8.3 Part 2 and the 21st Century Cures Act
Key Takeaways
42 CFR Part 2 still protects federally assisted substance use disorder records, but the February 8, 2024 HHS/SAMHSA/OCR final rule (compliance February 16, 2026) aligns many operations with HIPAA
A single patient consent now covers future TPO uses and disclosures, and a HIPAA covered entity or BA that receives Part 2 records under that consent may redisclose them under the HIPAA Rules
Part 2 remains stricter than HIPAA on use of records or testimony against the patient in legal proceedings, which still requires specific consent or a qualifying court order
The 21st Century Cures Act and 45 CFR Part 171 prohibit information blocking by providers, certified health IT developers, and HIEs/HINs, and ONC rules require patient access to EHI through standardized APIs
Interoperability is the default; privacy, preventing-harm, and infeasibility exceptions exist, but “HIPAA forbids sharing” is the wrong answer when HIPAA or a Part 2 TPO consent already permits the exchange
Why Part 2 Exists — and Why 2024 Changed the Mechanics
42 CFR Part 2 implements 42 U.S.C. 290dd-2. It protects records of the identity, diagnosis, prognosis, or treatment of a patient maintained in connection with a federally assisted program that provides substance use disorder (SUD) education, prevention, training, treatment, rehabilitation, or research. “Federally assisted” reaches a wide set of opioid treatment programs, specialty SUD clinics, and other programs that receive federal funds, tax-exempt status, or a DEA registration used to dispense controlled substances for SUD treatment. Confidentiality exists because fear of discrimination and prosecution keeps people out of care.
Historically, Part 2 was stricter than HIPAA in daily operations. A program generally needed patient consent for each disclosure, including many treatment and payment shares that HIPAA would have allowed as TPO. Recipients were told they could not redisclose without a new consent. CIPP/US candidates who still recite that world as current law will miss the 2024 reset.
On February 8, 2024, HHS — through the Substance Abuse and Mental Health Services Administration (SAMHSA) and OCR — issued a final rule modifying Part 2. The rule implements section 3221 of the Coronavirus Aid, Relief, and Economic Security (CARES) Act (March 27, 2020), which directed HHS to align specified Part 2 provisions with the HIPAA Rules and HITECH. The rule was published February 16, 2024, became effective April 16, 2024, and required compliance by February 16, 2026. HHS updated its fact sheet on January 30, 2026. Teach the aligned-but-not-identical regime that is now in force.
The 2024 Alignment — and What Still Differs
The operational centerpiece is consent. Part 2 now allows a single consent for all future uses and disclosures for treatment, payment, and health care operations. A HIPAA covered entity or business associate that receives Part 2 records under that consent may redisclose those records in accordance with the HIPAA regulations. That is the care-coordination change Congress ordered. A hospital, health plan, or HIE that is a HIPAA regulated entity no longer needs a fresh Part 2 consent for every TPO redisclosure of records it received under the new consent.
Alignment does not mean identity. HHS’s own footnote is the exam sentence: those records still cannot be used in legal proceedings against the patient without specific consent or a court order that meets Part 2 — a standard more stringent than HIPAA. Consent for use or disclosure in civil, criminal, administrative, or legislative proceedings cannot be combined with consent for any other purpose. SUD counseling notes — a clinician’s notes analyzing the conversation in an SUD counseling session that the clinician voluntarily keeps separate from the rest of the SUD and medical record — require their own consent and cannot ride on a broad TPO consent. That structure is analogous to HIPAA’s extra protection for psychotherapy notes.
Other 2024 alignments you should be able to name:
| Topic | Current Part 2 rule (post-2024 / compliance 2026) | Still different from HIPAA? |
|---|---|---|
| TPO sharing | One consent can cover current and future TPO uses and disclosures | Consent is still the on-switch; HIPAA TPO does not require consent |
| Redisclosure | HIPAA CEs/BAs may redisclose under HIPAA once they received the records under the TPO consent | Legal-process use against the patient still needs specific consent or a Part 2 court order |
| Public health | De-identified disclosures to public health authorities without patient consent, using HIPAA de-identification standards | Identifiable public-health reporting is not a free-for-all |
| Breach | HIPAA Breach Notification Rule applies to Part 2 records | Same clocks and 500-person split; Part 2 calls affected people “patients” |
| Penalties | Civil and criminal authorities that apply to HIPAA violations replace the old Part 2-only criminal scheme | Enforcement posture is HIPAA-like, not a return to the pre-CARES criminal-only model |
| Patient rights | Accounting of disclosures and restriction requests, plus a right to complain to the Secretary; Patient Notice aligned with the HIPAA Notice of Privacy Practices | Accounting-of-disclosures compliance waits on the parallel HIPAA HITECH revision |
| Segmentation | Express statement that segregating or segmenting Part 2 records is not required | Programs may still segment as a control; the rule does not mandate a separate silo |
Two protections HHS lists as unchanged: SUD treatment records cannot be used to investigate or prosecute the patient without written consent or a qualifying court order, and records obtained in an audit or evaluation of a Part 2 program cannot be used to investigate or prosecute patients without that consent or order. Investigative agencies get a safe harbor if they used reasonable diligence — checking SAMHSA’s treatment-facility locator and the provider’s Patient Notice or HIPAA Notice of Privacy Practices — before demanding records, and if they follow prescribed steps after discovering they received Part 2 records without the required order.
Scenario. A patient signs one Part 2 TPO consent at an opioid treatment program. The program sends the record to the patient’s HIPAA-covered health system. The health system may redisclose that record to a treating specialist and to the patient’s health plan under HIPAA TPO rules. If a prosecutor later demands the same record to charge the patient with possession, the health system still needs the patient’s specific consent or a Part 2 court order. The 2024 alignment does not convert Part 2 records into ordinary HIPAA litigation files.
The 21st Century Cures Act: Information Blocking and APIs
The 21st Century Cures Act (2016) made sharing electronic health information (EHI) the expected norm. ONC’s Cures Act Final Rule (2020) and 45 CFR Part 171 define information blocking as a practice by an actor that is likely to interfere with the access, exchange, or use of EHI, except as required by law or covered by an exception. Actors are health care providers, health IT developers of certified health IT, and health information exchanges / health information networks (HIEs/HINs).
Knowledge standards differ on purpose. Developers and HIEs/HINs are measured by whether they know or should know the practice is likely to interfere. Providers are measured by whether they know the practice is unreasonable and likely to interfere. Exceptions in Part 171 (preventing harm, privacy, security, infeasibility, health IT performance, content and manner, fees, licensing, and later TEFCA-manner and protecting-care-access additions) are voluntary safe harbors. Missing an exception is not automatic liability; ONC and the HHS Office of Inspector General (OIG) evaluate leftover practices case by case. Claims go to ONC’s information-blocking portal. ONC reviews possible certification non-conformities by developers; OIG may investigate all actor types. A 2024 HHS final rule sets disincentives for providers OIG finds to have committed information blocking (for example, effects on Medicare Promoting Interoperability scoring). Do not invent a single civil-penalty dollar figure for providers; Cures treated developers/HINs and providers differently, and the provider remedy is the disincentive rule.
Cures also pushed patient access through application programming interfaces (APIs). Certified health IT must support standardized APIs — in practice, Health Level Seven Fast Healthcare Interoperability Resources (HL7 FHIR) aligned with the United States Core Data for Interoperability (USCDI) — so a patient can pull EHI into an app of the patient’s choice without special effort. The information-blocking EHI definition expanded from the USCDI data elements (April 5, 2021 compliance posture) to all EHI on October 6, 2022. “Call the medical-records desk and wait 30 days for a CD” is the practice the API rules were written to make unnecessary for electronic copies the patient can get directly.
Interoperability Versus Privacy
This is the tension Domain II.B expects you to hold in one sitting. HIPAA’s right of access, HITECH’s electronic-copy rule, Cures’ anti-blocking rule, and ONC’s API certification criteria all push release. Part 2, HIPAA psychotherapy notes, SUD counseling notes, adolescent confidentiality, and proxy (parent or caregiver) portal access all push segmentation or delay. ONC has been explicit that the information-blocking regulations are designed to work with HIPAA, not to override it: a practice required by HIPAA or Part 2 is not information blocking, and the privacy exception is there for actors who deny access to comply with those laws.
The exam trap is using “privacy” as a blanket refusal when the law actually requires access. A health system that disables the patient-facing API because a competitor’s app might see ordinary TPO data, or that delays release of a lab result solely to force patients through the portal’s advertising, is in information-blocking territory. A health system that withholds a Part 2 record from a party who has no TPO consent and no court order, or that withholds SUD counseling notes absent the specific consent, is applying a privacy law Cures does not preempt. When a parent’s proxy access would expose an adolescent’s sensitive notes and the actor cannot segment, the privacy exception — not ad-hoc blocking — is the documented path.
Scenario. A certified EHR vendor charges a patient’s chosen third-party app a special “connection fee” that is not cost-based and is designed to steer patients to the vendor’s own app. That practice is aimed at certified API technology and is the kind of interference ONC’s information-blocking and API materials flag. Contrast a Part 2 program that refuses to send identifiable SUD records to a marketing analytics pixel: that refusal is required by Part 2 and HIPAA, not information blocking.
Exam traps
- Do not teach pre-2024 Part 2 (consent for every TPO disclosure; no HIPAA redisclosure) as if the 2024 rule never happened. Compliance was required February 16, 2026.
- Do not say Part 2 is now “just HIPAA.” Legal-process use against the patient, SUD counseling notes, and anti-prosecution limits remain SUD-specific.
- Segmentation is not mandated; neither is dumping SUD records into a public portal without the right consent.
- Information blocking is not limited to EHR vendors. Providers and HIEs/HINs are actors, with a different knowledge standard for providers.
- “We are a HIPAA covered entity” is not a license to block patient API access to EHI the Privacy Rule already requires the entity to provide to the individual.
A patient of a federally assisted opioid treatment program signs a single Part 2 consent covering future treatment, payment, and health care operations. The program sends the record to the patient’s HIPAA-covered hospital. What may the hospital do under the 2024 Part 2 final rule?
Nothing without a brand-new Part 2 consent for every specialist and payer, because redisclosure is still categorically forbidden
Use the record in a criminal prosecution of the patient, because HIPAA TPO now overrides Part 2’s court-order requirement
Redisclose the record for HIPAA-permitted TPO purposes; a separate specific consent or Part 2 court order is still required to use the record against the patient in a legal proceeding
Post the identifiable record to a public health dashboard without de-identification, because the 2024 rule eliminated all Part 2 consent
Which Part 2 protection did HHS identify as unchanged by the 2024 alignment?
Every TPO disclosure still requires a one-time-use, recipient-specific consent form
Part 2 programs must physically segregate SUD records from the rest of the designated record set
Business associates remain outside Part 2 and HIPAA enforcement for SUD records
SUD treatment records still cannot be used to investigate or prosecute the patient without written patient consent or a court order that meets Part 2
A hospital disables third-party API connections so patients can obtain electronic copies of ordinary laboratory results only through the hospital’s own portal. No privacy law forbids releasing those results to the patient. How should a CIPP/US candidate analyze the practice?
It is required by the HIPAA Security Rule, which forbids any API access to ePHI
It is required by 42 CFR Part 2, which automatically covers every hospital lab result
It is the kind of interference with access, exchange, or use of EHI that the 21st Century Cures Act and 45 CFR Part 171 address as information blocking, unless a regulatory exception applies
It is always lawful because Cures Act information blocking applies only to health IT developers, never to health care providers
Sections you finish are checked off in the contents.