Issue #6: Health Privacy Changed in 2026 — What Providers Need to Know About Part 2
Most healthcare organizations have built their privacy programs around HIPAA. That foundation matters. But HIPAA is not the only federal confidentiality framework that can affect how sensitive patient information is handled.
As of February 16, 2026, organizations subject to updated federal requirements for substance use disorder records under 42 CFR Part 2 must comply with significant changes intended to align portions of Part 2 more closely with HIPAA. At the same time, the HHS Office for Civil Rights has begun accepting Part 2 complaints and breach reports under a new civil enforcement program.
For healthcare leadership, the practical issue is not simply that the regulation changed. The more useful question is whether Part 2-protected information enters the organization, how it moves through existing workflows, and whether current privacy practices account for the additional protections that may apply.
Top 4 Part 2 Issues to Watch
1. HIPAA-Compliant Handling Is Not Automatically Part 2-Compliant Handling
The updated rule brings Part 2 closer to HIPAA in several important areas. Patients can now provide a single consent for future uses and disclosures of Part 2 records for treatment, payment, and healthcare operations, and certain recipients may generally redisclose those records as permitted by HIPAA.
But Part 2 has not simply become HIPAA.
Important confidentiality protections remain, particularly around the use of substance use disorder records in civil, criminal, administrative, and legislative proceedings against a patient. In practice, a disclosure that appears routine under HIPAA may still require a closer look if Part 2 information is involved.
The organization needs a practical way to recognize when those additional restrictions apply and route the records accordingly.
2. Part 2 Exposure Can Extend Beyond the Treatment Program
Not every healthcare provider is a Part 2 program. The regulation principally applies to federally assisted programs that provide substance use disorder diagnosis, treatment, or referral for treatment.
However, Part 2 responsibilities do not necessarily end when information leaves the originating program. Qualified service organizations, lawful holders of Part 2 records, and other organizations or persons holding protected records may also have responsibilities under the regulation.
That makes applicability a record-flow question as much as an organizational-label question.
It is not enough to ask, “Are we a substance use disorder treatment program?” A more useful question is, “Do Part 2-protected records enter our environment, and if they do, where do they go?”
Without that visibility, an organization may be managing information subject to heightened confidentiality requirements without recognizing the distinction.
3. Privacy Classification Now Matters During Incident Response
Beginning February 16, 2026, OCR began accepting complaints alleging Part 2 violations and breach reports involving protected substance use disorder records. Civil enforcement mechanisms can include corrective action, settlements, and civil money penalties.
This moves Part 2 identification out of the realm of legal interpretation alone and into daily operations.
During an incident, the organization may need to determine what information was involved, where it originated, which privacy requirements apply, who must be notified, and which response process governs the event. Those decisions become much harder if the team does not know whether Part 2 records are present in the affected system.
A mature incident-response process should therefore account for what kind of health information is involved, not just whether PHI was exposed.
It is far better to establish privacy classification before an incident occurs than to reconstruct it after a complaint or breach has already created regulatory pressure.
4. Written Privacy Documentation Must Match Day-to-Day Operations
Part 2 readiness is not accomplished by updating a policy and placing it back on the shelf.
Organizations subject to the requirements should look at how protected records are identified, how consent is managed, who may access or disclose the information, how legal requests are handled, how incidents are escalated, and whether workforce members recognize when additional confidentiality protections apply.
The 2026 requirements also affect patient privacy notices. Part 2 programs have specific patient-notice obligations, while HIPAA covered healthcare providers and health plans that create or maintain Part 2 records have corresponding Notice of Privacy Practices requirements.
The key test is whether the written privacy program reflects what actually happens in daily operations.
A policy may say that Part 2 records receive appropriate protections. Leadership should also be able to show where those records exist, who handles them, what controls apply, and how exceptions are escalated. That operational evidence is what turns written compliance into defensible privacy governance.
How SecureHealth Can Help
Part 2 Applicability & Record-Flow Review – Evaluate where substance use disorder information enters, moves through, or is maintained within healthcare workflows, and identify areas that warrant closer review
Privacy Policy & Workflow Alignment – Review consent, use and disclosure, escalation, legal-request handling, and incident-response procedures against applicable privacy requirements
Administrative Readiness Support – Help privacy, records, clinical, and operational personnel understand when heightened confidentiality requirements may apply and how those responsibilities can be documented and managed
What to Do This Month
1. Determine Applicability: Identify whether your organization operates a Part 2 program or receives and maintains records that originated from one.
2. Map Part 2 Record Flows: Document where applicable records enter the organization, where they are stored, who can access them, and when they may be disclosed or redisclosed.
3. Test Current Privacy Procedures: Confirm that consent, legal-request handling, incident response, escalation, and patient-notice processes can account for Part 2 requirements when they apply
Final Thought
The 2026 Part 2 changes reinforce a practical privacy-management principle: healthcare information does not always carry the same legal requirements simply because it sits in the same EHR, inbox, document repository, or workflow.
Organizations that understand what sensitive information they hold, which requirements apply to it, and how those requirements show up in routine operations are better positioned to protect patients, respond appropriately when incidents occur, and demonstrate stronger privacy governance.
The goal is not to create another layer of paperwork. It is to ensure that sensitive information receives the protections the law requires throughout its lifecycle.