42 CFR Part 2
Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.
2024 final rule · HHS — Confidentiality of Substance Use Disorder Patient Records · published 2024-02-16
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
42 CFR Part 2 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; obligations not modelled as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Patient consent · Redisclosure · Notice of privacy practices · Breach notification · Enforcement
- Applies to
- healthcare · behavioral health · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- Compliance was required by 2026-02-16. OCR announced its civil enforcement program 2026-02-13 and began accepting complaints, breach notifications, and resolving noncompliance findings (resolution agreements, settlements, corrective actions, civil monetary penalties) starting 2026-02-16. This is now enforced, not upcoming. hhs.gov blocks automated fetch (403); corroborated via independent legal-industry sources.Expected: In force and enforced
03Version ledger
| Pre-2024 Part 2 | Superseded | date not published |
| 2024 final rule | Current edition · supersedes Pre-2024 Part 2 | 2024-02-16 |
05Change history
06Related frameworks
- Health Industry Cybersecurity Practices2023 edition
Also applies to healthcare · HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.
- HIPAA Breach Notification Rule45 CFR §§ 164.400–414
Also applies to healthcare · What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.
- Colorado AI ActSB 26-189
Also applies to healthcare · Colorado's AI law, rewritten. SB 26-189 repealed and reenacted the 2024 statute, dropping the high-risk-AI regime for narrower notice and disclosure duties on automated decision-making technology used in consequential decisions.
- HHS HPH Cybersecurity Performance GoalsCurrent HPH CPGs
Also applies to healthcare · HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.