Healthcare privacy in the United States is not governed by one law. Most patient information falls under HIPAA, but records related to substance use disorder (SUD) treatment are covered by a second, older, and in several ways stricter federal regulation: 42 CFR Part 2. Organizations that provide or touch SUD treatment services, including behavioral health clinics, integrated health systems, and the technology vendors that serve them, need to understand where the two frameworks overlap and where they diverge.
Here is the core distinction in one sentence: HIPAA broadly governs how health information can be used and disclosed across the healthcare system, while 42 CFR Part 2 imposes stricter, consent-centered protections specifically on records that would identify someone as having sought or received substance use disorder treatment from a federally assisted program.
This article compares the two frameworks side by side: what each covers, who must comply, how consent works, what happens on redisclosure, and how the 2024 final rule brought them closer together.
The Two Frameworks at a Glance
HIPAA (the Health Insurance Portability and Accountability Act of 1996) is implemented through the Privacy, Security, and Breach Notification Rules at 45 CFR Parts 160 and 164. It is administered and enforced by the HHS Office for Civil Rights (OCR). HIPAA applies to covered entities (health plans, healthcare clearinghouses, and most healthcare providers) and their business associates.
42 CFR Part 2 ("Part 2") implements the federal SUD confidentiality statute, 42 U.S.C. 290dd-2. It is administered by the Substance Abuse and Mental Health Services Administration (SAMHSA) within HHS. Part 2 dates to federal confidentiality laws of the 1970s, decades before HIPAA, and exists for a specific reason: fear that treatment records could be used against patients (in prosecutions, custody disputes, employment, housing) discourages people from seeking addiction treatment at all.
That origin explains the design difference. HIPAA permits many disclosures without patient authorization, most notably for treatment, payment, and healthcare operations (TPO). Part 2 historically required specific written patient consent for nearly every disclosure, even between treating providers.
Side-by-Side Comparison
| Dimension | HIPAA (45 CFR Parts 160/164) | 42 CFR Part 2 |
|---|---|---|
| What it protects | Protected health information (PHI): virtually all individually identifiable health information | SUD records: records that would identify a person as having applied for, participated in, or received SUD diagnosis, treatment, or referral from a Part 2 program |
| Who must comply | Covered entities and business associates | Federally assisted Part 2 programs, plus recipients of Part 2 records who receive notice of the protections (including lawful holders) |
| Default posture | Permits use and disclosure without authorization for TPO and other enumerated purposes | Disclosure generally prohibited without written patient consent, with narrow exceptions |
| Consent model | Authorization required only for uses outside permitted categories | Written consent required; since the 2024 final rule, a single consent can cover all future TPO uses |
| Redisclosure | Recipients who are not covered entities or business associates are generally outside HIPAA | Records disclosed with consent must carry a notice restricting redisclosure (42 CFR 2.32) |
| Use in legal proceedings | PHI can be obtained through subpoenas and court processes under Privacy Rule conditions | Records cannot be used or disclosed in civil, criminal, administrative, or legislative proceedings against the patient absent consent or a special court order under Part 2's court order provisions |
| Breach notification | HIPAA Breach Notification Rule (45 CFR 164.400 et seq.) | Aligned to HIPAA-style breach notification by the 2024 final rule |
| Enforcement | OCR; civil money penalties in tiers, criminal referral to DOJ | Historically criminal penalties; the CARES Act aligned Part 2 enforcement with HIPAA's civil and criminal penalty framework |
| Penalty structure | Tiered civil penalties based on culpability, criminal penalties for knowing violations | Now referenced to the same HIPAA civil and criminal penalty authorities |
Scope: What Records Are Actually Covered
The most common compliance mistake is assuming Part 2 covers all mental health or all addiction-related information anywhere in healthcare. It does not.
Part 2 applies to records created or received by a Part 2 program: a federally assisted individual, entity, or identified unit within a general medical facility that holds itself out as providing, and does provide, SUD diagnosis, treatment, or referral for treatment. "Federally assisted" is interpreted broadly (it includes, for example, programs with DEA registration to dispense controlled substances for SUD treatment, tax-exempt status, or federal funding), so most treatment providers qualify.
By contrast, a primary care physician who notes a patient's alcohol use in a general medical record is typically governed by HIPAA alone, not Part 2, because the practice does not hold itself out as an SUD program. The same clinical fact can be a Part 2 record in one setting and ordinary PHI in another. The setting and source, not the diagnosis alone, determine the framework.
HIPAA, meanwhile, covers essentially all individually identifiable health information held by covered entities and business associates, including Part 2 records when held by an entity subject to both frameworks. When both apply, the organization must satisfy both, which in practice means following the stricter Part 2 requirement wherever the two conflict.
Consent: The Defining Difference
Under HIPAA's Privacy Rule, a hospital can share your records with another treating physician, bill your insurer, and run internal quality operations without ever asking you to sign an authorization. Those TPO disclosures are permitted by regulation.
Under Part 2, the default has always been the opposite: written patient consent before disclosure, with the consent form itself required to contain specific elements listed in 42 CFR 2.31 (we detail every element in our companion guide to 42 CFR Part 2 consent requirements).
The 2024 final rule narrowed this gap significantly. Implementing Section 3221 of the CARES Act, HHS and SAMHSA now allow a patient to sign a single consent covering all future uses and disclosures for treatment, payment, and healthcare operations. Once given, TPO consent brings Part 2 record sharing much closer to the HIPAA workflow, though the consent itself is still required (unlike HIPAA, where no authorization is needed for TPO at all), and patients retain the right to revoke it. For the full picture of what changed, see our summary of the 42 CFR Part 2 final rule.
Redisclosure and Legal Protections
Two Part 2 features have no true HIPAA equivalent:
- The redisclosure notice. Under 42 CFR 2.32, each disclosure made with patient consent must be accompanied by a written notice stating that the records are protected by federal confidentiality rules and restricting further disclosure. HIPAA imposes no comparable notice obligation on authorized disclosures.
- Protection in proceedings. Part 2 records generally cannot be used against the patient in civil, criminal, administrative, or legislative proceedings without patient consent or a court order issued under Part 2's own heightened standards. This protection against use in legal proceedings, reinforced by the CARES Act amendments to 42 U.S.C. 290dd-2, is the heart of why Part 2 exists: patients should not fear that entering treatment creates evidence against them.
Penalties and Enforcement After the CARES Act
Historically, Part 2 violations carried criminal fines under a separate statute, and enforcement was rare. HIPAA violations, by contrast, are enforced by OCR through a tiered civil money penalty structure, with criminal penalties available for knowing violations under 42 U.S.C. 1320d-6.
The CARES Act changed this by aligning Part 2 enforcement with HIPAA's civil and criminal enforcement authorities, and the 2024 final rule implemented that alignment. Practically, this raises the stakes: Part 2 violations are now subject to the same kind of enforcement machinery that has produced substantial HIPAA settlements, and Part 2 breaches now trigger HIPAA-style breach notification duties.
What This Means for Patient Communication and Texting
For organizations that communicate with patients by SMS, the dual framework has direct operational consequences. A general appointment reminder program governed by HIPAA alone is one design problem; messaging patients of an SUD treatment program is another, because the mere fact that a message links a person to a Part 2 program can itself be protected information. Consent management, message content discipline, and vendor safeguards all carry extra weight, which we cover in depth in our guide to 42 CFR Part 2 texting rules.
At the platform level, the baseline is the same as for any sensitive health messaging: a vendor that supports HIPAA compliance, signs a Business Associate Agreement, encrypts data, and gives the organization control over consent and content. Our HIPAA-compliant text messaging pillar guide covers those requirements, and our healthcare solutions page shows how FRANSiS applies them for providers.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
Is 42 CFR Part 2 stricter than HIPAA?
In most respects, yes. Part 2's default rule is that SUD records cannot be disclosed without written patient consent, while HIPAA permits many disclosures (including treatment, payment, and operations) without any authorization. Part 2 also restricts redisclosure by recipients and blocks use of records against patients in legal proceedings. The 2024 final rule narrowed the gap for TPO disclosures but did not eliminate Part 2's stricter baseline.
Does 42 CFR Part 2 apply to all mental health records?
No. Part 2 applies specifically to records from federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral. General mental health records, and SUD-related notes made by providers who are not Part 2 programs (such as a primary care doctor), are typically governed by HIPAA and applicable state law instead.
Can a provider covered by both HIPAA and Part 2 follow just one?
No. An organization subject to both must comply with both, and where the frameworks differ, the effect is that the stricter requirement controls the conduct. In practice this usually means HIPAA policies form the base and Part 2's consent, redisclosure notice, and proceedings protections are layered on for SUD records.
Who enforces 42 CFR Part 2?
SAMHSA administers the regulation, and following the CARES Act and the 2024 final rule, enforcement is aligned with HIPAA's civil and criminal penalty framework under HHS. The HHS Office for Civil Rights handles HIPAA enforcement, and the 2024 rulemaking was issued jointly through HHS with OCR and SAMHSA coordination.
What changed between Part 2 and HIPAA in the 2024 final rule?
The February 2024 final rule, implementing CARES Act Section 3221, aligned Part 2 more closely with HIPAA: a single patient consent can now cover all future treatment, payment, and healthcare operations disclosures; breach notification follows the HIPAA model; penalties reference HIPAA's enforcement authorities; and patients gained HIPAA-style rights such as an accounting of certain disclosures.
Communicate Carefully Across Both Frameworks with FRANSiS
FRANSiS supports HIPAA compliance for healthcare SMS programs, with a signed BAA included, encrypted data handling, and consent-first messaging workflows managed with help from an AI Powered Helper. If your organization handles sensitive treatment populations and needs texting that respects both HIPAA and Part 2 obligations, contact the FRANSiS team to talk through your requirements.


