Part 2 breach notification applicability comes from 42 CFR 2.16(b). It applies 45 CFR part 160 and part 164 subpart D to Part 2 programs for breaches of unsecured records in the same manner those provisions apply to covered entities for breaches of unsecured protected health information. Classification, investigation, mitigation, documentation, and each notice route need named owners and clocks.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.16(b) applies 45 CFR part 160 and 45 CFR part 164 subpart D to Part 2 programs for breaches of unsecured records in the same manner those provisions apply to covered entities for breaches of unsecured protected health information. The HHS breach guidance organizes the federal notification framework, and the HHS Part 2 fact sheet identifies February 16, 2026 as the compliance date.
Start with the exact entity and record
The current Part 2 rule names Part 2 programs and breaches of unsecured records. Determine program status, affected records, security treatment, event facts, discovery date, people affected, recipient, jurisdiction, and any separate HIPAA, state, contract, payer, licensing, or insurance duties.
Classify before selecting a notice path
The incorporated breach provisions define breach, exceptions, the low-probability assessment option, individual notice, media notice, notice to the Secretary, business-associate notice, law-enforcement delay, and administrative duties. Each has its own conditions.
Response and notification run together
Contain the event, preserve evidence, support care, identify affected people and data, assess misuse risk, apply safeguards, maintain a decision log, prepare accurate communications, and track required recipients and deadlines. A maximum deadline is never a waiting period.
Start the incident clock and preserve facts
Record when and how the event was found, who discovered it, when the organization knew or would have known through reasonable diligence, systems and locations, people, records, information, actors, recipients, acquisition or viewing evidence, security treatment, and ongoing risk. Assign incident, privacy, security, legal, clinical, communications, vendor, and executive owners.
Contain accounts, tokens, devices, paper, links, interfaces, malware, forwarding, exports, and vendor access while preserving logs, images, messages, configuration, chain of custody, and business continuity. Avoid destroying evidence through a hurried reset.
Determine the entity, record, and incorporated rule
Confirm Part 2 program status and whether the affected material is a patient-identifying record subject to the provision. Analyze whether the record was unsecured under the incorporated framework and whether a business associate or other organization has a reporting role. Review HIPAA, state law, contracts, licensing, payer, insurance, law enforcement, and other duties separately.
Maintain a decision log with sources, facts, assumptions, open questions, owners, dates, and counsel direction. A vendor's severity label or statement that data was encrypted is evidence to verify rather than a completed legal conclusion.
Perform the breach analysis
Apply the current definition, exclusions, and presumption in subpart D. When relying on the low-probability-of-compromise route, document at least the nature and extent of information and likelihood of identification, the unauthorized person who used or received it, whether information was actually acquired or viewed, and the extent of mitigation. Add other relevant facts.
Identify affected individuals and exact data through validated queries, logs, paper inventories, recipient confirmation, and vendor evidence. Track uncertainty and update the population when facts change. Do not wait for proof of misuse if the rule requires action sooner.
Build a route-and-deadline matrix
Determine individual notice, media notice, notice to the Secretary, substitute notice, business-associate notice, law-enforcement delay, and any separate state or contract path. Calculate discovery, outer deadline, operational target, dependencies, approver, delivery, returned mail, posting period, and proof from the current provisions.
Draft notices from verified facts, including what happened, information involved, protective steps, organizational response, and contact routes as required. Avoid exposing additional SUD information in envelopes, subject lines, voicemail, portals, media statements, or contact-center scripts. An outer deadline is not a waiting period.
Mitigate, communicate, and close the event
Support affected patients with accessible language, interpreters, alternative formats, safe communication preferences, fraud or identity guidance relevant to the data, clinical continuity, and a knowledgeable contact. Coordinate regulator, media, payer, partner, insurer, and workforce communications without inconsistency.
Close only after containment, population validation, analysis, notices or documented rationale, mitigation, remediation, sanctions where appropriate, patient support, evidence retention, policy and risk updates, and effectiveness testing. Preserve documentation for the period required by applicable rules.
Example
Ten suspected Part 2 events reach classification. Seven have event facts, unsecured-record analysis, breach decision, affected-person count, owner, clocks, notices or documented rationale, mitigation, and closure; three lack a discovery date. Readiness is 7 of 10 events.
Part 2 breach checklist
- capture discovery, diligence, systems, people, information, recipient, and security facts;
- contain risk while preserving evidence and continuity;
- confirm Part 2 program, record, unsecured status, and all applicable frameworks;
- document definition, exclusions, presumption, and compromise-risk analysis;
- calculate every notice route, recipient, deadline, safe channel, and proof; and
- complete mitigation, patient support, remediation, documentation, and validation.
Breach classification and notice are fact-specific and time-sensitive. Current federal and state requirements and experienced breach counsel should guide the live response.
Related terms
Sources
- Electronic Code of Federal Regulations, 42 CFR 2.16, Security for Records and Notification of Breaches
- Electronic Code of Federal Regulations, 45 CFR Part 164 Subpart D, Breach Notification
- U.S. Department of Health and Human Services, 42 CFR Part 2 Final Rule Fact Sheet
- U.S. Department of Health and Human Services, Breach Notification Rule
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni