EHR Compliance Considerations for Behavioral Health in Post-Acute Settings

Behavioral health clinician reviewing compliance documentation in a calm office setting

Behavioral health documentation in post-acute settings sits at the intersection of several distinct regulatory frameworks, and the way those frameworks interact — or fail to interact cleanly — creates compliance exposure that many practices don't fully understand until an audit or a patient complaint surfaces it. The default assumption that HIPAA covers everything is where most problems begin.

This article addresses the specific compliance considerations relevant to post-acute behavioral health teams: the 42 CFR Part 2 framework for substance use disorder records, the way state confidentiality laws layer on top of federal requirements, the implications for how care coordination notes are shared across a post-acute care team, and what this means practically for EHR system design and workflow.

HIPAA Is the Floor, Not the Ceiling

HIPAA's Privacy Rule establishes baseline protections for protected health information (PHI) and defines when covered entities may use or disclose health information without patient authorization. For most clinical records in a post-acute setting, HIPAA provides the operative framework. But behavioral health records — particularly those related to substance use disorder treatment — are governed by a separate federal framework that is significantly more restrictive.

42 CFR Part 2, originally promulgated under the Comprehensive Alcohol Abuse and Alcoholism Prevention, Treatment, and Rehabilitation Act of 1970 and substantially updated in 2017 and again in 2020, applies to records generated by "Part 2 programs" — federally-assisted programs that provide SUD diagnosis, treatment, or referral. The practical reach of Part 2 extends to any documentation that would identify an individual as having or having had a substance use disorder, generated by or within a covered program.

The core restriction under Part 2 is that patient-identifying records cannot be disclosed without specific written patient consent that meets Part 2's formal requirements — not the general HIPAA authorization, but a consent document that must identify the specific program disclosing the information, the specific receiving entity, the specific information to be disclosed, the purpose of the disclosure, and an expiration date or condition. Treatment, payment, and healthcare operations — the three categories that carry broad HIPAA permission — do not automatically authorize Part 2 disclosures without compliant consent.

The 2020 amendments to Part 2 aligned it more closely with HIPAA in several respects, particularly around redisclosure restrictions and breach notification. But the consent specificity requirements remain stricter than HIPAA's general authorization framework, and the consequences of non-compliant Part 2 disclosure are significant: criminal penalties under the Part 2 regulations, separate from any HIPAA enforcement action.

State Law Complications

Layered on top of the federal HIPAA and Part 2 frameworks are state-level behavioral health privacy laws, which vary considerably by jurisdiction. Tennessee, where many post-acute behavioral health providers in the Southeast operate, has statutory provisions governing the confidentiality of mental health records (TCA 33-3-103 and related provisions) that establish consent requirements and limitations on disclosure that apply independently of HIPAA.

Several other state-level frameworks create similar complexity: psychotherapy notes receive additional protections under HIPAA that distinguish them from general mental health treatment records; HIV-related information carries enhanced confidentiality protections under most state laws; and records related to minors in behavioral health treatment involve consent and access complications that vary between states.

We're not saying that compliance with these overlapping frameworks is impossible or that behavioral health practices in post-acute settings are uniquely exposed relative to other care settings. What we are saying is that an EHR system that treats all clinical records as a single, uniformly governed data object — without the ability to apply differential access controls based on record sensitivity — creates real compliance risk in behavioral health contexts that doesn't exist in the same way for wound care or rehabilitation documentation.

Practical Implications for EHR System Design

The operational requirements that fall out of Part 2 and state behavioral health privacy frameworks have direct implications for EHR design and vendor selection.

First, the system needs to support record segmentation — the ability to flag specific records or portions of records as subject to enhanced access restrictions, and to apply those restrictions in the context of care team sharing, interoperability data exchange, and patient portal access. A behavioral health note that meets the criteria for Part 2 protection should not be freely visible to a physical therapist accessing the shared care record for a co-managed post-acute patient, unless an appropriately specific consent has been documented.

Second, consent management needs to be integrated into the clinical workflow in a way that is specific enough to satisfy Part 2 requirements. A system that offers only a general HIPAA consent form, or a single broad release of records authorization, is not adequate for Part 2 documentation. The consent records for Part 2 disclosures need to be associated with the specific records they authorize, timestamped, and retrievable on audit.

Third, care coordination workflows — the sharing of care summaries, transition of care documents, and team communication — need to respect behavioral health record restrictions at the data-element level, not just at the patient level. A care summary generated for a hospital discharge transition may appropriately include a patient's functional status, medication list, and wound care status without including their SUD treatment records, even if all of those records are present in the same EHR. Achieving that separation requires an EHR that supports data segmentation at a granular level.

The Redisclosure Challenge in Post-Acute Care Coordination

Post-acute care is by nature a coordinated, multi-provider environment. A patient transitioning from a skilled nursing facility to home health may have their care managed simultaneously by a primary care physician, a wound care specialist, a behavioral health provider, and a care coordinator. The expectation that data flows freely across that team — which is good clinical practice and increasingly required under value-based care arrangements — runs directly into the Part 2 redisclosure prohibition.

Under 42 CFR Part 2 as amended, a receiving entity that has obtained Part 2 records through a compliant consent may re-disclose those records to a third party only if the patient's consent also authorized that redisclosure. A home health agency that receives behavioral health records from an SNF as part of a care transition cannot then share those records with the home health clinical team without either a consent that authorized that specific redisclosure or a separate consent obtained from the patient.

This creates an operational requirement that many post-acute practices have not built into their care coordination workflows: a systematic process for identifying which records in an incoming transition package are subject to Part 2 restrictions, and ensuring that the consent documents that accompanied those records authorize the intended use within the receiving organization. In practice, this often requires a clinical coordinator role and a documentation review step that adds time to transition intake — and that is entirely absent from care coordination workflows designed without behavioral health in mind.

What to Ask Your EHR Vendor

When evaluating EHR platforms for behavioral health use in post-acute settings, the compliance-relevant questions go beyond general HIPAA alignment claims. Specific capabilities to ask about include: does the system support record segmentation with audit-trail logging of access to segmented records; can the system generate and store consent records that meet 42 CFR Part 2's specificity requirements; can care summaries and transition of care documents be generated with behavioral health records excluded or included based on documented consent status; and how does the system handle the Part 2 requirement that disclosures for treatment, payment, and operations require specific consent rather than the general TPO exception?

Many general-purpose EHR platforms have not built Part 2 workflows into their core design — these capabilities are often add-on configurations or third-party integrations that vary in how completely they address the regulatory requirements. Post-acute practices providing behavioral health services need to evaluate those specifics before assuming that a HIPAA-aligned platform is adequate for their compliance environment.

The behavioral health privacy landscape is also evolving. The 2020 Part 2 amendments moved in the direction of greater alignment with HIPAA, and further regulatory changes are possible as the federal government continues to address the tension between behavioral health privacy protections and the interoperability goals of the 21st Century Cures Act. Practices that build their compliance workflows on a solid understanding of current requirements — rather than the assumption that HIPAA covers everything — will be better positioned to adapt as the regulatory environment continues to develop.

Put time back in the visit

See how DocNow handles documentation for your post-acute specialty.