{"@context":"https://schema.org","@type":"Article","headline":"Part 2 contractor written-instrument control","description":"Learn what a non-HIPAA lawful holder should verify in the written contract or legal instrument before contractor access to Part 2 patient records.","url":"https://finnihealth.com/resources/glossary/part-2-contractor-written-instrument-control","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 contractor written-instrument control","item":"https://finnihealth.com/resources/glossary/part-2-contractor-written-instrument-control"}]}}
Glossary term

Part 2 contractor written-instrument control

Learn what a non-HIPAA lawful holder should verify in the written contract or legal instrument before contractor access to Part 2 patient records.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

SUD contractor legal instrument lawful holder vendor contract requirement

The written-instrument control for a contractor is the § 2.33 requirement for a non-HIPAA lawful holder that wants to redisclose patient-identifying information to a contractor, subcontractor, or voluntary legal representative. A written contract or comparable legal instrument must be in place first. The signed instrument should connect the recipient, duties, data, purpose, Part 2 terms, safeguards, reporting, and downstream conditions.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.33(c) requires a non-HIPAA lawful holder to have a written contract or comparable legal instrument before redisclosing patient-identifying information to a contractor, subcontractor, or voluntary legal representative under paragraph (b)(3). The instrument must bind the recipient to Part 2 on receipt, and the lawful holder must furnish the section 2.32 notice, require appropriate safeguards and incident reporting, limit information to what the duties require, and constrain further disclosure.

Tie the instrument to the actual relationship

Current 42 CFR 2.33(c) requires the legal instrument before redisclosure. Record legal names, covered services, effective dates, termination, information categories, approved systems, locations, subcontractors, incident route, return or deletion, and accountable owners.

Verify execution and scope

A template, unsigned order form, expired agreement, or unrelated master services agreement does not prove that this recipient and task are covered. Preserve signatures, amendments, incorporated exhibits, priority terms, approval, renewal, and current vendor inventory linkage.

Include the disclosure notice workflow

The lawful holder must furnish the recipient the notice required by 42 CFR 2.32. Assign the notice version, delivery point, recipient acknowledgment when used, evidence location, and update process rather than relying on a hidden policy.

Confirm that this route applies

Document the lawful holder's receipt and non-HIPAA status, the payment or health care operations activity specified in consent, and why the recipient is performing that work on the holder's behalf. Identify the contractor, subcontractor, or voluntary legal representative and the precise task. Do not use a contractor instrument to support an independent purpose or unrelated service.

Preserve the classification analysis, source consent, data, responsible reviewer, date, and change triggers.

Assemble the operative instrument

Capture the correct legal names, entities, services, duties, information, systems, locations, authorized users, effective date, term, termination, subprocessing, access removal, return or deletion, audit rights, incident contacts, and priority among incorporated documents. Obtain all required signatures before access.

Review the master agreement, order form, data schedule, security exhibit, amendments, and referenced policies together. An unsigned template or purchase order does not prove coverage of the live relationship.

Include each Part 2 control

State that the recipient is fully bound by Part 2 upon receipt. Require the lawful holder to furnish the section 2.32 notice; require appropriate safeguards; require reports of unauthorized uses, disclosures, or breaches to the holder; and limit data to what the recipient needs for its stated duties. Restrict third-party disclosure to qualifying contract agents and the return-only path in section 2.33(c).

Counsel should approve language for the actual service and applicable law. A clause that merely says “comply with Part 2” may not operationalize the rule's elements.

Connect terms to access

Link the executed instrument and current vendor record to provisioning. Do not activate production routes until privacy, security, service owner, data map, notice delivery, user scope, and downstream agent review are complete. Configure expiration and termination holds rather than relying on calendar reminders.

Test the actual transfer, storage, logs, support access, exports, outputs, incident route, and return flow. Preserve approval, test results, and exceptions.

Renew, change, and close

Reassess amendments, new data, new systems, subprocessors, offshore locations, new purposes, corporate changes, renewals, and incidents. Suspend access when the instrument expires or no longer covers the service. At closure, disable access, resolve retained copies, verify return or deletion, and preserve evidence.

Audit the full vendor population for access without a current instrument, mismatched entities, omitted schedules, hidden agents, stale notices, excess data, weak incident clauses, and incomplete termination.

Example

Sixteen contractor relationships reach renewal. Thirteen have an executed current instrument mapped to service, data, notice, safeguards, reporting, agent chain, and end-of-service controls; three rely on old purchase orders. Instrument completeness is 13 of 16 relationships.

Written-instrument checklist

  • prove lawful-holder, non-HIPAA, consented-purpose, recipient, and task eligibility;
  • execute the complete instrument with correct entities, service, data, systems, and term;
  • bind recipients to Part 2 and include notice, safeguards, reporting, and data limits;
  • restrict third parties to qualifying agents and the return-only path;
  • connect signed terms to provisioning, testing, monitoring, renewal, and suspension; and
  • verify termination, access removal, retained copies, return, deletion, and evidence.

The control is the executed agreement plus its operational enforcement. Neither piece is sufficient on its own.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni