{"@context":"https://schema.org","@type":"Article","headline":"Part 2 administrative-controller recipient restriction","description":"Learn how Part 2 continues to restrict covered information after a program communicates it to the entity with direct administrative control.","url":"https://finnihealth.com/resources/glossary/part-2-administrative-controller-recipient-restriction","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 administrative-controller recipient restriction","item":"https://finnihealth.com/resources/glossary/part-2-administrative-controller-recipient-restriction"}]}}
Glossary term

Part 2 administrative-controller recipient restriction

Learn how Part 2 continues to restrict covered information after a program communicates it to the entity with direct administrative control.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

SUD parent entity received information Part 2 administrative control recipient

The administrative controller restriction in 42 CFR 2.12 applies to covered information a Part 2 program communicates to an entity with direct administrative control under the internal communication exception. The eligible relationship and workforce need support the communication, while the receiving entity remains responsible for the Part 2 restrictions attached to that information.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

The live 42 CFR 2.12(c)(3)(ii) allows a need-based communication between a Part 2 program and the entity with direct administrative control over it. Section 2.12(d)(2)(i)(B) separately applies Part 2 restrictions to the controlling person for information received through that route. eCFR displays section 2.12 as current through August 20, 2026 and last amended August 13, 2026. The HHS fact sheet confirms the February 16, 2026 compliance date for the 2024 amendments.

The receiver needs a supported control relationship

The current recipient provision identifies persons with direct administrative control. Preserve governance documents, delegated authority, organizational boundaries, effective dates, recipient role, assigned duty, information need, data elements, and sender.

Receipt creates continuing handling duties

Apply role-limited access, purpose controls, secure transmission and storage, logs, training, workforce changes, incident routing, legal-demand review, retention, return or destruction, and redisclosure analysis. Shared ownership by itself supplies incomplete evidence.

Organizational changes can change the route

Reassess after ownership transactions, MSO changes, new affiliates, reorganizations, delegated management, system consolidation, staff transfers, or program closure. Preserve historical relationships for older communications.

Establish why the entity received the information

Preserve the governance evidence for direct administrative control, including the exact program, legal entities, authority, effective dates, and operational powers. Then document each recipient's duty arising from the provision of SUD diagnosis, treatment, or referral, the information needed for that duty, purpose, patient or cohort, system, sender, and date.

Shared ownership, investment, affiliation, branding, payroll, technology, facilities, or a management contract may be relevant without proving the required relationship. Keep the communication decision separate from broader corporate access and send divided or changing authority to experienced counsel.

Inventory received records and copies

Maintain a register of source program, records, recipients, consent or exception, purpose, received date, systems, extracts, reports, analytics, backups, downstream copies, retention, and accountable owner. Preserve provenance when the information enters an enterprise record, warehouse, legal file, board packet, support system, or reporting tool.

Restrict users and service accounts to the approved duty. Apply purpose controls, field and patient limits, secure transmission and storage, export controls, logging, monitoring, legal-demand routing, incident handling, correction, and termination. A valid initial communication does not authorize every later use or redisclosure.

Manage organizational change

Reassess after a merger, acquisition, program transfer, management-service change, delegation, restructuring, new affiliate, system consolidation, service launch, or closure. Disable obsolete access before moving data or enabling a successor, and retain prior governance and decisions for historical communications.

At least annually, reconcile governance, program roster, system groups, data inventory, retention, and actual recipient activity. Sample one communication per material role and record exceptions, corrective owner, completion evidence, and follow-up date.

Example

Ten controller data sets are sampled. Seven have current control, duty, need, source, access, and retention evidence; three entered an enterprise warehouse after a reorganization. Readiness is 7 of 10 data sets.

Decide at the data-set and use level

Classify each data set as supported for the named controlling entity and duty, narrowed to a smaller recipient or field set, restricted pending evidence, or removed from the route. Record governance, program, recipient, purpose, records, dates, systems, decision-maker, and next review. A supported relationship does not approve unrelated uses inside the same entity.

For a supported use, configure the role, patient scope, fields, purpose, duration, exports, monitoring, and retention. Verify the control with a test account and a recent record. For a failed or unresolved use, preserve logs, contain access, assess prior activity, and assign correction and follow-up.

At reorganization, compare old and new data inventories before migration. Document which records remain under the earlier relationship, which move under supported authority, which require another basis, and which must stay segregated or inaccessible.

Retain the comparison, approvals, exceptions, and completed migration test with the governance record.

Administrative-controller recipient checklist

  • retain direct-control governance evidence, parties, powers, and effective dates;
  • tie each recipient, duty, purpose, patient scope, and data element to the program;
  • inventory records, extracts, reports, systems, backups, and downstream copies;
  • enforce purpose, access, export, retention, legal-demand, and incident controls;
  • preserve historical decisions and terminate access after organizational change; and
  • sample live use and document correction through verified completion.

This restriction does not make every parent, owner, manager, director, or affiliate an eligible recipient. Direct control, duty, data need, continuing Part 2 restrictions, HIPAA, state law, and the proposed later action need qualified review.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni