Good faith record receipt occurs when an investigative agency discovers that it received Part 2 records while investigating or prosecuting a program, record holder, employee, or agent. The agency secures the records under Part 2 security requirements and immediately stops using or disclosing them. It then follows the court-order, return, or destruction pathway within a reasonable time and the applicable 120-day outer limit.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Under live 42 CFR 2.66(a)(3), an investigative agency that discovers in good faith that it received Part 2 records during a program-side investigation must secure them and immediately stop using or disclosing them. It must then seek a qualifying order, lawfully return the records, or render patient identity non-retrievable through destruction within the stated timing rules.
Discovery starts an immediate control sequence
42 CFR 2.66 requires security and an immediate stop on use and disclosure. Record the discovery time, agency, matter, source, data set, systems, copies, people with access, prior activity, containment action, legal owner, and deadline.
Good faith is a fact, not a blanket cure
Preserve how the agency received and recognized the records. The later order application has added conditions, and information from records obtained in violation of Part 2 cannot support an application to obtain those records. Qualified counsel assesses provenance and next steps.
The holder should coordinate without broadening access
A program learning of the event can preserve its own evidence, verify destinations, identify affected data, restrict further transfer, and communicate through counsel and the designated privacy route. Avoid sending replacement files or narrative detail before authority and need are established.
Establish the discovery event
Record who recognized the Part 2 records, the exact date and time, how they recognized them, the original source, transfer route, matter, and responsible counsel. Preserve the request, subpoena, production, cover message, access logs, search history, and system alerts. Keep the discovery record factual because it starts the control sequence and timing analysis.
Identify every person who knew or reasonably should have known, without circulating the protected content to investigate awareness.
Secure records and stop activity
Isolate primary files, attachments, exports, local downloads, shared folders, analytic workspaces, notes, reports, images, printouts, and removable media. Apply access restrictions consistent with Part 2 security requirements. Pause searches, analysis, testimony, referrals, automated processing, model use, and external sharing that depend on the records.
Preservation can continue under counsel direction. A legal hold keeps evidence available internally; it does not authorize investigative use.
Examine provenance and diligence
Determine whether receipt and discovery were genuinely in good faith and whether the agency satisfied the section 2.3(b) reasonable-diligence conditions where relevant. Document pre-demand searches, timing, provider website or location review, available privacy notices, and what the agency knew. Do not rely on the protected records themselves to repair unlawful provenance.
Counsel should separate past activity, current containment, potential noncompliance, and future authority. Each question may require a different response.
Choose and complete a lawful path
Create an early decision date for seeking an order, returning records when legally permissible, or destroying them so identity is non-retrievable. Track the reasonable-time duty and 120-day outer limit. If the court finally rejects an application, trigger immediate return or destruction after notice.
Reconcile all copies, derivatives, recipients, backups, and disposition evidence. Coordinate with the source holder through a protected legal or privacy channel without requesting unnecessary replacement data.
Assess activity before discovery
Under counsel direction, preserve who accessed, searched, analyzed, quoted, transferred, or relied on the records before the stop. Use system logs and interviews that minimize renewed exposure. Separate protected-source facts from independently obtained evidence, and flag any report, lead, decision, or testimony that may be tainted. The review supports containment and legal assessment; it does not permit additional investigative use of the records.
Example with discovered data sets
Six discovered data sets are reviewed. Five have documented security, immediate stop, copy inventory, counsel owner, and deadline; one remains active in an analytic workspace. Response completeness is 5 of 6 data sets.
Owner controls
The 2024 final rule created this procedure. Use discovery triggers, system isolation, access logs, copy inventories, no-use flags, counsel escalation, 120-day clocks, and verified disposition.
Good-faith-discovery checklist
- preserve the receipt, recognition, discovery time, source, and access history;
- secure every copy and immediately stop use and disclosure;
- suspend derivatives, searches, reports, referrals, testimony, and automation;
- document provenance and applicable section 2.3(b) diligence;
- select the order, lawful-return, or non-retrievable-destruction path; and
- reconcile timing, court outcome, copies, recipients, and final disposition.
Good faith is supported by the facts surrounding receipt and discovery. The operational response must still satisfy every security, no-use, timing, and disposition duty.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni