PogoWasRight.org

Menu
  • About
  • Privacy
Menu

HHS Secretary Robert F. Kennedy, Jr. Empowers Office for Civil Rights to Administer and Enforce Confidentiality of Substance Use Disorder Patient Records

Posted on August 27, 2025August 27, 2025 by Dissent

The U.S. Department of Health and Human Services (HHS) today displayed in the Federal Register a delegation of authority from Secretary Robert F. Kennedy, Jr., to the Office for Civil Rights (OCR) to administer and enforce the “Confidentiality of Substance Use Disorder (SUD) Patient Records” regulations at 42 CFR part 2 (“Part 2”), which protect the privacy of patients’ SUD treatment records.

In February 2024, HHS published a final rule modifying the Part 2 regulations to implement section 3221 of the Coronavirus Aid, Relief, and Economic Security (CARES) Act, to increase coordination among providers treating patients for SUDs, strengthen confidentiality protections through civil enforcement, align certain Part 2 requirements with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules, and enhance integration of behavioral health information with other medical records to improve patient health outcomes. The final rule provides the public with the ability to file complaints alleging violations of the Part 2 confidentiality provisions, requires Part 2 programs to provide notification of breaches of Part 2 records, and implements in regulation HHS’s civil enforcement authority, including the potential for civil money penalties for violations of Part 2.

The delegation of authority to OCR to administer and enforce the “Confidentiality of SUD Patient Records” regulations includes the authority to:

  • Enter into resolution agreements, monetary settlements, and corrective action plans, or impose civil money penalties for failures to comply with these requirements;
  • Issue subpoenas requiring the attendance and testimony of witnesses and the production of any evidence that relates to any matter under investigation or compliance review for failure to comply with these requirements; and
  • Make decisions regarding the interpretation, implementation, and enforcement of these requirements.

Persons subject to these regulations must comply with the applicable requirements of the 2024 final rule by February 16, 2026.

A fact sheet on the final rule may be found at: https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html

Source: HHS OCR

Related posts:

  • BULLETIN: HIPAA Privacy and Novel Coronavirus — from HHS OCR
  • HHS Office for Civil Rights Settles with Holy Redeemer Hospital Over Disclosure of Patient’s Protected Health Information, Including Reproductive Health Information
  • How can you safely respond to a negative online review by a patient?
  • The Biden-Harris Administration Issues New Rule to Support Reproductive Health Care Privacy Under HIPAA
Category: HealthcareLawsU.S.

Post navigation

← Spain’s data protection agency takes hard line on hotels and accommodation providers asking guests for copies of ID cards or passports
Fourth Amendment Victory: Michigan Supreme Court Reins in Digital Device Fishing Expeditions →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
  • ANNOUNCEMENT: EFF Launches Age Verification Hub as Resource Against Misguided Laws
  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit

RSS Recent Posts at DataBreaches.net

  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition (1)
  • US Posts $10 Million Bounty for Iranian Hackers
  • South Korea police raid e-commerce giant Coupang over data leak; govt schedules hearing
  • FinCEN Report: Reported Ransomware Incidents and Payments Reached All-Time High in 2023
©2025 PogoWasRight.org. All rights reserved.