The HHS Office for Civil Rights (OCR) has issued new guidance clarifying when Substance Use Disorder (SUD) records protected under 42 CFR Part 2 and HIPAA may be disclosed to verify Medicaid community engagement exclusions. The clarification affects state Medicaid agencies, healthcare providers, and beneficiaries with SUD histories who are subject to work or community engagement requirements.
The HHS Office for Civil Rights (OCR) has issued new guidance addressing a longstanding compliance question: when can Substance Use Disorder (SUD) records be lawfully used to verify whether a Medicaid beneficiary is subject to a community engagement exclusion? The clarification, published on October 1, 2026, comes amidst ongoing state-level efforts to implement Medicaid work requirements and community engagement initiatives.
The guidance intersects two critical regulatory frameworks: HIPAA's Privacy Rule and the federal confidentiality requirements for SUD treatment records under 42 CFR Part 2. This intersection has created operational confusion for state Medicaid agencies that need to confirm whether beneficiaries are exempt from community engagement mandates due to SUD treatment or disability status.
At the core of the clarification is the recognition that SUD records are among the most sensitive categories of health information under federal law. Under 42 CFR Part 2, records from federally assisted SUD treatment programs generally cannot be disclosed without the patient's specific written consent, even to other healthcare providers or government entities administering benefits.
The OCR guidance clarifies several key points:
1. Consent remains the default requirement. State Medicaid agencies cannot simply access SUD treatment records from Part 2 programs to verify whether a beneficiary should be exempted from community engagement requirements without first obtaining the patient's explicit consent.
2. Limited exceptions apply. Certain narrow exceptions under 42 CFR Part 2 may permit disclosure in specific circumstances, such as in medical emergencies or pursuant to a court order. However, routine administrative verification of community engagement exclusions does not fall within these exceptions.
3. HIPAA does not preempt state privacy laws. Where state privacy laws offer greater protection for SUD information than HIPAA, those state laws continue to apply. This is particularly relevant for states with comprehensive behavioral health privacy statutes.
4. Minimum necessary standard applies. Even where disclosure is permitted, covered entities and business associates must limit the information disclosed to the minimum necessary to accomplish the verification purpose. Full treatment records are almost never necessary for verifying an exclusion status.
State Medicaid agencies are the primary audience for this guidance. These agencies must now review their verification processes to ensure they are not using SUD records in ways that violate Part 2 or HIPAA. This includes reviewing data-sharing agreements with managed care organizations and third-party eligibility vendors.
Healthcare providers, particularly SUD treatment facilities and behavioral health providers, are also directly affected. These entities must continue to protect SUD records rigorously and refuse inappropriate requests from state agencies that lack valid consent.
Medicaid beneficiaries with SUD histories benefit from the clarification, as it reinforces the confidentiality of their treatment records and ensures that participation in community engagement programs does not come at the cost of privacy.
The clarification has significant compliance implications for covered entities and state agencies:
Given the heightened scrutiny, organizations should take several immediate steps:
1. Conduct a compliance gap analysis. Review all current data flows involving SUD records and Medicaid verification processes to identify potential Part 2 violations.
2. Update consent mechanisms. Ensure that consent forms for SUD disclosure are compliant with both HIPAA and 42 CFR Part 2 requirements, including specific purpose identification and revocation rights.
3. Train staff on SUD confidentiality. Frontline eligibility workers and privacy officers should receive training on the heightened protections afforded to SUD records and the limitations on disclosure without specific consent.
4. Evaluate alternative verification methods. State agencies should explore alternative ways to verify community engagement exemptions that do not require access to SUD treatment records, such as self-attestation with follow-up verification through means that do not implicate Part 2 protections.
5. Document compliance decisions. Maintain clear documentation of the legal basis for any disclosure of SUD information in the Medicaid administration context.
The OCR clarification provides much-needed guidance for state Medicaid agencies and healthcare organizations navigating the complex intersection of SUD confidentiality and community engagement verification. Organizations should treat this guidance as a compliance priority and take proactive steps to align their policies and procedures with both HIPAA and 42 CFR Part 2 requirements.
Medicaid community engagement exclusions are exemptions that certain beneficiaries qualify for under state work requirement programs, such as exemptions for individuals receiving substance use disorder treatment, those with disabilities, or those who are medically frail.
SUD records protected under 42 CFR Part 2 generally cannot be disclosed for Medicaid community engagement verification without the patient's specific written consent. Limited exceptions like medical emergencies or court orders do not cover routine administrative verification purposes.
No. Even under HIPAA, state Medicaid agencies must comply with 42 CFR Part 2 requirements for SUD records. HIPAA does not preempt stricter state privacy laws, and Part 2 consent requirements supersede HIPAA's general provisions for treatment, payment, and healthcare operations.
Violations of 42 CFR Part 2 can result in criminal penalties including fines up to $500 for first offenses and up to $5,000 for subsequent offenses. Additionally, OCR may impose civil monetary penalties under HIPAA for related privacy violations.
States should implement consent-based verification processes, use self-attestation mechanisms with follow-up through non-SUD sources, or rely on eligibility determinations made through means that do not require access to federally assisted SUD treatment program records under Part 2.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free