Part 2 Penalties Went From $500 to HIPAA-Scale. Most Programs Missed It.
Until this year, violating 42 CFR Part 2 carried a criminal fine of $500 for a first offense and $5,000 after that. Not a typo. Those numbers were set decades ago and never adjusted.
As of February 16, 2026, Part 2 violations carry the same civil and criminal penalties as HIPAA. Thousands to millions, depending on severity. OCR is accepting complaints, accepting breach notifications, and running the same enforcement playbook it has used against covered entities for years: investigations, corrective action plans, resolution agreements, civil money penalties.
The rule that made this happen was published in February 2024. The two-year runway ended this February, and a lot of organizations spent it assuming Part 2 was somebody else's problem.
What actually changed on February 16?
Three things, and they compound.
Enforcement authority moved to OCR. HHS delegated Part 2 enforcement to the Office for Civil Rights in August 2025. OCR announced the civil enforcement program on February 13, 2026, effective three days later.
Penalties aligned with HIPAA. The old criminal-only scheme is gone. Part 2 violations now sit under 45 CFR part 160, subparts C, D and E, the same enforcement provisions that apply to HIPAA covered entities and business associates.
Breach notification attaches. This is the operational change most organizations have not absorbed. A breach involving SUD records now triggers the HIPAA Breach Notification Rule: affected individuals within 60 days of discovery, notice to OCR, and media notification above the threshold.
Part 2 confidentiality stopped being compliance-by-policy. It is now an enforcement regime with the same teeth as HIPAA, applied to a narrower and more sensitive category of record.
Who does 42 CFR Part 2 actually apply to?
This is where most of the risk sits, because the common answer is "addiction treatment centers," and that answer is incomplete.
The definition is narrow. A Part 2 program is a federally assisted operation that holds itself out as providing, and does provide, diagnosis, treatment, or referral for substance use disorder.
The application is not. That definition catches far more than freestanding addiction treatment centers:
- A federally qualified health center with a behavioral health program alongside primary care
- A hospital with an identified addiction medicine service line
- A primary care practice with a clinician whose role includes SUD treatment
- A general behavioral health organization treating substance use among other conditions
And "federally assisted" is broader than the phrase suggests. It is not limited to direct federal grant funding. Organizations that assume it means "we don't take federal money for this program" frequently find on review that they meet it another way. The specific criteria are worth checking against SAMHSA's definition rather than assuming.
Then there are the recipients. Organizations that legitimately receive Part 2 records, called lawful holders, carry obligations of their own. A payer, a referring provider, a health information exchange or a billing vendor handling SUD records is not simply holding ordinary PHI, and OCR's enforcement program explicitly contemplates complaints against lawful holders and qualified service organizations, not only against programs.
So the population with Part 2 exposure is considerably larger than the population that thinks of itself as a Part 2 program.
Did the 2024 rule make Part 2 stricter?
In one important way, no. It made sharing easier.
Patients can now sign a single consent covering future disclosures for treatment, payment, and healthcare operations, and recipients may redisclose within HIPAA's limits. The old regime required consent for essentially every disclosure, which made care coordination genuinely difficult and pushed some organizations toward simply not sharing.
That is a real improvement. But it changes the shape of the risk rather than removing it. More records moving under a broad consent, to more recipients, with HIPAA-scale penalties if something goes wrong and a breach clock if it does.
One carve-out survived: counseling session notes. Like psychotherapy notes under HIPAA, they require their own specific consent and cannot ride along on the general one.
What does the breach clock actually require?
The same thing HIPAA requires, applied to records that are harder to reconstruct.
Sixty days from discovery to notify affected individuals. That window covers determining what was exposed, identifying whose records were involved, assessing whether the notification threshold is met, and preparing notices.
That determination depends on a record of what moved and where. For SUD records specifically, it depends on something more: knowing which of the records that left were Part 2 records at all, since a program treating substance use alongside other conditions holds both categories in the same systems.
Most organizations cannot answer "what did we send this payer between March and July, and which of it was Part 2" without a manual reconstruction. That project starts after the clock does.
What can you actually do about it?
Four things, in rough order of impact.
Determine whether you are a Part 2 program, in writing. Not an assumption, a documented analysis. The costliest version of this is an organization that never formally asked and finds out during an investigation.
Find where Part 2 records live and where they go. Which systems hold them, which external parties receive them, under what consent. Organizations routinely discover during this exercise that SUD records are moving through general-purpose channels alongside ordinary PHI.
Update the paperwork. Notices of Privacy Practices, policies, business associate and qualified service organization agreements. The February deadline covered these and many organizations treated it as a documentation task and stopped there.
Make the exchange produce its own record. If a breach notification requires knowing what left and who accessed it, that has to exist before the incident rather than being assembled after. This is the part that is difficult to retrofit under a 60-day clock.
Does a file transfer platform help with Part 2 compliance?
Partly, and it is worth naming the part.
No product makes you Part 2 compliant. Compliance is a property of your program: your consent management, your policies, your training, your determination of scope. Anyone selling you a Part 2 compliance product is selling you something that does not exist.
What software affects is narrower. Every external exchange produces a structured, append-only, tamper-evident audit event exported to storage you control, so "what did we send this recipient, when, and who opened it" is a query rather than a reconstruction project. Access is identity-bound and short-lived, so a recipient's access ends rather than persisting indefinitely.
In a 60-day notification window, the difference between a query and a reconstruction is often the difference between meeting the deadline and missing it. That is one input into Part 2 readiness, not a compliance program.
More on audit evidence and, for healthcare specifically, HIPAA-compliant file sharing. Related: your breach clock starts when your vendor tells you.
The short version
Part 2 enforcement went live on February 16, 2026. The penalty exposure moved from $500 to HIPAA-scale, breach notification now attaches, and OCR is accepting complaints.
The question worth asking this quarter is not whether your Part 2 policies are current. It is whether you have determined, in writing, that Part 2 applies to you or does not, and if it does, whether you could produce what left and who received it inside sixty days.
For a lot of organizations the honest answer to the first question is that nobody has formally asked it.
Sources
- HHS Office for Civil Rights, Fact Sheet: 42 CFR Part 2 Final Rule
- eCFR, 42 CFR Part 2, Confidentiality of Substance Use Disorder Patient Records (enforcement provisions at 42 CFR 2.3)
- Foley Hoag, 42 C.F.R. Part 2 Civil Enforcement Is Here
- Woods Rogers, Compliance Deadline Approaches for 42 CFR Part 2 Amendments (prior penalty figures)
- HIPAA Journal, February 16, 2026 Compliance Deadline for Part 2 Final Rule