Skip to main content
—
Framework library
Framework module · sud-records-42-cfr-part-2

42 CFR Part 2

Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.

2024 final rule · HHS — Confidentiality of Substance Use Disorder Patient Records · published 2024-02-16

Standing today
Directory entry

00Answer

from the registry record
What is 42 CFR Part 2?
Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.
Who does 42 CFR Part 2 apply to?
42 CFR Part 2 applies to healthcare, behavioral health, US, per HHS — Confidentiality of Substance Use Disorder Patient Records.
What is the current version of 42 CFR Part 2?
The current edition is 2024 final rule, issued by HHS — Confidentiality of Substance Use Disorder Patient Records and published 2024-02-16. Source: https://www.hhs.gov/hipaa/part-2/index.html.
What does an assessment under 42 CFR Part 2 require?
No control catalog has been ingested for 42 CFR Part 2 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

42 CFR Part 2 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; obligations not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Patient consent · Redisclosure · Notice of privacy practices · Breach notification · Enforcement
Applies to
healthcare · behavioral health · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
Compliance was required by 2026-02-16. OCR announced its civil enforcement program 2026-02-13 and began accepting complaints, breach notifications, and resolving noncompliance findings (resolution agreements, settlements, corrective actions, civil monetary penalties) starting 2026-02-16. This is now enforced, not upcoming. hhs.gov blocks automated fetch (403); corroborated via independent legal-industry sources.Expected: In force and enforced

03Version ledger

2 editions
Pre-2024 Part 2Supersededdate not published
2024 final ruleCurrent edition · supersedes Pre-2024 Part 22024-02-16

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.

  2. HIPAA Breach Notification Rule45 CFR §§ 164.400–414

    Also applies to healthcare · What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.

  3. Also applies to healthcare · Colorado's AI law, rewritten. SB 26-189 repealed and reenacted the 2024 statute, dropping the high-risk-AI regime for narrower notice and disclosure duties on automated decision-making technology used in consequential decisions.

  4. Also applies to healthcare · HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.

42 CFR Part 2 | ControlFrame