loader from loading.io

Episode 605: 42 CFR Part 2, HIPAA NPPs, and the February 16 Deadline: What Actually Needs to Change

Group Practice Tech

Release Date: 02/06/2026

Episode 613: You Discovered Non-Compliant AI Use in Your Practice. Now What? show art Episode 613: You Discovered Non-Compliant AI Use in Your Practice. Now What?

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share concrete steps to take if you’ve discovered staff members using non-approved AI platforms in your practice. We discuss: The misconceptions around what constitutes PHI (and why information used to write a progress note absolutely is PHI) Why this is a reportable HIPAA breach Why reporting a HIPAA breach is nowhere near as scary or impactful as you may fear  The difference between a large breach and a small breach, and reporting deadlines for...

info_outline
Episode 612: Free Email Isn't Worth It: Why It's a Bad Idea and What To Do Instead show art Episode 612: Free Email Isn't Worth It: Why It's a Bad Idea and What To Do Instead

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we explain why free email providers are inherently not HIPAA compliance compatible. We discuss: Why it’s necessary to have a Business Associate Agreement with your email service provider Why clients can’t opt out of HIPAA What requests for alternative or non-secure communication actually mean under the HIPAA Privacy Rule What counts as Protected Health Information (PHI) Why a free email address might be a red flag for prospective clients How to get a BAA...

info_outline
Episode 611: The Real Risks of Using Non-Vetted AI Platforms with Client Information show art Episode 611: The Real Risks of Using Non-Vetted AI Platforms with Client Information

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we continue our series on AI use within therapy practices by sharing how to explain to your team members why using non-vetted AI platforms is not permissible. We discuss: What counts as Protected Health Information and a breakdown of the often misunderstood 18th identifier under HIPAA How therapy progress notes and clinical notes are inherently identifying AI re-identification risk and why this is possible Why AI use involving client information must be...

info_outline
Episode 610: Don't Panic - But Do Pay Attention: What the Darksword iPhone Exploit Actually Means show art Episode 610: Don't Panic - But Do Pay Attention: What the Darksword iPhone Exploit Actually Means

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share information about the recent Darksword iPhone exploit, and what that means for therapy practice owners regarding device security. We discuss: What you need to know about this exploit Device hardening within your security circle Device security gaps we see in everyday practice Pairing technical security measures with behavioral security measures PCT’s resources around risk management and device security Listen here: For more, PCT Resources ...

info_outline
Episode 609: Update: HHS Releases Model NPP for Part 2 Changes — What It Means for Your Practice show art Episode 609: Update: HHS Releases Model NPP for Part 2 Changes — What It Means for Your Practice

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we discuss HHS’s new model Notice of Privacy Practice for Part 2 programs, what has changed, and what that means for your practice.  We cover: The Part 2 Final Rule from 2024 Why the Feb. 16th enforcement deadline has been so confusing The model Part 2 NPP and Patient Notice from HHS, and the function of each document Who is considered a lawful holder and what that means Whether you need to switch to the HHS templates What to do if you already used...

info_outline
Episode 608: AI Isn’t the Problem, Lack of Governance Is – A PSA for Group Practice Leadership show art Episode 608: AI Isn’t the Problem, Lack of Governance Is – A PSA for Group Practice Leadership

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share a PSA for group practice owners to address unauthorized AI use within your practice. We discuss: What we mean by governance What counts as Protected Health Information (PHI) The standard we use at PCT to determine if something is PHI Why AI tools like ChatGPT are inappropriate for PHI De-identification standards under HIPAA Ethical standards and informed consent for clinical use of AI Concrete next steps to take as a practice leader to address AI...

info_outline
Episode 607: HIPAA After Retirement – How to Close Your Practice the Right Way show art Episode 607: HIPAA After Retirement – How to Close Your Practice the Right Way

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we discuss the HIPAA responsibilities for therapy practice owners when closing their practice or retiring. We cover: Common assumptions about responsibilities after retirement What determines your record retention length How long you must remain contactable after closing your practice and why The key functionalities you need to maintain, and the most economical ways to DIY them Outsourcing to an executor service as an alternative to the DIY approach Common...

info_outline
Episode 606: Being Findable in an AI-Shaped Referral World show art Episode 606: Being Findable in an AI-Shaped Referral World

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we offer actionable tips for practice owners regarding the rapidly changing landscape of online referral sources. We discuss: How online referral sources have changed over the last year Why Psychology Today is no longer the dominant referral pathway Emphasizing community based referrals How clients are using AI to find therapists How AI tools prioritize results Practical do’s and don’ts for being findable via AI Listen here: For more, PCT Resources ...

info_outline
Episode 605: 42 CFR Part 2, HIPAA NPPs, and the February 16 Deadline: What Actually Needs to Change show art Episode 605: 42 CFR Part 2, HIPAA NPPs, and the February 16 Deadline: What Actually Needs to Change

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what’s actually necessary when updating your Notice of Privacy Practices due to Part 2. We discuss: The confusion around updating NPPs without an updated model from HHS A quick refresher on Part 2 Who is considered a lawful holder under Part 2 Next steps for updating your NPP if you are a Part 2 program or lawful holder Our free resource on updating your NPP before the 2/16 enforcement deadline Listen here: For more, PCT Resources PCT Free...

info_outline
Episode 604: Don't Get Phished! show art Episode 604: Don't Get Phished!

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share advice on how to avoid phishing scams. We discuss: Phishing scams in text messages and email Common scams you might encounter What not to do when you get a suspicious text message PCT resources for how to identify scams and social engineering Listen here: For more, 

info_outline
 
More Episodes

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.

In our latest episode, we share what’s actually necessary when updating your Notice of Privacy Practices due to Part 2.

We discuss:

  • The confusion around updating NPPs without an updated model from HHS
  • A quick refresher on Part 2
  • Who is considered a lawful holder under Part 2
  • Next steps for updating your NPP if you are a Part 2 program or lawful holder
  • Our free resource on updating your NPP before the 2/16 enforcement deadline

Listen here: https://personcenteredtech.com/group/podcast/

For more, visit our website.

PCT Resources

  • PCT Free Resource: 42 CFR Part 2 & HIPAA Notices of Privacy Practices: A Decision Guide and Sample Language for Covered Entities
    • a practical resource designed to help HIPAA-covered practices determine whether the updated 42 CFR Part 2 rules apply to them — and, if so, what belongs in their Notice of Privacy Practices. The guide includes a clear decision flow, plain-language explanations of Part 2 program vs. lawful holder obligations, and sample NPP language tailored to each category. It was created to fill the gap left by the absence of an updated HHS model NPP following the 2024 Part 2 Final Rule.

Resources

  • HHS Fact Sheet on the 42 CFR Part 2 Final Rule
    • this HHS Fact Sheet summarizes the 2024 Final Rule updating 42 CFR Part 2, including new consent provisions, redisclosure alignment with HIPAA, enforcement changes, and the February 16, 2026 compliance deadline. It provides high-level regulatory context for healthcare organizations handling substance use disorder records.
  • JD Supra Article: 42 CFR Part 2 and Privacy Rule Compliance: Action Required by February 16, 2026
    • This JD Supra article from Snell & Wilmer outlines the compliance steps healthcare organizations must take in response to the 2024 Final Rule updating 42 CFR Part 2. It explains which entities are required to update their Notices of Privacy Practices by February 16, 2026, including both Part 2 programs and HIPAA-covered entities that receive or maintain Part 2-protected records. The article highlights required NPP updates, enforcement risks, and the importance of aligning privacy notices with the amended regulations.