{"@context":"https://schema.org","@type":"Article","headline":"Part 2 discontinued-record dual-media option","description":"Learn the Part 2 original-and-backup encrypted-media option for records retained after SUD program closure, with separation, verification, and custody controls.","url":"https://finnihealth.com/resources/glossary/part-2-discontinued-record-dual-media-option","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 discontinued-record dual-media option","item":"https://finnihealth.com/resources/glossary/part-2-discontinued-record-dual-media-option"}]}}
Glossary term

Part 2 discontinued-record dual-media option

Learn the Part 2 original-and-backup encrypted-media option for records retained after SUD program closure, with separation, verification, and custody controls.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

encrypted original and backup SUD records Part 2 separate media closure archive

The Part 2 dual media option for discontinued records permits electronic records and a backup copy to be transferred to separate electronic media when both copies use encryption at rest and access controls for the confidential process or key. The two copies need independent inventory, custody, location, integrity testing, equipment, protection, access logs, and final sanitization.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.19(b)(2)(i)(B) permits legally retained discontinued-program electronic records to be transferred with a backup copy to separate electronic media. Both the original and backup media must have encryption at rest that creates a low probability of assigning meaning without a confidential process or key, plus access controls for that process or key. NIST SP 800-88 Rev. 2 is technical guidance rather than Part 2 authority.

Separate media should reduce one failure path

The § 2.19 option calls for records plus a backup copy on separate electronic media. Document media identifiers, copy relationship, physical or logical separation, location, custodian, encryption, key access, environment, and shared dependencies.

Verify both copies

Reconcile record counts and checksums where appropriate, test representative retrieval, record failed files, confirm required readers and software, protect the original during testing, and schedule periodic integrity and compatibility checks across the retention period.

Treat aging and failure deliberately

Use current technical guidance such as NIST SP 800-88 Rev. 2 for media-program design. Plan media refresh, format migration, device failure, lost equipment, compromise, replacement, copy retirement, sanitization validation, and evidence.

Define two complete and distinct media copies

Inventory the retained databases, files, attachments, messages, email, logs, schemas, keys, indexes, software, and reader equipment. Record legal authority, end date, holds, source, counts, checksums, size, owner, and the original and backup media identifiers.

Confirm both media contain the complete approved record set and only that set. A backup that omits attachments or an “original” that depends on the discontinued production database will not provide the intended retained archive.

Select media and encryption deliberately

Choose separate electronic media appropriate to capacity, retention length, durability, interface, storage conditions, support, and future readability. Document manufacturer, model, serial or asset identifier, storage type, firmware, encryption design, initialization, and destination.

Apply encryption at rest and access controls for each copy's confidential process or key. Decide whether copies use the same or different key material through a documented risk and recovery design. Prevent one lost account, credential, device, or vendor relationship from making both copies unreadable or exposed.

Create, reconcile, and test both copies

Use controlled exports and verified tools. Compare file and row counts, checksums, metadata, date ranges, and readable samples against the source inventory and between media. Record operator, date, tool version, errors, correction, verification, and final hash or comparable integrity evidence.

Test restoration and decryption from each copy using the preserved reader equipment and responsible-person process. Avoid leaving test extracts behind. Schedule periodic condition, readability, and key-availability checks appropriate to the medium and duration.

Seal, store, and govern access

Follow section 2.19's sealed-container and labeling procedure with equipment needed to read or access the information. Assign the responsible person, access-control-list membership, decryption means, separate key or tool storage, protected environment, opening log, resealing, and succession plan.

Document the physical location and custody of each media item even when the prescribed materials are held together. “Separate electronic media” requires distinct media; backup status should not be inferred from two directory names on one physical device.

Remove source copies and execute final disposition

Inventory prior media and sanitize it within one year of discontinuation or acquisition, including email and other electronic communications. Cover servers, cloud services, laptops, removable media, backups, vendors, caches, and exports. Investigate unverified deletion or missing assets.

At the retention end, recheck legal authority and holds, authorize final sanitization, reconcile both media and reader equipment, apply appropriate methods, verify non-retrievability, preserve evidence, and close the archive inventory.

Example

Nine dual-media archives reach review. Seven have two reconciled encrypted copies, separate locations, controlled keys, read tests, equipment, monitoring, and final treatment; two share one failed reader. Readiness is 7 of 9 archives.

Dual-media checklist

  • inventory exact retained records, dependencies, authority, holds, and end date;
  • create a complete original and backup on distinct electronic media;
  • encrypt both at rest and control each confidential process or key;
  • reconcile counts and integrity and test decryption from each copy;
  • seal, label, protect, log, inspect, and maintain equipment and key access; and
  • sanitize all prior media within one year and both archive media after retention.

Two folders on one device are not separate media. The option depends on two controlled, encrypted, readable, reconciled media copies and an executable disposition plan.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni