{"@context":"https://schema.org","@type":"Article","headline":"Part 2 covered-entity TPO redisclosure","description":"Learn the Part 2 boundary for further TPO disclosures by a HIPAA covered entity or business associate that receives consented records and verifies purpose.","url":"https://finnihealth.com/resources/glossary/part-2-covered-entity-tpo-redisclosure","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 covered-entity TPO redisclosure","item":"https://finnihealth.com/resources/glossary/part-2-covered-entity-tpo-redisclosure"}]}}
Glossary term

Part 2 covered-entity TPO redisclosure

Learn the Part 2 boundary for further TPO disclosures by a HIPAA covered entity or business associate that receives consented records and verifies purpose.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

HIPAA recipient Part 2 redisclosure covered entity SUD TPO sharing

A TPO redisclosure by a covered entity is the § 2.33 pathway for a HIPAA covered entity or business associate that receives Part 2 records for treatment, payment, or health care operations. The recipient may further disclose those records according to HIPAA, while the separate Part 2 restriction on uses and disclosures in proceedings against the patient still applies. Recipient status and purpose must be verified.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.33(b)(1) permits a covered entity or business associate that receives Part 2 records for treatment, payment, or health care operations to further disclose them in accordance with HIPAA. The paragraph expressly excludes uses and disclosures for civil, criminal, administrative, and legislative proceedings against the patient. HIPAA status, TPO receipt, HIPAA authority, and the proceeding screen all matter.

Classify the recipient before applying the rule

Current 42 CFR 2.33(b)(1) applies to a covered entity or business associate receiving records for TPO. Record entity status, business-associate role where relevant, consented purpose, source program, receipt date, data, and downstream activity.

Preserve the proceeding restriction

A HIPAA-permitted TPO disclosure does not erase Part 2's protections for civil, criminal, administrative, or legislative proceedings against the patient. Route subpoenas, testimony requests, investigations, litigation holds, and agency demands to qualified privacy and legal review.

Map both rule sets

The HHS Part 2 final-rule fact sheet describes alignment with HIPAA while retaining specific Part 2 protections. Document which HIPAA permission applies, which Part 2 restriction remains, who decided, and what evidence supports the decision.

Verify recipient status and receipt

Document whether the recipient is a HIPAA covered entity or business associate, the basis for that status, applicable service and relationship, reviewer, date, and change triggers. Link the records to the consented TPO disclosure through which they were received. Do not rely only on a directory label, contract title, or vendor assertion.

Reassess after corporate changes, new services, terminated agreements, or role changes. The same organization may act in different capacities for different data and activities.

Identify the HIPAA permission

Classify the downstream use or disclosure as treatment, payment, health care operations, or another specific HIPAA permission and document its conditions. Apply minimum-necessary rules where applicable, verify recipients, protect transmission, and preserve the selected records and decision.

The HHS Part 2 fact sheet explains alignment, but alignment does not mean the Part 2 origin or remaining restrictions can be discarded.

Screen proceedings against the patient

Before using or producing the records for a civil, criminal, administrative, or legislative proceeding against the patient, stop this route. Identify subpoenas, warrants, testimony, discovery, investigations, agency requests, legislative inquiries, litigation holds, internal legal tickets, and requests framed as routine records work.

Send the matter to Part 2 privacy and experienced counsel for the specific subpart E or other analysis. A HIPAA permission, subpoena language, or requester deadline alone does not remove the Part 2 restriction.

Carry provenance and restrictions

Tag the data with Part 2 origin, consent or receipt pathway, source, patient, permitted handling, proceeding restriction, and disclosure history. Preserve that context through chart ingestion, HIEs, data warehouses, billing, vendors, analytics, exports, legal systems, and backups. Configure access and export controls around actual use.

Use the section 2.32 notice when it applies to the disclosure and preserve its version with the payload. Do not assume a banner that users can dismiss controls downstream copies.

Audit real redisclosures

Sample TPO and non-TPO decisions, legal requests, exports, vendor access, merged data, and blocked matters. Verify entity role, source receipt, HIPAA pathway, Part 2 screen, selected content, recipient, notice, secure delivery, and evidence. Include denials and abandoned requests in the review.

For an improper disclosure, contain it, preserve request and transmission evidence, seek qualified legal guidance, assess notifications, correct routing and access, and retest the controls.

Train legal, compliance, records, and clinical teams on the proceeding screen together. A request can enter through any of those functions, and fragmented ownership can allow the same restricted records to leave through a different queue.

Example

Thirteen downstream disclosures are sampled. Eleven record covered-entity or business-associate status, TPO purpose, HIPAA pathway, Part 2 proceeding screen, recipient, and evidence; two rely only on a vendor directory. Control completeness is 11 of 13 disclosures.

Covered-entity redisclosure checklist

  • verify covered-entity or business-associate status for the actual activity;
  • link records to their consented treatment, payment, or operations receipt;
  • document the HIPAA permission and every applicable condition;
  • block proceedings against the patient from this redisclosure route;
  • preserve Part 2 provenance, notice, access, export, and disclosure evidence; and
  • audit legal requests, merged systems, vendors, denials, incidents, and corrections.

HIPAA supplies the downstream permission in this branch. Part 2 still supplies a specific boundary that the recipient must enforce.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni