Contact Us
Categories
- Part 2
- Data Privacy
- Department of Health and Human Services' Office of Civil Rights
- Medical Malpractice
- Medical Cannabis
- Workplace health
- Workplace Violence
- Assisted Living Facilities
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- COVID-19
- Prescription Drugs
- Telemedicine
- Medical Spas
- Code Enforcement
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Compliance
- HIPAA
- Kentucky Board of Nursing
- Managed Care Organizations (“MCOs”)
- Anti-Kickback Statute
- False Claims Act
- KASPER
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Medicaid
- Mental Health Care
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Physician Assistants
- Primary Care Physicians ("PCPs")
- Qui Tam
- Stark Laws
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- APRNs
- Centers for Medicare & Medicaid Services (“CMS”)
- Charitable Hospitals
- Data Breach
- Electronic Protected Health Information (ePHI)
- Federally Qualified Health Centers (“FQHCs”)
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HPSA
- HRSA
- Medicare
- Mid-Level Practitioners
- Patient Protection and Affordable Care Act (“ACA”)
- Pharmacists
- Rural Health Centers (“RHCs”)
- Rural Health Clinic
- Telehealth
- Business Associate Agreements
- Compliance Programs
- Fraud
- Hospice
- Overpayments
- Part D
- Appeal
- Electronic Health Records (“EHR")
- ERISA
- Advanced Practice Registered Nurses
- Business Associates
- Denied Claims
- Division of Regulated Child Care
- Employee Agreement
- Fair Labor Standards Act (FLSA)
- Licensed practical nurses (LPN)
- Licensure Requirements
- Nurse practitioners (NP)
- Part A
- Part B
- Patient Autonomy
- Personal Health Information
- Personal Service Entities
- Physician Payments
- Qualified Health Plan ("QHP")
- Registered nurses (RN)
- Abuse and Waste
- Occupational Safety and Health Administration (“OSHA”)
- Department of Health and Human Services (HHS)
- Health Insurance
- Healthcare Regulation
- Health Care Law
McBrayer Blogs
Showing 3 posts in Part 2.
When HIPAA Says Yes but Part 2 Says No, Part Three: Proactive Steps to Take If Your Program Is Under Investigation
In this three-part series, we investigate the duties of SUD providers under Part 2 in the face of subpoenas and investigations. Part One discussed the contours of the duties in the face of a subpoena, while Part Two walked you through what happens when your employees are contacted by investigators. Part Three will guide you throughout the investigatory process.
Receiving a subpoena or learning that your program is under investigation is concerning and stressful, but there are proactive steps you can take to protect your patients, your staff, and your program while demonstrating good faith cooperation. More >
When HIPAA Says Yes but Part 2 Says No, Part Two: When Investigators Contact Your Employees
In this three-part series, we investigate the duties of SUD providers under Part 2 in the face of subpoenas and investigations. Part One discussed the contours of the duties in the face of a subpoena, while Part Two walks you through what happens when your employees are contacted by investigators.
In a Medicaid fraud investigation, it is common for investigators, whether from a state attorney general’s office, an inspector general, or another agency, to contact your employees directly. They may show up at your facility, call staff members, or request informal interviews with your employees outside the work environment. Just as it is important to train employees on HIPAA compliance, SUD program employees must also be trained on Part 2. More >
When HIPAA Says Yes but Part 2 Says No, Part One: What SUD Providers Must Know When Responding to a Subpoena
Part 2 increases protections for SUD patient records because of the stigma and legal consequences associated with substance use treatment. Protecting patient records serves an important public health interest, because weakening confidentiality discourages patient participation in treatment. Federal courts have enforced Part 2 to protect patients. The increased privacy protection for substance use treatment was originally intended to prevent prosecution of patients in active treatment programs, and it still does. While Part 2 is not a new regulation, it did undergo major changes when the 2024 Final Rule was adopted on April 16, 2024 (with a two-year implementation period). Enforcement for the updated Part 2 rules began on February 16, 2026, when the HHS Office for Civil Rights (“OCR”) launched a civil enforcement program and began accepting complaints alleging Part 2 violations and breach notification violations.
Substance use disorder (“SUD”) treatment providers face increasing scrutiny from Medicaid fraud and control units and other government agencies that regularly use subpoenas as an early investigation tool. The United States Department of Health and Human Services (“HHS”) Office of Inspector General (“OIG”) Work Plan also targets SUD providers and focuses on billing accuracy, regulatory compliance, patient monitoring, and other provider-related issues. Because SUD treatment is now provided in such a wide range of settings — including rural health clinics, physician practices, federally qualified health centers, primary care centers, behavioral health providers, hospitals, and independent treatment programs — these providers are targets for heightened oversight but are also subject to complex federal privacy laws that mandate extra protection for the private health information of SUD patients. SUD providers should actively manage these regulatory risks. Although a subpoena may feel urgent and intimidating, federal privacy law strictly limits what SUD providers may disclose, even when the request comes from law enforcement or a state agency. SUD providers must understand and comply with their privacy obligations when responding to the first-line investigative tool, the subpoena. More >

