<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-19-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0945-AA16</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202310</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0945</CODE>
            <NAME>Office for Civil Rights</NAME>
            <ACRONYM>OCR</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Confidentiality of Substance Use Disorder Patient Records</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This final rule, to be issued in coordination with the Substance Abuse and Mental Health Services Administration (SAMHSA), would implement provisions of section 3221 of the CARES Act. Section 3221 amended 42 U.S.C. 290dd-2 to better harmonize the 42 CFR part 2 (part 2) confidentiality requirements with certain permissions and requirements of the HIPAA Rules and the HITECH Act.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>42 CFR 2</CFR>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>42 U.S.C. 290dd-2 amended by the Coronavirus Aid, Relief, and Economic Security Act (the CARES Act), Pub. L. 116-136, sec. 3221 (March 27, 2020)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Health Information Technology for Economic and Clinical Health (HITECH) Act, Pub. L. 111-5, sec. 13402 and 13405 (February 17, 2009)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Health Insurance Portability and Accountability Act of 1996 (HIPAA) Pub. L. 104-191, sec. 264 (August 21, 1996)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Social Security Act, Pub. L. 74-271 (August 14, 1935) (see secs. 1171 to 1179 of the Social Security Act, 42 U.S.C. 1320d to 1320d–8).</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST>
            <LEGAL_DLINE_INFO>
                <DLINE_TYPE>Statutory</DLINE_TYPE>
                <DLINE_ACTION_STAGE>NPRM</DLINE_ACTION_STAGE>
                <DLINE_DATE>03/27/2021</DLINE_DATE>
                <DLINE_DESC></DLINE_DESC>
            </LEGAL_DLINE_INFO>
        </LEGAL_DLINE_LIST>
        <LEGAL_DLINE_OVERALL_DESC>The CARES Act requires revisions to regulations with respect to uses and disclosures of information occurring on or after the date that is 12 months after the date of enactment of the Act (March 27, 2021); and not later than one year after the date of enactment, an update to the Notice of Privacy Practices (NPP) provisions of the HIPAA Privacy Rule at 45 CFR 164.520.</LEGAL_DLINE_OVERALL_DESC>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>Rulemaking is needed to implement section 3221 of the CARES Act, which modified the statute that establishes protections for the confidentiality of substance use disorder (SUD) treatment records and authorizes the implementing regulations at 42 CFR part 2 (part 2). As required by the CARES Act, this&nbsp;regulation will:&nbsp;(1) Align certain provisions of part 2 with aspects of the HIPAA Privacy, Breach Notification, and Enforcement Rules. (2) Strengthen part 2 protections against uses and disclosures of patients&rsquo; SUD records for civil, criminal, administrative, and legislative proceedings. (3) Require that a HIPAA Notice of Privacy Practices address privacy practices with respect to part 2 records.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>Section 3221(i) of the CARES Act requires rulemaking as may be necessary to implement and enforce section 3221.</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HHS considered whether the CARES Act provisions could be implemented through guidance. However, rulemaking is required because the current part 2 regulations are inconsistent with the authorizing statute, as amended by the CARES Act. HHS considered whether to include the anti-discrimination provisions of section 3221(g) in this rulemaking. However, because implementation of the anti-discrimination provisions implicates numerous civil rights authorities, which require collaboration with the Department of Justice, HHS will address the anti-discrimination provisions in a separate rulemaking.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HHS estimates that the effects of the requirements for regulated entities would result in new costs of $64,299,891 within 12 months of implementing the final rule, followed by $2,514,756 of recurring annual costs in years two through five. HHS estimates these first-year costs would be partially offset by $12,755,378 annual cost savings, resulting in overall net costs of $10,582,027 over 5 years.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>To be determined.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>12/02/2022</TTBL_DATE>
                <FR_CITATION>87 FR 74216</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>01/31/2023</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Action</TTBL_ACTION>
                <TTBL_DATE>11/00/2023</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
            <SMALL_ENTITY>Governmental Jurisdictions</SMALL_ENTITY>
            <SMALL_ENTITY>Organizations</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
            <GOVT_LEVEL>Local</GOVT_LEVEL>
            <GOVT_LEVEL>State</GOVT_LEVEL>
            <GOVT_LEVEL>Tribal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marissa</FIRST_NAME>
                <LAST_NAME>Gordon-Nguyen</LAST_NAME>
                <TITLE>Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>800 368-1019</PHONE>
                <TDD_PHONE>800 537-7697</TDD_PHONE>
                <EMAIL>ocrprivacy@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
