Back to Intelligence

OCR Guidance on 42 CFR Part 2 Records and Medicaid Community Engagement Exclusions: What Healthcare Privacy Teams Must Get Right

SA
Security Arsenal Team
October 2, 2026
9 min read

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance clarifying when substance use disorder (SUD) treatment records protected under 42 CFR Part 2 can be used and disclosed to verify exemptions from Medicaid community engagement requirements. This matters far more than a routine policy memo: states are standing up community engagement verification infrastructure now, and a single impermissible disclosure of Part 2-protected records can trigger federal civil and criminal penalties under 42 U.S.C. § 290dd-2, OCR enforcement action, and state-level liability.

For covered entities, Part 2 programs, state Medicaid agencies, and the managed care organizations and clearinghouses sitting between them, this guidance draws a compliance line that privacy officers, compliance teams, and security practitioners need to understand and operationalize immediately. In my experience leading HIPAA compliance and incident response engagements for healthcare clients, the most damaging violations are rarely exotic — they are workflow failures: a well-meaning eligibility worker, a batch data feed, or an improperly scoped consent form that exposes SUD treatment information without authorization. This guidance is OCR telling the industry exactly where that line sits before enforcement begins.

What Happened

Federal legislation enacted in 2025 requires states to implement community engagement requirements (work, education, or community service activities) as a condition of Medicaid eligibility for certain adult enrollees. Critically, the statute carves out exclusions and exemptions, including for individuals with substance use disorders who are receiving treatment or who have a disabling SUD condition. States must verify these exclusions to determine who is subject to the community engagement mandate.

That verification requirement created an immediate legal collision. SUD treatment records held by federally assisted SUD treatment programs are governed by 42 CFR Part 2, which is substantially more restrictive than HIPAA. Part 2 prohibits the use or disclosure of records that would identify a patient as having or having had a SUD — including for eligibility and enrollment purposes — absent written patient consent meeting specific regulatory requirements, or a narrow statutory exception. Even confirming or denying that an individual is a patient of a Part 2 program is itself a protected disclosure.

State Medicaid agencies and their contractors began asking the obvious question: can we use SUD treatment data to verify community engagement exclusions? OCR's guidance answers it.

Technical and Regulatory Analysis

The Core Regulatory Framework

Three bodies of law intersect here:

  • 42 CFR Part 2 — Confidentiality of Substance Use Disorder Patient Records. Applies to federally assisted SUD treatment programs ("Part 2 programs"). Prohibits disclosure of patient-identifying SUD information without compliant written consent (§ 2.31), subject to limited exceptions (e.g., medical emergencies under § 2.51, crimes on premises under § 2.12(c)(5), qualified service organization agreements, and court orders under § 2.61–2.67).
  • HIPAA Privacy Rule (45 CFR Parts 160, 164) — Governs PHI held by covered entities and business associates. The 2024 Part 2 Final Rule aligned Part 2 more closely with HIPAA in several respects (including a single consent for treatment, payment, and health care operations), but eligibility verification for public benefits is not treatment, payment, or health care operations.
  • Medicaid statute and state plan requirements — Now incorporate community engagement mandates with verification obligations.

What OCR Clarified

The operative points of the guidance, from a compliance operations standpoint:

  1. Verification of a Medicaid exemption is not TPO. A disclosure from a Part 2 program to a state Medicaid agency to confirm that an enrollee qualifies for a SUD-related exclusion is not treatment, payment, or health care operations. The 2024 Final Rule's broadened TPO consent does not cover it.
  2. Patient consent is the primary lawful pathway. Part 2 programs may disclose records to a state Medicaid agency for exclusion verification only with a written consent that satisfies § 2.31 — naming the recipient, the purpose, the information to be disclosed, and bearing a date/event-based expiration. General HIPAA authorizations or intake-form boilerplate do not suffice.
  3. Medicaid agencies are not Qualified Service Organizations for this purpose. A QSOA permits disclosures to entities performing services for the Part 2 program. Eligibility verification serves the Medicaid agency's interests, not the program's — QSOAs do not legitimize this data flow.
  4. Patient-identifying information means patient-identifying. Even a yes/no response to an eligibility query from a Part 2 program — "is this person in SUD treatment with you?" — is a Part 2 disclosure. States cannot design verification workflows that ping Part 2 programs for coverage confirmation without consent.
  5. Data already lawfully held by the Medicaid agency is treated differently. If a Medicaid agency independently holds SUD-related claims or encounter data (from non-Part-2 sources, or received with valid consent), HIPAA and state law — not Part 2 — govern its internal use for eligibility functions, though redisclosure restrictions and minimum-necessary principles still apply.

Why This Is a Security Problem, Not Just a Legal One

Every engagement where I've investigated an impermissible Part 2 disclosure traced back to one of three technical control failures:

  • Unsegmented data stores — SUD treatment records commingled in the EHR or data warehouse without Part 2 segmentation flags, so eligibility extracts and analytics jobs pull them by default.
  • Overbroad interfaces — HIE connections, 270/271 eligibility transactions, and batch extracts to state portals that were never scoped to exclude Part 2 data.
  • Consent management gaps — No system-level enforcement of consent directives; consent captured on paper but never mapped to release-of-information logic.

States building community engagement verification systems in 2026 are creating new data flows, new interfaces, and new batch jobs — each one a fresh opportunity for Part 2 data to leak into eligibility pipelines.

Exploitation and Enforcement Status

There is no CVE here and no adversary campaign — the threat is regulatory enforcement, OCR civil money penalties, potential criminal referral under 42 U.S.C. § 290dd-2(f), state attorney general action, and private litigation following a breach of particularly sensitive records. OCR has consistently treated Part 2 violations as high-priority enforcement matters because of the discrimination and harm that flow from SUD record exposure. Expect OCR to be unforgiving of entities that build verification workflows contrary to published guidance.

Executive Takeaways

This is a compliance and data-governance event, not a technical threat — so the response is procedural and architectural. These are the actions I would direct a client to take this quarter:

  1. Map every data flow between SUD treatment systems and Medicaid eligibility functions. Inventory interfaces, HIE connections, batch extracts, ETL jobs, and manual release-of-information processes. Flag anything that could move patient-identifying Part 2 data toward a state Medicaid agency, MCO, or eligibility vendor. If you cannot produce this map, that is your first finding.
  2. Implement and enforce § 2.31-compliant consent for exclusion verification. Work with counsel to build a consent instrument specific to community engagement exclusion verification — naming the Medicaid agency as recipient, the verification purpose, and the scope of information. Deploy it in the EHR/HIM workflow so consent status is machine-checkable before any disclosure occurs. Consent captured on paper but not enforced in code is not consent.
  3. Segment Part 2 data at the system level. Enforce segmentation in the EHR, data warehouse, and downstream reporting layers using recognized standards (e.g., HL7 security labeling / DS4P sensitivity tags). Eligibility extracts and analytics pipelines must exclude Part 2-segmented records by default, with an explicit, logged, consent-gated exception path.
  4. Push contract language downstream to Medicaid agencies, MCOs, and vendors. Amend BAAs, data use agreements, and state portal terms to prohibit redisclosure of Part 2 data, require minimum-necessary scoping of any SUD-related eligibility data, and mandate incident notification timelines for impermissible disclosures. Do not assume the state's verification system was designed with Part 2 in mind — validate it contractually and technically.
  5. Train HIM, registration, and eligibility-facing staff on the verification scenario specifically. Generic annual HIPAA training will not prepare a staff member who receives a call from a state eligibility worker asking to "confirm whether John Doe is in your program." That call requires a scripted refusal pending compliant consent. Run tabletop exercises on this exact scenario before states go live with verification.
  6. Stand up audit controls now. Log all access to and disclosures of Part 2-segmented records, alert on bulk queries and exports touching SUD-segmented data, and reconcile disclosure logs against consent records on a defined cadence. If OCR comes knocking after a complaint, your disclosure accounting is either your defense or your indictment.

Remediation and Hardening Steps

  • Review OCR's guidance directly and retain a copy in your compliance documentation: monitor https://www.hhs.gov/hipaa and the OCR Part 2 guidance pages for the published text and any FAQs that follow. Consult https://www.hipaajournal.com/ocr-guidance-part-2-records-medicaid-community-engagement-exclusions/ for the initial reporting on this development.
  • Engage healthcare counsel to validate your consent instruments and disclosure workflows against 42 CFR §§ 2.31, 2.33 (redisclosure notice requirements), and the 2024 Final Rule amendments before your state implements verification.
  • Establish a disclosure decision tree for any request involving SUD treatment information and benefits eligibility: consent on file and § 2.31-compliant? Disclose per scope. No consent? Decline and route to privacy office. Unclear whether the record is Part 2-segmented? Treat as protected until proven otherwise.
  • Apply the redisclosure notice (§ 2.32) to every permitted disclosure so downstream recipients understand the data's protected status.
  • Prepare breach response procedures specific to Part 2 data. An impermissible disclosure to a state agency may constitute a HIPAA breach requiring risk assessment and notification — and the sensitivity of SUD records raises the harm analysis substantially. Have counsel-reviewed notification templates and an escalation path ready.
  • Track your state's implementation timeline. Community engagement requirements phase in on state-specific schedules; some states may implement ahead of the federal floor. Your compliance deadline is your state's go-live date, not the statute's.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.