Contact Us
Categories
- Part 2
- Data Privacy
- Department of Health and Human Services' Office of Civil Rights
- Medical Malpractice
- Medical Cannabis
- Workplace health
- Workplace Violence
- Assisted Living Facilities
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- COVID-19
- Prescription Drugs
- Telemedicine
- Medical Spas
- Code Enforcement
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Compliance
- HIPAA
- Kentucky Board of Nursing
- Managed Care Organizations (“MCOs”)
- Anti-Kickback Statute
- False Claims Act
- KASPER
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Medicaid
- Mental Health Care
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Physician Assistants
- Primary Care Physicians ("PCPs")
- Qui Tam
- Stark Laws
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- APRNs
- Centers for Medicare & Medicaid Services (“CMS”)
- Charitable Hospitals
- Data Breach
- Electronic Protected Health Information (ePHI)
- Federally Qualified Health Centers (“FQHCs”)
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HPSA
- HRSA
- Medicare
- Mid-Level Practitioners
- Patient Protection and Affordable Care Act (“ACA”)
- Pharmacists
- Rural Health Centers (“RHCs”)
- Rural Health Clinic
- Telehealth
- Business Associate Agreements
- Compliance Programs
- Fraud
- Hospice
- Overpayments
- Part D
- Appeal
- Electronic Health Records (“EHR")
- ERISA
- Advanced Practice Registered Nurses
- Business Associates
- Denied Claims
- Division of Regulated Child Care
- Employee Agreement
- Fair Labor Standards Act (FLSA)
- Licensed practical nurses (LPN)
- Licensure Requirements
- Nurse practitioners (NP)
- Part A
- Part B
- Patient Autonomy
- Personal Health Information
- Personal Service Entities
- Physician Payments
- Qualified Health Plan ("QHP")
- Registered nurses (RN)
- Abuse and Waste
- Occupational Safety and Health Administration (“OSHA”)
- Department of Health and Human Services (HHS)
- Health Insurance
- Healthcare Regulation
- Health Care Law
McBrayer Blogs
When HIPAA Says Yes but Part 2 Says No, Part One: What SUD Providers Must Know When Responding to a Subpoena
Part 2 increases protections for SUD patient records because of the stigma and legal consequences associated with substance use treatment. Protecting patient records serves an important public health interest, because weakening confidentiality discourages patient participation in treatment. Federal courts have enforced Part 2 to protect patients. The increased privacy protection for substance use treatment was originally intended to prevent prosecution of patients in active treatment programs, and it still does. While Part 2 is not a new regulation, it did undergo major changes when the 2024 Final Rule was adopted on April 16, 2024 (with a two-year implementation period). Enforcement for the updated Part 2 rules began on February 16, 2026, when the HHS Office for Civil Rights (“OCR”) launched a civil enforcement program and began accepting complaints alleging Part 2 violations and breach notification violations.
Substance use disorder (“SUD”) treatment providers face increasing scrutiny from Medicaid fraud and control units and other government agencies that regularly use subpoenas as an early investigation tool. The United States Department of Health and Human Services (“HHS”) Office of Inspector General (“OIG”) Work Plan also targets SUD providers and focuses on billing accuracy, regulatory compliance, patient monitoring, and other provider-related issues. Because SUD treatment is now provided in such a wide range of settings — including rural health clinics, physician practices, federally qualified health centers, primary care centers, behavioral health providers, hospitals, and independent treatment programs — these providers are targets for heightened oversight but are also subject to complex federal privacy laws that mandate extra protection for the private health information of SUD patients. SUD providers should actively manage these regulatory risks. Although a subpoena may feel urgent and intimidating, federal privacy law strictly limits what SUD providers may disclose, even when the request comes from law enforcement or a state agency. SUD providers must understand and comply with their privacy obligations when responding to the first-line investigative tool, the subpoena.
Federal Laws Control Disclosure of SUD Records
When a subpoena seeks SUD-related information, two federal confidentiality laws must be considered: (1) HIPAA and (2) 42 C.F.R. Part 2 (“Part 2”).
All healthcare providers should be familiar with HIPAA and its requirements. HIPAA allows certain disclosures of patient information in response to subpoenas or court orders. Importantly, HIPAA does not, however, override Part 2, which provides more rigid privacy controls than its broader counterpart. SUD providers must comply with both HIPAA and Part 2. Part 2 is the primary regulation governing most patient privacy inquiries involving SUD providers. It applies to any federally assisted substance use disorder treatment program, which includes providers that:
- Accept Medicaid or Medicare,
- Are licensed or certified by a federal or state agency, or
- Receive any form of federal assistance.
Part 2 increases protections for SUD patient records because of the stigma and legal consequences associated with substance use treatment. Protecting patient records serves an important public health interest, because weakening confidentiality discourages patient participation in treatment. Federal courts have enforced Part 2 to protect patients. The increased privacy protection for substance use treatment was originally intended to prevent prosecution of patients in active treatment programs, and it still does.
While Part 2 is not a new regulation, it did undergo major changes when the 2024 Final Rule was adopted on April 16, 2024 (with a two-year implementation period). Enforcement for the updated Part 2 rules began on February 16, 2026, when the HHS Office for Civil Rights (“OCR”) launched a civil enforcement program and began accepting complaints alleging Part 2 violations and breach notification violations.
SUD Patient Records Covered by Part 2
Under Part 2, SUD patient records may not be disclosed in response to a subpoena alone. This includes, among other things:
- Clinical assessments
- Treatment plans
- Individual or group counseling notes
- SUD counseling notes (a new protected category under the 2024 Final Rule, analogous to psychotherapy notes under HIPAA)
- Psychotherapy notes
- Peer support notes
- Medication information
- Session documentation
- EHR audit trails tied to patient care
Even when a subpoena is issued by a state attorney general’s Medicaid fraud unit as part of a Medicaid fraud investigation, Part 2 still applies. Federal law preempts state law in this area. Neither participation in Medicaid nor the investigative purpose of the subpoena eliminates Part 2’s restrictions. Even confirming whether named individuals are patients can violate Part 2. If a subpoena lists names, dates of birth, or partial Social Security numbers, a Part 2 program generally may not confirm, deny, or supplement that information unless there is patient consent or a qualifying court order. Patient identifying information that links an individual to an SUD program is protected.
What Is Required to Disclose Part 2 Records
The disclosure rules differ depending on whether the patient or the program is being investigated.
- Investigations of the Program or Provider (§ 2.66)
When an investigative agency (such as a state Medicaid fraud and abuse control unit) seeks patient records to investigate a Part 2 program or the person holding the records, disclosure is permitted only if:
- The patient provides valid written consent, or
- A Part 2-compliant court order is entered under § 2.66, plus a subpoena or other compulsory legal process compels production.
A § 2.66 court order must satisfy the content requirements of § 2.64(e), meaning it must:
- Limit disclosure to only those parts of the patient’s record that are essential to fulfill the objective of the order;
- Limit disclosure to only those persons whose need for information is the basis for the order; and
- Include other protective measures as necessary to protect the patient, the physician-patient relationship, and treatment services (e.g., sealing the record from public scrutiny).
Importantly, no information obtained under § 2.66 may be used to investigate or prosecute any patient in connection with a criminal matter. The court order must include this specific prohibition.
- Investigations of a Patient (§ 2.65)
When law enforcement seeks SUD records to investigate or prosecute a patient in connection with a criminal proceeding, the bar is even higher. A court may authorize disclosure only if it finds:
- The crime involved is extremely serious (e.g., homicide, kidnapping, armed robbery, child abuse and neglect);
- There is a reasonable likelihood the records will disclose information of substantial value;
- Other ways of obtaining the information are not available or would not be effective; and
- The public interest and need for disclosure outweigh the potential injury to the patient, the physician-patient relationship, and the program’s ability to serve other patients.
- The person holding the records must also be afforded the opportunity to be represented by independent counsel.
Penalties Are Now Serious
Under the 2024 Final Rule, the penalties for Part 2 violations have changed dramatically. Part 2 penalties are now aligned with HIPAA by replacing criminal penalties currently in Part 2 with civil and criminal enforcement authorities that also apply to HIPAA. HHS OCR now has authority to conduct investigations, issue corrective action plans, enter into resolution agreements, and impose civil money penalties using the same enforcement tools it has under HIPAA. SUD providers can face significant monetary penalties.
Please join us tomorrow for Part Two of this series to learn what should happen when investigators contact your employees.
Lisa English Hinkle is a Member of McBrayer and chairs the healthcare law practice. Ms. Hinkle is based in the Lexington office. You can contact her at lhinkle@mcbrayerfirm.com or (859) 551-3668.
Valerie Michael is a Member at McBrayer's Lexington office. Ms. Michael focuses her area of practice on healthcare law, handling a wide variety of matters, such as healthcare professional licensure defense, compliance, and regulatory issues. Ms. Michael can be reached at vmichael@mcbrayerfirm.com or (859) 551-3624.

