8.3 Part 2 and the 21st Century Cures Act

Key Takeaways

  • 42 CFR Part 2 still protects federally assisted substance use disorder records, but the February 8, 2024 HHS/SAMHSA/OCR final rule (compliance February 16, 2026) aligns many operations with HIPAA
  • A single patient consent now covers future TPO uses and disclosures, and a HIPAA covered entity or BA that receives Part 2 records under that consent may redisclose them under the HIPAA Rules
  • Part 2 remains stricter than HIPAA on use of records or testimony against the patient in legal proceedings, which still requires specific consent or a qualifying court order
  • The 21st Century Cures Act and 45 CFR Part 171 prohibit information blocking by providers, certified health IT developers, and HIEs/HINs, and ONC rules require patient access to EHI through standardized APIs
  • Interoperability is the default; privacy, preventing-harm, and infeasibility exceptions exist, but “HIPAA forbids sharing” is the wrong answer when HIPAA or a Part 2 TPO consent already permits the exchange
Last updated: August 2026

Why Part 2 Exists — and Why 2024 Changed the Mechanics

42 CFR Part 2 implements 42 U.S.C. 290dd-2. It protects records of the identity, diagnosis, prognosis, or treatment of a patient maintained in connection with a federally assisted program that provides substance use disorder (SUD) education, prevention, training, treatment, rehabilitation, or research. “Federally assisted” reaches a wide set of opioid treatment programs, specialty SUD clinics, and other programs that receive federal funds, tax-exempt status, or a DEA registration used to dispense controlled substances for SUD treatment. Confidentiality exists because fear of discrimination and prosecution keeps people out of care.

Historically, Part 2 was stricter than HIPAA in daily operations. A program generally needed patient consent for each disclosure, including many treatment and payment shares that HIPAA would have allowed as TPO. Recipients were told they could not redisclose without a new consent. CIPP/US candidates who still recite that world as current law will miss the 2024 reset.

On February 8, 2024, HHS — through the Substance Abuse and Mental Health Services Administration (SAMHSA) and OCR — issued a final rule modifying Part 2. The rule implements section 3221 of the Coronavirus Aid, Relief, and Economic Security (CARES) Act (March 27, 2020), which directed HHS to align specified Part 2 provisions with the HIPAA Rules and HITECH. The rule was published February 16, 2024, became effective April 16, 2024, and required compliance by February 16, 2026. HHS updated its fact sheet on January 30, 2026. Teach the aligned-but-not-identical regime that is now in force.

The 2024 Alignment — and What Still Differs

The operational centerpiece is consent. Part 2 now allows a single consent for all future uses and disclosures for treatment, payment, and health care operations. A HIPAA covered entity or business associate that receives Part 2 records under that consent may redisclose those records in accordance with the HIPAA regulations. That is the care-coordination change Congress ordered. A hospital, health plan, or HIE that is a HIPAA regulated entity no longer needs a fresh Part 2 consent for every TPO redisclosure of records it received under the new consent.

Alignment does not mean identity. HHS’s own footnote is the exam sentence: those records still cannot be used in legal proceedings against the patient without specific consent or a court order that meets Part 2 — a standard more stringent than HIPAA. Consent for use or disclosure in civil, criminal, administrative, or legislative proceedings cannot be combined with consent for any other purpose. SUD counseling notes — a clinician’s notes analyzing the conversation in an SUD counseling session that the clinician voluntarily keeps separate from the rest of the SUD and medical record — require their own consent and cannot ride on a broad TPO consent. That structure is analogous to HIPAA’s extra protection for psychotherapy notes.

Other 2024 alignments you should be able to name:

TopicCurrent Part 2 rule (post-2024 / compliance 2026)Still different from HIPAA?
TPO sharingOne consent can cover current and future TPO uses and disclosuresConsent is still the on-switch; HIPAA TPO does not require consent
RedisclosureHIPAA CEs/BAs may redisclose under HIPAA once they received the records under the TPO consentLegal-process use against the patient still needs specific consent or a Part 2 court order
Public healthDe-identified disclosures to public health authorities without patient consent, using HIPAA de-identification standardsIdentifiable public-health reporting is not a free-for-all
BreachHIPAA Breach Notification Rule applies to Part 2 recordsSame clocks and 500-person split; Part 2 calls affected people “patients”
PenaltiesCivil and criminal authorities that apply to HIPAA violations replace the old Part 2-only criminal schemeEnforcement posture is HIPAA-like, not a return to the pre-CARES criminal-only model
Patient rightsAccounting of disclosures and restriction requests, plus a right to complain to the Secretary; Patient Notice aligned with the HIPAA Notice of Privacy PracticesAccounting-of-disclosures compliance waits on the parallel HIPAA HITECH revision
SegmentationExpress statement that segregating or segmenting Part 2 records is not requiredPrograms may still segment as a control; the rule does not mandate a separate silo

Two protections HHS lists as unchanged: SUD treatment records cannot be used to investigate or prosecute the patient without written consent or a qualifying court order, and records obtained in an audit or evaluation of a Part 2 program cannot be used to investigate or prosecute patients without that consent or order. Investigative agencies get a safe harbor if they used reasonable diligence — checking SAMHSA’s treatment-facility locator and the provider’s Patient Notice or HIPAA Notice of Privacy Practices — before demanding records, and if they follow prescribed steps after discovering they received Part 2 records without the required order.

Scenario. A patient signs one Part 2 TPO consent at an opioid treatment program. The program sends the record to the patient’s HIPAA-covered health system. The health system may redisclose that record to a treating specialist and to the patient’s health plan under HIPAA TPO rules. If a prosecutor later demands the same record to charge the patient with possession, the health system still needs the patient’s specific consent or a Part 2 court order. The 2024 alignment does not convert Part 2 records into ordinary HIPAA litigation files.

The 21st Century Cures Act: Information Blocking and APIs

The 21st Century Cures Act (2016) made sharing electronic health information (EHI) the expected norm. ONC’s Cures Act Final Rule (2020) and 45 CFR Part 171 define information blocking as a practice by an actor that is likely to interfere with the access, exchange, or use of EHI, except as required by law or covered by an exception. Actors are health care providers, health IT developers of certified health IT, and health information exchanges / health information networks (HIEs/HINs).

Knowledge standards differ on purpose. Developers and HIEs/HINs are measured by whether they know or should know the practice is likely to interfere. Providers are measured by whether they know the practice is unreasonable and likely to interfere. Exceptions in Part 171 (preventing harm, privacy, security, infeasibility, health IT performance, content and manner, fees, licensing, and later TEFCA-manner and protecting-care-access additions) are voluntary safe harbors. Missing an exception is not automatic liability; ONC and the HHS Office of Inspector General (OIG) evaluate leftover practices case by case. Claims go to ONC’s information-blocking portal. ONC reviews possible certification non-conformities by developers; OIG may investigate all actor types. A 2024 HHS final rule sets disincentives for providers OIG finds to have committed information blocking (for example, effects on Medicare Promoting Interoperability scoring). Do not invent a single civil-penalty dollar figure for providers; Cures treated developers/HINs and providers differently, and the provider remedy is the disincentive rule.

Cures also pushed patient access through application programming interfaces (APIs). Certified health IT must support standardized APIs — in practice, Health Level Seven Fast Healthcare Interoperability Resources (HL7 FHIR) aligned with the United States Core Data for Interoperability (USCDI) — so a patient can pull EHI into an app of the patient’s choice without special effort. The information-blocking EHI definition expanded from the USCDI data elements (April 5, 2021 compliance posture) to all EHI on October 6, 2022. “Call the medical-records desk and wait 30 days for a CD” is the practice the API rules were written to make unnecessary for electronic copies the patient can get directly.

Interoperability Versus Privacy

This is the tension Domain II.B expects you to hold in one sitting. HIPAA’s right of access, HITECH’s electronic-copy rule, Cures’ anti-blocking rule, and ONC’s API certification criteria all push release. Part 2, HIPAA psychotherapy notes, SUD counseling notes, adolescent confidentiality, and proxy (parent or caregiver) portal access all push segmentation or delay. ONC has been explicit that the information-blocking regulations are designed to work with HIPAA, not to override it: a practice required by HIPAA or Part 2 is not information blocking, and the privacy exception is there for actors who deny access to comply with those laws.

The exam trap is using “privacy” as a blanket refusal when the law actually requires access. A health system that disables the patient-facing API because a competitor’s app might see ordinary TPO data, or that delays release of a lab result solely to force patients through the portal’s advertising, is in information-blocking territory. A health system that withholds a Part 2 record from a party who has no TPO consent and no court order, or that withholds SUD counseling notes absent the specific consent, is applying a privacy law Cures does not preempt. When a parent’s proxy access would expose an adolescent’s sensitive notes and the actor cannot segment, the privacy exception — not ad-hoc blocking — is the documented path.

Scenario. A certified EHR vendor charges a patient’s chosen third-party app a special “connection fee” that is not cost-based and is designed to steer patients to the vendor’s own app. That practice is aimed at certified API technology and is the kind of interference ONC’s information-blocking and API materials flag. Contrast a Part 2 program that refuses to send identifiable SUD records to a marketing analytics pixel: that refusal is required by Part 2 and HIPAA, not information blocking.

Exam traps

  • Do not teach pre-2024 Part 2 (consent for every TPO disclosure; no HIPAA redisclosure) as if the 2024 rule never happened. Compliance was required February 16, 2026.
  • Do not say Part 2 is now “just HIPAA.” Legal-process use against the patient, SUD counseling notes, and anti-prosecution limits remain SUD-specific.
  • Segmentation is not mandated; neither is dumping SUD records into a public portal without the right consent.
  • Information blocking is not limited to EHR vendors. Providers and HIEs/HINs are actors, with a different knowledge standard for providers.
  • “We are a HIPAA covered entity” is not a license to block patient API access to EHI the Privacy Rule already requires the entity to provide to the individual.
Loading diagram...
Part 2 Consent Versus Cures Information Blocking
Test Your Knowledge

A patient of a federally assisted opioid treatment program signs a single Part 2 consent covering future treatment, payment, and health care operations. The program sends the record to the patient’s HIPAA-covered hospital. What may the hospital do under the 2024 Part 2 final rule?

A
B
C
D
Test Your Knowledge

Which Part 2 protection did HHS identify as unchanged by the 2024 alignment?

A
B
C
D
Test Your Knowledge

A hospital disables third-party API connections so patients can obtain electronic copies of ordinary laboratory results only through the hospital’s own portal. No privacy law forbids releasing those results to the patient. How should a CIPP/US candidate analyze the practice?

A
B
C
D