Behavioral health and substance-use providers
AI, automation and custom software for behavioral health practices, built for the consent rule HIPAA alone misses
A substance-use note is the risk in your chart. Under 42 CFR Part 2 it needs its own written consent before it moves anywhere, even to another provider on the same case. Most behavioral health platforms don't know that rule exists. We build intake, scheduling, outcome tracking and telehealth prescribing around your EHR so yours does.
What a behavioral health buyer should ask any vendor
4 things that decide this
- 01Ask if the system separates substance-use records from your general behavioral health notes. Under 42 CFR Part 2, a record tied to a federally assisted substance-use program needs its own consent trail. HIPAA alone would let the same disclosure through without one.
- 02Ask how consent gets tracked once it's collected, not just captured. Part 2 consent names who can receive the record and why. A checkbox at your intake form isn't a record of that, and you'll need one when an auditor asks.
- 03Ask which states the platform prescribes in. Controlled-substance telehealth, including buprenorphine, runs under DEA rules that shifted more than once after the pandemic-era flexibilities ended. Your state licensure sits on top.
- 04Ask how outcome measures get captured. Measurement-based care means a PHQ-9 or GAD-7 score tracked over time in your chart, not a form filled in once at intake and filed away.
HIPAA covers the record. Part 2 covers who may see it
42 CFR Part 2 applies to any record your program creates under federal substance-use funding. It sits on top of HIPAA rather than replacing it. Disclosure needs the patient's written consent naming who gets the record and why. That's true even for care coordination with another provider on the same case, which surprises most practices the first time it comes up.
A general behavioral health platform built for anxiety or depression usually has no concept of this. It follows HIPAA's disclosure rules, which allow treatment-related sharing without asking again. Add a substance-use program to your practice, and the software is now wrong for part of your patient list. Nothing looks broken. It just is.
Telehealth prescribing adds a second constraint. You can prescribe buprenorphine and other controlled substances by video under specific DEA and state rules, and those rules have changed more than once since 2020. A platform built around one year's flexibility breaks the day the rule does, usually without telling you.
- 01Flag any substance-use record at the schema level, not with a tag staff can forget to apply.
- 02Store consent as a structured record naming the recipient and purpose, not a signature on a PDF.
- 03Treat controlled-substance telehealth rules as configuration that changes, not a fact baked into the build.
- IntakeSubstance-use history disclosed, or not.
- Program flag setRecord marked as Part 2 scope, or missed.
- Coordination requestAnother provider asks for the chart.
- Consent checkNamed recipient, named purpose, on file or not.
- Outcome trackingPHQ-9 or GAD-7 logged over time, not once.
- Telehealth prescribingState and DEA rules applied at the visit, not at launch.
Most builds handle intake and outcomes well. It's the consent check on step four where a general HIPAA build quietly does the wrong thing.
Measurement-based care is a tracking problem, not a form
Measurement-based care means a standard tool, a PHQ-9 for depression or a GAD-7 for anxiety, scored at intake and again on a schedule. Your clinician sees the trend, not a single number. Payers increasingly expect to see it too. A form your intake staff file away once produces no trend at all.
It's the same shape as outcome tracking in clinical research work: a scored instrument, captured on a schedule, checked against a threshold. Your system flags a person for follow-up instead of waiting on a chart review months later. Instruments change from field to field. Capture, score, flag stays the same.
Consent tracking follows the same shape as any sensitive-record permission problem: who can see this record, for what reason, and until when. Part 2 names that rule in more detail than most systems enforce. We design your schema around it first and the interface second.
- Score outcome instruments on capture and store the trend alongside the latest value.
- Flag a declining score against a threshold instead of relying on a clinician to notice.
- Model Part 2 consent as an expiring, purpose-bound grant, the same shape as any sensitive-record permission.

Where patient information travels is the first design decision, made on paper, with your compliance officer
Most practices we talk to have had an AI tool vetoed by compliance, and the veto was usually right. A vendor couldn't say where your data went. It wouldn't sign a BAA covering every party in the chain, or it trained on inputs. So every build starts with a one-page PHI map for your practice: which system holds what, which vendor touches it, which region, what's logged, what's retained, and which fields get de-identified before a model ever sees them.
What follows is simple to state, and we put it in writing. A BAA with every business associate in the chain before any PHI moves. Access scoped to the role and the patient, never practice-wide. No training on your data. An audit trail of who saw what. The clinical decision, the diagnosis and anything that touches care stays with your clinician; the software schedules, verifies, drafts and reminds.
- 01BAA with every vendor in the chain, signed before anything is built.
- 02PHI scoped to role and patient; de-identified where a model is involved; audit trail on every access.
- 03A Part 2 disclosure log kept separately from the general HIPAA access log, so the two never get confused.
The behavioral health work we take
Built around the consent and tracking rules your field adds on top of general HIPAA scope, and wired to the EHR or intake system you already run.
42 CFR Part 2 consent tracking
Structured consent records naming recipient and purpose, enforced at the point a record would otherwise be shared.
HIPAA-compliant development →
Measurement-based care tools
PHQ-9, GAD-7 and similar instruments, scored on capture with the trend visible and threshold alerts on decline.
Custom software for practices →
Telehealth prescribing workflows
Visit records that carry the state and DEA rule in effect at the time of the prescription, not a rule fixed at launch.
EHR integration for practices →
Referral and coordination portals
Sharing between providers gated by the same consent record intake created, not a separate permissions system nobody maintains.
Custom software for practices →
Intake and scheduling that answers the phone
New clients calling after a bad day deserve a line that answers, screens by your rules and books, with anything in crisis going straight to a person.
AI front desk for practices →
Group and program-level reporting
Outcome and utilization views built for a practice or network, with substance-use scope kept separate from general behavioral health data.
Which practice KPIs actually matter →
“I am extremely happy with the results and would highly recommend Hashlogics to anyone.”
Daniel Khin · CEO, PremiumAudit.io
Some of the systems we have shipped
General HIPAA build against one scoped for Part 2
A platform built for general behavioral health handles most of your practice correctly. It's the substance-use portion that needs the second column.
Sharing with another provider
General HIPAA-only build
Allowed for treatment purposes, no extra check.
What a Part 2-aware build does
Blocked until a named-recipient, named-purpose consent exists.
Substance-use records
General HIPAA-only build
Stored the same as any other clinical note.
What a Part 2-aware build does
Flagged at the schema level and handled under a separate disclosure rule.
Outcome tracking
General HIPAA-only build
A form filled in once, filed with the chart.
What a Part 2-aware build does
A scored instrument tracked over time with threshold alerts.
Telehealth prescribing
General HIPAA-only build
One rule set, fixed at build time.
What a Part 2-aware build does
Rule applied per visit, matched to current state and DEA requirements.
Audit trail
General HIPAA-only build
One access log for every record type.
What a Part 2-aware build does
A separate Part 2 disclosure log, distinct from the general access log.
The stack this work runs on
Compliance
- 42 CFR Part 2 consent modeling
- HIPAA-scoped data design
- Signed BAAs
Data
- PostgreSQL
- Field-level encryption
- Record-level audit logging
Application
- React + TypeScript
- NestJS
- Telehealth video integration, or whatever your EHR already runs
What behavioral health providers ask us first
01How is 42 CFR Part 2 different from HIPAA?+
HIPAA lets you share a record for treatment, payment or operations without asking again each time. Part 2 covers substance-use records from a federally assisted program. It requires written consent naming the recipient and purpose before most disclosures, even to another provider on the same care team.
02Can one platform hold both general behavioral health and substance-use records?+
Yes, and most practices need exactly that. Your record gets flagged as Part 2 scope the moment it's created. The software then applies the stricter consent rule on its own, instead of relying on staff to remember which patients it covers.
03What are the current rules for prescribing buprenorphine by telehealth?+
DEA and state rules have both changed since the pandemic-era flexibilities that first allowed it, and they can differ by your state and registration type. We build your prescribing workflow to read the current rule as configuration, so a rule change doesn't force a rebuild.
04What does measurement-based care actually require from the software?+
A standard scored instrument, commonly the PHQ-9 or GAD-7, captured at intake and again at set intervals. Your clinician sees the trend and a flag on a declining score. A single intake form doesn't meet that bar, because there's no trend for you to see.
05How do you handle consent for a group practice with multiple programs?+
As a structured record tied to your specific program and patient, not a blanket agreement signed once. A patient in both a therapy program and a substance-use program can consent to sharing for one and refuse it for the other, and your system has to keep that distinction straight.
06Is this the whole of what you do for behavioral health practices?+
No. Consent and outcome tracking are the loudest problem in your segment, and that's usually where we start. The same team also builds your intake and scheduling automation, EHR integrations and practice dashboards. Our healthcare hub lays out all eight areas and which page owns each one.
A senior engineer, not a sales rep
Abdul Basit founded Hashlogics in 2017, and the team runs from Lahore with a US LLC. Clients rate the work 5.0 on Clutch, and in 2026 it was named Best AI-Native Software House of the Year at TechNova. TrialTriage, an AI clinical-trial matching system for oncology, is one of the systems we built and can show you.
Your audit call is with an engineer who has read consent logs and outcome trackers like yours. Bring your current PHQ-9 or GAD-7 process if you have one, and we'll work from that.
- BAA and NDA before the first conversation about real data.
- No pitch on the call. A note you could hand to another vendor.
- Fixed price after the diagnostic, so the number isn't a guess.

More for practices
- Healthcare hub →The eight areas every practice leaks time and revenue, and what we put in each one.
- AI front desk for practices →The crisis-aware intake line: answers, screens, books, escalates to a person.
- HIPAA-compliant development →The PHI map, the BAA chain and how we build for regulated data.
- EHR integration for practices →FHIR, HL7 and vendor APIs; intake and documentation into the chart.
- Custom software for practices →Multi-location operations, dashboards, portal and patient communication.
- Home care software →Scheduling, visit verification and documents across a workforce that's never in the office.
- How do you build HIPAA-compliant AI? →Where AI touches protected health data, and what has to be true before it does.

