42 CFR Part 2 Vendor Checklist for Behavioral Health Software
Use this 42 CFR Part 2 vendor checklist to assess scope, patient records, consent, redisclosure, notices, legal requests, breach, BAAs, security, rights, testing, and exit.

On this page: Direct answer
Direct answer
42 CFR Part 2 vendor checklist: what operators need to know
Use this 42 CFR Part 2 vendor checklist to assess scope, patient records, consent, redisclosure, notices, legal requests, breach, BAAs, security, rights, testing, and exit. Determine program, record, entity, and workflow scope before reviewing features. Map each use and disclosure to its authority, recipient, purpose, minimum data, and evidence.
A 42 CFR Part 2 vendor checklist should test the configured service, contracts, data flows, disclosures, user actions, and failure paths against the organization's current legal analysis. The 2024 Part 2 final rule had a February 16, 2026 compliance date, and HHS now places civil enforcement with the Office for Civil Rights while aligning several features more closely with HIPAA.
Alignment does not make Part 2 and HIPAA identical or make a vendor Part 2 compliant by slogan. Determine whether the program and records are within Part 2, which entities and workflows are involved, what consent or other permission supports each use or disclosure, and how notices, redisclosure, legal process, breach, individual rights, security, correction, retention, and exit operate in practice. Use qualified legal and privacy counsel.
Key takeaways
The short version
- Determine program, record, entity, and workflow scope before reviewing features.
- Map each use and disclosure to its authority, recipient, purpose, minimum data, and evidence.
- Test consent, revocation, restriction, accounting, complaint, breach, and legal-request paths end to end.
- Reconcile the BAA, service agreement, subprocessor chain, data use, and configured controls.
- Require evidence from representative workflows, not a general compliance claim.
1. Start the 42 CFR Part 2 vendor checklist with scope
- Identify each Part 2 program, component, location, service, legal entity, and accountable privacy or legal owner.
- Inventory patient-identifying SUD records across inquiries, forms, communications, recordings, transcripts, notes, insurance, scheduling, billing, logs, exports, analytics, backups, and support.
- Map covered entities, business associates, Part 2 programs, intermediaries or other recipients, subprocessors, and workforce roles without assuming labels are interchangeable.
- Record why each vendor and subprocessor creates, receives, maintains, transmits, views, derives, or deletes the data.
- Separate production, test, development, support, analytics, model, backup, disaster-recovery, and customer-managed environments.
- Have qualified counsel document which current Part 2, HIPAA, state, professional, contractual, and other requirements apply to each workflow.
3. Test notice, individual rights, complaints, and legal requests
Do not accept an answer that the customer handles rights while the vendor holds data the customer cannot search, export, correct, or restrict. Contract terms, support procedures, product permissions, APIs, and response timing must enable the customer's reviewed process.
- Current notice of privacy practices workflow, acknowledgment or distribution evidence when applicable, accessibility, language, and version control
- Access search across systems, subprocessors, archives, recordings, transcripts, messages, billing, and designated record sets as legally defined
- Amendment or correction intake, source review, linked-system update, denial or explanation, version history, and downstream notification
- Requested restrictions, accounting of disclosures, representative access, identity verification, and response tracking where applicable
- Complaint intake, non-retaliation, vendor cooperation, audit evidence, escalation, investigation, and corrective action
- Subpoena, warrant, court order, law-enforcement, discovery, legal hold, and other request workflow with qualified review before disclosure

4. Reconcile contracts, HIPAA, security, and breach response
- Applicable BAA and service terms define permitted and required uses, safeguards, incidents, subcontractors, rights support, HHS access, termination, and return or destruction.
- Part 2-specific duties, prohibited uses, disclosure support, legal requests, complaints, enforcement cooperation, and current notices are addressed where needed.
- Risk analysis covers all ePHI and relevant Part 2 records, technology, locations, people, interfaces, recordings, derived data, exports, support paths, and backups.
- Access, authentication, encryption, audit, integrity, transmission, availability, backup, recovery, vulnerability, training, and workforce controls have current evidence.
- Incident responsibilities define detection, preservation, containment, notice timing, investigation facts, subprocessor flow, breach assessment support, remediation, and communications.
- Liability, indemnity, insurance, audit rights, regulatory change, data location, retention, deletion, transition, and order-of-precedence terms are reconciled across agreements.
5. Validate representative workflows and govern change
- 01
Build cases
Use authorized synthetic scenarios for consent, change or revocation, treatment or payment workflow, disclosure, restriction, access, correction, complaint, legal request, incident, and termination.
- 02
Trace evidence
Inspect the user view, permission decision, API payload, message or document, recipient, event log, downstream copy, retry, export, backup behavior, and deletion result.
- 03
Test failure
Exercise wrong classification, excessive access, stale consent, duplicate disclosure, delayed integration, unavailable vendor, subprocessor incident, and incomplete deletion.
- 04
Resolve gaps
Record severity, affected workflow and people, interim control, owner, legal or privacy decision, deadline, retest, and production restriction.
- 05
Monitor change
Review legal updates, vendor releases, new subprocessors, data uses, integrations, locations, incidents, access, audit samples, and contract renewals on a risk-based cadence.
Common questions
Answers before you build.
Is HIPAA compliance enough for 42 CFR Part 2?+
No. The rules now align in several areas, but Part 2 has its own scope and requirements. Organizations should complete a current program-, record-, entity-, use-, disclosure-, notice-, and workflow-specific analysis with qualified counsel.
Can a vendor certify that a customer is Part 2 compliant?+
A vendor can provide evidence about its service and controls, but the customer's program scope, policies, consents, disclosures, workforce, contracts, configurations, legal obligations, and use of the service determine the broader compliance posture.
Does a Part 2 software vendor also need a BAA?+
If the vendor is a HIPAA business associate for the service, an applicable BAA is required even when Part 2 also applies. Determine each legal role and reconcile Part 2-specific obligations with HIPAA and the service agreement.
What evidence should be requested from a Part 2 vendor?+
Request data flows, architecture, roles, subprocessors, agreements, risk and control evidence, access and audit demonstrations, consent and disclosure tests, rights support, incident records, retention and deletion tests, continuity evidence, and current change history.
Practical closeout
Use this operator checklist.
- Determine program, record, entity, and workflow scope before reviewing features.
- Map each use and disclosure to its authority, recipient, purpose, minimum data, and evidence.
- Test consent, revocation, restriction, accounting, complaint, breach, and legal-request paths end to end.
- Reconcile the BAA, service agreement, subprocessor chain, data use, and configured controls.
- Require evidence from representative workflows, not a general compliance claim.
Continue through the cluster
Verified customer case studies are added only with customer permission and supporting evidence; none is implied by these operational examples.
Sources & methodology
Trace the operational claims.
Marsa Health Editorial reviewed the primary and research sources below on July 22, 2026. We translate them into workflow controls, distinguish proposals from final rules, and flag where plan, program, state, contract, or clinical requirements vary.
- 01Fact Sheet: 42 CFR Part 2 Final Rule U.S. Department of Health and Human ServicesUpdated January 2026 overview of SUD patient-record confidentiality changes and the February 16, 2026 compliance date.Accessed or rechecked July 22, 2026
- 02Understanding Confidentiality of Substance Use Disorder Patient Records or Part 2 U.S. Department of Health and Human ServicesCurrent OCR overview of Part 2 scope, the 2024 final rule, the February 16, 2026 compliance date, enforcement, breach reporting, and model notices.Accessed or rechecked July 22, 2026
- 03Business Associate Contracts U.S. Department of Health and Human ServicesOCR explanation and sample provisions covering permitted uses, safeguards, incidents, individual rights, subcontractors, termination, and return or destruction.Accessed or rechecked July 22, 2026
- 04Guidance on HIPAA and Cloud Computing U.S. Department of Health and Human ServicesOCR guidance on cloud business associates, subcontractors, BAAs, risk analysis, shared security responsibilities, SLAs, data return, and breach duties.Accessed or rechecked July 22, 2026
- 05Summary of the HIPAA Security Rule U.S. Department of Health and Human ServicesCurrent Security Rule overview covering administrative, physical, and technical safeguards, access controls, risk analysis, and review of ePHI activity.Accessed or rechecked July 22, 2026
- 06Guidance on Risk Analysis U.S. Department of Health and Human ServicesOfficial guidance that risk analysis must cover all ePHI an organization creates, receives, maintains, or transmits.Accessed or rechecked July 22, 2026
- 07Direct Liability of Business Associates U.S. Department of Health and Human ServicesOCR fact sheet describing provisions of the HIPAA Rules for which business associates can be directly liable.Accessed or rechecked July 22, 2026
- 08Minimum Necessary Requirement U.S. Department of Health and Human ServicesHIPAA guidance on limiting uses, disclosures, and requests for protected health information when the standard applies.Accessed or rechecked July 22, 2026
Organizational author. Editorial review covers source accuracy, search intent, workflow boundaries, and human-oversight requirements. This material is educational and does not provide clinical, legal, coding, or coverage advice.
No named clinical or legal expert reviewer is attributed to this version. Marsa Health does not invent reviewer credentials.
Read our editorial methodRevision history
What changed and when
July 22, 2026
Initial publication, source review, and operational editing.