{"@context":"https://schema.org","@type":"Article","headline":"Part 2 discontinued-record encrypted-device option","description":"Learn the Part 2 encrypted portable-device option for electronic records retained after program closure, including key control, access, equipment, and evidence.","url":"https://finnihealth.com/resources/glossary/part-2-discontinued-record-encrypted-device-option","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 discontinued-record encrypted-device option","item":"https://finnihealth.com/resources/glossary/part-2-discontinued-record-encrypted-device-option"}]}}
Glossary term

Part 2 discontinued-record encrypted-device option

Learn the Part 2 encrypted portable-device option for electronic records retained after program closure, including key control, access, equipment, and evidence.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

portable encrypted SUD closure archive Part 2 retained electronic device

The Part 2 encrypted-device option for discontinued records permits retained electronic records to be transferred to a portable electronic device with encryption at rest and access controls for the confidential process or key. The implementation should prove completeness, encryption state, key custody, authorized access, readability, equipment availability, protected storage, and eventual sanitization.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.19(b)(2)(i)(A) permits legally retained discontinued-program electronic records to be transferred to a portable electronic device with encryption at rest that creates a low probability of assigning meaning without a confidential process or key, plus access controls for that process or key. NIST SP 800-88 Rev. 2 is technical sanitization guidance rather than Part 2 authority. The HHS fact sheet identifies February 16, 2026 as the compliance date.

The archive needs two kinds of control

Current 42 CFR 2.19(b)(2) requires encryption at rest that creates a low probability of assigning meaning without the confidential process or key, plus access controls for that process or key. Device possession alone is incomplete.

Validate the transfer

Inventory systems and record sets, export with integrity checks, reconcile counts, test representative files, preserve formats and required software, verify encryption before movement, document chain of custody, and retain transfer and error logs.

Plan the media lifecycle

NIST SP 800-88 Rev. 2 offers current general guidance for a media-sanitization program. It does not replace Part 2. Record device type, sensitivity, approved treatment, validation, storage, refresh or migration, failure handling, and final sanitization.

Define the archive record set and dependencies

Inventory databases, files, attachments, messages, email, logs, indexes, schemas, lookup tables, images, exports, audit history, software, drivers, licenses, and equipment needed to interpret the records. Record legal authority, retention end, holds, size, source systems, checksums, owner, and portable-device target.

Separate records that transfer by consent, qualify for another exception, or should be destroyed. Do not copy the full production environment merely because extracting the retained set requires work.

Select and configure the portable device

Choose media appropriate for capacity, retention duration, reliability, interface, environmental conditions, security, and future readability. Document device identifier, manufacturer and model, storage type, firmware, encryption design, initialization, owner, and intended storage container.

Implement encryption at rest and access controls for the confidential process or key as the rule requires. Use authorized identities, strong authentication, limited administration, tested recovery, and logging where feasible. Avoid a key written on the device, stored in the same bag, or shared through an abandoned closing-program account.

Create and verify the archive

Use controlled export, malware-safe handling, integrity checks, row and file counts, readable samples, metadata validation, and reconciliation to the source inventory. Record tools, versions, operator, date, result, exceptions, and verifier. Keep temporary working copies restricted and assign their disposition.

Test decryption and retrieval with the equipment and credentials that the future responsible person will have. Confirm that the test does not create an untracked clear-text copy. Preserve documentation in a form usable after staff, systems, and vendors leave.

Seal, store, and separate decryption capability

Place the portable device with needed reader equipment in the prescribed sealed and labeled container. Assign the responsible person to the access-control list and provide a usable decryption means. Store decryption tools on a separate device or at a separate location from the encrypted data.

Protect the container from theft, fire, water, temperature, humidity, physical damage, and unauthorized access. Record seals, location, access, inspections, opening, resealing, key tests, equipment replacement, and custody changes.

Sanitize former and final media

Within one year of discontinuation or acquisition, sanitize all media that held the information before the section 2.19 transfer, including email and other electronic communications, under section 2.16 procedures. Track systems, devices, backups, vendors, exports, and exceptions to completion.

After the legal retention period, recheck authority and holds and sanitize the portable device and remaining media so information is non-retrievable. NIST guidance can inform method selection and evidence, but the organization must apply the Part 2 end-state requirement.

Example

Ten encrypted-device archives are tested. Eight have complete inventory, transfer reconciliation, encryption verification, key-access control, read test, equipment, protected container, and final-action plan; two lack a readable format test. Readiness is 8 of 10 archives.

Encrypted-device checklist

  • inventory retained data, dependencies, authority, holds, end date, and source systems;
  • choose and document a reliable, supportable portable device and reader equipment;
  • implement encryption at rest and controlled confidential process or key access;
  • export, reconcile, integrity-check, decrypt-test, and document the archive;
  • seal, label, protect, inspect, and maintain separate decryption capability; and
  • sanitize former media within one year and final media after retention.

An encrypted portable device is one prescribed archive option, not a shortcut around inventory, custody, key governance, readability, source cleanup, or final sanitization.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni