Formal security policies under 42 CFR 2.16 are required for Part 2 programs and other lawful holders of patient-identifying information, subject to the rule's informal-caregiver exception. The policies and procedures must reasonably protect against unauthorized uses and disclosures and reasonably anticipated threats or hazards. They also must address the listed paper and electronic record activities across the information lifecycle.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.16(a) requires each Part 2 program or other lawful holder of patient-identifying information to maintain formal policies and procedures that reasonably protect against unauthorized uses and disclosures and reasonably anticipated security threats or hazards. Paragraph (a)(1) lists paper and electronic lifecycle topics the policies must address. The HHS fact sheet identifies February 16, 2026 as the compliance date for the 2024 amendments.
Start with role and data scope
Current 42 CFR 2.16 assigns the duty to Part 2 programs and other lawful holders. Inventory entities, programs, lawful-holder roles, records, systems, paper media, devices, locations, vendors, recipients, data flows, owners, and applicable exceptions.
Cover every listed lifecycle activity
Policies should address paper transfer, removal, destruction, secure storage, use, access, and de-identification, plus electronic creation, receipt, maintenance, transmission, destruction, use, access, and de-identification. Map each item to procedures and evidence.
Formal policy needs operating proof
Assign approval, version, owner, effective date, training, role access, technical and physical controls, vendor requirements, incident routing, testing, audit, corrective action, change review, retention, and retirement. Align HIPAA and state duties where applicable.
Start with the information and systems actually in scope
Inventory where patient-identifying information is created, received, maintained, transmitted, viewed, printed, copied, exported, backed up, archived, and destroyed. Include clinical and billing systems, portals, email, messaging, file exchange, devices, removable media, paper, scanners, printers, faxes, call recordings, data warehouses, logs, tickets, test environments, vendors, and informal workarounds.
For each location, record owner, purpose, data, users, access path, recipient, retention, backup, disposal, agreement, and incident contact. Reconcile the inventory with contracts, network and application discovery, role lists, printer and storage walkthroughs, and staff interviews.
Turn the regulatory topics into owned procedures
The policy set should address paper transfer and removal, destruction and hard-copy sanitization, secure storage, workstations and physical access, and de-identification. For electronic records, cover creation, receipt, maintenance, transmission, destruction and media sanitization, access and use, and de-identification. Link each requirement to a detailed procedure, accountable role, system control, evidence, exception process, and review interval.
Also define risk assessment, access approval, authentication, workforce changes, training, vendor oversight, monitoring, backup, recovery, incident response, breach escalation, legal hold, retention, change management, and corrective action. Avoid a policy that merely repeats the regulation without telling staff what to do.
Govern approval, exceptions, and evidence
Name executive, privacy, security, records, clinical, legal, facilities, information-technology, and vendor owners. Record approver, effective date, version, systems covered, review date, and superseded policy. Make current procedures accessible to the people who perform them while limiting sensitive security detail appropriately.
Require documented risk acceptance for exceptions, with reason, data, duration, compensating controls, approver, monitoring, and closure. Preserve training records, access reviews, configuration evidence, destruction certificates, incident tests, vendor reviews, and remediation results.
Test the policy against real events
Run tabletop and technical scenarios involving misdirected email, stolen paper, lost device, improper portal access, insider curiosity, vendor compromise, ransomware, backup failure, printing, remote work, and emergency downtime. Compare actual actions with the written procedure and fix both where they diverge.
Review after incidents, material system or vendor changes, acquisitions, new locations, rule changes, and at a defined interval. Measure overdue access removal, unresolved risks, failed backups, unsupported systems, untracked exports, late incident escalation, and corrective-action closure.
Keep a minimum evidence package
For each required topic, retain the approved policy, operating procedure, control owner, system or location scope, last review, staff training, configuration or physical evidence, test result, exception, incident linkage, and remediation status. A reviewer should be able to trace the rule to a daily action and then to proof that the action occurred.
Sample evidence across locations, shifts, remote work, vendors, and downtime rather than relying on headquarters documentation. Interview staff who transfer, store, print, release, administer, and destroy records. Differences between the written process and actual work become tracked findings with owners and dates.
Leaders can ask which information remains uninventoried, which control lacks evidence, which exception is overdue, which vendor has not been tested, and which incident should have changed policy. Review those answers with the risk register and budget.
Example
Eighteen policy domains are assessed. Fifteen have current owner, procedure, control, training, test, evidence, and remediation; three are copied templates without implementation. Completeness is 15 of 18 domains.
Formal-security-policy checklist
- inventory every paper, electronic, device, communication, vendor, and backup location;
- map each section 2.16 lifecycle topic to an owned procedure and control;
- define access, training, vendor, risk, incident, retention, and change processes;
- version, approve, distribute, review, and retire policies and procedures;
- document exceptions, evidence, testing, findings, and corrective action; and
- update after incidents, system changes, organizational changes, and legal changes.
Formal means approved, implemented, testable, and maintained. A template or policy document alone does not show reasonable protection in practice.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni