{"@context":"https://schema.org","@type":"Article","headline":"Part 2 unconditional-compliance rule","description":"Learn why Part 2 duties continue despite a requester's claimed knowledge, other access, official status, subpoena, or unsupported justification.","url":"https://finnihealth.com/resources/glossary/part-2-unconditional-compliance-rule","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 unconditional-compliance rule","item":"https://finnihealth.com/resources/glossary/part-2-unconditional-compliance-rule"}]}}
Glossary term

Part 2 unconditional-compliance rule

Learn why Part 2 duties continue despite a requester's claimed knowledge, other access, official status, subpoena, or unsupported justification.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

SUD disclosure justification insufficient Part 2 lawful holder duty

Part 2 makes compliance unconditional under its request rule when a program or lawful holder receives an inquiry. The requester may claim prior knowledge, another means of obtaining the information, law-enforcement or government status, a subpoena, or another justification. None of those claims replaces a use or disclosure route permitted by Part 2. Staff should verify authority and use a nonconfirming response when disclosure is impermissible.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.13(b) keeps Part 2 restrictions in force even when a lawful holder believes the requester already knows the information, has another way to obtain it, is law enforcement or another government official, has a subpoena, or offers another justification outside Part 2. eCFR displays the provision as current through August 20, 2026 and last amended August 13, 2026. The HHS fact sheet confirms the February 16, 2026 compliance date for the amended framework.

Requester confidence supplies no authority

Current 42 CFR 2.13 lists several common claims and keeps the restrictions in force. Record requester, identity, organization, claim, legal process, data sought, patient, purpose, deadline, channel, and response owner.

Use a consistent request gate

Authenticate the requester, classify the record and holder, identify the precise Part 2 route, verify any consent or court order, limit information to the purpose, log the response, and route uncertainty to privacy counsel. Avoid improvising from urgency or rank.

Train every public contact point

Reception, intake, clinicians, billing, medical records, IT, executives, vendors, call centers, security, and after-hours staff may receive requests. Give each role a short script, escalation path, secure intake method, and prohibition on informal confirmation.

Treat every claim as request context

Record requester identity, organization, verified contact, patient named, information sought, claim of knowledge or alternate source, government role, legal document, purpose, deadline, channel, and responsible intake owner. Preserve the original wording and attachments without confirming that the person is a patient.

The requester's confidence, rank, urgency, relationship, or access to public information may guide authentication and escalation. It does not replace a permitted Part 2 route. Staff should avoid debating facts or correcting the requester before authority is established.

Run one consistent decision gate

Classify the record, program, holder, requested action, recipient, and purpose. Identify current consent, exception, authorizing order, or other Part 2 route. Confirm scope, necessary information, notice, secure delivery, logging, and expiration. Route uncertainty to privacy and experienced counsel.

Use a nonconfirming response when disclosure is impermissible or unresolved. Centralize subpoenas, warrants, government requests, family inquiries, payer calls, media, employers, and vendors. Keep ordinary customer-service pressure from bypassing the same review.

Train and test every contact point

Provide reception, intake, clinicians, records, billing, IT, executives, security, vendors, call centers, portals, and after-hours staff with a short approved script and escalation route. Configure tickets and shared channels so they do not reveal patient status in titles, queues, notifications, or auto-replies.

Test phone, email, in-person, fax, portal, legal service, and emergency contacts. Review logs for informal confirmation, transfer patterns, repeated inquiry, and delayed escalation. Record defects, containment, retraining, owner, and follow-up sample.

Example

Fifteen requests are sampled. Twelve have authenticated requester, record classification, authority review, scope, response, and log; three were answered from the requester's stated knowledge. Control completion is 12 of 15 requests.

Record the request disposition

Classify each request as authorized and scoped, redirected to a secure evidence channel, answered with an approved neutral response, denied, or pending qualified review. Record requester, claim, patient named, information, authority, purpose, deadline, decision-maker, response, and next action.

For pending requests, set an owner and response deadline without confirming record existence. For denied requests, preserve the basis and exact wording. For approved disclosures, record the necessary data set, recipient verification, notice, transmission, and receipt.

Investigate informal confirmations, revealing transfers, or excessive releases. Preserve evidence, contain further communication, contact recipients as directed, assess incident or breach obligations, correct scripts or configuration, and test the fix.

Measure reliability across roles and shifts. Sample after-hours, executive, government, legal-service, family, payer, and vendor scenarios so one well-trained records team does not mask weak public contact points.

Unconditional-compliance checklist

  • preserve requester, identity, claim, patient named, information, purpose, and deadline;
  • avoid confirmation or correction while authenticating and classifying the request;
  • require a current Part 2 route regardless of knowledge, source, rank, or document;
  • use an approved nonconfirming response and centralized escalation path;
  • train every public, clinical, administrative, technical, and after-hours contact; and
  • test request channels and close defects with verified follow-up.

This rule does not determine whether a particular request is valid under another law or which Part 2 route applies. Current authority, scope, record facts, state law, recipient, and response wording require qualified review.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni