A TPO redisclosure by a covered entity is the § 2.33 pathway for a HIPAA covered entity or business associate that receives Part 2 records for treatment, payment, or health care operations. The recipient may further disclose those records according to HIPAA, while the separate Part 2 restriction on uses and disclosures in proceedings against the patient still applies. Recipient status and purpose must be verified.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.33(b)(1) permits a covered entity or business associate that receives Part 2 records for treatment, payment, or health care operations to further disclose them in accordance with HIPAA. The paragraph expressly excludes uses and disclosures for civil, criminal, administrative, and legislative proceedings against the patient. HIPAA status, TPO receipt, HIPAA authority, and the proceeding screen all matter.
Classify the recipient before applying the rule
Current 42 CFR 2.33(b)(1) applies to a covered entity or business associate receiving records for TPO. Record entity status, business-associate role where relevant, consented purpose, source program, receipt date, data, and downstream activity.
Preserve the proceeding restriction
A HIPAA-permitted TPO disclosure does not erase Part 2's protections for civil, criminal, administrative, or legislative proceedings against the patient. Route subpoenas, testimony requests, investigations, litigation holds, and agency demands to qualified privacy and legal review.
Map both rule sets
The HHS Part 2 final-rule fact sheet describes alignment with HIPAA while retaining specific Part 2 protections. Document which HIPAA permission applies, which Part 2 restriction remains, who decided, and what evidence supports the decision.
Verify recipient status and receipt
Document whether the recipient is a HIPAA covered entity or business associate, the basis for that status, applicable service and relationship, reviewer, date, and change triggers. Link the records to the consented TPO disclosure through which they were received. Do not rely only on a directory label, contract title, or vendor assertion.
Reassess after corporate changes, new services, terminated agreements, or role changes. The same organization may act in different capacities for different data and activities.
Identify the HIPAA permission
Classify the downstream use or disclosure as treatment, payment, health care operations, or another specific HIPAA permission and document its conditions. Apply minimum-necessary rules where applicable, verify recipients, protect transmission, and preserve the selected records and decision.
The HHS Part 2 fact sheet explains alignment, but alignment does not mean the Part 2 origin or remaining restrictions can be discarded.
Screen proceedings against the patient
Before using or producing the records for a civil, criminal, administrative, or legislative proceeding against the patient, stop this route. Identify subpoenas, warrants, testimony, discovery, investigations, agency requests, legislative inquiries, litigation holds, internal legal tickets, and requests framed as routine records work.
Send the matter to Part 2 privacy and experienced counsel for the specific subpart E or other analysis. A HIPAA permission, subpoena language, or requester deadline alone does not remove the Part 2 restriction.
Carry provenance and restrictions
Tag the data with Part 2 origin, consent or receipt pathway, source, patient, permitted handling, proceeding restriction, and disclosure history. Preserve that context through chart ingestion, HIEs, data warehouses, billing, vendors, analytics, exports, legal systems, and backups. Configure access and export controls around actual use.
Use the section 2.32 notice when it applies to the disclosure and preserve its version with the payload. Do not assume a banner that users can dismiss controls downstream copies.
Audit real redisclosures
Sample TPO and non-TPO decisions, legal requests, exports, vendor access, merged data, and blocked matters. Verify entity role, source receipt, HIPAA pathway, Part 2 screen, selected content, recipient, notice, secure delivery, and evidence. Include denials and abandoned requests in the review.
For an improper disclosure, contain it, preserve request and transmission evidence, seek qualified legal guidance, assess notifications, correct routing and access, and retest the controls.
Train legal, compliance, records, and clinical teams on the proceeding screen together. A request can enter through any of those functions, and fragmented ownership can allow the same restricted records to leave through a different queue.
Example
Thirteen downstream disclosures are sampled. Eleven record covered-entity or business-associate status, TPO purpose, HIPAA pathway, Part 2 proceeding screen, recipient, and evidence; two rely only on a vendor directory. Control completeness is 11 of 13 disclosures.
Covered-entity redisclosure checklist
- verify covered-entity or business-associate status for the actual activity;
- link records to their consented treatment, payment, or operations receipt;
- document the HIPAA permission and every applicable condition;
- block proceedings against the patient from this redisclosure route;
- preserve Part 2 provenance, notice, access, export, and disclosure evidence; and
- audit legal requests, merged systems, vendors, denials, incidents, and corrections.
HIPAA supplies the downstream permission in this branch. Part 2 still supplies a specific boundary that the recipient must enforce.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni