civil Monetary Penalty tiers under HITECH / HIPAA (45 CFR Part 160) enforced by HHS OCR.
- Patient Rights: Granted Part 2 patients the formal right to request an accounting of disclosures and the right to request restrictions on disclosures for TPO.
- Shielding Records in Legal Proceedings: Absolute prohibition against using Part 2 records, testimony, or evidence in criminal, civil, administrative, or legislative proceedings against the patient without an explicit court order based on good cause and a showing that other means of obtaining the information are unavailable.
- Notice of Privacy Practices: A conforming amendment to 45 CFR § 164.520 requires covered entities that create, receive, or maintain Part 2 records to revise and redistribute their NPP to describe Part 2 protections.
Effective Date vs. Compliance Date: The 2024 Part 2 Final Rule was published on February 16, 2024 and took effect on April 16, 2024, but HHS granted a two-year transition period: full compliance, including the revised Notice of Privacy Practices, was required by February 16, 2026. Expect the exam to test this distinction, since the effective date and the compliance date are two years apart.
Genetic Information Nondiscrimination Act of 2008 (GINA)
Enacted as Public Law 110-233, the Genetic Information Nondiscrimination Act (GINA) protects individuals from genetic discrimination in health insurance and employment. GINA addresses public anxiety that genetic testing for hereditary diseases (e.g., BRCA1/BRCA2 breast cancer mutations or Huntington's disease) could lead to insurance cancellation or job loss.
Statutory Structure of GINA
- Title I (Health Insurance Protections): Prohibits group health plans and individual health insurance issuers from adjusting premiums, modifying contribution amounts, conditioning eligibility, or imposing pre-existing condition exclusions based on genetic information. Plans are strictly prohibited from requesting, requiring, or purchasing genetic information for underwriting purposes.
- Title II (Employment Protections): Prohibits employers, employment agencies, and labor organizations from using genetic information in hiring, discharge, compensation, terms, or privileges of employment. Employers cannot request, require, or purchase genetic data, with narrow exceptions (e.g., voluntary wellness programs with explicit written consent, or FMLA documentation).
Definition of Genetic Information
Under GINA § 201 and the HIPAA Privacy Rule, genetic information includes:
- An individual's genetic tests (e.g., DNA, RNA, chromosomal analyses).
- The genetic tests of family members of the individual (up to fourth-degree relatives).
- The manifestation of a disease or disorder in family members of the individual (family medical history).
- Requests for, or receipt of, genetic services (genetic counseling, education, or clinical research testing).
HIPAA Privacy Rule Integration (45 CFR § 164.502(a)(5)(i))
Pursuant to GINA mandates, the 2013 HIPAA Omnibus Rule explicitly amended the Privacy Rule to classify genetic information as PHI and codified a categorical underwriting ban:
A health plan (other than an issuer of long-term care policies) shall not use or disclose protected health information that is genetic information for underwriting purposes. (45 CFR § 164.502(a)(5)(i))
Underwriting purposes include determining eligibility, computing premiums, applying pre-existing condition limits, and creating or adjusting policy terms.
Critical Candidate Trap: GINA's underwriting prohibition applies exclusively to health insurance. GINA does not apply to life insurance, disability insurance, or long-term care insurance policies unless prohibited by specific state statutes.
FERPA vs. HIPAA: Student Health Records and Educational Institutions
The boundary between the Family Educational Rights and Privacy Act of 1974 (FERPA, 20 U.S.C. § 1232g; 34 CFR Part 99) and the HIPAA Privacy Rule is one of the most heavily tested jurisdictional concepts on the CHPS exam.
The Statutory Exclusion under HIPAA
Under the statutory definitions of the HIPAA Privacy Rule, Congress explicitly excluded educational records from the definition of PHI:
Protected health information excludes individually identifiable health information in: (i) Education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g; (ii) Records described at 20 U.S.C. 1232g(a)(4)(B)(iv) [student treatment records]... (45 CFR § 160.103)
Because of this express carve-out, an educational institution subject to FERPA cannot simultaneously hold HIPAA PHI for enrolled students.
Educational Healthcare Jurisdiction Flowchart:
Clinical Record Created at Educational Facility
│
├──► Primary/Secondary School (K-12) Public / Federally Funded
│ └── Governed 100% by FERPA as Education Records (Parents hold access rights)
│
└──► Postsecondary Institution (College / University Health Clinic)
│
├── Patient is Enrolled Student
│ └── Governed by FERPA as Student Treatment Records (Excluded from HIPAA)
│
└── Patient is Non-Student (Faculty, Staff, or Community Member)
└── Governed by HIPAA Privacy Rule as PHI (Hybrid Entity Status Required)
Operational Distinctions: K-12 vs. Postsecondary Institutions
- K-12 Public Schools: Student health records (immunization charts, nurse visit logs, IEP medical evaluations) maintained by a school receiving federal funding from the Department of Education are education records under FERPA. Parents have the right to inspect and review these records under 34 CFR § 99.10. HIPAA does not apply, even if the school bills Medicaid electronically for special education services.
- University Health Clinics (Hybrid Entities): Postsecondary student medical charts maintained by university physicians are FERPA Treatment Records. They are maintained solely for medical care and can only be disclosed to treating professionals or with the student's written consent. However, if the university clinic also opens its doors to treat non-student faculty, staff, or local community members, records for those individuals are HIPAA PHI. The university must designate itself as a Hybrid Entity under 45 CFR § 164.105, strictly firewalling FERPA student treatment records from HIPAA PHI databases.
21st Century Cures Act & ONC Information Blocking Rule
Enacted in December 2016 (Public Law 114-255), the 21st Century Cures Act introduced landmark statutory mandates to eliminate electronic data siloing. While HIPAA established rules regarding when health data may be shared or must be protected, the Office of the National Coordinator for Health Information Technology (ONC) Information Blocking Rule (45 CFR Part 171) establishes mandates regarding when data must not be withheld.
Definition of Information Blocking (45 CFR § 171.103)
Information blocking is defined as a business, operational, or technical practice that is likely to interfere with, prevent, or materially discourage access, exchange, or use of Electronic Health Information (EHI).
Regulated Actors and Subjective Intent Standards
The rule applies to three distinct categories of 'Actors', each governed by a specific statutory knowledge standard:
- Healthcare Providers: Any hospital, skilled nursing facility, physician practice, or clinical laboratory. Knowledge Standard: The provider knows that the practice is unreasonable and is likely to interfere with access, exchange, or use of EHI.
- Health IT Developers of Certified Health IT: Vendors of certified electronic health record technology (CEHRT). Knowledge Standard: The developer knows, or should know, that the practice is likely to interfere with access, exchange, or use of EHI.
- Health Information Networks (HINs) / Health Information Exchanges (HIEs): Entities that orchestrate multi-provider data routing. Knowledge Standard: The HIN/HIE knows, or should know, that the practice is likely to interfere with access, exchange, or use of EHI.
Scope of Electronic Health Information (EHI)
EHI encompasses all individually identifiable electronic health data to the extent it is transmitted or maintained in electronic media and would be classified as part of a Designated Record Set (DRS) under HIPAA (45 CFR § 164.501). It includes clinical notes, diagnostic imaging, lab results, billing records, and pathology reports, structured around the United States Core Data for Interoperability (USCDI).
The Eight Information Blocking Exceptions (45 CFR Part 171)
Failing to provide electronic access is not a violation if the actor satisfies all operational criteria of one of the eight statutory exceptions categorized into two groups:
| Exception Category | Exception Name | 45 CFR Citation | Regulatory Summary & Operational Criteria |
|---|---|---|---|
| Exceptions that Involve NOT Fulfilling Requests | Preventing Harm | § 171.201 | The actor holds a reasonable belief that withholding EHI substantially reduces a risk of physical harm to a patient or other person, determined by an individualized clinical assessment. |
| Privacy | § 171.202 | Withholding EHI is required by federal (HIPAA, 42 CFR Part 2) or state privacy law, or specific statutory preconditions (e.g., patient consent) have not been satisfied. | |
| Security | § 171.203 | Practice is tailored to protect the confidentiality, integrity, or availability of EHI against specific cybersecurity threats, consistent with organizational security policies. | |
| Infeasibility | § 171.204 | Actor cannot fulfill the request due to uncontrollable events (war, disaster, cyberattack), technical inability to segment data, or documented infeasibility under the circumstances. | |
| Health IT Performance | § 171.205 | Systems are temporarily unavailable due to planned maintenance, software upgrades, or performance degradation remediation. | |
| Exceptions that Involve Procedures for Fulfilling Requests | Content and Manner | § 171.301 | Actor fulfills request using alternative standard technical formats (e.g., FHIR APIs or USCDI formats) when unable to provide the exact technical manner requested. |
| Fees | § 171.302 | Actor charges objective, cost-based fees reasonably related to providing access, strictly excluding fees for electronic access via patient portals or standard APIs. | |
| Licensing | § 171.303 | Actor licenses interoperability software elements on fair, reasonable, and non-discriminatory (FRAND) terms. |
Enforcement and Penalties
- Developers and HIEs: Investigated by the HHS Office of Inspector General (OIG); subject to Civil Monetary Penalties of up to $1,000,000 per violation.
- Healthcare Providers: Under the CMS/OIG final rule, non-compliant providers face appropriate disincentives across Medicare programs, including zero scores in the MIPS Promoting Interoperability performance category and exclusion from the Medicare Shared Savings Program (MSSP) for at least one year.
Multi-Law Comparative Synthesis
| Dimension | 42 CFR Part 2 | GINA (Title I / II) | FERPA (34 CFR Part 99) | HIPAA Privacy Rule | Cures Act Info Blocking |
|---|---|---|---|---|---|
| Primary Scope | Specialized SUD treatment records | Genetic tests & family medical history | Student education & treatment records | Individually identifiable PHI | Electronic Health Information (EHI) |
| Primary Regulator | SAMHSA / HHS OCR | EEOC / HHS OCR | Department of Education (FPCO) | HHS Office for Civil Rights | ONC / HHS OIG / CMS |
| TPO Sharing Without Consent | Historically No; 2024 Rule permits single broad TPO consent | Prohibited for health plan underwriting | Prohibited without parental/student consent | Permitted without authorization (§ 164.506) | Mandated; withholding constitutes blocking |
| Individual Rights | Access, accounting, restriction (2024 Rule) | Protection against underwriting / job bias | Parental/student inspection & amendment | Access, amendment, accounting, restrictions | Immediate electronic access via portal/API |
CHPS Exam Tips and Common Traps
[!TIP] Exam Tip: The 'Preventing Harm' Standard Requires Physical Harm When an exam question involves withholding records under the Information Blocking 'Preventing Harm' exception (45 CFR § 171.201), remember that the risk must be physical harm to the patient or another individual. A physician's desire to withhold a bad prognosis (e.g., terminal cancer staging) simply to prevent emotional distress or anxiety does not qualify for the Preventing Harm exception unless the clinician documents a substantial risk of self-harm or physical violence.
[!WARNING] Candidate Trap: General Hospitals Receiving Part 2 Records When a general acute care hospital receives Part 2 SUD records pursuant to patient consent, those records do not suddenly lose their statutory protection. While the 2024 Final Rule permits re-disclosure for TPO if the patient executed a broad consent, the receiving hospital cannot use those records in any civil or criminal proceeding against the patient without a specialized Part 2 court order under Subpart E.
[!CAUTION] Candidate Trap: Assuming GINA Covers Life and Disability Policies A standard exam question presents an individual undergoing predictive genetic screening who is subsequently denied a $1,000,000 life insurance policy or long-term care policy based on BRCA2 positivity. Candidates incorrectly flag this as an illegal GINA violation. GINA Title I covers health insurance exclusively; life, disability, and long-term care underwriters are legally permitted to review and underwrite based on genetic data unless restricted by state insurance law.
A private university operates an on-campus student health center that provides primary medical care to enrolled undergraduate students. The health center also treats university staff and non-student neighborhood residents through an outpatient physical therapy annex. A county prosecutor issues an administrative subpoena requesting the medical records of both an undergraduate student and an administrative staff member. How must the university's privacy officer evaluate the legal frameworks governing these disclosures?
An employer sponsoring a self-insured ERISA group health plan requests genetic testing reports and multi-generational family cancer histories for all prospective executive candidates, intending to assess future medical claims risk prior to extending formal job offers. When the HR director seeks approval from the plan privacy officer, how must the privacy officer evaluate this request under federal law?
A hospital CIO configures the electronic health record system to withhold all automated releases of diagnostic pathology and laboratory reports to the patient portal for a mandatory period of 14 calendar days, arguing that ordering physicians require two weeks to review findings before patients view them. A patient files a complaint with the ONC. Under the 21st Century Cures Act Information Blocking Rule (45 CFR Part 171), how is this institutional policy evaluated?