{"@context":"https://schema.org","@type":"Article","headline":"Part 2 audit and evaluation disclosure","description":"Learn how Part 2 handles on-site and copied records for management, financial, payer, quality, government, and program audits or evaluations.","url":"https://finnihealth.com/resources/glossary/part-2-audit-and-evaluation-disclosure","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 audit and evaluation disclosure","item":"https://finnihealth.com/resources/glossary/part-2-audit-and-evaluation-disclosure"}]}}
Glossary term

Part 2 audit and evaluation disclosure

Learn how Part 2 handles on-site and copied records for management, financial, payer, quality, government, and program audits or evaluations.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

SUD audit records access Part 2 program evaluation

An audit evaluation disclosure under Part 2 is access to patient-identifying information for a qualifying management audit, financial audit, program evaluation, quality review, payer review, government review, or related activity under 42 CFR 2.53. The rule distinguishes records reviewed without copying or removal from records copied, downloaded, removed, or forwarded. The actor, sponsor, written commitments, purpose, data movement, and downstream limits determine the pathway.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Start with purpose, sponsor, and data movement

42 CFR 2.53 identifies qualifying actors and activities. Record who conducts the work, on whose behalf, the audit or evaluation question, legal or contractual basis, records needed, whether data leaves the controlled environment, systems and devices involved, and the qualified decision-maker.

Create a structured intake covering program or lawful holder, reviewer, employer and role, sponsor, government or payer relationship, purpose, authority, scope, population, dates, fields, counseling notes, location, copy or download, remote access, tools, vendors, outputs, retention, destruction, and legal-demand route. Separate what the requester calls the activity from what the rule and facts support.

An audit label, contract right, regulator status, accreditation visit, payer request, or quality project does not by itself answer every Part 2 condition. Route uncertain actors, sponsors, purposes, or data movement to qualified privacy, compliance, audit, payer, and legal owners before access.

On-site review has a written limit

When records remain within the program or lawful holder's premises or system under the no-copy pathway, the reviewer agrees in writing to the rule's use and redisclosure limits. The program or lawful holder also determines qualification when that provision applies.

Map screenshots, printouts, handwritten identifying notes, browser downloads, clipboard use, local files, sync, caches, remote-desktop transfers, analytics extracts, logs, and exports. A review can occur remotely in a controlled environment while still requiring exact analysis of where data resides and whether it moves.

Use time-limited accounts, smallest necessary records, session controls, observer or monitoring where appropriate, output review, and access closure. Preserve the signed commitment and qualification evidence before the first session.

Copied or forwarded records add duties

A person who copies, removes, downloads, or forwards patient-identifying records agrees in writing to maintain and destroy information under Part 2 security policies, follow applicable retention laws, and comply with use and disclosure limits. Eligible sponsors remain specified by the rule.

Inventory every copy and destination. Record encryption, users, access dates, purpose, backup, vendor, retention source, legal hold, destruction deadline, sanitization method, and evidence. Prevent forwarding or secondary analysis outside the approved audit or evaluation.

Changing from screen review to download is a pathway change, not a minor technical preference. Stop access, obtain the additional agreement and sponsor analysis, approve the environment, and update scope before data moves.

Activities and special programs vary

The section addresses care and outcome improvement, resource management, payment policy, medical necessity, utilization, quality assurance, Medicare, Medicaid, CHIP, CMS-regulated organizations, mandated audits, and certain health-care-operations disclosures. Each has distinct conditions that need page-specific review.

Match the work to the exact clause and supporting facts. Research, marketing, employment, law enforcement, litigation discovery, product development, and general data brokerage do not become audit or evaluation because someone plans to analyze records. Preserve the rationale and any specialized conditions.

Control outputs and close the review

Review reports, findings, workpapers, screenshots, evidence packets, dashboards, and presentations for patient-identifying content and approved purpose. Keep remediation activity within the supported relationship. A finding does not authorize publication or reuse of source records.

At closure, terminate access, recover devices and copies, reconcile logs, apply retention and destruction rules, sanitize media where required, document unresolved findings, and preserve oversight evidence. If unsupported access or data movement occurred, contain it and route privacy, security, compliance, audit, payer, legal, clinical, and patient communication decisions.

Example with audit intake

Sixteen review requests enter an audit queue. Twelve have a qualifying purpose, sponsor, written commitment, and data-movement plan; four remain unsupported. Intake readiness is 12 of 16 requests.

Two requesters narrow their work to controlled on-site review, one supplies the missing copied-record commitments, and one unrelated analytics project remains held. The program preserves all decisions and starts access only after the applicable gates are complete.

Audit-intake checklist

  • Verify reviewer, sponsor, purpose, authority, scope, and qualified decision-maker.
  • Map every screen, copy, device, destination, vendor, and output.
  • Use the correct written commitment for on-site or moved records.
  • Treat a later download or forwarding request as a pathway change.
  • Match specialized activities to their exact conditions.
  • Review outputs and reconcile access, copies, retention, and destruction.
  • Contain unsupported work and inspect related audit configurations.

Owner controls

The 2024 final rule supplies current context. Use audit intake, actor and sponsor validation, written agreements, environment controls, download approval, retention and destruction terms, report review, and post-audit closure.

Monitor requests, pathway type, qualification, agreements, records viewed, copies, outputs, access duration, closure, destruction, and incidents. Audit from each access event back to supported purpose and sponsor, then from active reviews into current environment and copy evidence. Retest after payer, regulator, platform, vendor, audit, or policy changes.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni