Key Takeaways: The 2024 Final Rule modernized 42 CFR Part 2 and aligned it with HIPAA. As of February 16, 2026, all Part 2 programs must comply, and OCR now administers and enforces both rules.
- Penalties run up to $2,190,294 per HIPAA violation and $1,538,970 per Part 2 violation
- OCR took over Part 2 enforcement on August 25, 2025, and announced its civil enforcement program on February 13, 2026
- Recent OCR settlements show mid-size SUD providers being penalized for risk analysis failures
- Billing workflows are a primary exposure point because PHI moves through every claim
- Consent forms, business associate agreements, workforce training, and email security are where the gaps usually sit
The rules for protecting substance use disorder patient records have changed. The compliance deadline has passed. The agency that enforces them has new authority. And the penalty exposure is the highest it has ever been. As of February 16, 2026, every Part 2 program in the country must comply with the modernized 42 CFR Part 2 rule. As of August 25, 2025, the HHS Office for Civil Rights administers and enforces it. The first SUD-provider enforcement action under the new framework came just three days after the compliance deadline. The exposure is real, the timeline is now, and many rehab operators are still evaluating how their billing workflows, consent processes, and vendor relationships align with the new requirements.
This is not abstract regulatory theory. This is the operational compliance environment every behavioral health and addiction treatment provider operates inside in 2026.
What Changed in 42 CFR Part 2 and Why It Matters in 2026
42 CFR Part 2 protects the confidentiality of substance use disorder patient records. It has been the foundational privacy law for SUD treatment since the 1970s, stricter than HIPAA in several respects and built around the principle that stigma around addiction should not deter patients from seeking care.
In February 2024, HHS published a Final Rule modernizing Part 2 under the CARES Act. The rule went into effect with a compliance deadline of February 16, 2026. Most operators are still catching up to what changed.
Five operational shifts matter most for rehab facilities:
- A single patient consent now authorizes future disclosures for treatment, payment, and healthcare operations.
- Part 2 breach notification requirements now align with the HIPAA Breach Notification Rule.
- Criminal penalties were replaced with HIPAA-style civil and criminal enforcement.
- A new category of SUD counseling notes was created, analogous to HIPAA psychotherapy notes.
- The segregation requirement for Part 2 records inside larger EHR systems was eliminated when records flow to a HIPAA-covered entity.
The practical consequence for rehab billing operations is that Part 2 and HIPAA now sit on the same enforcement chassis. A breach involving SUD records is now investigated, settled, and penalized by the same agency that handles HIPAA breaches, under aligned procedures and aligned penalty tiers.
OCR Is Now the Enforcer for SUD Patient Records
On August 25, 2025, the HHS Secretary formally delegated administration and enforcement of 42 CFR Part 2 to the Office for Civil Rights, the same agency that enforces HIPAA. On February 13, 2026, OCR announced its civil enforcement program for Part 2. Three days after the February 16 compliance deadline, OCR announced a HIPAA Security Rule settlement involving an SUD treatment provider under its broader Risk Analysis Initiative, reinforcing the agency’s focus on security compliance across behavioral health organizations.
This consolidation has three direct implications for rehab operators.
The first is that OCR brings serious enforcement infrastructure to Part 2. OCR can now investigate Part 2 violations, conduct compliance reviews and investigations, impose civil monetary penalties where authorized, and negotiate resolution agreements that may include corrective action plans. None of those enforcement tools existed under the old Part 2 framework.
The second is that OCR’s enforcement priorities under HIPAA now apply directly to SUD providers. The agency has been running a Risk Analysis Initiative since 2024, with twelve resolved enforcement actions targeting healthcare entities that failed to conduct accurate and thorough risk analyses. Behavioral health and SUD providers are no longer adjacent to that initiative. They are squarely inside it.
The third is that OCR has stepped up enforcement under the current administration. The agency settled thirteen HIPAA cases in 2025 through August alone, on top of sixteen in 2024 and fourteen in 2023. The enforcement environment is the most active it has been in years, and rehab providers now sit fully inside it.
The Penalties Are Significant and They Just Increased
On January 28, 2026, HHS published inflation-adjusted civil monetary penalties in the Federal Register. The increases apply to all violations occurring on or after November 2, 2015, with penalties assessed under the new amounts on or after January 28, 2026.
The maximum penalty for a single HIPAA violation is now $2,190,294. The maximum penalty for a 42 CFR Part 2 violation is $1,538,970. For certain violation categories, annual caps can reach $2,190,294 under the current inflation-adjusted schedule.
| Tier | Culpability | Penalty range per violation |
|---|---|---|
| Tier 1 | Lack of knowledge | $145 to $73,011 |
| Tier 2 | Reasonable cause | $1,461 to $73,011 |
| Tier 3 | Willful neglect, corrected within thirty days | $14,602 to $73,011 |
| Tier 4 | Willful neglect, not corrected | $73,011 to $2,190,294 |
HIPAA civil monetary penalty tiers as of January 28, 2026. Amounts are assessed per violation, so a single breach can compound across records and provisions.
The numbers above are per violation. A single breach involving multiple patient records can compound rapidly. A phishing attack that exposes the ePHI of two thousand patients may involve multiple compliance violations depending on the facts, affected records, and regulatory provisions implicated. Under the OCR enforcement framework, violations can be assessed across affected records, applicable provisions, and the duration of the underlying compliance failure.
Recent settlements give operators a real-world reference point. In February 2026, OCR settled with Top of the World Ranch Treatment Center, an Illinois SUD provider, for $103,000 after a 2023 phishing attack exposed the ePHI of 1,980 patients. OCR’s primary finding centered on deficiencies in the organization’s risk analysis process under the HIPAA Security Rule. The root finding was a failure to conduct an accurate and thorough risk analysis. The settlement was small relative to the statutory maximum, but the corrective action plan, ongoing monitoring, and reputational impact carry real operational cost.
The pattern matters more than any single dollar figure. OCR is targeting risk analysis failures specifically, settling cases that involve mid-size SUD and behavioral health providers, and prioritizing enforcement actions that signal to the rest of the industry what compliance looks like.
Why Billing Workflows Are a Primary Compliance Exposure
Protected health information does not sit still. It moves. Every claim submission, every benefit verification, every utilization review note, every payment posting, every collection letter, every clearinghouse handoff, every payer follow-up, every appeal package carries PHI through systems, vendors, and workflows.
For rehab facilities, the SUD-specific layer on top of HIPAA means that every billing-side interaction with a Part 2 record requires Part 2-compliant handling. The 2024 Final Rule simplified some of this through the single-consent framework, but it did not eliminate it. PHI generated by billing workflows is still subject to Part 2 protections wherever it originates from a Part 2 program.
The exposure points cluster in five recurring places.
- Patient consent forms that have not been updated to the 2024 Final Rule standard: Many facilities are still using pre-2024 consent language that does not authorize the broader treatment, payment, and operations disclosures the new rule allows. That is a compliance gap on the consent side and a workflow inefficiency on the billing side.
- Business associate agreements and vendor contracts that do not address Part 2: Billing vendors, clearinghouses, EHR providers, and revenue cycle partners all touch SUD records. Organizations should review BAAs and other applicable vendor agreements to ensure Part 2-related obligations, permitted disclosures, safeguards, and redisclosure requirements are appropriately addressed. Many do not.
- Workforce training that covers HIPAA but skips Part 2: Front-desk staff, intake teams, billers, and clinicians need to understand the additional Part 2 protections that apply to SUD records. Generic HIPAA training does not cover the consent, redisclosure, and notice requirements that Part 2 adds.
- Phishing and email compromise as the dominant breach vector: The recent OCR enforcement actions repeatedly trace back to phishing attacks on workforce email accounts. Billing teams, which routinely communicate with payers, patients, and clearinghouses by email, are prime targets.
- Risk analyses that exist on paper but do not reflect current operations: OCR’s Risk Analysis Initiative is settling cases against providers whose risk analyses are outdated, generic, or fail to map how ePHI actually flows through their systems. Billing workflow changes such as a new clearinghouse, a new EHR integration, or a new vendor relationship trigger the need to update the risk analysis.
What Rehab Operators Should Do Now
The Part 2 compliance deadline has passed. OCR enforcement is active. The penalty framework is fully operational. The defense has to be built immediately, not next quarter.
Six actions matter most:
- Update patient consent forms to reflect the 2024 Final Rule single-consent framework.
- Update the Notice of Privacy Practices to include Part 2 language using OCR’s model template.
- Conduct or update a risk analysis that maps how SUD records flow through clinical, billing, and administrative systems.
- Review and update business associate agreements with billing vendors, clearinghouses, and EHR providers to address Part 2.
- Train workforce members on the Part 2 layer in addition to HIPAA, with specific attention to billing and intake staff.
- Tighten email security and phishing defenses, since these are the primary breach vector in recent enforcement actions.
None of these actions are new compliance categories. They are baseline operational hygiene. What has changed is that the consequences of skipping them are now enforceable within an increasingly active OCR enforcement environment that has shown a growing focus on risk analysis, security controls, and behavioral health providers, against the highest inflation-adjusted penalty schedule the framework has ever supported. The operational discipline that holds a behavioral health revenue operation together applies as squarely to compliance as it does to revenue.
CodeMax works with rehab operators on the billing-workflow side of this compliance picture. Our billing infrastructure, business associate framework, and revenue cycle processes are designed to support organizations working to meet both Part 2 and HIPAA requirements through integrated operational workflows. While compliance ultimately depends on each organization’s policies, procedures, workforce practices, and legal obligations, operational alignment can help reduce risk and improve consistency.
Final Thoughts
The 2024 Final Rule made Part 2 enforceable in a way it never was before. The February 2026 compliance deadline closed the runway for catching up. OCR enforcement is active, penalty amounts are at all-time highs, and billing workflows are a primary exposure point because PHI moves through every claim. For rehab operators, this is not a once-a-year compliance project. It is an everyday operational reality.
Rebuilding billing and revenue cycle workflows to meet the modernized 42 CFR Part 2 standard? CodeMax provides the billing infrastructure, business associate framework, and operational discipline that integrates Part 2 and HIPAA compliance into daily revenue cycle operations. Explore CodeMax Billing & Claims Management.
Frequently Asked Questions
42 CFR Part 2 is a federal regulation protecting the confidentiality of substance use disorder patient records. It applies to federally assisted SUD treatment programs and lawful holders of records covered by the regulation, including clinics, hospitals, counseling centers, and most behavioral health providers receiving federal support.
HHS issued a Final Rule in February 2024 aligning Part 2 with HIPAA. Key changes include single-consent disclosures for treatment, payment, and operations, HIPAA-aligned breach notification, civil enforcement penalties, and a new category of SUD counseling notes. The compliance deadline was February 16, 2026.
As of January 28, 2026, the maximum penalty for a Part 2 violation is $1,538,970 per violation. HIPAA penalties range from $145 in Tier 1 to $2,190,294 in Tier 4 for willful neglect not corrected. Penalties can compound across records and provisions.
As of August 25, 2025, the HHS Office for Civil Rights administers and enforces 42 CFR Part 2. OCR is the same agency that enforces HIPAA. It can investigate violations, issue subpoenas, impose civil monetary penalties, and negotiate resolution agreements with corrective action plans.