Outsource Psychiatric Billing Services With Confidence: A 42 CFR Part 2 Controls Checklist
Outsource psychiatric billing services only after Part 2 vendor controls are in place. A checklist for BAAs, QSOAs, clearinghouses, and breach limits.

Outsource Psychiatric Billing Services With Confidence: A 42 CFR Part 2 Controls Checklist
The compliance deadline for the 2024 rewrite of 42 CFR Part 2 was February 16, 2026. It passed 8 months ago. HHS OCR now accepts Part 2 complaints directly from patients, and HIPAA civil penalty tiers attach to Part 2 violations, running from $145 to $73,011 per violation with an annual cap of $2,190,294 for the same category.
If you outsource psychiatric billing services and your vendor has never signed a Qualified Service Organization Agreement, you have a live exposure. A business associate agreement alone does not satisfy Part 2.
Here is what changed, which records are covered, and the specific contract and configuration controls your vendor needs before you send a single SUD claim.
Key takeaways
- The Part 2 compliance date passed on February 16, 2026. Compliance is enforceable now, not planned.
- A single consent covers treatment, payment, and health care operations. SUD counseling notes need their own separate consent.
- Every disclosure made under consent must carry a copy of the consent or a plain-language explanation of its scope, per 42 CFR 2.32.
- Segmentation of Part 2 records is expressly not required, which removes the single most expensive technical requirement vendors used to quote.
- A QSOA is legally distinct from a HIPAA BAA. Most generalist billing vendors only have the latter.
- JAMA Internal Medicine data: 61.5% of SUD denials get overturned at independent review. That is the number that should drive your vendor decision.
What changed on February 16, 2026
HHS issued the final rule on February 8, 2024, published it at 89 FR 12623 on February 16, 2024. It took effect April 16, 2024. Entities had 11 months to comply, and that clock ended February 16, 2026.
Six changes matter to a billing operation.
Change | What it means for your billing team |
|---|---|
Single TPO consent | One patient consent now covers all current and future treatment, payment, and operations disclosures |
Separate counseling notes consent | SUD counseling notes require their own consent, apart from the TPO consent |
Notice plus consent on every disclosure | Under 42 CFR 2.32, each disclosure must include a copy of the consent or an explanation of its scope |
Segmentation not required | The 2024 rule states expressly that segregating or segmenting Part 2 records is not required |
HIPAA breach notification applied | Part 2 records now follow the HIPAA Breach Notification Rule, including notice to individuals within 60 days |
Direct complaint right | Patients may file an OCR complaint themselves, concurrently with filing to your program |
That last row is why this moved from a policy question to a revenue question. Before 2026, a Part 2 grievance was an internal customer service problem. Now a patient can go straight to the federal complaint portal, and your notice of privacy practices has to hold up on its own.
Which records count as Part 2 records
Part 2 reaches records created by or for a federally assisted Part 2 program, and it extends to anyone who receives those records, including your billing vendor. Most SUD practices qualify as federally assisted because of federal funding, certification, or participation in a federal program.
The practical test is simpler than the legal definition. If the record has anything to do with identifying a person as having or having had a substance use disorder, and it came from a federally assisted program, treat it as protected.
The category that causes the most confusion is SUD counseling notes. These are notes recorded by a provider who is a clinical professional, intended for that provider's own use. Under the 2024 rule they need a separate written consent before disclosure. A broad TPO consent does not cover them.
Not every practice maintains counseling notes. Ask the vendor whether your EHR exports them at all, because that determines whether you need a second consent workflow or can document that none exist.
We broke down the counseling notes and billing record split in detail in SUD counseling notes vs. billing records under Part 2.
How the consent architecture works for billing vendors
Before 2024, a Part 2 program needed specific written consent for each disclosure to each named recipient. Every claim submission could carry its own authorization.
That is gone. The 2024 rule allows one TPO consent covering all future TPO disclosures. A patient signs once, and your vendor can submit claims for the life of the relationship.
The rule attaches a hard condition. Under 42 CFR 2.32(b), every disclosure made under the consent has to be accompanied by a copy of the consent or a clear explanation of its scope. Separately, 2.32(a) requires one of two notice statements to travel with the record. Statement 2 is the short form: "42 CFR part 2 prohibits unauthorized use or disclosure of these records." Statement 1 is the long form, and it carries the proceedings restriction that Part 2 records can't be used against a patient in civil, criminal, administrative, or legislative proceedings without consent or a qualifying court order.
Practically, that means your consent form has to carry the notice language itself. Send the signed form with the record and one requirement is satisfied. Send a record with no notice and you have a Part 2 violation on a claim that might have been perfectly coded.
Your vendor's clearinghouse has to be able to carry that notice on every SUD transaction. Ask to see the transmission spec.
The contract terms your vendor must sign
This is where most practices get burned, because a HIPAA business associate agreement gets signed and everyone assumes the problem is solved.
A QSOA is a different instrument. Under 42 CFR 2.11, a qualified service organization is a person that meets the business associate definition and has entered into a written agreement acknowledging that, in receiving, storing, processing, or otherwise dealing with patient records from a Part 2 program, it is fully bound by the regulations in this part. The federal rule preamble is explicit that a QSOA is distinct from a HIPAA BAA.
Lawful holders who aren't covered entities or BAs have a narrower path. Under 42 CFR 2.33(b)(3), when a record is disclosed for payment to a lawful holder that is not a covered entity or business associate, the recipient may pass those records to its contractors and subcontractors as needed to carry out the payment activity. Under 2.33(c), the lawful holder must hold a written contract with that contractor providing the contractor is fully bound by Part 2 on receipt, and can only pass along what the contractor needs to do its job.
Audit access has hard physical limits. Under 42 CFR 2.53, management audits, financial audits, and program evaluations can happen without patient consent. But if records are not downloaded, copied, or removed from the premises, patient identifying information can be disclosed during a review to someone who agrees in writing to the Part 2 use and redisclosure limits. A vendor asking for a full data export to "run it through our analytics tool" is asking for something the regulation treats differently from an on-premise review.
Records from an audit cannot be used to prosecute patients. Absent written consent or a qualifying court order, that's absolute.
We map out how audit and denial work interacts with these limits in behavioral health billing claim denial management.

A 12-point checklist for clearinghouses and business associates
Work through this with the vendor before the contract is signed. Every line is traceable to the rule.
# | Control | Requirement |
|---|---|---|
1 | QSOA executed | Written agreement binding the vendor to all of Part 2, not just HIPAA |
2 | Single TPO consent verified | Vendor can accept and retain one consent covering future TPO disclosures |
3 | Counseling notes consent flag | Separate consent status tracked per record, not assumed from the TPO consent |
4 | Notice text on every disclosure | Copy of consent or scope explanation attached to each Part 2 transmission |
5 | Notice text exact | "42 CFR Part 2 prohibits unauthorized use or disclosure of these records" |
6 | No segmentation requirement | Vendor does not charge for or require a separate Part 2 data store |
7 | Subcontractor chain written | Written contracts binding every subcontractor and downstream vendor by Part 2 |
8 | Audit access controls | Records stay on premises; no export for third-party analytics without written Part 2 terms |
9 | Breach notification timeline | Vendor notifies you fast enough for you to meet the 60-day individual notice clock |
10 | Accounting of disclosures | Vendor logs every disclosure so you can produce a 3-year accounting on request |
11 | Restriction requests honored | Patient payment-in-full triggers mandatory restriction under 42 CFR 2.26(a)(6) |
12 | Deletion certificate | Written confirmation of destruction at contract end, with the Part 2 obligation surviving |
Point 10 deserves emphasis. Under 42 CFR 2.25, a patient has a right to an accounting of disclosures of electronic records for the past 3 years. Vendors that can't produce that log can't support you when a patient asks.
What a Part 2 breach costs
The 2024 rule applied the HIPAA Breach Notification Rule to Part 2 records. Affected individuals must be notified, HHS must be notified, and media notification applies at scale. Individuals get 60 days from discovery.
The penalty structure changed too. Civil penalties under the HIPAA tiers now reach $73,011 per violation with a $2,190,294 annual cap per violation category, and criminal penalties are aligned to HIPAA's structure. Programs that assumed Part 2 enforcement was softer than HIPAA discovered that assumption in 2026.
One more restriction people forget: Part 2 records cannot be used or disclosed in civil, criminal, administrative, or legislative proceedings against a patient without specific written consent or a court order. Your notice of privacy practices has to say so explicitly.
Our broader compliance services overview covers how this sits alongside HIPAA Security Rule obligations.
The denial math: how a compliant vendor pays for itself
Compliance work sounds expensive until you price the denials you are leaving on the table.
Bruch and colleagues at the University of Chicago published an analysis of 51,394 closed external appeals in New York State covering May 2019 through December 2025, in JAMA Internal Medicine. The headline finding for SUD practices: denied care for substance abuse treatment was overturned 61.5% of the time at independent review. Mental health denials were overturned 60.6% of the time. The overall overturn rate across all specialties rose from 38% in 2019 to 52.5% in 2025.
That is the number that matters. A compliant vendor who actually appeals denials is chasing revenue you are currently writing off.
Here is a worked model. This is our calculation, not a published benchmark.
Assumptions: 6-provider outpatient SUD group, 4,000 claims per month, $180 average allowed amount, 18% denial rate (midpoint of the 16% to 21% range reported for outpatient psychotherapy), 60% of denials never appealed per McKinsey's finding, 61.5% overturn rate from the JAMA data, $57.23 average rework cost per denied claim from AHIMA.
Line | Calculation | Result |
|---|---|---|
Gross charges per year | 4,000 × $180 × 12 | $8,640,000 |
Clean collections per year | 82% × $8,640,000 | $7,084,800 |
Denials per month | 4,000 × 18% | 720 |
Worked today | 720 × 40% | 288 |
Recovered today | 288 × 61.5% × $180 | $31,882 per month |
Recovered with full appeal workflow | 720 × 61.5% × $180 | $79,704 per month |
Annual revenue gained | ($79,704 − $31,882) × 12 | $573,864 |
Vendor fee at 6% of collections | 6% × $7,084,800 | $425,088 |
Net annual gain | $573,864 − $425,088 | $148,776 |
Break-even vendor rate | $573,864 ÷ $7,084,800 | 8.1% |
At these volumes, a vendor charging up to 8.1% of collections beats the status quo on appeal recovery alone. You have not counted rework labor savings ($57.23 per denial on 432 additional claims monthly is roughly $24,700 per month), and you have not counted any reduction in the denial rate itself.
Change any single input and the model breaks. Push the denial rate to 12% and the break-even rate falls below 5%. Push average allowed to $400 and the same vendor at 6% becomes an easy decision. Run your own numbers before you sign anything.
Questions to ask before you sign
Ask these in writing. The answers belong in the contract, not in a sales deck.
- Show me your QSOA. If the only agreement they have is a BAA, they have not done this work.
- Who handles the counseling notes consent flag? Name the person and the system.
- What notice text attaches to a Part 2 transmission? They should recite it without looking.
- Can you produce a 3-year accounting of disclosures for one of my patients today? If yes, you can test the answer.
- Which subcontractors touch my data? Claim clearinghouse, EHR integration, analytics, offshore staff. All of them.
- What happens on termination? Destruction certificate with Part 2 obligations surviving in writing.
If a vendor gets defensive about question 4, that is your answer.
We went deeper on the selection criteria in mental health billing vendor selection, and our addiction treatment billing service page covers how we run SUD accounts day to day.

Frequently asked questions
Does a single TPO consent cover my billing vendor's subcontractors? Yes, if the contractual chain binds each subcontractor by Part 2. Under 42 CFR 2.33(c), a lawful holder must hold a written contract with each contractor and subcontractor providing they are fully bound by Part 2 on receipt.
Do we still need to segregate Part 2 records in our EHR? No. The 2024 rule adds an express statement that segregating or segmenting Part 2 records is not required.
Does HIPAA still apply to Part 2 records? Yes, and in some places Part 2 is stricter. The HHS fact sheet is explicit that any disclosure of Part 2 records remains subject to stricter Part 2 standards even where HIPAA would otherwise permit the use or disclosure without authorization.
Can a patient restrict disclosure of a paid-in-full record to their health plan? Yes, and you must agree. Under 42 CFR 2.26(a)(6), a program must agree to restrict disclosure to a health plan when the disclosure is for payment or operations, isn't required by law, and the patient paid the program in full.
Is mental health parity enforcement active? Partially. The Departments will not enforce the portions of the 2024 MHPAEA final rule that are new relative to the 2013 rule until 18 months after a final decision in the ERIC litigation. Statutory and 2013-rule obligations still apply and are still enforced. We track that in detail in MHPAEA documentation requirements in 2026.
How many SUD treatment OTPs are there in the US? 2,151 certified by SAMHSA as of May 2024. Medicare pays them through 16 HCPCS G-codes, and G2080 covers each additional 30 minutes of counseling.
If you're handing off psychiatric billing and you don't know whether your vendor's agreements survive the February 2026 deadline, we can tell you in one pass.
