Skip to main content
Under Seal is pre-release.Review the readiness gates.

Editorial guide

HIPAA, Business Associates, and 42 CFR Part 2 in Legal AI Review

A boundary guide for medical records, business-associate analysis, security safeguards, and substance-use-disorder record protections.

By . Updated August 12, 2026. Educational summary only; current counsel must determine applicability and obligations. No named legal review is claimed unless identified here.

Short answer

Legal work involving medical records does not make every AI tool or law firm automatically HIPAA compliant or noncompliant. The analysis depends on the parties, functions, information, authorizations, contracts, and applicable law. Covered substance-use-disorder records can also trigger separate 42 CFR Part 2 requirements.

Key takeaways

  • Determine whether HIPAA applies and whether any party is acting as a business associate for the specific work.
  • Local processing changes data flow but does not eliminate administrative, physical, technical, contractual, or incident obligations.
  • Identify Part 2 and other more-specific data classes separately instead of treating all medical records as one category.

Editorial methods are identified as such. Numbered links beside a paragraph or section point to the authority or framework relevant to that claim; a source does not certify Under Seal or replace current jurisdiction-specific review.

Start with roles and data flow

Basis: external sources listed below

Identify the covered entity, business associate, subcontractor, law firm, client, vendor, and intended function. Map what information is received, created, maintained, or transmitted. HHS explains that legal and data-processing services can create business-associate relationships in some circumstances; a product page cannot decide the result for every matter.

Sources for this section: [2] Business Associates (opens in a new tab)

Security is an operating program

Basis: external sources listed below

When the HIPAA Security Rule applies, administrative, physical, and technical safeguards matter. A local workstation still needs access controls, encryption decisions, physical protection, backup and recovery, updates, logging, risk analysis, and incident procedures. A ‘HIPAA certified’ badge is not a substitute for the applicable analysis and documentation.

Sources for this section: [1] The HIPAA Security Rule (opens in a new tab)

Treat Part 2 as a separate flag

Basis: external sources listed below

HHS’s Part 2 rule addresses confidentiality of covered substance-use-disorder patient records and includes requirements that are not safely collapsed into a generic HIPAA label. Intake should identify the possibility of Part 2 data and route it for current legal and contractual review before processing.

HHS states that the 2024 final rule has been effective since April 16, 2024 and that compliance was required by February 16, 2026. The current HHS overview and eCFR text should be checked again when this guide is reviewed because enforcement, court decisions, and guidance can change.

Sources for this section: [3] Understanding Part 2 (opens in a new tab), [4] 42 CFR Part 2 Final Rule Fact Sheet (opens in a new tab), [5] 42 CFR Part 2 (opens in a new tab)

Authorities and frameworks

Each source is classified below. It may govern a specific legal point, offer professional or government guidance, or provide a voluntary framework. The collection does not validate every editorial method in this guide and does not resolve a firm-specific question.

  • [1]The HIPAA Security Rule Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
  • [2]Business Associates Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
  • [3]Understanding Part 2 Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
  • [4]42 CFR Part 2 Final Rule Fact Sheet Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
  • [5]42 CFR Part 2 Opens in a new tab. — Electronic Code of Federal Regulations · Rule

Connect the general guidance to the product record