Part 2 subparts organize the regulation into general provisions, uses and disclosures with patient consent, uses and disclosures without consent or a court order, and court orders authorizing use or disclosure. The structure helps route a question, while the facts and specific section determine the answer. A heading alone does not establish authority for a particular record action.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.2(a) describes Part 2's operational structure: Subpart B contains definitions, applicability, and general restrictions; Subpart C covers uses and disclosures with patient consent; Subpart D covers specified uses and disclosures without patient consent or authorizing court order; and Subpart E covers authorizing court orders and their procedures, criteria, and scope.
Each subpart answers a different layer
42 CFR 2.2 identifies Subpart B for general provisions, Subpart C for consent, Subpart D for uses without consent, and Subpart E for court orders. Start with applicability and definitions before selecting a pathway.
One event can require several sections
A disclosure may involve consent elements, recipient restrictions, notices, security, accounting, complaint rights, HIPAA, state law, and later reuse. Build a source map instead of treating the chosen exception as the entire analysis.
Route decisions to qualified roles
Operations can collect facts and surface relevant sources. Privacy and legal owners classify authority. Qualified clinicians decide clinical content within scope. Software may enforce approved rules and holds without creating legal permission.
Start with applicability and definitions
Identify the program, lawful holder or other recipient, patient, record, data source, purpose, requester, and relationship. Apply Subpart B definitions, coverage, recipient restrictions, security, notices, and general rules before choosing a disclosure route. Record uncertainty about entity or record status and obtain expert review.
Routing directly to a familiar consent or exception provision can miss a threshold limitation.
Use Subpart C for consent-based activity
Classify the proposed use or disclosure, consent type, signer authority, required elements, recipients, purpose, expiration, revocation, counseling-note treatment, accompanying notice, and later-use limits. Verify the consent applies to the actual information and transaction. Keep clinical consent, service agreements, HIPAA authorization, payer permission, and Part 2 consent distinct.
Preserve the form and disclosure record together so later reviewers can reproduce the authority.
Use Subpart D for defined routes without consent
Identify the exact provision and every condition for the event, such as a defined medical emergency, research, audit and evaluation, reporting, or another codified route. Limit information, purpose, recipients, and onward use as the selected rule requires. Avoid combining features from several exceptions into a pathway none of them authorizes.
Document why the route applies and what ends or changes the permission.
Use Subpart E for court-order authority
Classify noncriminal use, patient criminal investigation, program or holder investigation, undercover placement, or another order setting. Verify applicant, jurisdiction, protected application, notice or hearing, findings, scope, recipients, identity protections, use limits, and valid compulsory process. An authorizing order and a subpoena answer different questions.
Route ambiguous or mixed-purpose demands through counsel before confirming record status or producing information.
Combine provisions without losing boundaries
One event may require Subpart B applicability, a Subpart C consent, a Subpart D condition, Subpart E legal-process controls, and Subpart A complaint or enforcement duties. Build a decision record that lists each required section, its facts, owner, evidence, and status. Apply the narrowest relevant scope and other governing law.
Audit whether systems retain source authority, revocation, recipient, purpose, access, incident, and disposition controls after information moves.
Use a scenario routing table
Create rows for routine treatment exchange, payer activity, patient request, emergency, research, audit, public-health reporting, legal demand, program investigation, and suspected incident. For each, list threshold definitions, chosen subpart, operative section, required evidence, prohibited uses, recipient limits, owner, and escalation. Keep an “unresolved” state that blocks disclosure while facts are reviewed.
Update the table after rule changes and test it against real workflows. A reference tool should guide expert analysis without replacing it.
Assign table ownership, approval, and revision dates.
Example and controls
Ten proposed disclosures are routed. Eight identify applicability, governing subpart, exact section, recipient duties, and other-law review; two stop at a subpart label. Routing completeness is 8 of 10.
Subpart-routing checklist
- classify the entity, program, record, recipient, purpose, and requester;
- apply Subpart B definitions, coverage, and general restrictions first;
- verify every Subpart C consent element for consent-based activity;
- select one complete Subpart D route for activity without consent or order;
- satisfy the correct Subpart E court-order and compulsory-process pathway; and
- document combined provisions, narrow scope, evidence, owners, and downstream controls.
The subpart structure is a routing map. It works only when threshold facts and every condition in the selected path are verified.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni