{"@context":"https://schema.org","@type":"Article","headline":"Part 2 QSO communication exception","description":"Learn when a Part 2 program may communicate information needed by a qualified service organization to provide services to or for the program.","url":"https://finnihealth.com/resources/glossary/part-2-qso-communication-exception","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 QSO communication exception","item":"https://finnihealth.com/resources/glossary/part-2-qso-communication-exception"}]}}
Glossary term

Part 2 QSO communication exception

Learn when a Part 2 program may communicate information needed by a qualified service organization to provide services to or for the program.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

qualified service organization record sharing Part 2 service vendor communication

The QSO communication exception in 42 CFR 2.12 applies to information exchanged between a Part 2 program and a qualified service organization when the information is needed for the QSO to provide services to or on behalf of the program. The QSO definition and written agreement must be satisfied, and each communication should stay within service need and other governing safeguards.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

The live 42 CFR 2.12(c)(4) addresses information needed by a qualified service organization to provide services to or on behalf of a Part 2 program. The current section 2.11 definition supplies the service and written-agreement requirements. eCFR displays Title 42 as current through August 20, 2026 and last amended August 13, 2026. The HHS fact sheet confirms the February 16, 2026 compliance date for the amended Part 2 framework.

QSO status is the first gate

42 CFR 2.12 refers to the defined organization. Verify actual service, Part 2 data, current written agreement, required acknowledgments, parties, effective dates, business-associate overlap, subcontractors, and termination.

Needed information sets the scope

Map service task, data element, patient or cohort, frequency, sender, recipient, system, output, retention, and access. Avoid sending a complete record when narrower information supports the contracted service.

Vendor governance should match actual handling

Use secure transfer, least-role access, logs, incident reporting, breach coordination, legal-demand routing, return or destruction, access removal, validation, audit, and change control. Verify HIPAA, state law, and contracts separately.

Verify the service and written agreement

Identify the legal parties, service, program, records, systems, locations, subcontractors, start and end, and responsible owners. Confirm that the vendor provides services to or for the Part 2 program and meets the current QSO definition. Product purchase, network membership, payment, or a general confidentiality clause does not establish the relationship.

Review the executed agreement for the required Part 2 acknowledgments, including being fully bound by Part 2 when dealing with patient records and resisting efforts to obtain access in judicial proceedings except as permitted. When the QSO is also a HIPAA business associate, confirm that the agreement deliberately satisfies each applicable Part 2 and HIPAA requirement rather than assuming a generic business-associate agreement is enough.

Limit communications to service need

Create a data map with service task, patient or cohort, fields, source, frequency, sender, recipient, transmission, storage, processing, output, return flow, retention, and deletion. Explain why each identifiable element is needed. Use narrower, aggregated, or de-identified data when it can perform the work.

Cover support access, implementation copies, backups, logs, testing, analytics, artificial-intelligence features, model training, offshore access, integrations, and downstream vendors. Disable unapproved secondary use and prevent output from revealing patient status to people outside the supported workflow.

Operate the relationship through exit

Verify identity and secure transfer, enforce least-role access, log activity, test incident reporting, coordinate breach analysis, route legal demands, and monitor service and security changes. Keep the released version and evidence that the QSO received only what the task required.

Before renewal or material change, compare actual handling with the agreement and data map. At termination, remove access, stop feeds, return or destroy records as required, obtain evidence, address retained backups, preserve legal holds, and confirm subcontractor closure. Investigate any unexplained copy or continuing connection.

Example

Twelve QSO data feeds are assessed. Nine have supported status, agreement, service need, data scope, access, and exit controls; three exceed the defined service. Readiness is 9 of 12 feeds.

Approve the service, not the vendor generally

Record a separate decision for every product, module, support route, integration, and data feed. State whether the QSO route is supported, which agreement and service it covers, the minimum data, subprocessors, locations, approved purposes, owner, and next review. One signed vendor agreement does not automatically cover a later analytics or AI feature.

For an unsupported feed, pause transmission, preserve evidence, contain vendor access, and decide whether prior handling requires incident or breach review. For an approved feed, test a sample payload and user account against the data map, contract, access settings, logs, retention, and output recipients.

Maintain a change register for releases, configuration, hosting, subprocessors, ownership, security events, purpose, and data fields. Require privacy, security, legal, and operational approval before a material change reaches patient records.

QSO communication checklist

  • verify the legal parties, defined service, current agreement, and effective period;
  • confirm required Part 2 acknowledgments and any HIPAA business-associate terms;
  • map and minimize data, recipients, systems, outputs, retention, and subprocessors;
  • govern testing, support, analytics, AI, backups, incidents, and legal demands;
  • monitor actual handling and approve material service or data changes; and
  • remove access and document return or destruction at termination.

QSO status does not authorize data unrelated to the service or every later use, redisclosure, or subcontractor. The current definition, agreement, service facts, HIPAA, state law, security duties, and proposed communication need qualified review.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni