Part2Ready
42 CFR Part 2 & HIPAA readiness · a practice of Trent Cyber Advisory
Self-assessment · 2026

42 CFR Part 2 & HIPAA Readiness Checklist

Since February 16, 2026, OCR enforces 42 CFR Part 2 against substance-use-disorder programs directly — with HIPAA-level penalties. The first thing they request in any complaint or audit is your written risk analysis. Score yourself honestly against what they'll ask to see.

How to use this: check a box only if you could produce the document or demonstrate the control today — not "we're working on it." What you can't produce is exactly what an auditor's letter will ask for first. Your unchecked boxes are your remediation roadmap.
Risk analysis on file: Part 2 rule items: 0/6 Total: 0/30
Section 1

The documents OCR asks for first

In an investigation, these are requested at the door. What you can't produce is itself the finding.

Section 2

Access & accountability

Knowing exactly who accessed which SUD record is the heart of Part 2.

Section 3

Network & endpoints

The cloud EHR doesn't cover the network around it — you're liable for that.

Section 4

Part 2 rule — enforced since Feb 16, 2026

The 2024 Final Rule items. Consent-form and notice wording are legal work — flag them to a healthcare attorney.

Section 5

Physical safeguards

The findings anyone can see by walking your hallway.

Why "we're too small" no longer holds

OCR now takes complaints against Part 2 programs directly — a single unhappy patient or former employee is the trigger, not your size. And the agency rarely fines a facility for being breached; it fines them because the investigation shows there was no current risk analysis, no access logging, and no proof of remediation. The documentation is the defense. Build it before the letter arrives — you can't backdate it after.

No current risk analysis — this is the one document OCR requests first. Start here; nothing else substitutes for it.
Risk analysis in place, but Part 2 or access gaps remain — you have real, citable exposure. Prioritize shared logins, MFA, segmentation, and the 2026 consent items.
All sections checked, with evidence you can produce — you're in strong, defensible shape. Keep the analysis and training current (annually).

Not sure how you'd really score — or how to close the gaps?

I do a fixed-fee 42 CFR Part 2 & HIPAA readiness assessment for behavioral-health and SUD facilities — your policies, your EHR configuration, your network, and your physical safeguards — and hand you an audit-ready risk analysis and a prioritized fix-it plan your team can actually execute.

Book a 15-minute call: [email protected] · part2ready.com

Reflects the HIPAA Security Rule (45 CFR §164.308–312), 42 CFR Part 2 and its 2024 Final Rule (compliance date February 16, 2026), and the OCR Audit Protocol. Enforcement dates and rule status current as of publication — verify before relying.

Part2Ready is a practice of Trent Cyber Advisory, a technical security and compliance advisory practice. This checklist is an educational self-assessment, not legal advice; consent-form and notice language and final compliance determinations are the responsibility of the facility and its counsel. © 2026 Trent Cyber Advisory.