Compliance decisions
42 CFR Part 2: AI records and consent
Part 2 can add specific protections to substance-use-disorder records. Before an AI disclosure, identify the record’s origin and applicable consent or exception. A general HIPAA BAA does not replace Part 2 analysis, and broad treatment, payment and healthcare-operations consent does not cover separately maintained SUD counselling notes.
For SUD programme privacy officers and healthcare IT teams
Separate the ordinary treatment record from protected SUD counselling notes.
General branch logic with a separate synthetic SUD programme case. No real consent, legal decision or provider approval is represented.01
Identify which records and programme are involved
Part 2 concerns particular substance-use-disorder patient records, not every mention of mental health or alcohol in every organisation. The HHS fact sheet describes the statute’s protection for records maintained in connection with federally conducted, regulated or assisted SUD programmes or activities.
Ask where the record originated, the role of the programme and how the receiving organisation obtained it. A filename or automated data label cannot establish that legal status. Where the origin or restrictions are unclear, resolve them with the programme’s privacy owner before including the content in an AI input.
Source context: HHS: 42 CFR Part 2 final rule fact sheet
02
Use the current consent framework
HHS’s fact sheet, updated 30 January 2026, says compliance with the applicable final-rule requirements was required by 16 February 2026. The changes allow a single consent for future treatment, payment and healthcare-operations uses and disclosures, and certain HIPAA covered entities and business associates receiving records under that consent may redisclose them in accordance with HIPAA.
That is not unconditional permission to send a record to any AI provider. Check the actual consent, purpose, recipient and any restrictions, as well as the relevant HIPAA obligations. The fact sheet says disclosures with consent must include a copy of the consent or a clear explanation of its scope.
Source context: HHS: 42 CFR Part 2 final rule fact sheet
03
Separate SUD counselling notes
The final rule creates specific protection for an SUD clinician’s analysis of a counselling conversation that the clinician voluntarily maintains separately from the rest of the treatment and medical record. These SUD counselling notes require specific consent and cannot be used or disclosed on the basis of broad TPO consent.
Do not assume a combined export contains only the ordinary treatment record. Ask the source owner whether separately maintained notes, attachments or copied passages are included. The purpose of this check is to identify the applicable permission path, not to claim that Part 2 universally requires technical segregation of records.
Source context: HHS: 42 CFR Part 2 final rule fact sheet
04
Review the AI recipient and onward use
Identify the AI provider, application operator and other recipients. Determine the permitted service, data handling and relevant agreements. The fact sheet preserves stronger restrictions on using records in civil, criminal, administrative or legislative proceedings against patients without the necessary consent or court order.
Consent for those proceedings cannot be combined with consent for other uses, according to HHS’s summary. Keep that question distinct from ordinary care or administrative processing. A provider’s ability to store a consent flag does not show that the consent covers the proposed use or that all legal restrictions have been met.
Source context: HHS: 42 CFR Part 2 final rule fact sheet · HHS: Guidance on HIPAA and cloud computing
05
Keep a decision record that travels with the scope
The worked example below traces two fictional record types to different review paths. It includes a general administrative alternative that needs no patient material. The point is to identify the consent and recipient evidence, not to generate an approval automatically.
Retain the relevant scope explanation, decision owner and data-flow record through the approved process. Revisit them when the AI service, recipient or use changes. HHS also applies HIPAA breach-notification requirements to Part 2 breaches, so suspected exposure belongs with the organisation’s incident and privacy teams.
Source context: HHS: 42 CFR Part 2 final rule fact sheet
Put it into practice
Part 2 AI disclosure branch map
Follow each yes, no or unknown outcome before a protected record reaches an AI service. A separate fictional worked case is included in the download.
General branch logic with a separate synthetic SUD programme case. No real consent, legal decision or provider approval is represented.
Scope
Yes: continue. No: review other duties. Unknown: stop and resolve.
Record type
Separate counselling note: specific consent. Ordinary record: applicable permission.
Permission
Established: review recipients. Unresolved: stop the upload.
Recipient
Complete: accountable decision. Incomplete: resolve before disclosure.
| Question | Finding | Stop or next outcome | Evidence to retain |
|---|---|---|---|
| Part 2 applies to this record and source? | Yes | Continue to record-type and permission checks. | Record the programme and record-origin evidence. |
| Part 2 applies to this record and source? | No | Leave this Part 2 branch; assess HIPAA and other applicable duties. | No Part 2 finding is not an approval of the AI disclosure. |
| Part 2 applies to this record and source? | Unknown | Stop the proposed patient-data upload and resolve origin/status. | Ask the source programme or accountable privacy owner. |
| Separately maintained SUD counselling note? | Yes | Assess specific consent; do not rely on broad TPO consent. | Identify the actual note and consent scope. |
| Separately maintained SUD counselling note? | No | Assess the permission applicable to the ordinary Part 2 record. | Review actual consent or an applicable exception for this use. |
| Record type or consent/exception established? | Unknown or unresolved | Stop the proposed upload until the applicable permission is established. | A BAA or tool label does not resolve this branch. |
| Applicable consent or exception established? | Yes | Continue to recipient, disclosure-scope and other safeguards review. | Include the consent copy or clear scope explanation where required. |
| Recipient and remaining conditions reviewed? | No or unknown | Stop the proposed disclosure on this route; resolve the missing conditions. | Map the AI service, connected recipients and applicable agreements. |
| Recipient and remaining conditions reviewed? | Yes | The accountable owner can record the scoped decision. | This table does not itself grant legal permission or product approval. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
part2-ai-records-consent.mdInspect
# Part 2 AI disclosure branch map
General branch logic with a separate synthetic SUD programme case. No real consent, legal decision or provider approval is represented.
Follow each yes, no or unknown outcome before a protected record reaches an AI service. A separate fictional worked case is included in the download.
| Question | Finding | Stop or next outcome | Evidence to retain |
| --- | --- | --- | --- |
| Part 2 applies to this record and source? | Yes | Continue to record-type and permission checks. | Record the programme and record-origin evidence. |
| Part 2 applies to this record and source? | No | Leave this Part 2 branch; assess HIPAA and other applicable duties. | No Part 2 finding is not an approval of the AI disclosure. |
| Part 2 applies to this record and source? | Unknown | Stop the proposed patient-data upload and resolve origin/status. | Ask the source programme or accountable privacy owner. |
| Separately maintained SUD counselling note? | Yes | Assess specific consent; do not rely on broad TPO consent. | Identify the actual note and consent scope. |
| Separately maintained SUD counselling note? | No | Assess the permission applicable to the ordinary Part 2 record. | Review actual consent or an applicable exception for this use. |
| Record type or consent/exception established? | Unknown or unresolved | Stop the proposed upload until the applicable permission is established. | A BAA or tool label does not resolve this branch. |
| Applicable consent or exception established? | Yes | Continue to recipient, disclosure-scope and other safeguards review. | Include the consent copy or clear scope explanation where required. |
| Recipient and remaining conditions reviewed? | No or unknown | Stop the proposed disclosure on this route; resolve the missing conditions. | Map the AI service, connected recipients and applicable agreements. |
| Recipient and remaining conditions reviewed? | Yes | The accountable owner can record the scoped decision. | This table does not itself grant legal permission or product approval. |
## Review steps
- Confirm origin and record type: Ask the source programme whether Part 2 and the special SUD counselling-note provisions apply.
- Match consent to the use: Review the actual permission, scope explanation and any separate-consent requirement.
- Trace every recipient: Include AI services, connected features and processing intermediaries rather than assuming a BAA covers all of them.
## Separate fictional worked case
The following example is separate from the conditional branch map. It does not establish a real patient consent or legal decision.
| Decision | Invented case finding | Next action |
| --- | --- | --- |
| Does Part 2 apply? | The source owner identifies a fictional record as protected Part 2 material. | Use the Part 2 review path; document actual origin in a real case. |
| Is it a separately maintained SUD counselling note? | One attachment contains a clinician’s separately kept session analysis. | Do not rely on broad TPO consent for that attachment; assess specific consent. |
| What consent covers the ordinary record? | A TPO consent exists in the scenario, but the proposed recipient is not yet reviewed. | Check its scope and applicable disclosure/redisclosure conditions. |
| Who receives the AI input? | External AI service and its connected feature are proposed. | Map each recipient and its role, agreements and permitted use. |
| Could the task use no patient record? | Staff only need generic reception wording. | Use invented context and keep the protected records out of that task. |
| Can the real disclosure proceed? | Required consent and recipient questions remain open in the exercise. | Obtain the accountable review; the worksheet does not authorise disclosure. |
## Safe alternative prompt
Invented exercise: Write a general reception message about contacting a service team for administrative questions. Include no patient, SUD diagnosis, treatment history or counselling note.
HHS fact sheet updated 30 January 2026; applicable compliance date 16 February 2026.
## Source and scope
Guide: https://aona.ai/resources/guides/42-cfr-part-2-ai-records-consent/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- HHS: 42 CFR Part 2 final rule fact sheet: https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html
- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
Download part2-ai-records-consent.mdpart2-ai-records-consent.csvInspect
Question,Finding,Stop or next outcome,Evidence to retain
Part 2 applies to this record and source?,Yes,Continue to record-type and permission checks.,Record the programme and record-origin evidence.
Part 2 applies to this record and source?,No,Leave this Part 2 branch; assess HIPAA and other applicable duties.,No Part 2 finding is not an approval of the AI disclosure.
Part 2 applies to this record and source?,Unknown,Stop the proposed patient-data upload and resolve origin/status.,Ask the source programme or accountable privacy owner.
Separately maintained SUD counselling note?,Yes,Assess specific consent; do not rely on broad TPO consent.,Identify the actual note and consent scope.
Separately maintained SUD counselling note?,No,Assess the permission applicable to the ordinary Part 2 record.,Review actual consent or an applicable exception for this use.
Record type or consent/exception established?,Unknown or unresolved,Stop the proposed upload until the applicable permission is established.,A BAA or tool label does not resolve this branch.
Applicable consent or exception established?,Yes,"Continue to recipient, disclosure-scope and other safeguards review.",Include the consent copy or clear scope explanation where required.
Recipient and remaining conditions reviewed?,No or unknown,Stop the proposed disclosure on this route; resolve the missing conditions.,"Map the AI service, connected recipients and applicable agreements."
Recipient and remaining conditions reviewed?,Yes,The accountable owner can record the scoped decision.,This table does not itself grant legal permission or product approval.
Download part2-ai-records-consent.csvpart2-fictional-worked-case.csvInspect
Decision,Invented case finding,Next action
Does Part 2 apply?,The source owner identifies a fictional record as protected Part 2 material.,Use the Part 2 review path; document actual origin in a real case.
Is it a separately maintained SUD counselling note?,One attachment contains a clinician’s separately kept session analysis.,Do not rely on broad TPO consent for that attachment; assess specific consent.
What consent covers the ordinary record?,"A TPO consent exists in the scenario, but the proposed recipient is not yet reviewed.",Check its scope and applicable disclosure/redisclosure conditions.
Who receives the AI input?,External AI service and its connected feature are proposed.,"Map each recipient and its role, agreements and permitted use."
Could the task use no patient record?,Staff only need generic reception wording.,Use invented context and keep the protected records out of that task.
Can the real disclosure proceed?,Required consent and recipient questions remain open in the exercise.,Obtain the accountable review; the worksheet does not authorise disclosure.
Download part2-fictional-worked-case.csvBefore you proceed
Keep these distinctions clear
- HIPAA alignment is not complete equivalence
- Part 2 retains distinct consent and legal-proceedings protections.
- A combined file can cross a boundary
- Check attachments and copied notes rather than treating the whole export as one permission category.
Apply it to employee AI use
Bring your actual data path.
Aona can support evaluation of sensitive-input policies for a selected employee application and input path.
It does not determine Part 2 status, validate patient consent or provide a legal authorisation to disclose.
Use a fictional note category and agree which input should be restricted, then record the actual result on the supported path.
Review your use caseFAQ
Questions for this decision
Does Part 2 apply to all mental-health information?
Does an AI provider’s BAA replace Part 2 consent?
Can broad TPO consent cover SUD counselling notes?
Is the 2026 compliance date still in the future?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- HHS: 42 CFR Part 2 final rule fact sheet
Part 2 applicability, consent and redisclosure changes, separate SUD counselling notes and the 16 February 2026 compliance date; fact sheet updated 30 January 2026.
regulator · checked 2026-09-21 - HHS: Guidance on HIPAA and cloud computing
Business-associate roles, BAAs, risk analysis and cloud-service safeguards, including providers without decryption keys.
regulator · checked 2026-09-21