{"@context":"https://schema.org","@type":"Article","headline":"Part 2 paper-record access controls","description":"Learn how Part 2 policies should govern access to workstations, rooms, cabinets, safes, containers, and facilities holding paper SUD records.","url":"https://finnihealth.com/resources/glossary/part-2-paper-record-access-controls","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 paper-record access controls","item":"https://finnihealth.com/resources/glossary/part-2-paper-record-access-controls"}]}}
Glossary term

Part 2 paper-record access controls

Learn how Part 2 policies should govern access to workstations, rooms, cabinets, safes, containers, and facilities holding paper SUD records.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

workstation locked file access SUD Part 2 paper storage access

Part 2 controls access to paper records under 42 CFR 2.16 across workstations, secure rooms, locked cabinets, safes, similar containers, and storage facilities that use or store patient-identifying information. Controls should connect each person to an approved role, task, location, record set, time period, key or credential, supervision rule, activity log, and access-removal event.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.16(a)(1)(i)(D) requires formal policies and procedures addressing use of and access to workstations, secure rooms, locked file cabinets, safes, similar containers, and storage facilities that use or store paper patient-identifying information. The HHS fact sheet identifies February 16, 2026 as the compliance date for the amended framework.

Physical access should reflect current duties

The paper-access provision covers both use and storage locations. Maintain authorized-person lists, role approvals, key and badge inventories, temporary access, visitor logs, escort requirements, after-hours rules, emergency entry, and periodic recertification.

Workstations can expose paper

Reception desks, scanning stations, fax areas, printers, copier trays, mail rooms, shared offices, clinical spaces, vehicles, and home-work areas need positioning, retrieval, clean-desk, screen, conversation, waste, and unattended-record controls.

Departure and role change need prompt action

Collect keys and badges, update access lists, retrieve files, inspect local work areas, transfer custody, stop forwarding, review recent activity, address missing items, document completion, and preserve evidence for incidents or disputes.

Define access by person, place, record, and purpose

List workforce, trainees, contractors, volunteers, records staff, clinicians, billing staff, facilities workers, cleaners, security, couriers, vendors, auditors, and emergency responders. For each, record approved location, container or workstation, patient population or record class, action, purpose, schedule, supervision, credential, approver, and end date.

Possession of a building badge or cabinet key should not imply access to every paper record. Separate entry to a room from authority to view, copy, remove, scan, disclose, amend, or destroy information.

Control workstations and paper-in-use areas

Position desks, counters, charts, whiteboards, printers, scanners, faxes, and mail stations away from public view. Use clear-desk and secure-return practices, privacy covers where useful, secure-print pickup, verified fax destinations, locked carts, and controlled handoff. Avoid patient names or SUD-identifying labels on public boards, doors, bins, or packages.

Define when records are “in use,” who maintains custody, where they may be placed, and how they return to storage. Prohibit unattended records in waiting rooms, vehicles, conference rooms, shared kitchens, hotel spaces, or homes unless an approved secure process applies.

Manage identity, keys, visitors, and vendors

Verify identity before issuing badges, keys, codes, or cabinet access. Maintain assignment, approval, duplication, loss, replacement, return, and termination records. Review access after role changes and recover credentials promptly.

Require visitor authorization, escort or supervision based on risk, restricted routes, sign-in, time limits, visible identification, and sign-out. Cover maintenance, cleaning, shredding, scanning, storage, courier, construction, and emergency vendor access in contracts and procedures.

Monitor, investigate, and improve

Reconcile room entry, file checkout, copy or scan activity, visitor records, workforce roles, and reported concerns. Investigate unusual after-hours access, missing files, propped doors, duplicate keys, unescorted vendors, exposed printouts, and repeated checkout delays.

Preserve evidence, contain access, identify patient and information scope, assess use, disclosure, breach, and safety, and correct both the individual event and the underlying control. Track findings to closure and test the repair.

Keep an access-control evidence set

Retain current role approvals, badge and key assignments, room and cabinet lists, visitor and vendor procedures, checkout logs, emergency-access records, access reviews, termination samples, incident links, and remediation results. Protect the evidence because it can reveal security design and patient-record locations.

Test a sample from both directions. Start with a worker and verify every room, key, file, and action matches the job. Then start with a room or cabinet and verify every person with access is current and approved. Include nights, weekends, remote sites, temporary workers, cleaning, facilities, and vendors.

Managers can ask who can enter today, which access is inherited or shared, which credential was not returned, which file is overdue, and which exception lacks an end date. Resolve each mismatch rather than merely certifying the list.

Example

Twenty access assignments are sampled. Seventeen have current role, location, record need, key or badge, approval, review, and removal evidence; three belong to transferred staff. Readiness is 17 of 20 assignments.

Paper-access checklist

  • approve person, place, record class, action, purpose, schedule, and duration;
  • separate room entry from authority to view, copy, remove, scan, or destroy;
  • secure desks, carts, printers, scanners, faxes, mail, and paper in use;
  • control and recover badges, keys, codes, visitor, vendor, and emergency access;
  • reconcile physical access, file checkout, workforce, and reported concerns; and
  • investigate scope, contain risk, remediate controls, and verify correction.

Physical access control should make the permitted workflow easy to follow and the unauthorized workflow difficult, visible, and reviewable.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni