Substance use disorder (SUD) treatment programs covered by 42 CFR Part 2 can email and share records, but each disclosure made with patient consent must carry a Part 2 notice, and recipients may redisclose only as the rule allows. Since February 16, 2026, breaches of unsecured Part 2 records follow the HIPAA breach notification rules. While encryption is not required, encrypted records are covered under a safe harbor exemption, which can prevent the need to notify the OCR Portal of a breach.
What is 42 CFR Part 2 and who does it cover?
42 CFR Part 2 protects the confidentiality of substance use disorder patient records. It applies to “Part 2 programs,” federally assisted programs that provide SUD diagnosis, treatment or referral for treatment, and to “lawful holders” that receive Part 2 records through patient consent or a statutory exception.
Part 2 is stricter than HIPAA in how records may be used and disclosed, and it binds recipients as well as the program that created the records. A behavioral health practice or small clinic that offers SUD treatment should confirm whether it meets the Part 2 program definition in 42 CFR 2.11 and 2.12(b).
What changed in the 2024 Part 2 final rule?
HHS published the final rule on February 16, 2024 (89 FR 12472). It took effect April 16, 2024, and programs had to comply by February 16, 2026. It allows a single consent for all future treatment, payment and health care operations disclosures, aligns redisclosure and penalties with HIPAA, and applies HIPAA breach notification to Part 2 records.
The HHS fact sheet states that the rule “applies the same requirements of the HIPAA Breach Notification Rule to breaches of records under Part 2” and aligns “Part 2 penalties with HIPAA by replacing criminal penalties currently in Part 2 with civil and criminal enforcement authorities.” The rule also adds a definition of SUD counseling notes, which require specific patient consent to disclose, and strengthens limits on using records in proceedings against patients.
Does 42 CFR Part 2 require encryption?
No. Part 2 does not name encryption or any other technology. Section 2.16(a) requires a Part 2 program or other lawful holder to “have in place formal policies and procedures to reasonably protect against unauthorized uses and disclosures of patient identifying information and to protect against reasonably anticipated threats or hazards to the security of patient identifying information.”
For electronic records, those policies must address creating, receiving, maintaining and transmitting records, destroying them (including sanitizing electronic media), controlling access, and de-identifying information. Encryption is one way a program can meet the transmission and access parts of those policies. Where the program is also a HIPAA covered entity, the Security Rule applies as well, with encryption as an addressable specification under 45 CFR 164.312(a)(2)(iv) and (e)(2)(ii).
How does breach notification work for Part 2 records?
Section 2.16(b) applies the HIPAA breach notification rules “to part 2 programs with respect to breaches of unsecured records in the same manner as those provisions apply to a covered entity with respect to breaches of unsecured protected health information.” Records encrypted consistent with HHS guidance are not unsecured, so their loss does not trigger notification.
Part 2 defines an unsecured record in the same terms HIPAA uses for unsecured PHI: a record not rendered “unusable, unreadable, or indecipherable to unauthorized persons” through a technology or method specified by the Secretary. HHS’s guidance names encryption consistent with NIST standards. Without that protection, a program faces the HIPAA notification timeline, including notice to affected individuals within 60 calendar days of discovery under 45 CFR 164.404(b).
What has to go with a Part 2 record sent by email?
Each disclosure made with the patient’s written consent must be accompanied by a written notice under 42 CFR 2.32(a) and by a copy of the consent or a clear explanation of its scope under 2.32(b). The short form of the notice reads: “42 CFR part 2 prohibits unauthorized use or disclosure of these records.”
The longer notice begins, “This record which has been disclosed to you is protected by Federal confidentiality rules (42 CFR part 2).” A program that emails records can carry the notice in the message body or in the attached record, alongside the consent. Encryption protects the message; the notice tells the recipient what it may do with the record.
| Requirement | Citation | Required? | How PreVeil supports it |
|---|---|---|---|
| Security policies and procedures | 42 CFR 2.16(a) | Required | Encrypted transmission and storage, and access limited to key holders, support the program’s policies |
| Breach notification for unsecured records | 42 CFR 2.16(b); 45 CFR 164.402, 164.404 | Required | Message contents, attachments and files encrypted end to end, with keys on user devices |
| Notice accompanying each consented disclosure | 42 CFR 2.32(a) | Required | Program’s responsibility; the notice travels inside the encrypted message |
| Copy or explanation of consent | 42 CFR 2.32(b) | Required | Consent document can be attached and encrypted end to end |
| Redisclosure limits | 42 CFR 2.33(b), (c) | Required | Program’s and recipient’s responsibility |
| Audit controls (covered entities) | 45 CFR 164.312(b) | Required | Admin console and system logs on the Business plan |
| Encryption (covered entities) | 45 CFR 164.312(a)(2)(iv), (e)(2)(ii) | Addressable | End-to-end encryption from the sender’s device |
Who can redisclose Part 2 records received by email?
Under 42 CFR 2.33(b), a covered entity or business associate that receives records for treatment, payment or health care operations “may further disclose those records in accordance with the HIPAA regulations,” except for use in proceedings against the patient. Other recipients are limited to what the consent allows, and lawful holders need written contracts with their contractors under 2.33(c).

Those limits make it important to know exactly who received a record. A program that sends records to a payer, a referring provider or a billing company benefits from an activity record. PreVeil’s admin console and system logs, on the Business plan, record user and administrator activity for the program’s review.
What agreement does a Part 2 program need with its email vendor?
A Part 2 program that is a HIPAA covered entity needs a business associate agreement (BAA) with any email vendor that stores or transmits its records, and PreVeil signs one. Part 2 also defines a qualified service organization, a service provider that enters a written agreement to be bound by Part 2 and to resist judicial efforts to obtain records.
HHS guidance treats a cloud provider that stores electronic PHI as a business associate “even if it does not hold a decryption key and therefore cannot view the information.” PreVeil also signs a qualified service organization agreement (QSOA) under 42 CFR Part 2.
How does PreVeil support Part 2 programs?
PreVeil encrypts message contents and attachments end to end on the sender’s device, inside Outlook, Gmail or Apple Mail, and encrypts files in PreVeil Drive the same way. PreVeil cannot access or decrypt a program’s records, because the encryption keys stay on users’ devices. PreVeil signs a BAA and a QSOA.
Other providers, payers and business associates that a program exchanges records with can read and reply for free from their browser. That fits common Part 2 exchanges, such as referrals and care coordination made with patient consent. PreVeil supports a program’s Part 2 policies; it does not replace the notice, consent or redisclosure steps the rule requires.
Frequently asked questions
When did the 2024 Part 2 rule take effect?
The final rule took effect April 16, 2024, and programs must comply beginning February 16, 2026.
Does HIPAA breach notification apply to Part 2 records?
Yes. Section 2.16(b) applies the HIPAA breach notification provisions to breaches of unsecured Part 2 records in the same manner as for unsecured PHI.
What notice must accompany a Part 2 disclosure?
Each disclosure made with written consent must carry a notice under 2.32(a), such as “42 CFR part 2 prohibits unauthorized use or disclosure of these records,” and a copy or clear explanation of the consent under 2.32(b).
Can PreVeil read Part 2 records sent through it?
No. PreVeil cannot access or decrypt message contents, attachments or files, because the encryption keys stay on users’ devices.
Sources
- Federal Register, Confidentiality of SUD Patient Records final rule, 89 FR 12472 (Feb 16, 2024)
- HHS, Fact sheet: 42 CFR Part 2 final rule
- 42 CFR 2.16, security for records (eCFR)
- 42 CFR 2.32, notice to accompany disclosure (eCFR)
- 42 CFR 2.33, uses and disclosures permitted with written consent (eCFR)
- 42 CFR 2.11, definitions (eCFR)
- 45 CFR 164.402, definitions (eCFR)
- 45 CFR 164.404, notification to individuals (eCFR)
- 45 CFR 164.312, technical safeguards (eCFR)
- HHS, Guidance to Render Unsecured PHI Unusable, Unreadable, or Indecipherable
- HHS, Guidance on HIPAA and cloud computing
How can a Part 2 program see where PreVeil fits?
A demo with PreVeil covers how it fits the program’s email and file sharing.