Part 2 electronic accounting is the patient's right to an accounting of disclosures of electronic records under Part 2 for the past three years. The notice states the right and briefly explains how to exercise it. Programs should define the request route, identity or authority check, electronic-record scope, disclosure events, three-year window, exclusions, response owner, format, corrections, and appeal or complaint path.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
The notice should lead to a working request
42 CFR 2.22 names the electronic-record accounting right and separately addresses other accounting and intermediary-list rights. The notice should help the patient choose the correct path without forcing them to know regulatory terminology.
Publish plain instructions through a monitored contact, form, phone, email, portal, or office route under program policy. Accept an ordinary request for “who received my records” and classify it rather than rejecting it for missing regulatory terms. Preserve receipt time, patient or representative, safe response preference, program and record scope, requested period, accessibility needs, owner, and clarification.
Define electronic records and source systems
Maintain an inventory of EHR, HIE, portal, API, document exchange, billing, laboratory, pharmacy, data warehouse, analytics, messaging, email, secure file transfer, vendor, archive, legacy, and backup systems that created, maintained, or transmitted relevant electronic records during the lookback. Record owner, active dates, event schema, retention, migration, export method, provenance, known gaps, and test date.
Do not limit the search to today's production systems. Acquired platforms, retired interfaces, vendor archives, copied documents, and migrated logs may hold part of the three-year history. Preserve contracts and export capabilities before decommissioning.
The three-year period needs event logic
Define the request received date, lookback boundary, time zone, disclosure date, record format, source systems, data migrations, event deduplication, exclusions, and response date. Preserve the query and source evidence used to assemble the accounting.
Use one documented window calculation with start, end, inclusion rule, and time zone. Normalize events without losing original timestamps. Define how retries, failed transmissions, batch disclosures, multi-recipient events, corrected identities, and duplicates are represented. Apply current exclusions and required fields through qualified review rather than filtering based on a generic audit-log label.
Map each event to patient, Part 2 record scope, source program, disclosure date, recipient, information or record category, purpose or authority, source system, and correction history as required for the response. Separate user access within a system from a disclosure event according to the governing definition.
Validate before secure delivery
Reconcile system inventory, sources queried, raw event totals, exclusions, duplicates, final rows, and unresolved gaps. Sample events back to source logs and patient records. Have a second reviewer check identity, period, recipient, completeness, plain-language formatting, and safe delivery. Avoid exposing another person's information or internal security detail that does not belong in the accounting.
Explain supported limitations, correction route, complaint route, and related rights. If a source is unavailable, keep the request under qualified ownership and pursue restoration rather than silently omitting it. Preserve the query code or parameters, exports, reviews, response, delivery evidence, and later corrections under restricted access.
Make migrations part of rights readiness
Before platform or vendor change, export disclosure events with schemas, time zones, identifiers, provenance, and documentation. Validate count and sample parity after migration. Maintain read access to legacy data through the full applicable periods. Include rights-response testing in decommission approval.
Example with source coverage
A request spans ten electronic systems active during the three-year window. Nine return validated disclosure data; one retired interface lacks an export. Source completeness is 9 of 10 systems. The response remains open with an owner and recovery plan.
The program restores the legacy export from a controlled archive, validates it against retained samples, and adds the events to the accounting. It records the initial 9-of-10 gap and final 10-of-10 source coverage. The patient receives the corrected, securely delivered response.
Electronic-accounting checklist
- Accept plain requests and preserve original receipt and safe contact.
- Inventory every active, legacy, vendor, and migrated electronic source.
- Calculate the three-year period with one documented time rule.
- Normalize, deduplicate, classify, and preserve original evidence.
- Reconcile all sources and sample events before response.
- Deliver securely with limitation, correction, and complaint routes.
- Test exports and rights retrieval before every decommission.
Owner controls
The 2024 final rule explains the aligned patient-right framework. Use a rights-request register, system inventory, event schema, retention and migration controls, secure delivery, correction path, and periodic retrieval test.
Monitor requests received, source coverage, retrieval age, unresolved systems, event corrections, secure delivery, complaints, and migration readiness. Audit from responses into source evidence and from every inventoried system into tested accounting output. Protect the rights queue because it can reveal Part 2 program participation.
Record every retrieval test, finding, owner, correction, and verified closure.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni