{"@context":"https://schema.org","@type":"Article","headline":"Part 2 neutral denial response","description":"Learn how to answer an impermissible Part 2 request without affirmatively revealing that an identified person has received SUD diagnosis or treatment.","url":"https://finnihealth.com/resources/glossary/part-2-neutral-denial-response","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 neutral denial response","item":"https://finnihealth.com/resources/glossary/part-2-neutral-denial-response"}]}}
Glossary term

Part 2 neutral denial response

Learn how to answer an impermissible Part 2 request without affirmatively revealing that an identified person has received SUD diagnosis or treatment.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

SUD records request nonconfirming response Part 2 cannot confirm or deny

A neutral denial response answers an impermissible Part 2 request without affirmatively revealing that an identified person has been or is being diagnosed or treated for an SUD. The response should avoid confirming record existence, patient status, program participation, dates, services, or the applicability of Part 2 to that person. Organizations should approve scripts and escalation routes before requests arrive.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.13(c)(2) requires any answer to an impermissible record request to avoid affirmatively revealing that an identified person has been or is being diagnosed or treated for an SUD. The response should protect status without misstating the law or obstructing a valid authority-review process. eCFR displays the provision as current through August 20, 2026 and last amended August 13, 2026. The HHS fact sheet confirms the February 16, 2026 compliance date.

A denial can still reveal protected status

The current response rule focuses on what the answer affirmatively reveals. Review every script, email template, portal status, voicemail, chatbot, fax cover, legal-response letter, and staff conversation for person-specific confirmation.

Build scripts around the request channel

Different roles may need separate wording for phone, front desk, law enforcement, subpoena intake, family, payer, media, employer, school, vendor, and government requests. Provide a secure route for documents and urgent escalation.

Keep the internal record complete

Internally record requester identity, contact, patient named, information sought, claimed authority, date, channel, deadline, triage, response, reviewer, and follow-up. Limit access to the request log and protect it from outward confirmation.

Test what the requester can infer

Review the entire interaction, including words, pauses, transfers, denial reasons, dates, program names, staff roles, signatures, sender domains, subject lines, file names, portal status, chatbot path, voicemail, and prior messages. A response can reveal status without saying that the person is a patient.

Avoid language such as “Part 2 protects this patient's records,” “we cannot release their treatment file,” or “the person is no longer here.” A correction, specific denial, or transfer to an SUD program can confirm the same fact.

Build channel-specific scripts

Prepare approved wording for phone, front desk, email, fax, portal, family, payer, employer, school, media, law enforcement, subpoena intake, vendor, and government contact. Provide a secure route for consent, orders, and other authority documents without acknowledging record existence.

Make the script usable during urgency and after hours. Name the privacy or legal owner, required intake facts, deadline handling, and safe escalation statement. Train staff to avoid collecting unnecessary SUD details before authority review.

Govern internal handling and mistakes

Record requester, verified contact, patient named, information sought, claim, purpose, channel, deadline, triage, response, reviewer, and follow-up in a restricted log. Keep ticket titles and notifications nonrevealing.

When a response exposed status, preserve evidence, contain further contact, notify privacy and security, determine affected patient and recipients, assess incident or breach duties, contact the requester as directed, correct scripts or systems, and test the repair.

Example

Fifteen denial responses are sampled. Thirteen use approved neutral language, correct escalation, and complete audit evidence; two state that Part 2 protects the named person's record. Control completion is 13 of 15 responses.

Record and test the response outcome

Classify each request as routed for authority review, answered with an approved neutral script, denied without confirmation, or escalated after a revealing contact. Record requester, patient named, information, purpose, channel, deadline, exact wording, responder, reviewer, and next action.

For pending legal or consent materials, provide a safe submission route and deadline owner. Do not vary the response based on whether the patient appears in a search result. Consistent behavior protects against inference from timing and routing.

Test scripts with a knowledgeable family member, urgent official, subpoena server, payer, media caller, employer, and person who names a specific program date. Review what each requester could infer from words and system behavior.

Close defects only after preserving the original response, correcting templates and routing, retraining affected roles, and passing a follow-up test on the same channel.

Retain the defect, affected recipient, incident decision, corrective owner, completion date, tester, and final evidence with the request log.

Archive securely.

Neutral-response checklist

  • review words, timing, transfers, metadata, routing, sender, and prior context;
  • avoid person-specific Part 2, patient, program, record, date, and treatment statements;
  • use approved channel-specific wording with secure authority-document intake;
  • protect restricted request logs, ticket titles, notifications, and after-hours handling;
  • preserve and assess any revealing answer, denial, correction, or system behavior; and
  • test scripts with realistic knowledgeable, urgent, and official requesters.

Neutral wording does not decide whether a request is valid or which disclosure route applies. Current Part 2, facility context, other law, claimed authority, safety facts, and the complete interaction need qualified review.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni