Editorial guide
HIPAA, Business Associates, and 42 CFR Part 2 in Legal AI Review
A boundary guide for medical records, business-associate analysis, security safeguards, and substance-use-disorder record protections.
By Jake Bauman. Updated August 12, 2026. Educational summary only; current counsel must determine applicability and obligations. No named legal review is claimed unless identified here.
Short answer
Legal work involving medical records does not make every AI tool or law firm automatically HIPAA compliant or noncompliant. The analysis depends on the parties, functions, information, authorizations, contracts, and applicable law. Covered substance-use-disorder records can also trigger separate 42 CFR Part 2 requirements.
Key takeaways
- Determine whether HIPAA applies and whether any party is acting as a business associate for the specific work.
- Local processing changes data flow but does not eliminate administrative, physical, technical, contractual, or incident obligations.
- Identify Part 2 and other more-specific data classes separately instead of treating all medical records as one category.
Editorial methods are identified as such. Numbered links beside a paragraph or section point to the authority or framework relevant to that claim; a source does not certify Under Seal or replace current jurisdiction-specific review.
Start with roles and data flow
Basis: external sources listed below
Identify the covered entity, business associate, subcontractor, law firm, client, vendor, and intended function. Map what information is received, created, maintained, or transmitted. HHS explains that legal and data-processing services can create business-associate relationships in some circumstances; a product page cannot decide the result for every matter.
Sources for this section: [2] Business Associates (opens in a new tab)
Security is an operating program
Basis: external sources listed below
When the HIPAA Security Rule applies, administrative, physical, and technical safeguards matter. A local workstation still needs access controls, encryption decisions, physical protection, backup and recovery, updates, logging, risk analysis, and incident procedures. A ‘HIPAA certified’ badge is not a substitute for the applicable analysis and documentation.
Sources for this section: [1] The HIPAA Security Rule (opens in a new tab)
Treat Part 2 as a separate flag
Basis: external sources listed below
HHS’s Part 2 rule addresses confidentiality of covered substance-use-disorder patient records and includes requirements that are not safely collapsed into a generic HIPAA label. Intake should identify the possibility of Part 2 data and route it for current legal and contractual review before processing.
HHS states that the 2024 final rule has been effective since April 16, 2024 and that compliance was required by February 16, 2026. The current HHS overview and eCFR text should be checked again when this guide is reviewed because enforcement, court decisions, and guidance can change.
Sources for this section: [3] Understanding Part 2 (opens in a new tab), [4] 42 CFR Part 2 Final Rule Fact Sheet (opens in a new tab), [5] 42 CFR Part 2 (opens in a new tab)
Authorities and frameworks
Each source is classified below. It may govern a specific legal point, offer professional or government guidance, or provide a voluntary framework. The collection does not validate every editorial method in this guide and does not resolve a firm-specific question.
- [1]The HIPAA Security Rule Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
- [2]Business Associates Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
- [3]Understanding Part 2 Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
- [4]42 CFR Part 2 Final Rule Fact Sheet Opens in a new tab. — U.S. Department of Health and Human Services · Government guidance
- [5]42 CFR Part 2 Opens in a new tab. — Electronic Code of Federal Regulations · Rule
Connect the general guidance to the product record
Continue the review
Under Seal is pre-release software, not a law firm. Do not submit matter details or client documents through this website.
Request a no-client-data readiness review