{"@context":"https://schema.org","@type":"Article","headline":"Part 2 contractor recipient binding clause","description":"Learn how a Part 2 contractor clause binds a downstream recipient to the regulation when patient-identifying information is received and accessed.","url":"https://finnihealth.com/resources/glossary/part-2-contractor-recipient-binding-clause","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 contractor recipient binding clause","item":"https://finnihealth.com/resources/glossary/part-2-contractor-recipient-binding-clause"}]}}
Glossary term

Part 2 contractor recipient binding clause

Learn how a Part 2 contractor clause binds a downstream recipient to the regulation when patient-identifying information is received and accessed.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

vendor bound by Part 2 SUD contractor compliance term

The contractor recipient binding clause is the legal term required by § 2.33 for specified non-HIPAA lawful-holder redisclosures. It provides that the contractor, subcontractor, or voluntary legal representative is fully bound by Part 2 when it receives patient-identifying information. The clause should apply to the correct recipient and data flow, then connect to usable safeguards, notice, reporting, and downstream restrictions.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.33(c) requires the written contract or comparable legal instrument to provide that each contractor, subcontractor, or voluntary legal representative is fully bound by Part 2 upon receiving patient-identifying information. The clause should cover the actual receiving entity and its role in the lawful holder's consented payment or health care operations task.

Name the covered recipient and receipt

Current 42 CFR 2.33(c) links the obligation to receipt of patient-identifying information. Define recipient entities, affiliates, workforce, subcontractors, systems, transfer methods, information, effective time, and any excluded service. Avoid a clause that covers only the vendor's parent company.

Turn the clause into operations

Contract language needs access provisioning, training, approved uses, logging, monitoring, incident escalation, subcontractor approval, correction, termination, return, deletion, and evidence. Assign owners on both sides and test the route before production data flows.

Do not substitute labels for analysis

The HHS Part 2 fact sheet explains the current alignment framework. Calling a company a vendor, processor, agent, business associate, or law firm does not settle Part 2 or HIPAA status. Classify the actual relationship.

Identify every receiving entity

Map the contracting party, affiliates, service entities, subprocessors, voluntary legal representatives, hosting providers, support teams, and contract agents that can receive or access the information. Record legal name, service, system, location, access route, data, and upstream relationship. A brand name or parent-company signature may not bind a different operating entity.

Distinguish mere infrastructure with no access from a recipient that can view, store, process, or recover the data. Route uncertainty to privacy, security, procurement, and counsel.

Draft the trigger and scope clearly

Tie the obligation to receipt of patient-identifying information and cover the approved service term, data locations, users, copies, backups, outputs, and incident evidence. State that the recipient is fully bound by Part 2, then align definitions and priority clauses so another term does not narrow the obligation.

Address subcontractor and agent flow-down before access. Do not rely on a promise that the vendor will “use industry standards” without Part 2 recipient coverage.

Translate the clause into controls

Provision only approved users and systems. Require role limits, authentication, training, logging, monitoring, secure transmission and storage, export controls, correction handling, incident escalation, and termination. Deliver and preserve the required notice. Verify that the vendor's support, disaster-recovery, and testing paths follow the same restrictions.

The HHS Part 2 fact sheet provides current framework context, but a HIPAA or generic processor label does not settle which Part 2 route and terms apply.

Test against the data map

Compare executed entities and services with network routes, cloud accounts, subprocessors, logs, tickets, backups, analytics, exports, and returned outputs. Use sample transactions to verify access and prohibited paths. Reconcile every recipient in the technical map to an approved instrument and role.

Block or suspend a route when an entity, system, or service is missing from the agreement. Do not wait for renewal to resolve an active coverage gap.

Govern change and failure

Require notice and approval for new subprocessors, locations, features, integrations, and uses. Revalidate the binding term after assignment, merger, restructuring, or service migration. At termination, remove access and resolve retained copies under the approved instrument.

If an unbound recipient received information, contain access, identify all data and downstream parties, preserve evidence, assess reporting and notification duties, execute corrective terms where appropriate, and verify technical remediation.

Keep evidence of the recipient's operational acceptance of these controls with the signed instrument and access approval, especially when implementation duties are divided among multiple vendor teams.

Example

Fourteen instruments are tested against live data maps. Twelve bind every receiving entity and system to Part 2 and connect the term to access, training, logs, incident routing, and termination; two omit a subcontractor platform. Clause coverage is 12 of 14 instruments.

Recipient-binding checklist

  • inventory each entity, affiliate, subcontractor, representative, agent, and system;
  • bind the actual recipient to Part 2 upon receipt of patient-identifying information;
  • align definitions, service scope, data, locations, term, and document priority;
  • connect the clause to notice, access, training, logs, safeguards, and incident response;
  • reconcile contractual recipients with technical routes and returned outputs; and
  • govern subprocessors, migrations, assignment, termination, gaps, and remediation.

A binding clause should follow every real recipient. Coverage of the vendor's parent or primary platform does not automatically cover the rest of the chain.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni