Episode 605: 42 CFR Part 2, HIPAA NPPs, and the February 16 Deadline: What Actually Needs to Change
Release Date: 02/06/2026
Group Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share concrete steps to take if you’ve discovered staff members using non-approved AI platforms in your practice. We discuss: The misconceptions around what constitutes PHI (and why information used to write a progress note absolutely is PHI) Why this is a reportable HIPAA breach Why reporting a HIPAA breach is nowhere near as scary or impactful as you may fear The difference between a large breach and a small breach, and reporting deadlines for...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we explain why free email providers are inherently not HIPAA compliance compatible. We discuss: Why it’s necessary to have a Business Associate Agreement with your email service provider Why clients can’t opt out of HIPAA What requests for alternative or non-secure communication actually mean under the HIPAA Privacy Rule What counts as Protected Health Information (PHI) Why a free email address might be a red flag for prospective clients How to get a BAA...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we continue our series on AI use within therapy practices by sharing how to explain to your team members why using non-vetted AI platforms is not permissible. We discuss: What counts as Protected Health Information and a breakdown of the often misunderstood 18th identifier under HIPAA How therapy progress notes and clinical notes are inherently identifying AI re-identification risk and why this is possible Why AI use involving client information must be...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share information about the recent Darksword iPhone exploit, and what that means for therapy practice owners regarding device security. We discuss: What you need to know about this exploit Device hardening within your security circle Device security gaps we see in everyday practice Pairing technical security measures with behavioral security measures PCT’s resources around risk management and device security Listen here: For more, PCT Resources ...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we discuss HHS’s new model Notice of Privacy Practice for Part 2 programs, what has changed, and what that means for your practice. We cover: The Part 2 Final Rule from 2024 Why the Feb. 16th enforcement deadline has been so confusing The model Part 2 NPP and Patient Notice from HHS, and the function of each document Who is considered a lawful holder and what that means Whether you need to switch to the HHS templates What to do if you already used...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share a PSA for group practice owners to address unauthorized AI use within your practice. We discuss: What we mean by governance What counts as Protected Health Information (PHI) The standard we use at PCT to determine if something is PHI Why AI tools like ChatGPT are inappropriate for PHI De-identification standards under HIPAA Ethical standards and informed consent for clinical use of AI Concrete next steps to take as a practice leader to address AI...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we discuss the HIPAA responsibilities for therapy practice owners when closing their practice or retiring. We cover: Common assumptions about responsibilities after retirement What determines your record retention length How long you must remain contactable after closing your practice and why The key functionalities you need to maintain, and the most economical ways to DIY them Outsourcing to an executor service as an alternative to the DIY approach Common...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we offer actionable tips for practice owners regarding the rapidly changing landscape of online referral sources. We discuss: How online referral sources have changed over the last year Why Psychology Today is no longer the dominant referral pathway Emphasizing community based referrals How clients are using AI to find therapists How AI tools prioritize results Practical do’s and don’ts for being findable via AI Listen here: For more, PCT Resources ...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what’s actually necessary when updating your Notice of Privacy Practices due to Part 2. We discuss: The confusion around updating NPPs without an updated model from HHS A quick refresher on Part 2 Who is considered a lawful holder under Part 2 Next steps for updating your NPP if you are a Part 2 program or lawful holder Our free resource on updating your NPP before the 2/16 enforcement deadline Listen here: For more, PCT Resources PCT Free...
info_outlineGroup Practice Tech
Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share advice on how to avoid phishing scams. We discuss: Phishing scams in text messages and email Common scams you might encounter What not to do when you get a suspicious text message PCT resources for how to identify scams and social engineering Listen here: For more,
info_outlineWelcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.
In our latest episode, we share what’s actually necessary when updating your Notice of Privacy Practices due to Part 2.
We discuss:
- The confusion around updating NPPs without an updated model from HHS
- A quick refresher on Part 2
- Who is considered a lawful holder under Part 2
- Next steps for updating your NPP if you are a Part 2 program or lawful holder
- Our free resource on updating your NPP before the 2/16 enforcement deadline
Listen here: https://personcenteredtech.com/group/podcast/
For more, visit our website.
PCT Resources
- PCT Free Resource: 42 CFR Part 2 & HIPAA Notices of Privacy Practices: A Decision Guide and Sample Language for Covered Entities
- a practical resource designed to help HIPAA-covered practices determine whether the updated 42 CFR Part 2 rules apply to them — and, if so, what belongs in their Notice of Privacy Practices. The guide includes a clear decision flow, plain-language explanations of Part 2 program vs. lawful holder obligations, and sample NPP language tailored to each category. It was created to fill the gap left by the absence of an updated HHS model NPP following the 2024 Part 2 Final Rule.
Resources
- HHS Fact Sheet on the 42 CFR Part 2 Final Rule
- this HHS Fact Sheet summarizes the 2024 Final Rule updating 42 CFR Part 2, including new consent provisions, redisclosure alignment with HIPAA, enforcement changes, and the February 16, 2026 compliance deadline. It provides high-level regulatory context for healthcare organizations handling substance use disorder records.
- JD Supra Article: 42 CFR Part 2 and Privacy Rule Compliance: Action Required by February 16, 2026
- This JD Supra article from Snell & Wilmer outlines the compliance steps healthcare organizations must take in response to the 2024 Final Rule updating 42 CFR Part 2. It explains which entities are required to update their Notices of Privacy Practices by February 16, 2026, including both Part 2 programs and HIPAA-covered entities that receive or maintain Part 2-protected records. The article highlights required NPP updates, enforcement risks, and the importance of aligning privacy notices with the amended regulations.