Behavioral health and substance-use providers
Behavioral health software built for the consent rule HIPAA alone misses
A substance-use record needs its own written consent before it moves anywhere, even inside your own referral network. Most health software was never built to track that.
What a behavioral health buyer should ask any vendor
4 things that decide this
- 01Ask if the system separates substance-use records from general behavioral health notes. Under 42 CFR Part 2, a record tied to a federally assisted substance-use program needs its own consent trail, even when HIPAA would allow the same disclosure without one.
- 02Ask how consent is tracked after it is collected. Part 2 consent names who can receive the record and for what purpose. A checkbox at intake is not a record of that.
- 03Ask which states the platform prescribes in. Controlled-substance telehealth, including buprenorphine, runs under DEA rules that shifted after the pandemic-era flexibilities ended, and state licensure adds another layer on top.
- 04Ask how outcome measures get captured. Measurement-based care means a PHQ-9 or GAD-7 score tracked over time, not a form filled in once and filed away.
HIPAA covers the record. Part 2 covers who may see it
42 CFR Part 2 applies to any record created by a federally assisted program that treats substance use. It sits on top of HIPAA. It does not replace it. Disclosure needs the patient's written consent naming who gets the record and why. That applies even for care coordination with another provider on the same case.
A general behavioral health platform built for anxiety or depression usually has no concept of this. It follows HIPAA's disclosure rules, which allow treatment-related sharing without asking again. Add a substance-use program to that same practice and the software is now wrong for part of its patient list.
Telehealth prescribing adds a second constraint. Buprenorphine and other controlled substances can be prescribed by video under specific DEA and state rules. Those rules have changed more than once since 2020. A platform built around one year's flexibility breaks when the rule does.
- 01Flag any substance-use record at the schema level, not with a tag that staff can forget to apply.
- 02Store consent as a structured record naming the recipient and purpose, not a signature on a PDF.
- 03Treat controlled-substance telehealth rules as configuration that changes, not a fact baked into the build.
- IntakeSubstance-use history disclosed, or not.
- Program flag setRecord marked as Part 2 scope, or missed.
- Coordination requestAnother provider asks for the chart.
- Consent checkNamed recipient, named purpose, on file or not.
- Outcome trackingPHQ-9 or GAD-7 logged over time, not once.
- Telehealth prescribingState and DEA rules applied at the visit, not at launch.
Most behavioral health builds handle intake and outcomes well. The consent check on step four is where a general HIPAA build quietly does the wrong thing.
Measurement-based care is a tracking problem, not a form
Measurement-based care means a standard tool, a PHQ-9 for depression or a GAD-7 for anxiety. It gets scored at intake and again on a schedule. The clinician sees the trend, not a single number. Payers increasingly expect to see it too. A form filed away once produces no trend.
This is the same shape as outcome tracking in clinical research work. A scored instrument, captured on a schedule, checked against a threshold. The system flags a person for follow-up instead of waiting on a chart review months later. The instrument changes. Capture, score, flag stays the same.
Consent tracking has the same shape as any sensitive-record permission problem. Who can see this record, for what reason, and until when. Part 2 names that rule in more detail than most systems are built to enforce.
- Score outcome instruments on capture and store the trend alongside the latest value.
- Flag a declining score against a threshold instead of relying on a clinician to notice.
- Model Part 2 consent as an expiring, purpose-bound grant, the same shape as any sensitive-record permission.

The behavioral health work we take
Built around the consent and tracking rules this field adds on top of general HIPAA scope.
42 CFR Part 2 consent tracking
Structured consent records naming recipient and purpose, enforced at the point a record would otherwise be shared.
Measurement-based care tools
PHQ-9, GAD-7 and similar instruments, scored on capture with the trend visible and threshold alerts on decline.
Telehealth prescribing workflows
Visit records that carry the state and DEA rule in effect at the time of the prescription, not a rule fixed at launch.
Referral and coordination portals
Sharing between providers gated by the same consent record the intake process created, not a separate permissions system.
Group and program-level reporting
Outcome and utilization views built for a practice or network, with substance-use scope separated from general behavioral health data.
Audit trails for who touched what
Access logged at the record level, with the extra Part 2 disclosure log kept separately from the general HIPAA audit trail.
“I am extremely happy with the results and would highly recommend Hashlogics to anyone.”
Daniel Khin · CEO, PremiumAudit.io
General HIPAA build against one scoped for Part 2
A platform built for general behavioral health handles most of a practice correctly. It is the substance-use portion that needs the second column.
| Criterion | General HIPAA-only build | What a Part 2-aware build does |
|---|---|---|
| Sharing with another provider | Allowed for treatment purposes, no extra check. | Blocked until a named-recipient, named-purpose consent exists. |
| Substance-use records | Stored the same as any other clinical note. | Flagged at the schema level and handled under a separate disclosure rule. |
| Outcome tracking | A form filled in once, filed with the chart. | A scored instrument tracked over time with threshold alerts. |
| Telehealth prescribing | One rule set, fixed at build time. | Rule applied per visit, matched to current state and DEA requirements. |
| Audit trail | One access log for every record type. | A separate Part 2 disclosure log, distinct from the general access log. |
The stack this work runs on
Compliance
Data
Application
What behavioral health providers ask us first
01How is 42 CFR Part 2 different from HIPAA?
HIPAA lets a provider share a record for treatment, payment or operations without asking again each time. Part 2 covers substance-use records from a federally assisted program. It requires written consent naming the recipient and purpose before most disclosures, even to another provider on the same care team.
02Can one platform hold both general behavioral health and substance-use records?
Yes, and most practices need exactly that. The record gets flagged as Part 2 scope when it is created. The software then applies the stricter consent rule on its own, instead of relying on staff to remember which patients it covers.
03What are the current rules for prescribing buprenorphine by telehealth?
DEA and state rules have both changed since the pandemic-era flexibilities that first allowed it. They can differ by state and by registration type. We build the prescribing workflow to read the current rule as configuration. A rule change does not force a rebuild.
04What does measurement-based care actually require from the software?
A standard scored instrument, commonly the PHQ-9 or GAD-7. It gets captured at intake and again at set intervals. The clinician sees the trend and a flag on a declining score. A single intake form does not meet that bar, because there is no trend to see.
05How do you handle consent for a group practice with multiple programs?
As a structured record tied to the specific program and patient, not a blanket agreement signed once. A patient in both a therapy program and a substance-use program can consent to sharing for one and refuse it for the other. The system has to keep that distinction.
Go deeper
- Telemedicine app development →The prescribing and video-visit rules that apply across telehealth generally.
- Healthcare software development →The wider constraints: audit trails, drift, and human-in-the-loop clinical AI.
- HIPAA-compliant development →The controls a build needs before protected health information reaches any system.
- How do you build HIPAA-compliant AI? →Where AI touches protected health data, and what has to be true before it does.

