A TPO redisclosure by a non-HIPAA program is the Part 2 route for a receiving program that is neither a HIPAA covered entity nor a business associate. When it received records under one consent for future treatment, payment, and health care operations, § 2.33 permits further disclosure consistent with that consent. The program cannot borrow broader HIPAA permissions that do not apply to it.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.33(b)(2) permits a Part 2 program that is not a HIPAA covered entity or business associate to further disclose records consistent with the patient's consent when the records were disclosed under consent given once for all future treatment, payment, and health care operations. The original consent, written-revocation state, program status, and negative HIPAA classification control this branch.
Document the negative and positive classifications
Current 42 CFR 2.33(b)(2) requires both a qualifying Part 2 program and absence of covered-entity or business-associate status for this branch. Preserve the legal classification, responsible reviewer, date, services, transactions, relationships, and change trigger.
Stay inside the original consent
Resolve the recipient, information, purpose, duration, and written-revocation state for the planned disclosure. A future-TPO consent supports only the scope it actually describes. Use another verified pathway for anything outside it.
Recheck the source instrument
The consent must remain consistent with 42 CFR 2.31. Keep the signed form and current revocation state available to the release workflow. Reassess if the program starts covered electronic transactions or enters a new business-associate relationship.
Prove the entity classification
Document that the recipient is a Part 2 program and is neither a covered entity nor a business associate for the activity. Preserve the services, HIPAA transactions, organizational relationships, contracts, responsible reviewer, date, evidence, and reassessment triggers. “Non-HIPAA” should be a supported legal and operational conclusion, not a default label.
Reevaluate when the program bills electronically, changes ownership, adds services, joins an enterprise, or performs work for a covered entity.
Trace the qualifying receipt
Link the records to the earlier disclosure under one consent for all future TPO. Preserve patient, source, signed consent, information, receipt time, purpose, recipient, transmission, and current written-revocation state. If the records arrived through a different pathway, do not force them into paragraph (b)(2).
Keep provenance at the record or dataset level when information from multiple sources is merged.
Stay consistent with consent
Resolve the proposed recipient or class, information, TPO purpose, duration, and other signed terms. Validate each section 2.31 element and confirm the consent has not been revoked in writing. A disclosure cannot exceed the consent merely because the program believes HIPAA would have allowed it elsewhere.
Select only the needed records, verify the route and destination, and preserve the actual payload. Use a new supported authority for anything outside the signed scope.
Control revocation and change
Propagate written revocation to every dependent release queue, exchange, vendor, and manual process. Distinguish earlier completed disclosures from new, retried, or queued activity. Hold open releases while identity, timing, or consent scope is resolved.
If the program later becomes a covered entity or business associate, stop using the old classification and reassess workflows under the correct branch. Preserve effective dates and historical decisions.
Monitor and remediate
Audit the full population of disclosures, denials, holds, revocations, classification changes, retries, exports, and manual releases. Test recipient resolution, consent match, data selection, secure delivery, notices, acknowledgments, and correction handling. Look for teams borrowing HIPAA permissions that do not apply.
When an unsupported release occurs, contain the information, identify recipients and copies, preserve evidence, obtain qualified review, correct configuration and training, and verify the remediation.
Maintain a short decision guide showing when this branch applies, who approves it, where consent and revocation evidence lives, and which route handles other requests. Review the guide with intake, records, billing, clinical, and vendor staff because each group may initiate a disclosure. Track questions and denials to find terms or classifications that staff routinely misunderstand.
Example
Eleven program configurations are reviewed. Eight have a current Part 2 classification, documented HIPAA-status analysis, matching TPO consent, revocation control, and release evidence; three have stale entity analyses. Readiness is 8 of 11 configurations.
Non-HIPAA program checklist
- document current Part 2 program status and absence of both HIPAA roles;
- trace the records to one future-TPO consent and qualifying receipt;
- match recipient, information, purpose, term, and revocation state to the consent;
- propagate written revocation and preserve historical effective dates;
- reassess after transaction, service, ownership, or relationship changes; and
- audit holds, denials, retries, excess scope, misclassification, and correction.
This route follows the patient's consent. It does not give a non-HIPAA program the broader permissions of a covered entity.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni