Direct comparison
42 CFR Part 2 vs. HIPAA Compared
How 42 CFR Part 2 and HIPAA differ on scope, consent, redisclosure, law-enforcement use, and the research-disclosure pathway each one provides.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · included with Regulatory Radar
Ask about 42 CFR Part 2 vs. HIPAA Compared
Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.
150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do 42 CFR Part 2, HIPAA Privacy Rule compare side by side?
The table below compares 42 CFR Part 2, HIPAA Privacy Rule across 8 procurement-relevant dimensions, from what it covers through typical research-administration instrument.
Side-by-side comparison
| Dimension | 42 CFR Part 2 | HIPAA Privacy Rule |
|---|---|---|
| What it covers | Records that would identify someone as a patient of a federally assisted substance use disorder (SUD) diagnosis, treatment, or referral program. | Protected health information (PHI) held by any covered entity or business associate, across all conditions, not just SUD. |
| Statutory basis | 42 U.S.C. § 290dd-2; implementing regulation at 42 CFR Part 2. | Health Insurance Portability and Accountability Act of 1996; Privacy Rule at 45 CFR Part 164, Subpart E. |
| Who must comply | “Part 2 programs” and anyone who receives Part 2-covered patient-identifying information from one — the obligation follows the data to the next recipient. | Covered entities (health plans, clearinghouses, most providers) and their business associates. |
| Redisclosure by the recipient | Generally prohibited unless the original consent or a Subpart D/E exception specifically permits it — the restriction travels downstream with the data. | Permitted for uses consistent with the original authorization or a permitted purpose; no equivalent blanket redisclosure bar. |
| Use in law enforcement / legal proceedings | Barred from being used to investigate or prosecute a patient without a specific Subpart E court order — a materially higher bar than HIPAA. | Several law-enforcement disclosure permissions exist (45 CFR 164.512(f)) without requiring the same court-order standard. |
| Consent for research use without individual consent | Subpart D permits disclosure to qualified research personnel without patient consent, subject to the regulation's confidentiality-security terms. | An IRB or Privacy Board can waive or alter authorization under 45 CFR 164.512(i) when the study meets the waiver criteria. |
| 2024/2026 rule changes | Final rule allows a single general consent for future treatment/payment/operations uses and aligns breach notification with HIPAA — narrowing, not eliminating, the gap. | Breach Notification Rule unchanged by the Part 2 final rule; Part 2 was brought closer to HIPAA's standard, not the reverse. |
| Typical research-administration instrument | A data use agreement carrying the redisclosure restriction forward in writing, alongside IRB protocol review. | A HIPAA authorization, or a documented IRB/Privacy Board waiver of authorization. |
Common questions
Common questions about 42 CFR Part 2 vs HIPAA Privacy Rule
Does a HIPAA waiver of authorization also satisfy 42 CFR Part 2?
+
No. A 45 CFR 164.512(i) HIPAA waiver addresses HIPAA specifically. If the same dataset includes Part 2-covered SUD-program records, Part 2's separate consent or research-disclosure requirements still have to be satisfied on their own terms.
Is 42 CFR Part 2 stricter than HIPAA in every respect?
+
No — it's stricter in specific, defined ways (redisclosure prohibition, the bar on law-enforcement use without a court order). HIPAA's authorization, de-identification, and minimum-necessary rules apply independently and aren't replaced by Part 2.
Can a dataset be covered by both 42 CFR Part 2 and HIPAA at the same time?
+
Yes, and this is the common case for research involving SUD-program records — both regimes apply concurrently, and a study team generally needs a compliance analysis (and often a separate consent or waiver pathway) for each one.








