{"@context":"https://schema.org","@type":"Article","headline":"Part 2 patient self-access","description":"Learn how Part 2 allows a program to give patients access to records it maintains about them, with identity, scope, delivery, and evidence controls.","url":"https://finnihealth.com/resources/glossary/part-2-patient-self-access","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 patient self-access","item":"https://finnihealth.com/resources/glossary/part-2-patient-self-access"}]}}
Glossary term

Part 2 patient self-access

Learn how Part 2 allows a program to give patients access to records it maintains about them, with identity, scope, delivery, and evidence controls.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

patient access to own SUD records Part 2 record access

Under Part 2, self access by a patient means the regulations do not prohibit a program from giving that patient access to records it maintains about them. Access can include inspection and copying. Programs should verify identity, personal-representative authority when relevant, record scope, requested format, accessibility, secure delivery, fees and timing under other law, completion, and unresolved exceptions.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.23(a) says Part 2 does not prohibit a program from giving patients access to records it maintains about them, including an opportunity to inspect and copy. The provision removes a Part 2 barrier; it does not itself create every deadline, fee, denial, review, representative, format, or accessibility rule. A program subject to HIPAA should separately apply 45 CFR 164.524 and any more protective state law.

Part 2 removes a federal barrier

Current 42 CFR 2.23 permits a program to provide access to the patient's own records. It does not define every timing, fee, denial, appeal, minor, representative, format, or retention rule that another applicable source may impose.

Use a complete request record

Capture requester, relationship, identity proof, authority, patient, requested records, date range, format, channel, accessibility, received date, due date, owner, search systems, exclusions, review, decision, delivery, receipt, fees, and complaint route.

Keep downstream protections visible

The 2024 final rule provides the current Part 2 context. Information obtained through access remains subject to the criminal-use restriction in §2.23(b). Secure delivery and correct-recipient checks still matter.

Identify the requester and access authority

Verify the patient's identity through proportionate methods that do not create unnecessary barriers. When another person requests access, determine whether that person is a personal representative or has another valid authority for the relevant records. A portal proxy, emergency contact, parent, spouse, caregiver, lawyer, or billing contact does not answer the legal-authority question by itself.

Address minors, emancipated minors, deceased patients, incapacity, delegated authority, and disputed representatives under Part 2, HIPAA where applicable, and state law. Record the source, scope, effective period, restrictions, and reviewer conclusion.

Define and search the maintained record set

Capture requested records, subjects, dates, services, locations, and preferred form. Search clinical and billing systems, notes, assessments, treatment plans, medication information, referrals, messages, email, portal content, attachments, scanned documents, images, recordings, legacy systems, archives, and vendors as applicable. Reconcile the collected set to the request and document unavailable or excluded material under the governing access rule.

Part 2's phrase “records that the part 2 program maintains about the patient” should not be reduced to whatever is easiest to export. Health-information management, privacy, clinical, and technical owners should define the systems and record categories that support a reproducible search.

Apply timing, form, fee, and review rules

Determine which access law governs each element. Track receipt, verification, clarification, deadline, permitted extension, copy form, electronic format, accessibility, language support, fee basis, denial ground, review right, complaint route, and completion. Avoid making the patient sign a Part 2 disclosure consent as a condition of self-access.

Offer the requested form when required or otherwise reach an acceptable alternative. Test readability, completeness, malware controls, password or key delivery, failed transmission, and receipt. A patient may direct a copy elsewhere under other law, but that raises recipient and delivery questions beyond simple self-access.

Protect privacy during inspection and delivery

Use a private setting or secure viewer for inspection. Verify the responsive set before display, prevent another patient's information from appearing, support disability access, control temporary exports, and document questions and follow-up copies. For delivery, confirm address or account, warn about material risks without coercion, use the agreed channel, and preserve proof.

Keep the section 2.23(b) criminal-use restriction attached to provenance. Access completion does not erase limits on using the information to investigate or prosecute the patient.

Close and improve the request

Record what was inspected or delivered, dates, format, recipient, transmission, fees, withheld items, authority, receipt, complaints, corrections, and closure. Sample completed and denied requests for timeliness, scope, accessible format, secure delivery, correct fees, supported decisions, and patient communication.

Example

Fourteen access requests reach their due date. Eleven have verified requester, scoped search, review, accessible format, secure delivery, receipt, and closure; three remain incomplete. Timely completion is 11 of 14 requests.

Patient self-access checklist

  • verify the patient or representative and document scope of authority;
  • define the maintained record set and search active, legacy, message, and vendor sources;
  • apply Part 2, HIPAA, state, minor, format, timing, fee, and denial rules separately;
  • provide private inspection or a complete, accessible, secure copy and verify delivery;
  • preserve criminal-use provenance, decisions, excluded items, receipts, and complaints; and
  • audit timeliness, completeness, security, accessibility, and unnecessary barriers.

Section 2.23 makes patient access compatible with Part 2. The operational right and process still depend on every other law that applies to the program and request.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni