{"@context":"https://schema.org","@type":"Article","headline":"Part 2 disclose definition","description":"Learn how Part 2 defines direct, indirect, and verification-based communication that identifies a person's SUD status, care, or referral in practice.","url":"https://finnihealth.com/resources/glossary/part-2-disclose-definition","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 disclose definition","item":"https://finnihealth.com/resources/glossary/part-2-disclose-definition"}]}}
Glossary term

Part 2 disclose definition

Learn how Part 2 defines direct, indirect, and verification-based communication that identifies a person's SUD status, care, or referral in practice.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

SUD patient status communication verification of public information

Part 2 disclose means communicating information that identifies a person as having or having had an SUD, receiving or having received an SUD diagnosis, or being or having been referred for SUD treatment. Identification may occur directly, by reference to public information, or by verifying another person's identification. Confirmation, correction, metadata, and contextual clues can therefore disclose protected status.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

The HHS Part 2 final-rule fact sheet explains current consent, redisclosure, complaint, breach, and proceeding protections and confirms the February 16, 2026 compliance date. The published final rule supplies the agency's adopted text. Disclosure controls should be tested against the live definition across current communication channels, not only traditional record releases.

Disclosure can be indirect

42 CFR 2.11 includes verification and linkage to public information. Review names, dates, locations, programs, providers, rare events, family details, images, voices, codes, file names, URLs, message subjects, and surrounding context.

Silence and correction need planned responses

A confirmation, denial that reveals the correct facility, redirected call, portal error, scheduling message, or public reply can communicate status. Give staff approved neutral scripts, escalation routes, identity verification, and secure channels.

Every communication route belongs in scope

Map verbal, written, electronic, visual, system-to-system, public, legal, vendor, payer, family, and emergency communications. Record authority, consent or exception, recipient, purpose, data, notice, minimum scope, and disclosure evidence.

Test what the recipient can learn

Review the entire communication from the recipient's perspective. A name, facility, provider, date, rare event, referral source, image, voice, URL, file name, subject line, calendar invitation, caller identification, portal route, or surrounding public fact can identify a person as having SUD status, diagnosis, treatment, or referral.

The definition includes direct communication, reference to publicly available information, and verification by another person. Confirmation is not required; a denial, correction, transfer, or “wrong program” response can reveal the protected fact when combined with what the requester already knows.

Give staff a safe response route

Create neutral scripts for phone, email, front desk, scheduling, portal, media, legal, payer, vendor, and family inquiries. Authenticate identity and authority through an approved channel before acknowledging a patient relationship. Move sensitive communication to a secure route and escalate uncertain requests without naming the program or person in a broad ticket.

Train staff to protect silence and nonresponse patterns. Consistently handle people who are and are not patients so workflow behavior does not confirm status. Test voicemail greetings, directory listings, envelopes, caller names, text previews, and shared calendars.

Build a send gate

Before communication, record sender, recipient, verified identity, authority, consent or exception, purpose, minimum information, date range, notice, secure channel, and logging requirement. Review attachments, metadata, hidden rows, tracked changes, links, access permissions, and reply-all risk. Require a second check for high-risk recipients or bulk releases.

Map downstream redisclosure and use terms separately. A permitted disclosure does not make every later use or communication permissible. Record the released version and any patient-facing explanation required by the workflow.

Handle public and automated channels

Public reviews, social media, fundraising, websites, chatbots, automated reminders, call routing, analytics pixels, and notification services can disclose through content or context. Avoid responding publicly in a way that confirms treatment status. Configure vendors and messages to minimize program identity and sensitive preview text.

When a message is misdirected or status is revealed, preserve evidence, contain access, notify privacy and security, perform the current incident and breach analysis, correct systems, and document recipient follow-up. Do not delete the only evidence before review.

Example

Twenty-two proposed messages receive review. Eighteen pass direct, indirect, verification, metadata, and context checks; four reveal status through subject lines or facility names. Readiness is 18 of 22.

Part 2 disclosure checklist

  • assess direct content, public linkage, verification, metadata, and context;
  • authenticate recipient and authority without first confirming patient status;
  • document consent or exception, purpose, minimum data, notice, and channel;
  • inspect attachments, permissions, previews, subject lines, and automated routing;
  • preserve the released version, disclosure log, and downstream restrictions; and
  • contain and review misdirected or revealing communications as incidents.

The definition does not decide that a communication is permitted or that an incident is a breach. Current Part 2, HIPAA, state law, contracts, recipient facts, and purpose require qualified privacy and legal review.

Keep a disclosure decision record that identifies sender, authenticated recipient, authority, consent or exception, purpose, minimum data, message and attachment version, metadata review, channel, notice, date, and downstream limits. Link the disclosure log to the protected source without putting revealing status in broad workflow labels. When a correction or misdirection occurs, preserve the original communication, contain access, document recipient contact, update affected systems, and record the qualified privacy, security, and legal conclusion.

Verify closure with the accountable privacy owner.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni