{"@context":"https://schema.org","@type":"Article","headline":"Part 2 on-site audit review","description":"Learn the Part 2 audit route for records reviewed in the holder's controlled environment without copying, downloading, removing, or forwarding data.","url":"https://finnihealth.com/resources/glossary/part-2-on-site-audit-review","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 on-site audit review","item":"https://finnihealth.com/resources/glossary/part-2-on-site-audit-review"}]}}
Glossary term

Part 2 on-site audit review

Learn the Part 2 audit route for records reviewed in the holder's controlled environment without copying, downloading, removing, or forwarding data.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

SUD audit no copying Part 2 records stay on premises

An on-site audit review under Part 2 is the pathway for reviewing patient-identifying records when they remain on the premises or in the controlled system of the Part 2 program or other lawful holder. The reviewer does not download, copy, remove, or electronically forward records to another system or device. A written agreement and a qualifying reviewer or sponsor still apply.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Data location defines this pathway

42 CFR 2.53 distinguishes a review with no copied, removed, downloaded, or forwarded patient records from one in which data moves. Map screenshots, exports, local files, printouts, sync tools, browser downloads, analytics caches, remote desktops, and notes before calling the work on-site.

Document the approved premises or controlled system, server and storage boundaries, reviewer device, network, remote-access design, clipboard, print, screen capture, file transfer, local cache, logs, backups, collaboration tools, and output. “View only” in an application may still allow browser saving, photographs, operating-system screenshots, accessibility exports, or copied text.

Test the configuration with the actual reviewer role. Preserve results for permitted and blocked actions, not only policy statements. If patient-identifying information can leave the environment, evaluate the copied-record pathway before access begins.

The reviewer signs the required limit

The person agrees in writing to comply with the section's limitations on use and redisclosure. The program or lawful holder also verifies that the person acts for a named eligible sponsor or has been determined qualified for the audit or evaluation.

Match the signed person, employer, sponsor, purpose, dates, and scope to the access account. Include subcontractors, interpreters, technical support, observers, and supervisors who may see records. A master services agreement or confidentiality clause may not contain the specific Part 2 commitment or apply to every individual.

Keep qualification evidence and approval separate from the account request. Expired credentials, changed employer, new sponsor, different purpose, or substituted reviewer requires revalidation.

Access should fit the review question

Define the approved records, date range, fields, search rights, session length, workspace, observer, output, and termination conditions. Prevent screenshots, copy and paste, external notes with patient-identifying content, unsanctioned device use, and persistent credentials.

Use the smallest cohort and fields that answer the audit question. Restrict counseling notes, unrelated episodes, free text, family information, contact details, and bulk lists unless specifically supported. Provide trained staff to help navigate without exposing nearby records through search results or shared screens.

Issue unique time-limited credentials with multifactor authentication where appropriate. Apply least privilege, session recording or monitoring under approved policy, inactivity timeout, export blocks, and same-day removal. Avoid shared auditor accounts or permanent payer access.

Govern reviewer notes and outputs

Define whether nonidentifying notes, counts, findings, screenshots, workpapers, or reports may leave the environment and how they are reviewed. A handwritten patient name or copied claim number is still removed information even when no source document is downloaded.

Inspect draft outputs for patient-identifying content, purpose, recipient, and approved disclosure. Store permitted findings in the designated system. Destroy temporary local notes and clear controlled workspaces as policy requires while preserving the audit trail.

Handle pathway changes and closure

If the reviewer asks to download, print, forward, photograph, query a new cohort, add a person, use a vendor tool, or continue from a different device, stop and reassess. Do not let schedule pressure convert an on-site review into an unapproved copied-record pathway.

At session end, disable access, reconcile logs, inspect the workspace, recover temporary materials, record outputs, and close exceptions. If information escaped the environment, contain access, preserve evidence, and route privacy, security, compliance, audit, payer, legal, clinical, and patient communication decisions.

Example with review sessions

Thirteen planned sessions are assessed. Ten keep records in the approved environment with a signed limit and qualifying reviewer; three permit uncontrolled screenshots or downloads. On-site readiness is 10 of 13 sessions.

The program blocks the three sessions, disables screen capture and download, and retests the auditor role. Two become controlled on-site reviews; the third needs an approved copied-record pathway. The original ten-of-thirteen result remains visible.

On-site review checklist

  • Map the full environment, devices, caches, clipboard, print, and transfer routes.
  • Test actual reviewer permissions for every form of copying or removal.
  • Verify reviewer, sponsor, purpose, qualification, dates, and written commitment.
  • Limit cohort, fields, search, session, accounts, and observers.
  • Review notes and outputs before they leave the environment.
  • Stop and reclassify any download, forwarding, new user, or new tool.
  • Close access and investigate information that escaped controls.

Owner controls

The 2024 final rule supplies current context. Use environment testing, reviewer verification, written terms, role-limited accounts, session monitoring, export controls, output review, and access closure.

Monitor sessions, reviewers, records viewed, blocked actions, output reviews, added people, access duration, pathway changes, and incidents. Audit from every view back to qualified purpose and from active auditor roles into current no-copy evidence. Retest after EHR, remote-access, browser, device, vendor, payer, or security changes.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni