Skip to main content
v2026.11,772 entries · CC-BY 4.0

Direct comparison

42 CFR Part 2 vs. HIPAA Compared

How 42 CFR Part 2 and HIPAA differ on scope, consent, redisclosure, law-enforcement use, and the research-disclosure pathway each one provides.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · included with Regulatory Radar

Ask about 42 CFR Part 2 vs. HIPAA Compared

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do 42 CFR Part 2, HIPAA Privacy Rule compare side by side?

The table below compares 42 CFR Part 2, HIPAA Privacy Rule across 8 procurement-relevant dimensions, from what it covers through typical research-administration instrument.

Side-by-side comparison

Dimension42 CFR Part 2HIPAA Privacy Rule
What it coversRecords that would identify someone as a patient of a federally assisted substance use disorder (SUD) diagnosis, treatment, or referral program.Protected health information (PHI) held by any covered entity or business associate, across all conditions, not just SUD.
Statutory basis42 U.S.C. § 290dd-2; implementing regulation at 42 CFR Part 2.Health Insurance Portability and Accountability Act of 1996; Privacy Rule at 45 CFR Part 164, Subpart E.
Who must comply“Part 2 programs” and anyone who receives Part 2-covered patient-identifying information from one — the obligation follows the data to the next recipient.Covered entities (health plans, clearinghouses, most providers) and their business associates.
Redisclosure by the recipientGenerally prohibited unless the original consent or a Subpart D/E exception specifically permits it — the restriction travels downstream with the data.Permitted for uses consistent with the original authorization or a permitted purpose; no equivalent blanket redisclosure bar.
Use in law enforcement / legal proceedingsBarred from being used to investigate or prosecute a patient without a specific Subpart E court order — a materially higher bar than HIPAA.Several law-enforcement disclosure permissions exist (45 CFR 164.512(f)) without requiring the same court-order standard.
Consent for research use without individual consentSubpart D permits disclosure to qualified research personnel without patient consent, subject to the regulation's confidentiality-security terms.An IRB or Privacy Board can waive or alter authorization under 45 CFR 164.512(i) when the study meets the waiver criteria.
2024/2026 rule changesFinal rule allows a single general consent for future treatment/payment/operations uses and aligns breach notification with HIPAA — narrowing, not eliminating, the gap.Breach Notification Rule unchanged by the Part 2 final rule; Part 2 was brought closer to HIPAA's standard, not the reverse.
Typical research-administration instrumentA data use agreement carrying the redisclosure restriction forward in writing, alongside IRB protocol review.A HIPAA authorization, or a documented IRB/Privacy Board waiver of authorization.

Common questions

Common questions about 42 CFR Part 2 vs HIPAA Privacy Rule

Does a HIPAA waiver of authorization also satisfy 42 CFR Part 2?

+

No. A 45 CFR 164.512(i) HIPAA waiver addresses HIPAA specifically. If the same dataset includes Part 2-covered SUD-program records, Part 2's separate consent or research-disclosure requirements still have to be satisfied on their own terms.

Is 42 CFR Part 2 stricter than HIPAA in every respect?

+

No — it's stricter in specific, defined ways (redisclosure prohibition, the bar on law-enforcement use without a court order). HIPAA's authorization, de-identification, and minimum-necessary rules apply independently and aren't replaced by Part 2.

Can a dataset be covered by both 42 CFR Part 2 and HIPAA at the same time?

+

Yes, and this is the common case for research involving SUD-program records — both regimes apply concurrently, and a study team generally needs a compliance analysis (and often a separate consent or waiver pathway) for each one.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.