{"@context":"https://schema.org","@type":"Article","headline":"Part 2 copied-record audit agreement","description":"Learn the written security, destruction, retention, and use duties required when Part 2 audit records are copied, downloaded, removed, or forwarded.","url":"https://finnihealth.com/resources/glossary/part-2-copied-record-audit-agreement","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 copied-record audit agreement","item":"https://finnihealth.com/resources/glossary/part-2-copied-record-audit-agreement"}]}}
Glossary term

Part 2 copied-record audit agreement

Learn the written security, destruction, retention, and use duties required when Part 2 audit records are copied, downloaded, removed, or forwarded.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

SUD audit download agreement Part 2 audit data removal

A copied record agreement under Part 2 is the written commitment required when an auditor or evaluator copies, removes, downloads, or forwards patient-identifying records to another system or device. The person agrees to maintain and destroy the information under the program's Part 2 security policies, follow applicable federal, state, and local retention laws, and comply with the rule's use and disclosure limits. Eligible sponsor conditions also apply.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Record movement triggers added commitments

42 CFR 2.53 covers paper copies, removed media, downloads, and electronic forwarding. Treat vendor portals, cloud folders, secure file transfer, local workstations, analytics platforms, backup copies, email, and print workflows as possible data movement.

Map the records from source screen or repository through query, staging, export, encryption, transmission, intake, processing, workpapers, outputs, backups, logs, archive, return, and destruction. Include screenshots, clipboard, browser cache, remote desktop transfer, collaboration tools, local notes, mobile devices, removable media, and subcontractors.

The pathway changes as soon as patient-identifying information leaves the controlled no-copy environment. Stop the session and complete copied-record review before permitting a new download, print, photograph, forward, or local note.

The agreement covers three rule areas

State how the recipient maintains and destroys patient-identifying information under 42 CFR 2.16 policies, retains required records under applicable law, and follows 42 CFR 2.53 use and disclosure limits. Add systems, locations, people, subcontractors, incidents, return, deletion, and evidence needed for the actual engagement.

Identify the audit, sponsor, purpose, population, fields, dates, users, devices, environments, approved outputs, onward recipients, access period, incident route, legal-demand route, security measures, retention source, litigation hold, return, destruction method, sanitization, verification, and responsible owners. Attach data-flow and copy inventories rather than relying on a generic confidentiality clause.

Resolve retention and destruction together. Some oversight records may need to be kept while patient-identifying working data must be removed when its supported period ends. Qualified privacy, records, audit, security, and legal owners should identify each artifact and source of obligation.

Turn the agreement into controls

Create named accounts, least-privilege roles, multifactor authentication where appropriate, secure transfer, encryption, download and forwarding restrictions, monitoring, access expiry, output review, incident reporting, and vendor flow-down. Verify that contract terms reach the actual systems and people.

Require approval before a new user, subcontractor, platform, data field, purpose, output, or copy. Scheduled transfers should stop on agreement or sponsor expiry. Preserve exceptions and compensating controls with an owner and date.

Eligible performance remains a separate gate

The person also performs the audit or evaluation for a government agency, financial-assistance source, payer or health plan, QIO, qualifying related party, or entity with direct administrative control as the rule provides. A signed security agreement alone does not establish that relationship.

Match the legal entity, contract, delegation chain, covered population, financial or regulatory relationship, and reviewer to the applicable route. Also verify that the activity itself is a qualifying audit or evaluation. A vendor may protect data well while lacking eligible sponsorship or using it for an unsupported analytics purpose.

Reconcile and close every copy

At project end, compare transfer manifests, system inventories, users, workpapers, outputs, backups, vendors, holds, retention, returned files, destruction certificates, and access logs. Investigate gaps rather than accepting a broad deletion attestation. Keep closure evidence and required audit records under the approved schedule.

If data reached an unsupported destination or survived beyond its period, contain access, preserve evidence, and route privacy, security, audit, payer, legal, clinical, and patient communication decisions. Review other engagements using the same vendor or platform.

Example with audit vendors

Nine vendors would receive copied records. Seven have qualifying sponsorship and complete written duties; two lack a supported sponsor or destruction term. Agreement readiness is 7 of 9 vendors.

One vendor obtains a supported sponsor delegation and a copy-level destruction schedule. The other remains held because its cloud service retains data for secondary use. The seven approved vendors proceed only after their technical configurations match the agreement.

Copied-record checklist

  • Map every copy, device, system, user, vendor, backup, and output.
  • Match the agreement to sponsor, purpose, records, dates, and data flow.
  • Address Part 2 security, retention, use, disclosure, and destruction duties.
  • Flow controls to subcontractors and real technical environments.
  • Stop access for new copies, users, tools, fields, or purposes pending review.
  • Reconcile manifests, retention, holds, return, deletion, and sanitization.
  • Investigate unexplained copies and related vendor configurations.

Owner controls

The 2024 final rule provides current context. Use data-flow maps, approved agreements, sponsor checks, secure-transfer tests, access inventories, retention schedules, deletion evidence, and final reconciliation.

Monitor copied-record engagements, users, transfers, destinations, contract changes, retention exceptions, deletions, output releases, and incidents. Audit from every copy back to an eligible sponsored purpose and from active vendor environments into current agreement and access evidence. Retest after platform, vendor, payer, security, or records-policy changes.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni