30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

42 CFR Part 2: AI records and consent

Part 2 can add specific protections to substance-use-disorder records. Before an AI disclosure, identify the record’s origin and applicable consent or exception. A general HIPAA BAA does not replace Part 2 analysis, and broad treatment, payment and healthcare-operations consent does not cover separately maintained SUD counselling notes.

For SUD programme privacy officers and healthcare IT teams

Aona field notesC06
Two records can need different consent
Scope before disclosure

Separate the ordinary treatment record from protected SUD counselling notes.

General branch logic with a separate synthetic SUD programme case. No real consent, legal decision or provider approval is represented.

01

Identify which records and programme are involved

Part 2 concerns particular substance-use-disorder patient records, not every mention of mental health or alcohol in every organisation. The HHS fact sheet describes the statute’s protection for records maintained in connection with federally conducted, regulated or assisted SUD programmes or activities.

Ask where the record originated, the role of the programme and how the receiving organisation obtained it. A filename or automated data label cannot establish that legal status. Where the origin or restrictions are unclear, resolve them with the programme’s privacy owner before including the content in an AI input.

Source context: HHS: 42 CFR Part 2 final rule fact sheet

02

Use the current consent framework

HHS’s fact sheet, updated 30 January 2026, says compliance with the applicable final-rule requirements was required by 16 February 2026. The changes allow a single consent for future treatment, payment and healthcare-operations uses and disclosures, and certain HIPAA covered entities and business associates receiving records under that consent may redisclose them in accordance with HIPAA.

That is not unconditional permission to send a record to any AI provider. Check the actual consent, purpose, recipient and any restrictions, as well as the relevant HIPAA obligations. The fact sheet says disclosures with consent must include a copy of the consent or a clear explanation of its scope.

Source context: HHS: 42 CFR Part 2 final rule fact sheet

03

Separate SUD counselling notes

The final rule creates specific protection for an SUD clinician’s analysis of a counselling conversation that the clinician voluntarily maintains separately from the rest of the treatment and medical record. These SUD counselling notes require specific consent and cannot be used or disclosed on the basis of broad TPO consent.

Do not assume a combined export contains only the ordinary treatment record. Ask the source owner whether separately maintained notes, attachments or copied passages are included. The purpose of this check is to identify the applicable permission path, not to claim that Part 2 universally requires technical segregation of records.

Source context: HHS: 42 CFR Part 2 final rule fact sheet

04

Review the AI recipient and onward use

Identify the AI provider, application operator and other recipients. Determine the permitted service, data handling and relevant agreements. The fact sheet preserves stronger restrictions on using records in civil, criminal, administrative or legislative proceedings against patients without the necessary consent or court order.

Consent for those proceedings cannot be combined with consent for other uses, according to HHS’s summary. Keep that question distinct from ordinary care or administrative processing. A provider’s ability to store a consent flag does not show that the consent covers the proposed use or that all legal restrictions have been met.

Source context: HHS: 42 CFR Part 2 final rule fact sheet · HHS: Guidance on HIPAA and cloud computing

05

Keep a decision record that travels with the scope

The worked example below traces two fictional record types to different review paths. It includes a general administrative alternative that needs no patient material. The point is to identify the consent and recipient evidence, not to generate an approval automatically.

Retain the relevant scope explanation, decision owner and data-flow record through the approved process. Revisit them when the AI service, recipient or use changes. HHS also applies HIPAA breach-notification requirements to Part 2 breaches, so suspected exposure belongs with the organisation’s incident and privacy teams.

Source context: HHS: 42 CFR Part 2 final rule fact sheet

Put it into practice

Part 2 AI disclosure branch map

Follow each yes, no or unknown outcome before a protected record reaches an AI service. A separate fictional worked case is included in the download.

General branch logic with a separate synthetic SUD programme case. No real consent, legal decision or provider approval is represented.

An unknown answer changes the route
01

Scope

Yes: continue. No: review other duties. Unknown: stop and resolve.

02

Record type

Separate counselling note: specific consent. Ordinary record: applicable permission.

03

Permission

Established: review recipients. Unresolved: stop the upload.

04

Recipient

Complete: accountable decision. Incomplete: resolve before disclosure.

Part 2 AI disclosure branch map
QuestionFindingStop or next outcomeEvidence to retain
Part 2 applies to this record and source?YesContinue to record-type and permission checks.Record the programme and record-origin evidence.
Part 2 applies to this record and source?NoLeave this Part 2 branch; assess HIPAA and other applicable duties.No Part 2 finding is not an approval of the AI disclosure.
Part 2 applies to this record and source?UnknownStop the proposed patient-data upload and resolve origin/status.Ask the source programme or accountable privacy owner.
Separately maintained SUD counselling note?YesAssess specific consent; do not rely on broad TPO consent.Identify the actual note and consent scope.
Separately maintained SUD counselling note?NoAssess the permission applicable to the ordinary Part 2 record.Review actual consent or an applicable exception for this use.
Record type or consent/exception established?Unknown or unresolvedStop the proposed upload until the applicable permission is established.A BAA or tool label does not resolve this branch.
Applicable consent or exception established?YesContinue to recipient, disclosure-scope and other safeguards review.Include the consent copy or clear scope explanation where required.
Recipient and remaining conditions reviewed?No or unknownStop the proposed disclosure on this route; resolve the missing conditions.Map the AI service, connected recipients and applicable agreements.
Recipient and remaining conditions reviewed?YesThe accountable owner can record the scoped decision.This table does not itself grant legal permission or product approval.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

part2-ai-records-consent.mdInspect
# Part 2 AI disclosure branch map

General branch logic with a separate synthetic SUD programme case. No real consent, legal decision or provider approval is represented.

Follow each yes, no or unknown outcome before a protected record reaches an AI service. A separate fictional worked case is included in the download.

| Question | Finding | Stop or next outcome | Evidence to retain |
| --- | --- | --- | --- |
| Part 2 applies to this record and source? | Yes | Continue to record-type and permission checks. | Record the programme and record-origin evidence. |
| Part 2 applies to this record and source? | No | Leave this Part 2 branch; assess HIPAA and other applicable duties. | No Part 2 finding is not an approval of the AI disclosure. |
| Part 2 applies to this record and source? | Unknown | Stop the proposed patient-data upload and resolve origin/status. | Ask the source programme or accountable privacy owner. |
| Separately maintained SUD counselling note? | Yes | Assess specific consent; do not rely on broad TPO consent. | Identify the actual note and consent scope. |
| Separately maintained SUD counselling note? | No | Assess the permission applicable to the ordinary Part 2 record. | Review actual consent or an applicable exception for this use. |
| Record type or consent/exception established? | Unknown or unresolved | Stop the proposed upload until the applicable permission is established. | A BAA or tool label does not resolve this branch. |
| Applicable consent or exception established? | Yes | Continue to recipient, disclosure-scope and other safeguards review. | Include the consent copy or clear scope explanation where required. |
| Recipient and remaining conditions reviewed? | No or unknown | Stop the proposed disclosure on this route; resolve the missing conditions. | Map the AI service, connected recipients and applicable agreements. |
| Recipient and remaining conditions reviewed? | Yes | The accountable owner can record the scoped decision. | This table does not itself grant legal permission or product approval. |

## Review steps

- Confirm origin and record type: Ask the source programme whether Part 2 and the special SUD counselling-note provisions apply.
- Match consent to the use: Review the actual permission, scope explanation and any separate-consent requirement.
- Trace every recipient: Include AI services, connected features and processing intermediaries rather than assuming a BAA covers all of them.

## Separate fictional worked case

The following example is separate from the conditional branch map. It does not establish a real patient consent or legal decision.

| Decision | Invented case finding | Next action |
| --- | --- | --- |
| Does Part 2 apply? | The source owner identifies a fictional record as protected Part 2 material. | Use the Part 2 review path; document actual origin in a real case. |
| Is it a separately maintained SUD counselling note? | One attachment contains a clinician’s separately kept session analysis. | Do not rely on broad TPO consent for that attachment; assess specific consent. |
| What consent covers the ordinary record? | A TPO consent exists in the scenario, but the proposed recipient is not yet reviewed. | Check its scope and applicable disclosure/redisclosure conditions. |
| Who receives the AI input? | External AI service and its connected feature are proposed. | Map each recipient and its role, agreements and permitted use. |
| Could the task use no patient record? | Staff only need generic reception wording. | Use invented context and keep the protected records out of that task. |
| Can the real disclosure proceed? | Required consent and recipient questions remain open in the exercise. | Obtain the accountable review; the worksheet does not authorise disclosure. |

## Safe alternative prompt

Invented exercise: Write a general reception message about contacting a service team for administrative questions. Include no patient, SUD diagnosis, treatment history or counselling note.

HHS fact sheet updated 30 January 2026; applicable compliance date 16 February 2026.

## Source and scope

Guide: https://aona.ai/resources/guides/42-cfr-part-2-ai-records-consent/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- HHS: 42 CFR Part 2 final rule fact sheet: https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html
- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
Download part2-ai-records-consent.md
part2-ai-records-consent.csvInspect
Question,Finding,Stop or next outcome,Evidence to retain
Part 2 applies to this record and source?,Yes,Continue to record-type and permission checks.,Record the programme and record-origin evidence.
Part 2 applies to this record and source?,No,Leave this Part 2 branch; assess HIPAA and other applicable duties.,No Part 2 finding is not an approval of the AI disclosure.
Part 2 applies to this record and source?,Unknown,Stop the proposed patient-data upload and resolve origin/status.,Ask the source programme or accountable privacy owner.
Separately maintained SUD counselling note?,Yes,Assess specific consent; do not rely on broad TPO consent.,Identify the actual note and consent scope.
Separately maintained SUD counselling note?,No,Assess the permission applicable to the ordinary Part 2 record.,Review actual consent or an applicable exception for this use.
Record type or consent/exception established?,Unknown or unresolved,Stop the proposed upload until the applicable permission is established.,A BAA or tool label does not resolve this branch.
Applicable consent or exception established?,Yes,"Continue to recipient, disclosure-scope and other safeguards review.",Include the consent copy or clear scope explanation where required.
Recipient and remaining conditions reviewed?,No or unknown,Stop the proposed disclosure on this route; resolve the missing conditions.,"Map the AI service, connected recipients and applicable agreements."
Recipient and remaining conditions reviewed?,Yes,The accountable owner can record the scoped decision.,This table does not itself grant legal permission or product approval.
Download part2-ai-records-consent.csv
part2-fictional-worked-case.csvInspect
Decision,Invented case finding,Next action
Does Part 2 apply?,The source owner identifies a fictional record as protected Part 2 material.,Use the Part 2 review path; document actual origin in a real case.
Is it a separately maintained SUD counselling note?,One attachment contains a clinician’s separately kept session analysis.,Do not rely on broad TPO consent for that attachment; assess specific consent.
What consent covers the ordinary record?,"A TPO consent exists in the scenario, but the proposed recipient is not yet reviewed.",Check its scope and applicable disclosure/redisclosure conditions.
Who receives the AI input?,External AI service and its connected feature are proposed.,"Map each recipient and its role, agreements and permitted use."
Could the task use no patient record?,Staff only need generic reception wording.,Use invented context and keep the protected records out of that task.
Can the real disclosure proceed?,Required consent and recipient questions remain open in the exercise.,Obtain the accountable review; the worksheet does not authorise disclosure.
Download part2-fictional-worked-case.csv

Before you proceed

Keep these distinctions clear

HIPAA alignment is not complete equivalence
Part 2 retains distinct consent and legal-proceedings protections.
A combined file can cross a boundary
Check attachments and copied notes rather than treating the whole export as one permission category.

Apply it to employee AI use

Bring your actual data path.

Aona can support evaluation of sensitive-input policies for a selected employee application and input path.

It does not determine Part 2 status, validate patient consent or provide a legal authorisation to disclose.

Use a fictional note category and agree which input should be restricted, then record the actual result on the supported path.

Review your use case

FAQ

Questions for this decision

Does Part 2 apply to all mental-health information?
No. Assess the programme, record origin and applicable legal definitions. Do not classify every health-related text as Part 2 solely from a keyword.
Does an AI provider’s BAA replace Part 2 consent?
No. The BAA addresses the relevant HIPAA business-associate relationship. Part 2 consent, permitted disclosure and any separate protections must be assessed for the actual record and use.
Can broad TPO consent cover SUD counselling notes?
HHS says the separately maintained SUD counselling notes defined by the final rule require specific consent and cannot be used or disclosed on the basis of a broad TPO consent.
Is the 2026 compliance date still in the future?
No. HHS’s updated fact sheet states that persons subject to the regulation must comply with applicable final-rule requirements by 16 February 2026. Review current obligations rather than presenting this as a future preparation deadline.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. HHS: 42 CFR Part 2 final rule fact sheet

    Part 2 applicability, consent and redisclosure changes, separate SUD counselling notes and the 16 February 2026 compliance date; fact sheet updated 30 January 2026.

    regulator · checked 2026-09-21
  2. HHS: Guidance on HIPAA and cloud computing

    Business-associate roles, BAAs, risk analysis and cloud-service safeguards, including providers without decryption keys.

    regulator · checked 2026-09-21
42 CFR Part 2: AI records and consent | Aona