The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) launched a new enforcement program and web portal for reporting breaches involving 42 CFR Part 2 substance use disorder (SUD) patient records, and updated its HIPAA breach website to direct covered entities to the new reporting mechanism. The initiative is intended to support newly effective mandates aimed at strengthening confidentiality protections for SUD records.
HHS OCR described the program as a “landmark” civil enforcement mechanism for Part 2 confidentiality requirements, enabling OCR to pursue civil monetary penalties and negotiate resolution agreements, settlements, and corrective actions for noncompliance. Reported penalties and enforcement options are positioned to align with OCR’s existing HIPAA breach enforcement approach, signaling increased regulatory scrutiny for organizations handling SUD treatment records.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The new federal mandates for reporting and enforcing breaches involving 42 CFR Part 2 substance use disorder records took effect, requiring reports within 60 days of discovery for breaches affecting 500 or more individuals and annual reporting for smaller incidents. HHS also updated its HIPAA breach reporting website to reflect OCR's authority to investigate and enforce both HIPAA and Part 2 breaches.
The U.S. Department of Health and Human Services, through its Office for Civil Rights, launched a new web portal and civil enforcement program for breaches involving substance use disorder records protected under 42 CFR Part 2. The program enables reporting and public viewing of breaches affecting 500 or more individuals and gives OCR enforcement options similar to HIPAA, including penalties, settlements, and corrective actions.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.