{"@context":"https://schema.org","@type":"Article","headline":"Part 2 TPO electronic-health-record accounting scope","description":"Learn the special Part 2 accounting scope for treatment, payment, and health care operations disclosures made through an electronic health record.","url":"https://finnihealth.com/resources/glossary/part-2-tpo-electronic-health-record-accounting-scope","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 TPO electronic-health-record accounting scope","item":"https://finnihealth.com/resources/glossary/part-2-tpo-electronic-health-record-accounting-scope"}]}}
Glossary term

Part 2 TPO electronic-health-record accounting scope

Learn the special Part 2 accounting scope for treatment, payment, and health care operations disclosures made through an electronic health record.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

Part 2 EHR TPO accounting SUD treatment payment operations disclosure accounting

Part 2 TPO EHR accounting scope is the rule's special treatment of disclosures for treatment, payment, and health care operations. Section 2.25 limits that future accounting requirement to TPO disclosures made through an electronic health record and to the three years before the request. The compliance date remains tolled. Practices should classify purpose and transmission route separately instead of treating every access event as a disclosure.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.25(b) limits the future Part 2 accounting of treatment, payment, and health care operations disclosures to records disclosed through an electronic health record and to the three years before the request. HHS continues to defer the section's compliance date. Both the TPO purpose and the EHR disclosure route must be supported.

Both purpose and route matter

Current 42 CFR 2.25(b) identifies TPO purpose and an EHR disclosure route. Record the disclosed recipient, purpose, outbound event, system of record, source timestamp, payload, correction, and evidence. Internal access and an external disclosure are different events.

Do not overread the future rule

HHS states in its Part 2 fact sheet that the accounting compliance date is tied to a future HIPAA revision. This section can guide data architecture now, but it should not be described as an active universal requirement to produce TPO EHR accountings.

Create a route decision

For each event, identify whether it moved through the EHR, a connected interface, an independent exchange, a payer portal, email, paper, or another system. Privacy and technical owners should document how the chosen route definition maps to source evidence.

Classify purpose from the real transaction

Record who initiated the disclosure, recipient, intended and actual purpose, workflow, consent, data, and evidence. Distinguish treatment coordination, claims and payment, operations, research, public health, legal process, patient direction, and mixed purposes. Do not infer TPO solely from the department, recipient type, or interface name.

Create review rules for events with more than one purpose or a changed purpose. Preserve the factual basis and qualified decision rather than only the final label.

Define the EHR route

Map how the record moved from the EHR to the recipient. Include native exchange, connected interfaces, HIE or network services, APIs, portal delivery, payer connectivity, direct messaging, document export, fax integration, printing, and manual handoff. Technical owners should show which routes are “through an electronic health record” under the approved legal interpretation.

An EHR user-access log is not by itself an external disclosure. A connected tool may create a disclosure even if the EHR records only a generic export. Link sending, transport, and recipient evidence to one stable event.

Preserve event-level proof

Useful fields include patient, Part 2 record, consent, purpose, sender, recipient, route, source and destination systems, date and time zone, payload, successful status, retry, correction, acknowledgment, reviewer, and evidence links. Retain raw and normalized values.

Define handling for partial delivery, multiple recipients, batch exchange, failed attempts, replaced payloads, and downstream redistribution. Avoid turning one disclosure into many because several systems logged it, or many disclosures into one because a batch shared an identifier.

Build readiness without overstating duty

Test event capture and export for a representative three-year interval. Include each EHR and connected route, legacy systems, acquired practices, vendors, consent types, TPO purposes, and recipient structures. Reconcile generated events to known transmissions and resolve unexplained gaps.

Label the control as preparation while the HHS fact sheet keeps the compliance date tied to a future HIPAA revision. Existing HIPAA, state, contract, audit, and access obligations should continue under their own requirements.

Plan for the future trigger

Version definitions, mappings, source coverage, and test results. Assign owners for regulatory monitoring, legal interpretation, EHR configuration, vendor contracts, data retention, patient response, corrections, and audit. Reevaluate whether the final HIPAA revision changes route or content assumptions before activation.

Maintain a route inventory with effective dates and a change-review requirement. New interfaces, payer connections, portal features, and acquisitions should not enter production until owners determine how their disclosure events will be classified and retained.

Example

Eighteen sampled TPO events are reviewed. Fourteen have purpose, sender, recipient, EHR-route decision, timestamp, payload evidence, and reviewer; four contain only a user-access log. Readiness is 14 of 18 events.

TPO-EHR-scope checklist

  • determine the disclosure's actual TPO purpose and preserve the reasoning;
  • map native, connected, portal, exchange, API, fax, print, and manual routes;
  • distinguish external disclosure from internal access, use, queue, and failed attempt;
  • link patient, consent, recipient, date, payload, route, status, and evidence;
  • test every EHR, legacy source, vendor, mixed purpose, retry, and batch pattern; and
  • keep controls preparatory until HHS sets and reviewers validate the compliance trigger.

The future paragraph (b) population is an intersection: qualifying TPO purpose, EHR disclosure route, and three-year period. Broad audit-log exports cannot prove that intersection.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni