Since February 16, 2026, OCR enforces 42 CFR Part 2 against substance-use-disorder programs directly — with HIPAA-level penalties. The first thing they request in any complaint or audit is your written risk analysis. Score yourself honestly against what they'll ask to see.
In an investigation, these are requested at the door. What you can't produce is itself the finding.
Knowing exactly who accessed which SUD record is the heart of Part 2.
The cloud EHR doesn't cover the network around it — you're liable for that.
The 2024 Final Rule items. Consent-form and notice wording are legal work — flag them to a healthcare attorney.
The findings anyone can see by walking your hallway.
OCR now takes complaints against Part 2 programs directly — a single unhappy patient or former employee is the trigger, not your size. And the agency rarely fines a facility for being breached; it fines them because the investigation shows there was no current risk analysis, no access logging, and no proof of remediation. The documentation is the defense. Build it before the letter arrives — you can't backdate it after.
I do a fixed-fee 42 CFR Part 2 & HIPAA readiness assessment for behavioral-health and SUD facilities — your policies, your EHR configuration, your network, and your physical safeguards — and hand you an audit-ready risk analysis and a prioritized fix-it plan your team can actually execute.
Book a 15-minute call: hello@part2ready.com · part2ready.com
Reflects the HIPAA Security Rule (45 CFR §164.308–312), 42 CFR Part 2 and its 2024 Final Rule (compliance date February 16, 2026), and the OCR Audit Protocol. Enforcement dates and rule status current as of publication — verify before relying.
Part2Ready is a practice of Trent Cyber Advisory, a technical security and compliance advisory practice. This checklist is an educational self-assessment, not legal advice; consent-form and notice language and final compliance determinations are the responsibility of the facility and its counsel. © 2026 Trent Cyber Advisory.