The short answer
For a behavioral-health organization subject to HIPAA, a practical work plan starts by identifying whether each operation is acting as a covered entity, business associate, or neither, because the applicable duties differ by role. The plan should cover Privacy Rule operations such as uses and disclosures, individual requests, notices, complaints, policies, and documentation; Security Rule risk analysis and safeguards for electronic protected health information (ePHI); business-associate arrangements; workforce training and sanctions; and incident assessment under the Breach Notification Rule. HHS summarizes these rule areas in its HIPAA resources for professionals. Separately assess whether 42 CFR Part 2 governs any substance-use-disorder records or workflows.
What does HIPAA compliance mean for behavioral health?
HIPAA work is broader than cybersecurity. Depending on the organization’s role and activities, it can include controlling uses and disclosures of PHI, operating individual-rights and complaint processes, maintaining required notices and documentation, training and sanctioning workforce members, safeguarding ePHI, managing business-associate relationships, and responding to potential breaches. The Privacy Rule, Security Rule, and Breach Notification Rule supply different parts of that work; not every duty applies identically to every organization.
Some SUD patient records are also governed by 42 CFR Part 2. Part 2 status does not follow from a behavioral-health label alone: document the program or activity involved, the records, the recipient, and the contemplated use or disclosure. Keep that applicability analysis distinct from the HIPAA role analysis.
A maintained HIPAA work-plan checklist
Use the areas below as a working register, first recording which items apply to the organization’s role and activities. Give each applicable item an owner, supporting evidence, review trigger, open findings, and remediation status.
| Operational area | Work item | Useful evidence |
|---|---|---|
| Privacy governance | Maintain applicable privacy policies, responsible contacts, complaint and sanction processes, mitigation steps, and required documentation under 45 CFR 164.530 | Policy register, role assignments, complaint log, sanction procedure, and retained decisions |
| Uses and disclosures | Map recurring PHI flows to a permitted basis, required conditions, and the minimum-necessary rule where it applies; start with 45 CFR 164.502 and 164.514 | Disclosure matrix, authorization forms, decision records, and disclosure logs where required |
| Notices and individual requests | For covered-entity operations, maintain the required notice process and route access, amendment, restriction, confidential-communication, and accounting requests under the applicable Privacy Rule provisions | Current notice, intake channels, request tracker, response records, and escalation rules |
| Security risk management | Perform an accurate and thorough assessment of risks and vulnerabilities to ePHI, implement risk-management measures, and update the analysis when operational changes affect its scope, as described by HHS risk-analysis guidance | System and data-flow inventory, risk register, treatment decisions, owners, and closure evidence |
| Security administration and continuity | Assign security responsibility, maintain security-incident procedures, and address the contingency-plan specifications for data backup, disaster recovery, emergency-mode operations, testing and revision, and application and data criticality under 45 CFR 164.308 | Security role assignment, incident records, contingency plans, backup and restoration results, exercise records, revisions, and criticality analysis |
| Physical safeguards | Address facility-access, workstation-use, workstation-security, and device-and-media-control standards under 45 CFR 164.310, including how equipment and media containing ePHI are received, moved, reused, and disposed of | Facility-access procedures and reviews, workstation rules, device and media inventory, movement records, and disposal or reuse evidence |
| Identity and access | Assign unique user identifiers and authorize access according to documented job functions and access decisions under the applicable administrative and technical safeguard standards | Access matrix, approvals, privileged-access reviews, and onboarding, transfer, and termination records |
| Technical safeguards | Address the audit-control, integrity, person-or-entity-authentication, and transmission-security standards and their implementation specifications under 45 CFR 164.312 | Audit-log configuration and review records, integrity-control decisions and tests, authentication settings, transmission assessments, and remediation evidence |
| Business associates | Analyze relationships against HIPAA’s business-associate criteria and obtain the required written assurances when applicable, using HHS contract guidance | Vendor inventory, role determination, executed agreement, and subcontractor or termination follow-up |
| Workforce implementation | Train workforce members on applicable policies and security practices, document completion and material updates, and apply the organization’s sanction process when appropriate under 45 CFR 164.530 and 164.308 | Role-based training matrix, completion records, change triggers, and sanction records |
| Breach assessment and notification | Route potential breaches for application of the Breach Notification Rule’s definitions, exceptions, and assessment, and make any notifications required for the organization’s role, using the HHS rule summary | Assessment record, notification decision and record, supporting facts, approvals, and exercise results |
Privacy governance, notices, and records
For a covered entity, identify the privacy official and the contact responsible for complaints, keep applicable policies and procedures current, and maintain the required notice workflow. 45 CFR 164.520 sets the Notice of Privacy Practices requirements, while 45 CFR 164.530 addresses administrative requirements including complaints, sanctions, mitigation, policies, and documentation. Its documentation provision generally requires covered records to be retained for six years from creation or from when the document was last in effect, whichever is later. An operational register should therefore name each required record, its custodian, retention start point, storage location, and retrieval method.
Uses, disclosures, and individual requests
Build a disclosure matrix around actual workflows: referrals, care coordination, billing, family communications, legal requests, health-information exchange, and patient-authorized disclosures. For each, record the purpose, sender, recipient, PHI involved, authority or authorization, conditions, and whether the minimum-necessary standard applies; HIPAA’s general use-and-disclosure rule and minimum-necessary provisions appear in 45 CFR 164.502 and 164.514. Covered entities should also operate tracked intake and response processes for applicable requests involving restrictions or confidential communications under 164.522, access under 164.524, amendment under 164.526, and accountings under 164.528.
Business associate agreements (BAAs)
A business associate generally performs specified functions or services for a covered entity involving PHI, but the result depends on the function, relationship, and regulatory exclusions. Inventory vendors and partners that create, receive, maintain, or transmit PHI for covered functions; record the analysis for each relationship; and use the written assurances described in HHS business-associate contract guidance when required. Track agreement execution, required amendments, termination handling, and any subcontractor follow-up as separate work items.
Workforce training
Create a training matrix that maps workforce roles to the privacy policies, security practices, systems, and disclosure workflows they use. The Privacy Rule requires training as necessary and when material policy changes affect workforce functions, while the Security Rule requires a security-awareness and training program with periodic security updates; see 45 CFR 164.530(b) and 164.308(a)(5). Define triggers rather than assuming one curriculum fits every role. A material policy, role, system, threat, or incident-driven change should prompt review of affected training, and completion should be documented.
Security risk management, safeguards, and resilience
Map where ePHI is created, received, maintained, or transmitted, including the EHR, billing services, email, backups, endpoints, telehealth tools, and interfaces. Use that inventory in the organization’s Security Rule risk analysis, then record risk-treatment decisions, owners, implementation status, and closure evidence.
Risk analysis does not replace review of the Security Rule’s individual standards. For operations subject to the rule, work through the administrative safeguards in 45 CFR 164.308, physical safeguards in 164.310, and technical safeguards in 164.312. Under 45 CFR 164.306(d), a required implementation specification must be implemented. For an addressable specification, assess whether it is reasonable and appropriate in the organization’s environment; implement it when it is, or document why it is not and implement an equivalent alternative measure when reasonable and appropriate.
Turn those decisions into reviewable work. Connect account provisioning, modification, and removal to workforce changes; review audit information; document integrity, authentication, and transmission-control decisions; inspect facility, workstation, device, and media controls; and exercise the applicable backup, restoration, emergency-operation, and security-incident handoffs. Record the scope and result of each test so that a successful test supports the specified control without being treated as a conclusion about the entire compliance program.
Breach notification procedures
Use one intake path for suspected compromises of PHI, with steps to contain the event, preserve relevant information, identify affected systems and recipients, and assign follow-up. Create linked but distinct records for security-incident handling and breach assessment. For a suspected security incident involving ePHI, document the identification, response, mitigation, and outcome required by 45 CFR 164.308(a)(6). When PHI may have been compromised, apply the definitions, exceptions, assessment, recipients, and timing described in the HHS Breach Notification Rule summary; duties differ for covered entities and business associates, and the notification rule applies to breaches of unsecured PHI. Preserve the facts considered, determination, approvals, and any notifications. Exercise the handoffs with a plausible scenario, such as client information sent to the wrong recipient, and convert observed failures into owned remediation items.
How HIPAA and 42 CFR Part 2 intersect
A provider may have obligations under both HIPAA and Part 2, but Part 2 coverage depends on the program or activity, federal involvement, records, and contemplated use or disclosure. HHS explains that the 2024 final rule aligned selected Part 2 provisions with HIPAA and set February 16, 2026 as the compliance date for persons subject to its applicable requirements. Use the current HHS Part 2 fact sheet for the distinctions below, then document how they apply to the specific workflow.
| Question | HIPAA | 42 CFR Part 2 |
|---|---|---|
| Which information is in scope? | PHI as defined by HIPAA when maintained or transmitted by a covered entity or business associate, subject to the regulation’s definitions and exclusions; the Security Rule specifically protects ePHI | Records identifying a patient as having or having had SUD that are maintained in connection with a qualifying Part 2 program or activity, as summarized in the HHS fact sheet |
| How are treatment, payment, and operations handled? | 45 CFR 164.506 permits specified treatment, payment, and health-care-operations uses and disclosures, subject to its conditions and other applicable provisions | The current rule permits a single consent for future treatment, payment, and health-care-operations uses and disclosures, subject to Part 2’s requirements, according to the HHS fact sheet |
| What happens after a consented disclosure? | The recipient’s HIPAA role and the purpose of the next use or disclosure determine which HIPAA provisions apply | HHS states that a HIPAA covered entity or business associate receiving records under the qualifying consent may redisclose them in accordance with HIPAA. HHS also states that the records may not be used in legal proceedings against the patient without specific consent or a Part 2 court order. See the HHS fact sheet and endnotes |
| Must Part 2 data be segregated? | HIPAA does not determine whether a record is subject to Part 2 | The 2024 final rule expressly states that segregating or segmenting Part 2 records is not required, although an organization still needs controls that apply the correct disclosure rules to each workflow, as described by HHS |
Do not infer Part 2 status from a mental-health, behavioral-health, or SUD service label. For each SUD-related workflow, keep a decision record identifying the program or activity, the records, the proposed recipient and purpose, the consent or other authority relied upon, and any restriction that must follow the records. Translate that decision into release-of-information instructions, role permissions, templates, and staff training, then test the configured workflow with a non-production example.
Where the EMR fits
Your EMR is one part of your privacy and security program. our EMR includes configurable templates, treatment plans, progress notes, and a client portal with secure messaging. Work with our team and your privacy lead to review who can view or change records, how access changes are administered, which activity can be reviewed, how exports support individual requests, how release restrictions are handled, and which integrations receive data. Document the controls and operating responsibilities your organization must maintain.
Continue reading
Primary sources
Sources reviewed September 9, 2026.
- HHS — Summary of the HIPAA Privacy Rule
- eCFR — 45 CFR Part 164, Subpart E: Privacy of Individually Identifiable Health Information
- HHS — Guidance on Risk Analysis
- eCFR — 45 CFR Part 164, Subpart C: Security Standards for ePHI
- HHS — Business Associate Contracts
- HHS — Breach Notification Rule
- eCFR — 45 CFR Part 164, Subpart D: Breach Notification
- HHS — Fact Sheet: 42 CFR Part 2 Final Rule
- eCFR — 42 CFR Part 2