Under Part 2's single-consent TPO rule, a Part 2 program, HIPAA covered entity, or business associate that receives records based on one consent for all treatment, payment, and health care operations need not segregate or segment those records. The segmentation provision addresses record handling after receipt. It does not establish the consent, recipient, purpose, access, or later disclosure authority.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
The last sentence of live 42 CFR 2.12(d)(2)(i)(C) says that a Part 2 program, covered entity, or business associate receiving records based on a single consent for all treatment, payment, and health-care operations is not required to segregate or segment those records. The live section 2.31 consent rule controls the consent elements and recipient language. eCFR displays Title 42 as current through August 20, 2026 and last amended August 13, 2026. The HHS fact sheet confirms the February 16, 2026 compliance date for the 2024 amendments.
The rule applies to named recipient classes
Current 42 CFR 2.12 names Part 2 programs, covered entities, and business associates receiving records under the specified consent. Verify each recipient's role, the consent, scope, covered purposes, effective period, patient, source, record set, and receipt route.
Segmentation and access are different controls
A system may store records together while applying role access, purpose limits, notices, audit logs, sensitive-data views, break-glass procedures, legal-demand routing, and disclosure controls. Document which technical and policy safeguards protect the combined record.
Changes require a new review
Reassess revocation, consent replacement, entity-role changes, business-associate termination, mergers, data migration, new uses, research, legal demands, public-health workflows, patient access, and exports. Preserve the source record and consent version.
Verify the prerequisites before relying on relief
Identify the receiving legal entity and whether it is a Part 2 program, covered entity, or business associate. Preserve the single TPO consent, patient, source, records, recipient designation, purposes, signature, dates, revocation status, expiration, and receipt route. Confirm that the disclosure and receipt actually occurred within the consent's supported scope.
Do not apply the sentence to a recipient class it does not name or to records received under an unrelated authority without a separate analysis. A broad organizational label, HIPAA status, or business-associate agreement does not prove the relevant consent and transaction.
Distinguish storage relief from permission
The rule removes a segmentation requirement for the named recipients and circumstances. It does not make an unsupported use or disclosure permissible, eliminate proceeding restrictions, cure a deficient consent, or resolve state law, SUD counseling notes, legal demands, employment, research, fundraising, or security duties.
Map which systems combine records and how provenance, consent, source, notice, purpose, access, disclosures, revocation, corrections, and legal restrictions remain discoverable. Use role permissions, patient and field controls, purpose rules, audit logs, sensitive views, export limits, break-glass, legal-demand routing, and incident response as the actual risk requires.
Plan for revocation and operational change
Document how the organization receives and propagates a written revocation, identifies actions already taken in reliance, stops unsupported future activity, and preserves the prior consent and transaction record. Test consent replacement, recipient-role change, business-associate termination, merger, migration, new use, and system export.
At least annually, sample records in combined repositories. Verify recipient class, consent, receipt route, allowed purpose, access, notice, downstream use, and response to legal demand. Record gaps, interim restrictions, corrective owner, completion evidence, and follow-up date.
Example
Twelve repositories are reviewed. Nine have verified recipient role, single TPO consent, record source, access, notice, and downstream controls; three rely on a general HIPAA label. Readiness is 9 of 12 repositories.
Record the repository decision
Classify each repository as eligible for the no-segmentation rule, outside the named recipient or consent conditions, or unresolved. State recipient class, consent, record sources, purposes, dates, systems, access model, decision-maker, and next review. For unresolved stores, retain provenance and apply an interim restriction.
Verify the decision with a patient-level trace from receipt through access, use, disclosure, revocation, legal demand, and export. Keep the test evidence and corrective action with the repository record.
Retain the tester and completion date.
Segmentation-rule checklist
- verify the recipient is a named Part 2 program, covered entity, or business associate;
- retain the single TPO consent, scope, patient, records, dates, and receipt evidence;
- distinguish no-segmentation relief from use, disclosure, access, and proceeding authority;
- preserve provenance, consent, notice, restrictions, and auditability in combined systems;
- test revocation, role change, termination, migration, export, and legal demand; and
- sample live records and close defects with verified evidence.
This rule does not require an organization to combine records or authorize every use after combination. Current Part 2, HIPAA, state law, consent facts, recipient role, system design, and the proposed action require qualified review.
Related terms
Sources
- Electronic Code of Federal Regulations, 42 CFR 2.12, Applicability
- U.S. Department of Health and Human Services, 42 CFR Part 2 Final Rule Fact Sheet
- Electronic Code of Federal Regulations, 42 CFR 2.31, Consent Requirements
- Federal Register, Confidentiality of Substance Use Disorder Patient Records, 2024 Final Rule
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni