42 CFR Part 2 Enforcement: What Behavioral Health Practices Need to Change

Federal civil enforcement now applies when behavioral health practices violate 42 CFR Part 2.

For starters, 42 CFR Part 2 protects records identifying patients receiving substance use disorder (SUD) diagnosis, treatment, or referral through federally assisted behavioral health programs.

The Office for Civil Rights (OCR) now accepts Part 2 complaints and breach reports. OCR can pursue settlements, corrective action plans, and civil money penalties under HIPAA's enforcement framework.

As a result, behavioral health practices must protect SUD information shared through calls, texts, voicemail, user accounts, and message archives. They cannot use or disclose these records in proceedings against a patient unless the patient consents or a court issues a qualifying order.

Which begs the question? 

What must behavioral health practices change to ensure compliance? 

We'll answer that question and more in this article. 

We'll also explain how iPlum provides behavioral health practices with a secure communication system to protect patient information and carry out their compliance policies.

Table of Contents

1. Does 42 CFR Part 2 apply to every behavioral health practice?

2.Why calls, texts, and voicemail require a Part 2 review

3. What should behavioral health practices change for Part 2 compliance?

4. How iPlum brings Part 2 communication policies into daily work

5. Protect Part 2 patient communication with iPlum

Does 42 CFR Part 2 apply to every behavioral health practice?

No. Part 2 applies when a behavioral health provider meets two conditions.

First, the provider must present itself as providing—and provide—SUD diagnosis, treatment, or referral. A Part 2 program can be:

  • An independent practitioner who provides SUD treatment
  • An identified SUD unit within a general medical facility
  • Medical personnel whose primary function involves SUD diagnosis, treatment, or referral

Second, the program must receive federal assistance. Federal assistance can include Medicare participation, federal funding, federal licensing or certification, qualifying Drug Enforcement Administration registration, or federal tax-exempt status.

Therefore, a therapist does not enter Part 2 solely because a patient discusses substance use during other treatment. Emergency personnel also do not qualify solely because they treat an overdose or make a referral.

However, mixed behavioral health practices should examine how they describe and structure their SUD services. A center that advertises addiction counseling, accepts Medicare, and assigns identified clinicians to SUD treatment can operate a Part 2 program.

Part 2 duties can also follow records after disclosure. Covered entities, business associates, qualified service organizations, intermediaries, and other lawful holders can acquire duties after receiving them. 

Therefore, a practice should identify which services qualify, which records come from its Part 2 program, and who can legally receive them.

Why calls, texts, and voicemail require a Part 2 review

Part 2 protects more than formal medical charts. Its definition of a record includes information that a Part 2 program creates, receives, or acquires about an SUD patient. The regulation names emails, voicemail, and texts as examples.

Thus, a short communication can reveal protected information. 

For instance, a routine appointment text can indicate that a patient is receiving SUD treatment. Likewise, a voicemail can expose medication details, while a notification preview can reveal a message on a shared personal phone.

Calls require review, too. 

A call recording, transcript, voicemail, intake note, or callback request can create an electronic Part 2 record. Even the program's name on the caller ID can reveal the patient's relationship with an SUD provider.

Therefore, practices should examine the full communication process. The review should identify:

  • Who sends and receives patient messages
  • Which devices and accounts can access them
  • What information appears in notifications
  • Where calls, texts, and voicemail are stored
  • Who can download or forward records
  • When archived communication is deleted

The practice can then set rules that protect SUD information from creation to deletion.


What should behavioral health practices change for Part 2 compliance?

Identifying the records that Part 2 protects is only the first stage. In addition, a behavioral health practice must turn that information into rules for daily patient communication.

42 CFR Part 2 requires programs and lawful holders to establish formal policies and procedures that reasonably protect patient information from unauthorized use, disclosure, and security threats.

For calls, texts, and voicemail, those policies should address the following changes.

1. Move SUD communication onto approved professional lines

While Part 2 does not specifically require a separate business number, personal lines make it difficult to manage SUD communication.

For example, patient texts and voicemail can remain on personal phones, synchronized computers, cloud backups, and notification logs. The practice can also lose access to those records after a clinician leaves.

Therefore, behavioral health practices should assign approved professional numbers to clinicians who communicate with Part 2 patients. Written policies should state:

  • Which number clinicians must use
  • Which communication methods patients can use
  • When personal texting is prohibited
  • Who monitors incoming calls and messages
  • What happens after a phone is lost or replaced
  • When the practice must revoke a user's access

A separate professional line gives the practice an approved channel where it can apply consent, permissions, archiving, and disclosure rules.

2. Update consent and redisclosure procedures

The updated rule allows a patient to sign a single consent form for future uses and disclosures related to treatment, payment, and health care operations.

Even so, consent must identify the information, the authorized discloser, the recipients or recipient classes, and the purpose. Practices must also record the patient's right to revoke consent in writing.

Once a patient revokes consent, the practice cannot make new disclosures under that permission. However, the revocation does not reverse disclosures that the practice already made in reliance on valid consent.

Some disclosures still require separate consent. 

For example, a practice cannot combine consent for legal proceedings with consent for another purpose. SUD counseling notes also require specific consent.

Furthermore, a disclosure made with consent must include a copy of the consent or an explanation of its scope. The recipient must receive the required Part 2 redisclosure notice as well.

3. Limit identifying information in routine messages

An appointment reminder can reveal a patient’s relationship with an SUD program. 

The same problem can occur when a voicemail mentions medication, a diagnosis, or the full name of an addiction treatment center.

Therefore, practices should create neutral message templates. A reminder can state that the practice is calling about an appointment and ask the patient to return the call. It does not need to name the treatment, medication, or clinician’s specialty.

During intake, verify the patient’s phone number and record their communication preferences. Ask if the practice can leave voicemail, send text messages, or use a secure portal.

Clinicians should also confirm the recipient’s identity before discussing treatment details. Meanwhile, encryption protects message transmission. 

4. Apply role-based account permissions

42 CFR Part 2 permits internal communication among personnel who need patient information for duties related to SUD diagnosis, treatment, or referral. It does not give all personnel unrestricted access.

Thus, practices should create individual user accounts and assign permissions according to job duties. For example, reception personnel can receive scheduling messages but do not need access to counseling discussions or medication information.

Administrators should review permissions after role changes, device loss, contract termination, or departure. They should also disable old accounts promptly and restrict who can view, download, forward, or delete archived conversations.

Shared accounts weaken accountability because the practice cannot determine who opened or sent a message.

5. Review vendor agreements beyond the HIPAA BAA

A phone or messaging provider that receives, stores, or processes Part 2 records can qualify as a business associate, qualified service organization, or another lawful holder.

The correct classification depends on the practice, the vendor’s services, and how the vendor uses the records.

A HIPAA Business Associate Agreement remains necessary when HIPAA applies. Even so, the practice should determine if the agreement also contains the Part 2 terms required for the vendor relationship.

For a qualified service organization, the written agreement must acknowledge that the vendor is bound by Part 2 when managing patient records. It must also address requests for patient information during legal proceedings.

Also, review subcontractors, permitted disclosures, security duties, breach reporting, record return, and destruction before sending SUD information through the service.

6. Set archiving, retention, and deletion rules

Part 2 does not establish a single retention period for all calls, texts, and voicemails. Behavioral health practices must determine which federal, state, licensing, payer, and contractual requirements apply to their records.

Nevertheless, Part 2 requires written procedures for creating, receiving, maintaining, transmitting, and destroying electronic records. Communication archives should follow a documented retention schedule.

The practice should define:

  • Which messages enter the archive
  • Who can search or export conversations
  • How long the practice retains them
  • When legal or clinical requirements prevent deletion
  • How the system permanently deletes expired records

Clinicians must still transfer diagnoses, medication instructions, treatment decisions, and follow-up actions into the electronic health record. A communication archive provides a record of the conversation, but it does not replace the clinical chart.

7. Update breach, complaint, notice, and training procedures

Part 2 programs must report breaches of unsecured Part 2 records. According to the HHS breach-reporting requirements, breaches affecting 500 or more patients must be reported no later than 60 days after discovery.

Smaller breaches require notice within 60 days after the end of the calendar year in which the practice discovered them.

Practices must also create a process for receiving patient complaints. They cannot intimidate, threaten, discriminate against, or retaliate against a patient who files one.

Finally, update the Part 2 patient notice and publish it on any practice website that describes patient services or benefits. Part 2 programs that are also HIPAA-covered entities can create a combined notice that meets both requirements. HHS provides updated model privacy notices.

Training should then use real communication scenarios, such as a message sent to the wrong number, a lost phone, an unauthorized archive export, or a voicemail left for the wrong recipient.


How iPlum brings Part 2 communication policies into daily work

After defining consent, access, messaging, archiving, and incident rules, a practice needs an approved system to apply them.

iPlum adds a professional line to existing smartphones, together with encrypted calling, secure texting, voicemail, permissions, and archiving.

Let’s unpack that.

Separate SUD communication from personal phone use

An iPlum secure second line provides clinicians with a dedicated business number on their existing smartphones.

Therefore, the practice can direct SUD communication through an approved number, preserve it after a clinician leaves, and reduce the amount of patient information in personal accounts.

Protect patient calls, texts, and voicemail

iPlum provides HIPAA-compliant calling, encrypted texting, and secure voicemail. With iPlum, patients can join secure text conversations through a free iPlum account, mobile app, or app-less portal.

That said, clinicians must still verify the recipient, use neutral message language, and obtain any consent Part 2 requires. iPlum secures the channel; it does not authorize the disclosure.

Give authorized users appropriate access

An iPlum business account lets administrators create individual accounts and modify user privileges. Administrators can:

  • Assign a professional number to an authorized user
  • Set profile and account permissions
  • Share selected lines with approved users
  • Reassign a line after a departure
  • End access after a role change or lost device

These controls allow the practice to apply its role-based access policy to calls, texts, voicemail, and shared lines.

Archive communication under a defined policy

iPlum offers text archiving and backup. Administrators can review business messages during an internal investigation and apply the practice’s retention schedule.

Still, the practice must decide how long to retain records and when deletion is legally permitted.

Clinicians must also transfer diagnoses, treatment decisions, medication instructions, and follow-up actions into the electronic health record. The archive does not replace the clinical chart.

Put the correct vendor agreements in place

iPlum provides a signed Business Associate Agreement for its HIPAA service. The agreement governs how iPlum manages electronic protected health information under HIPAA.

Still, a BAA does not automatically settle every Part 2 requirement. 

The practice must determine if iPlum acts as a business associate, qualified service organization, or another lawful holder for its use of the service. It must then obtain any additional Part 2 contractual terms required for that relationship.

The point is, iPlum provides the communication system. 

The practice remains responsible for consent, patient notices, message content, retention decisions, breach reporting, complaint procedures, training, and clinical documentation.


Protect Part 2 patient communication with iPlum

OCR enforcement makes informal communication practices harder to defend. 

Behavioral health practices must know which services fall under Part 2, route SUD conversations to approved channels, document valid consent, restrict user access, review vendor contracts, set retention rules, and prepare for complaints and breaches.

iPlum gives clinicians a separate professional line for encrypted calling, secure texting, voicemail, permissions, and archiving.

Get in touch with iPlum to create a secure communication system that puts your Part 2 and HIPAA policies into daily practice and provides clinicians with an approved professional channel.

Contact iPlum

Tags
No items found.
Download Our APP Now!