{"@context":"https://schema.org","@type":"Article","headline":"Part 2 agreed-restriction control","description":"Learn how a Part 2 program should translate an agreed TPO restriction into testable record, release, billing, workforce, and exception controls.","url":"https://finnihealth.com/resources/glossary/part-2-agreed-restriction-control","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 agreed-restriction control","item":"https://finnihealth.com/resources/glossary/part-2-agreed-restriction-control"}]}}
Glossary term

Part 2 agreed-restriction control

Learn how a Part 2 program should translate an agreed TPO restriction into testable record, release, billing, workforce, and exception controls.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

honoring an SUD record restriction Part 2 restriction implementation

An operational control for an agreed Part 2 restriction keeps a program from using or disclosing records in violation of a TPO limit it accepted. The record should specify affected information, purposes, recipients, systems, effective period, owners, exceptions, and termination state. A banner alone is weak evidence. The practice should test each route that could use, send, display, or bill from the restricted record.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.26(a)(3) says a program that agrees to a TPO restriction may not use or disclose records in violation of it, subject to the emergency-treatment provision. Paragraph (a)(5) preserves required-by-law disclosures and Part 2-permitted uses or disclosures for purposes outside TPO. The control must therefore enforce the accepted scope and route exceptions for qualified review.

An agreement creates an operating duty

Current 42 CFR 2.26(a)(3) says a program that agrees to a restriction may not violate it, subject to the emergency-treatment path. Use structured fields plus readable instructions so clinical, privacy, billing, records, and technical teams see the same scope.

Map every affected route

Review EHR access, release of information, referrals, care coordination, claims, eligibility, payer portals, interfaces, health information exchange, analytics, vendors, paper, fax, email, exports, and manual workarounds. Define hold and escalation behavior for ambiguity.

Keep non-TPO boundaries accurate

Section 2.26(a)(5) says an agreed restriction does not prevent disclosures required by law or permitted by Part 2 for a purpose other than TPO. The HHS fact sheet does not replace case-specific source review. Route exceptions rather than coding a blanket block.

Convert the agreement into structured scope

Record the patient, authority, restriction identifier, affected records, data categories, purposes, recipients, programs, sites, systems, vendors, effective date and time, duration, future records, accepted and excluded scope, exceptions, decision-maker, and termination route. Preserve the patient communication and underlying request.

Use structured fields alongside readable instructions. A free-text banner can warn a user but cannot reliably stop interfaces, claims, portals, exports, vendors, or background jobs.

Map every use and disclosure path

Trace clinical viewing, care coordination, referrals, release of information, claims, eligibility, prior authorization, remittance, payer portals, HIE, APIs, secure messages, patient portal, analytics, reporting, research, vendors, paper, fax, email, mobile access, downloads, and manual workarounds. Mark whether each path uses the restricted data for TPO and what control applies.

Include historical and future records as the agreement requires. Test mixed records and workflows where restricted and unrestricted information travel together.

Implement layered controls

Use access rules, disclosure holds, route suppression, claim and payer flags, consent and recipient checks, interface filters, queue review, vendor instructions, training, alerts, and attributable overrides as appropriate. Synchronize effective times and confirm downstream configuration.

Limit override authority and require purpose, source, affected data, approver, time, and evidence. A technical administrator should not decide the legal exception merely because the system permits bypass.

Route exceptions without weakening the restriction

For emergency treatment, follow paragraphs (a)(3) and (4), including the request to the receiving provider not to further use or disclose information derived from the restricted record. For required-by-law or non-TPO Part 2 permissions under paragraph (a)(5), verify the exact authority, conditions, minimum information, recipient, and documentation.

Keep exception events visible to privacy and the accountable owner. Do not turn one approved exception into a permanent general rule.

Test, monitor, and correct

Before closure, run representative permitted and blocked scenarios through each route. Verify correct data, purpose, recipient, time, alert, queue, override, vendor, log, and user instruction. Retest after upgrades, new interfaces, payer changes, mergers, role updates, and amended restrictions.

Monitor blocked attempts, overrides, emergency uses, complaints, wrong releases, unnecessary care disruption, failed notifications, stale controls, and terminations. Contain and investigate violations, correct affected workflows and recipients, evaluate required notices, and preserve evidence.

Give the patient a reliable contact for questions and changes. When a restriction affects scheduling, referrals, billing, or portal behavior, explain the practical effect without revealing more information to family members, payers, vendors, or other recipients than the patient authorized.

Example

Sixteen agreed restrictions are tested across named routes. Thirteen have active controls, exception routing, user instructions, audit evidence, and a passed test; three rely on a free-text note. Control readiness is 13 of 16 restrictions.

Agreed-restriction checklist

  • encode records, data, purposes, recipients, systems, dates, owners, and exceptions;
  • map every clinical, billing, exchange, portal, vendor, export, and manual path;
  • combine structured blocking, readable instructions, alerts, queues, and controlled overrides;
  • verify emergency, required-law, and non-TPO exceptions through qualified review;
  • test both permitted and prohibited scenarios before closing and after changes; and
  • monitor attempts, incidents, care impact, vendors, complaints, and termination state.

Agreement changes operations. The program should be able to prove that real disclosure routes honor the accepted scope, not merely that a note exists.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni