{"@context":"https://schema.org","@type":"Article","headline":"Part 2 person definition","description":"Learn how Part 2 adopts the HIPAA person definition, covering natural people and listed private or public legal entities for rule analysis in practice.","url":"https://finnihealth.com/resources/glossary/part-2-person-definition","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 person definition","item":"https://finnihealth.com/resources/glossary/part-2-person-definition"}]}}
Glossary term

Part 2 person definition

Learn how Part 2 adopts the HIPAA person definition, covering natural people and listed private or public legal entities for rule analysis in practice.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

natural and legal person under Part 2 SUD privacy entity person meaning

The person definition used by Part 2 is the HIPAA meaning in 45 CFR 160.103. It includes a natural person, defined there as a human being born alive, plus a trust or estate, partnership, corporation, professional association or corporation, and another public or private entity. The term can therefore refer to individuals or organizations, depending on the provision and facts.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.11 gives person the meaning in 45 CFR 160.103: a natural person, meaning a human being born alive, as well as a trust or estate, partnership, corporation, professional association or corporation, or another public or private entity. The definition identifies who can occupy a regulatory role; it does not establish authority, consent, or recipient eligibility by itself.

Identify the person named by the provision

Current 42 CFR 2.11 incorporates the HIPAA definition. Record the legal identity, natural-person or entity category, organizational role, jurisdiction, relationship to the patient or program, authority, record receipt, action, and specific Part 2 provision.

Use the complete incorporated text

Current 45 CFR 160.103 supplies the categories. A department, vendor brand, facility, workforce member, professional practice, parent organization, trust, estate, government unit, or contractor may require legal-entity resolution before the correct person is known.

Do not infer authority from personhood

Fitting the definition does not establish consent authority, personal-representative status, licensure, covered-entity or business-associate status, lawful-holder status, payer rights, record access, subpoena power, or permission to use or disclose records. Verify each separately.

Resolve the actual legal or natural person

For an individual, verify identity and the role in the specific transaction. For an organization, preserve legal name, entity type, jurisdiction, registration, parent and affiliate relationships, operating names, site, authorized contacts, and effective dates. Distinguish a brand, department, platform, or mailing address from the legal person.

Use authoritative sources and qualified review for trusts, estates, public agencies, reorganizations, and dissolved or merged entities.

Assign each role separately

Determine whether the person is a patient, representative, covered entity, business associate, Part 2 program, lawful holder, qualified service organization, contractor, recipient, requester, authority, workforce member, vendor, or another actor. One person can hold several roles, and the same organization can act differently across workflows.

Do not turn personhood into authorization. Verify the rule and facts for every role.

Match consents and disclosures

Resolve the person or category identified in consent to the actual destination, account, site, and route. Authenticate the requester and recipient, confirm purpose and data, and preserve intermediaries. A corporate name can be too broad when the signed consent or rule requires a more specific person, category, program, or authority.

When ownership, name, address, affiliate, or service changes, determine whether existing consent and contracts still match.

Configure identity and organization records

Use stable identifiers for legal entities and natural people while preserving historical names, relationships, mergers, and effective dates. Separate identity from permissions. Link contracts, consents, credentials, roles, sites, systems, notices, and audit evidence without giving a parent or affiliate automatic access.

Test cross-tenant, cross-site, shared-service, vendor-support, and proxy scenarios. Avoid collapsing multiple legal persons under one user or customer record.

Audit role and recipient resolution

Review entity inventories, identity proofing, role assignment, consent matching, disclosures, agreements, acquisitions, closures, and access. Investigate ambiguous brands, stale affiliates, duplicate entities, shared credentials, wrong-site routing, and unsupported recipients.

Correct identity and access together, notify affected workflows, and preserve the earlier state for audit.

Handle organizational change

Before a merger, acquisition, assignment, legal-name change, dissolution, estate transition, or trust change, inventory consents, contracts, credentials, routes, access, notices, and retained records tied to the affected person. Determine whether authority transfers, requires amendment, or ends. Preserve effective dates and the identity of both predecessor and successor without silently rewriting historical transactions.

For natural people, keep identity proofing proportionate and accessible while preventing shared accounts and mistaken matches. Correct duplicate or merged patient and representative identities through a controlled process that preserves disclosure history. A technical merge can expose one person's Part 2 records to another if role and recipient evidence are not revalidated.

Example

Sixteen recipient records are audited. Thirteen preserve legal name, person category, entity hierarchy, role, authority, Part 2 status, address, and reviewer; three store only a vendor brand. Identity completeness is 13 of 16 records.

Person-definition checklist

  • identify the natural or legal person through authoritative facts;
  • distinguish entity, brand, affiliate, component, site, account, and contact;
  • assign patient, representative, program, holder, recipient, vendor, and other roles separately;
  • match consent, contracts, credentials, purpose, and route to the actual person;
  • maintain stable identity with effective-dated names and relationships; and
  • audit duplicates, ambiguous entities, mergers, shared access, and misrouting.

“Person” is broad enough to include individuals and many entity forms. Every authority and access decision still depends on the person's specific role and facts.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni