All articles

September 7, 2026

U.S. Rehab Privacy: What 2026–26 HIPAA and Part 2 Changes Mean

U.S. Rehab Privacy: What 2026–26 HIPAA and Part 2 Changes Mean

Rehab and substance use disorder records are protected under HIPAA (45 CFR Parts 160 and 164), and for federally assisted treatment programs, under the stricter 42 CFR Part 2. Disclosure without your consent is narrow: medical emergencies, a Part 2-specific court order, or limited mandatory reporting like child abuse. The 2024 Part 2 final rule and the February 16, 2026 Notice of Privacy Practices deadline are changing how consent and disclosure tracking actually work.


TL;DR:

  • Federal assistance, federal licensing, or drug treatment specialization typically triggers Part 2 protections even if the program also follows HIPAA.
  • Providers can generally deny record disclosures without patient consent unless there’s a court order, emergency, or mandatory reporting requirement.
  • The new 2024 rule simplifies consent with a combined treatment, payment, and operations authorization, but shifting responsibility to patients to understand what they sign.
  • Electronic health records must implement granular data segmentation to prevent SUD information from being disclosed unlawfully inside shared systems.
  • Stricter state laws can add protections beyond federal rules, so patients should confirm both federal and local confidentiality requirements at intake.

Sylmartreatmentcenter
Discuss Recovery Care With Confidence
Sylmar Treatment Center provides compassionate, personalized addiction and mental health care in an intimate, supportive six-bed setting.
Explore Sylmar Treatment Center

Table of Contents

What’s the Difference Between HIPAA and 42 CFR Part 2?

HIPAA sets a national floor for protecting health information across nearly every doctor, hospital, and insurer in the country. It covers your records, but it allows disclosure for routine treatment, payment, and operations without asking you each time.

Part 2 is narrower and tougher. It applies specifically to programs that are “federally assisted” and that hold themselves out as providing substance use disorder diagnosis, treatment, or referral. Where HIPAA might let a hospital share your chart with an insurer, Part 2 restricts even confirming that you’re a patient at all, unless you consent or a court order meets Part 2’s specific standard.

To figure out which law governs your records:

  • Ask the intake staff directly whether the program is a Part 2 program.
  • Check the Patient Notice or Notice of Privacy Practices you received at admission.
  • Look for federal funding, tax-exempt status, or federal licensing tied to the facility, since any of those can trigger Part 2 status.

Which Rehab Programs Count as Part 2 Programs?

Not every treatment provider falls under Part 2. It applies to programs that meet federal-assistance criteria and hold themselves out as treating substance use disorders. Here’s how that plays out in practice:

  1. Federally assisted programs. Any program receiving federal funds, Medicare or Medicaid certification, a federal tax exemption, or authorization from a federal agency (like DEA registration to dispense controlled substances) generally qualifies.
  2. Specialized SUD treatment settings. Detox units, residential rehab facilities, and outpatient counseling programs that identify SUD treatment as a service they provide are the clearest examples.
  3. General medical providers offering SUD services. A hospital or primary care practice that has a dedicated SUD treatment unit may be a Part 2 program for that unit specifically, even if the rest of the facility only follows HIPAA.

If you’re unsure, SAMHSA’s treatment locator is a practical starting point for confirming what a program advertises itself as, and the Patient Notice a facility gives you at intake should spell out its Part 2 status in plain language.

When Can Someone Legally Access Your SUD Records?

Providers can’t hand over SUD treatment records just because someone asks, even a family member or a police officer with a badge. The exceptions are specific and few:

  • Written patient consent, which under the current rule can be a single consolidated authorization for treatment, payment, and operations rather than a separate form for every use.
  • A Part 2-specific court order, which requires a judge to find good cause after weighing your privacy interest against the public need for disclosure. A standard subpoena or search warrant does not meet this bar on its own.
  • Medical emergencies, where a treating provider needs information to respond to a bona fide threat to your health.
  • Crimes on program premises or against program staff, which programs may report to law enforcement without violating Part 2.
  • Mandatory reporting required by state law, such as suspected child abuse or neglect.

Law enforcement access is deliberately hard to get. Legal guidance on Part 2 confirms that officers seeking your records generally must show they exercised “reasonable diligence” to obtain a proper Part 2 court order rather than relying on an ordinary subpoena, and providers can lawfully decline to even confirm you’re a patient absent that order or your consent.

What Rights Do You Have Over Your Own Records?

You’re not a passive subject of these rules. You have real, exercisable rights, and knowing them changes how you interact with any treatment program.

  • Right to access. You can request and receive copies of your own treatment records.
  • Right to an accounting of disclosures. You can ask a program to list who received your information and when, a right the 2024 final rule strengthened.
  • Right to give specific or broader consent. You can authorize a single provider or use the newer combined treatment, payment, and operations consent, though psychotherapy and counseling notes usually get extra protection beyond a general authorization.
  • Right to revoke consent or request restrictions. You can withdraw permission at any time going forward, and you can ask a provider to limit certain disclosures.

Pro Tip: Ask for a copy of every consent form you sign at intake, and write down the date. If you ever revoke consent, you’ll want a paper trail showing exactly what you agreed to and when it ended.

The 2024 final rule is the biggest shift to SUD confidentiality law in decades, and it’s built around aligning Part 2 with HIPAA rather than replacing it. The centerpiece is the treatment, payment, and operations (TPO) consent, which lets you sign one authorization covering routine care coordination instead of a separate form for every provider involved in your treatment.

That convenience comes with fine print worth knowing:

  • Once you sign a TPO consent, your information can be redisclosed to other HIPAA covered entities and business associates involved in your care, though additional limits still apply to court and law enforcement disclosures.
  • Breach notification for Part 2 records now largely tracks HIPAA’s breach rules, meaning programs must notify you under similar timelines and thresholds if your data is compromised.
  • Providers face real technical challenges tracking and segmenting Part 2 data inside shared electronic health record systems, so ask how a facility actually separates your SUD records from your general medical chart.

Every covered program has to update its Notice of Privacy Practices to reflect these changes by February 16, 2026. When you get a new or revised notice from any provider, read the SUD-specific language rather than skimming it.

How Do You Protect Your Privacy When Entering Rehab?

Confidentiality protections only work if you use them. A few deliberate moves at intake and throughout treatment make a real difference.

  1. Ask directly if the program is a Part 2 program and request a copy of the Patient Notice before you sign anything.
  2. Name specific recipients on any consent form rather than signing a blanket authorization, and add an expiration date if the form allows it.
  3. Keep your own file of every consent and revocation you sign, separate from what the facility keeps.
  4. Use your accounting-of-disclosures right periodically to confirm your records went only where you authorized.
  5. Handle employer and insurance requests carefully. An employer generally cannot get your SUD records directly from a rehab facility without your written authorization, and if you’re using FMLA leave for treatment, your employer typically only needs enough documentation to confirm eligibility, not your clinical file.

Pro Tip: If your insurer requests records for a claim, ask the facility exactly what information the authorization covers before you sign. Insurers often only need billing codes and dates of service, not full clinical notes.

What Happens If Your Records Are Breached or Disclosed Illegally?

Breach notification for Part 2 records now mirrors HIPAA’s framework, so if your information is exposed, the program generally has to notify you within a defined window and report larger breaches to federal regulators.

Unlawful disclosure carries real teeth. Violations can trigger civil penalties against the program and, in cases of willful or knowing disclosure, criminal penalties for the individuals responsible. That liability is a strong institutional incentive to lock down access controls in the first place.

If you believe your records were improperly disclosed:

  • File a complaint with the HHS Office for Civil Rights, which enforces both HIPAA and Part 2 violations.
  • Notify your state’s health licensing board if the facility is state licensed.
  • Contact SAMHSA if the violation involves a federally funded program directly.

How Do Accredited Providers Actually Protect Your Records?

The rules only matter if a facility actually builds them into daily operations. Look for concrete signals rather than a general promise of privacy.

Sylmar Treatment Center holds a DHCS license and Joint Commission accreditation, and its six-bed setting limits how many staff members ever handle your file. That small footprint matters for confidentiality in a way a 100-bed facility structurally can’t replicate.

What that should look like in practice at any accredited program: a clear Patient Notice at intake, documented consent procedures before any disclosure, secure electronic recordkeeping, and a working process for handling an accounting-of-disclosures request. If you’re navigating a legal requirement alongside treatment, resources on court-directed placement documentation can help you understand what gets shared with courts and what stays protected.

Does State Law Add Extra Protection Beyond HIPAA?

Yes, and this is where a lot of readers get tripped up. HIPAA and Part 2 set a federal floor, not a ceiling. States are free to layer on stricter privacy protections, and many do, particularly around mental health records, minors’ treatment records, and HIV status.

When a state law is stricter than HIPAA or Part 2, the stricter standard generally controls. That means a California facility, for instance, may have additional state confidentiality requirements around minors’ consent to treatment or specific state-mandated reporting exceptions that don’t exist federally. A New York provider might face different rules on release-of-information forms than a Texas one does.

This layering creates real friction for multi-state providers and for patients who move between states during care. A program licensed in one state and coordinating with a provider in another has to satisfy both the stricter state rule and the federal baseline, which is part of why consent forms at accredited facilities can look more detailed than a simple one-page authorization.

Practically, this means two things for you as a patient. First, don’t assume a rule you read about federally is the whole story. Ask the facility directly whether your state imposes additional consent requirements, especially if you’re a minor, if HIV status is part of your treatment record, or if you’re coordinating care across state lines. Second, understand that stricter state protections don’t weaken your federal rights under Part 2 or HIPAA. They add to them. A facility’s Notice of Privacy Practices should reflect both layers, and if it only cites federal rules with no mention of state-specific provisions, that’s worth asking about directly.

How Should Rehab Facilities Secure Electronic Health Records?

Paper charts locked in a filing cabinet used to be the whole story. Now, most SUD treatment records live in electronic health record systems, and that shift creates both convenience and risk that HIPAA’s Security Rule and Part 2 both address.

The baseline technical safeguards look similar to what you’d expect at any HIPAA covered entity: encryption of data at rest and in transit, role-based access controls so only staff directly involved in your care can open your file, and audit logs that track exactly who accessed your record and when. For Part 2 programs specifically, that access control has to go further, since even confirming your presence in the system requires the same consent protections as disclosing clinical details.

Electronic health record privacy safeguards

The harder technical problem accredited providers are wrestling with right now is segmentation, keeping SUD-specific data separately flagged inside a shared EHR system so it doesn’t get swept up in a routine HIPAA disclosure that wouldn’t be permitted under Part 2’s stricter standard. This is one of the practical implementation challenges providers are actively working through as the 2024 final rule takes effect, since older EHR systems weren’t built with that kind of granular flagging in mind.

For patients, the practical question to ask a facility isn’t abstract. Ask how your SUD records are flagged inside their system, whether staff outside your direct care team can see your diagnosis or treatment notes, and what happens technically if a routine medical records request comes in from another provider. A facility that can answer specifically, rather than gesturing at “we’re HIPAA compliant,” is one that has actually built the segmentation Part 2 requires rather than bolted it on as an afterthought.

How Should Rehab Staff Be Trained on Confidentiality Rules?

Confidentiality protections are only as strong as the staff member answering the phone. A facility can have a flawless written policy and still leak information because a front desk employee didn’t know a caller claiming to be a family member wasn’t authorized to receive any confirmation at all.

Effective training for rehab staff on HIPAA and Part 2 has to go beyond a one-time onboarding module. New hires need to understand the specific difference between HIPAA’s routine disclosure allowances and Part 2’s stricter consent requirement before they ever answer a phone call or email asking about a client. That distinction, that Part 2 protects even the fact that someone is a patient, trips up staff more than any other rule, since it runs against the instinct to be helpful to a worried parent or employer calling in.

Practical training should cover a few recurring scenarios specifically: how to respond when someone calls asking to confirm a person is in treatment, what documentation is required before releasing any information to a court, how to recognize when a request is actually a routine subpoena versus a proper Part 2 court order, and how to log every disclosure so the facility can produce an accurate accounting if a patient requests one. Staff also need refreshers when the underlying rules change, and the 2024 final rule’s TPO consent mechanism is exactly the kind of update that requires retraining rather than assuming staff will absorb it passively.

The facilities that do this well tend to build confidentiality training into regular case conferences and supervision, not just an annual compliance checkbox. Ask a program directly how often staff are trained on Part 2 specifically, not just general HIPAA compliance, and how new hires are onboarded before they have any contact with patient information.

How Should Rehab Staff Be Trained on Confidentiality Rules? — overview diagram

How Do Treatment Teams Share Information Without Violating Part 2?

Modern SUD treatment rarely involves just one provider. A typical client might see a medical doctor for detox, a therapist for individual counseling, a psychiatrist for medication management, and a case manager coordinating aftercare, and every one of those roles needs some information to do their job well.

The 2024 final rule’s TPO consent was built partly to solve this exact coordination problem. Before the update, care teams often needed separate signed consent for every single provider touching a case, which slowed down coordination and sometimes meant a psychiatrist prescribing medication didn’t know about a recent relapse a counselor was tracking. The consolidated consent now lets a patient authorize their full internal care team at once for treatment, payment, and operations purposes, which is meaningfully different from authorizing disclosure to an outside party like an employer or an ex-spouse.

That said, research on the tension between confidentiality and collaborative care makes clear this isn’t a free pass to share everything with everyone on staff. Information should still flow on a need-to-know basis inside a treatment team. A psychiatrist managing medication doesn’t necessarily need the same level of detail from individual counseling notes that a primary therapist does, and best practice keeps that segmentation intact even under a single consolidated consent.

Practically, patients should ask how a facility’s internal team actually shares information: whether it’s a shared chart with role-based access, verbal case conferences with limited written detail, or something in between. If you’re coordinating outside the immediate treatment team, for instance sharing information with an insurer for billing coordination like the coding and coverage guidance partner resources cover, that’s a separate disclosure requiring its own scoped consent, not an extension of your internal care team’s authorization.

Why the Real Risk Isn’t the Law, It’s the Paperwork

The legal protections around SUD records are genuinely strong, arguably stronger than protections for most other health conditions, and that’s by design. HHS built Part 2 to be strict specifically because fear of discrimination keeps people out of treatment, and a law with real teeth was the policy answer.

Where I think most people get the wrong idea is assuming the risk lives in some dramatic scenario, a rogue employee selling records, or police storming a facility with a routine warrant. That’s not where breaches actually happen. The real vulnerability is administrative: a blanket consent form signed without reading it, a facility that hasn’t updated its Notice of Privacy Practices ahead of the February 2026 deadline, an EHR system that hasn’t properly segmented SUD flags from the rest of a shared medical record.

The TPO consent change is a net positive for patients who want coordinated care without ten separate signatures, but it shifts more responsibility onto you to read what you’re authorizing rather than assuming a single generic form protects you the way five specific ones used to. If there’s one thing worth prioritizing over everything else in this article, it’s asking pointed questions at intake rather than trusting a boilerplate form. A facility that answers those questions specifically and confidently is telling you something real about how it operates.

— Jim

Ready for Private, Accredited Care? Here’s What to Expect

A reputable treatment center is built around confidentiality that actually matches what the law requires, not just a policy on paper. An intimate setting means your file passes through a small, consistent care team rather than a rotating cast of staff, and every admission starts with a clear Patient Notice explaining exactly how your consent and disclosure rights work under HIPAA and Part 2.

Sylmartreatmentcenter

Care here is licensed by the DHCS and accredited by the Joint Commission, covering individualized treatment planning, dual diagnosis support, and court-directed placements for anyone navigating a legal requirement alongside treatment. If you or someone you love needs a private, accredited place to start, reach out to admissions any time and ask directly how consent and confidentiality work before committing to treatment. You can review the full range of residential and detox programs or contact the Sylmar Treatment Center admissions team today to talk through your options and what privacy protections apply to your specific situation.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

Admissions Available 24/7

Help starts with one conversation.

Our admissions team is available 24/7 to assist families, referral partners, and individuals seeking immediate support. No judgment — just help.

Call (818) 438-7746