Programme Scope Determination
Whether a provider or unit is a Part 2 programme is a legal question with real consequences either way. Scope determination belongs to your counsel, and we configure to their conclusion.
Part 2 compliance software enforces the consent, segmentation, and re-disclosure rules that govern substance use disorder treatment records. It controls what leaves a programme, under what consent, and to whom. It does not interpret the regulation, determine whether your programme is covered, or substitute for legal advice.
Part 2 is enforced architecturally or not at all. A policy stating that treatment records must not be re-disclosed cannot stop a downstream system that received them from sharing onward, and a consent form filed in a drawer does not constrain an interface. Taction has built this: CHIPSS, our behavioural health system, was designed around record segmentation from the outset.

Our experts are ready to understand your business goals.






























































It implements the confidentiality regime for substance use disorder treatment records: consent capture with the required content, segmentation so protected records are separable, re-disclosure controls with notice, disclosure accounting, and audit. It sits inside a wider healthcare compliance programme and depends on the same foundations as our behavioural health software practice, where these constraints are routine rather than exceptional. Records received from a programme carry the same restrictions onward, and our EHR and EMR integration services work covers enforcing them inside a receiving system rather than only inside the programme that created them.
Whether a provider or unit is a Part 2 programme is a legal question with real consequences either way. Scope determination belongs to your counsel, and we configure to their conclusion.
Consent must identify the recipient, the purpose, the records covered, and an expiry, with revocation possible. Consent content is prescribed rather than left to local form design. Generic authorisation forms do not satisfy it.
Protected records must be separable from the rest of the chart so disclosure can exclude them. Our consent management work covers segmentation architecture in depth. Interface and export paths count as disclosure too.
Recipients must be notified that onward disclosure is prohibited, and your systems must not enable it. Re-disclosure prevention is an architectural obligation rather than a notice. Notice without control accomplishes very little.
Every disclosure records what was released, to whom, under which consent, for what purpose, and when. Disclosure records are the evidence of compliance. Refused requests are recorded alongside approved ones deliberately.
It does not interpret Part 2, determine programme status, decide whether a disclosure is lawful, or provide legal advice. Those judgements are your counsel’s. We build to their determinations rather than substituting ours.
The work is architecture rather than forms. Segmentation has to exist in the data model, consent has to be machine-enforceable at every disclosure path, and re-disclosure prohibition has to be carried with the data rather than stated in a covering letter. We build all three, using our identity and access management practice for the access layer, and we design against the exchange paths that most commonly leak protected records without anyone intending it. Where your counsel needs the wider privacy position implemented alongside Part 2, our HIPAA compliance practice covers that layer.
Protected records identified, tagged, and separable at every layer including exports, reports, and interfaces. Every path is enumerated, because segmentation that covers only the user interface fails. Printed output counts as a path.
Consent capture with required content, scope, expiry, revocation, and machine-readable enforcement at disclosure points. Machine enforcement is what distinguishes this from a filed form. Scanned forms cannot be evaluated by an interface at runtime.
Every route by which data leaves the organisation is catalogued and controlled: interfaces, exchange, reports, exports, and portals. Path enumeration is the honest core of this work. Support and vendor access count.
Required notice attached to disclosures, and downstream sharing prevented where you control the path. Notice plus control together, since notice alone accomplishes nothing. Downstream systems you do not control require contractual handling instead.
Every disclosure and every denied request recorded with its consent basis, retained for audit. Denied requests matter as much as approved ones. Retention follows your counsel’s advice rather than a technical default.
Participation in exchange configured so protected records are excluded absent consent, alongside our interoperability practice. Exchange defaults are the biggest exposure. Default participation settings are where protected records most often leak.
We publish no figures on disclosure volumes, consent rates, or audit outcomes, because those depend entirely on your programme, your patient population, and your counsel’s positions. What we deliver is instrumentation so your team measures impact against its own data. There is a clinical point worth making: blanket refusal to share anything is technically safe and clinically harmful, because care coordination suffers. Granular, enforceable consent is the design that serves patients rather than only the organisation. Read the items below as enforcement rather than as any claim about your legal position, which remains your counsel’s to assess.
Protected records are separable across every disclosure path rather than only in the chart view. Real segmentation is the whole compliance position. A new report should not be able to bypass it.
Disclosure is permitted or refused based on machine-readable consent rather than staff recollection. Automatic enforcement removes the most common failure mode. Staff cannot accidentally disclose what the system will not release.
Granular consent allows exchange participation without exposing protected records by default. Safe participation avoids the blanket withdrawal that harms care coordination. Patients then benefit from coordination rather than paying for your caution.
Every release and refusal is recorded with its basis, timestamp, and requester. Complete accounting is the evidence any investigation will ask for. Investigations begin with exactly this record rather than with recollection.
Consent revocation takes effect at every enforcement point rather than in one system only. Working revocation is a patient right that must function in practice. Propagation is tested rather than assumed to function.
Software cannot make a legal determination about your programme status. Scope questions go to counsel, and we build to their answer rather than around it. We would be wrong to attempt it.
We begin with disclosure path enumeration, because organisations consistently underestimate how many ways data leaves. Interfaces, exchange participation, reporting extracts, portals, and printed output all count, and any uncontrolled path defeats the rest. Discovery is paid and time-boxed and produces an itemised fixed-scope estimate. Where your counsel has not yet determined programme scope, that conversation precedes any build we would quote. The path inventory is the deliverable we would want first as a buyer, because an uncontrolled export route defeats every other control you have paid to build, however carefully.
Your counsel’s positions on programme scope, consent design, and disclosure practice are established first. Legal positions are inputs rather than outputs of our work. Building ahead of those positions wastes everyone’s money.
Every outbound route is catalogued: interfaces, exchange, reports, exports, portals, printing, and support access. Complete enumeration frequently uncovers uncontrolled paths that nobody in the organisation had documented. Support and vendor access count.
How protected records are identified and separated in your data model, including historical records. Historical segmentation is usually the hardest part. Records created before segmentation existed have to be handled deliberately.
Consent capture, scope, expiry, revocation, and enforcement points built with our data governance practice. Enforcement points are tested individually. Enforcement points are tested individually rather than trusted as a set.
Each enumerated path tested with protected records to confirm exclusion absent consent. Path testing is the evidence that segmentation works. Protected test records are used to confirm exclusion at each route.
Live enforcement with disclosure monitoring, then handover covering consent configuration and path controls. Path inventory is maintained as systems change. New systems add paths, so the inventory needs a named owner.
We build enforcement architecture. We are not your counsel, we provide no legal advice or regulatory interpretation, and programme scope and consent design are determinations your legal team makes. Compliance covers HIPAA safeguards alongside Part 2, protected health information handling generally, state confidentiality law where stricter, and disclosure accounting. Our own experience here is concrete: CHIPSS was built with segmentation in the data model rather than added afterwards. We record which counsel position was implemented and when it changed, because these interpretations have shifted with harmonisation and your evidence should show what applied.
Protection is a property of the record enforced at every access and disclosure path. Model-level segmentation cannot be bypassed by a new report or interface. Bypass would require changing the model itself.
Consent is structured data evaluated at disclosure time rather than a scanned document. Structured consent is the only form software can actually enforce. Expiry and revocation are evaluated at every request.
We decline to build classifiers that infer likely substance use disorder to route or flag records. Inference recreates the disclosure the rule exists to prevent. That refusal precedes any contracting discussion.
Part 2 restricts use of these records in proceedings against a patient. We decline to build access paths designed for law enforcement use. Court-ordered disclosure follows your counsel’s process rather than a feature.
Revoked consent takes effect at every enforcement point immediately, with the change logged. Propagation is tested rather than assumed to work. Patients are entitled to have revocation work in practice.
Disclosures, refusals, consent versions, and enforcement decisions are retained immutably. Audit integrity is your evidence in any investigation or dispute. Criminal exposure exists in this regime, which raises the evidentiary bar.
We have been building healthcare software since 2013, which is over 12 years, and we have delivered more than 200 healthcare projects. We built CHIPSS, a behavioural health system, where consent segmentation of sensitive records drove the architecture rather than being retrofitted. We are ISO 27001 certified, our leadership brings more than 20 years of personal experience in the field, and we work from four US offices in Chicago, Cheyenne, Austin, and Sacramento. We will also tell you when scope questions for your counsel have to be settled before any build can sensibly begin.
CHIPSS required segmentation and re-disclosure control in the data model, so this is practised architecture for us rather than a regulation we have read about. Retrofitting segmentation afterwards is considerably harder.
We catalogue every disclosure route before designing enforcement. Enumeration is unglamorous and it is where compliance positions actually succeed or fail. One uncontrolled export defeats an otherwise sound compliance position.
We argue for granular consent rather than blanket refusal, because refusal harms care coordination. That position takes more engineering and serves patients better. Blanket refusal protects the organisation and harms the patient.
Taction is ISO 27001 certified, with documented access control, encryption, immutable audit logging, and change control that survives external review. Every disclosure decision, including each refusal, is logged immutably for audit.
We build software and provide no legal advice, scope determination, or regulatory interpretation. Role clarity matters especially in a regime with criminal exposure. We refer you to counsel for interpretation and scope questions.
Four US offices in Chicago, Cheyenne, Austin, and Sacramento, with delivery overlapping your hours through path testing and rollout. Escalation reaches a named delivery lead rather than a shared support queue.
Pricing turns on how many disclosure paths exist, whether historical records need segmenting, and how many systems enforce consent. The tiers below cover engineering. Third-party licensing, cloud infrastructure, data subscriptions, and hardware are separate from engineering cost and itemised clearly. Legal advice, scope determination, consent form review, and any compliance audit performed as a service are obtained elsewhere and sit outside our estimate entirely. Historical segmentation deserves separate mention: identifying which existing records are protected across years of accumulated data is usually the largest single line in an estimate like this.
$40,000 to $80,000 for consent capture with machine-readable enforcement and segmentation across a limited set of disclosure paths. Remaining paths are enumerated and scoped honestly for a subsequent phase of work.
$80,000 to $200,000 for full segmentation architecture, consent management with revocation, complete path enforcement, re-disclosure controls, and disclosure accounting. This tier covers most single-organisation programmes that we are asked to scope.
Starting at $200,000 for multi-system enforcement, historical record segmentation, exchange participation controls, and intermediary obligations across participants. System count and historical record volume drive the figure more than patient numbers.
A paid, time-boxed discovery phase produces a disclosure path inventory, segmentation feasibility assessment, consent model design, and an itemised fixed-scope estimate. The path inventory is yours whether or not we build.
Disclosure path count, historical record volume, system count, and exchange participation scope. Historical segmentation is usually the largest single cost. Uncontrolled paths discovered during enumeration frequently change the whole scope.
Budget annually for path inventory maintenance, enforcement testing after system changes, consent model review, and audit reporting. New systems add paths that need enforcing. Enforcement is retested after every system change.
If you cannot list every route by which data leaves your organisation, start there. A paid discovery phase gives you a complete disclosure path inventory covering interfaces, exchange, reports, exports, portals, and support access, a segmentation feasibility assessment including historical records, a consent model design your counsel can review, and an itemised fixed-scope estimate. Where your counsel has not yet determined programme scope, we will say that conversation comes first.
These are the questions compliance officers, privacy officers, and behavioural health leaders raise before scoping Part 2 work. Several concern boundaries: scope determination and interpretation are legal work rather than ours. One concerns a capability we refuse to build. Where an answer depends on your counsel’s positions, that conversation precedes any build, and the path inventory is worth having in either case. We would rather tell you that a scope question belongs with your counsel than configure enforcement against an interpretation nobody at your organisation has actually adopted in writing.
That is a legal determination your counsel makes, and it matters considerably in both directions. We do not assess programme status, and we would be wrong to. Once your counsel has concluded, we configure enforcement to their position and record which interpretation was applied and when.
Because a policy cannot stop an interface. If protected records are not separable in the data model, then every report, export, exchange transaction, and downstream system carries them regardless of what your procedures say. Segmentation that exists only in the user interface fails at the first extract.
That is technically safe and clinically harmful. Care coordination suffers, and patients with substance use disorders frequently have complex needs requiring shared information. Granular, enforceable consent lets you participate in exchange and share appropriately, which is more engineering work and considerably better for the people involved.
No. A classifier inferring treatment status to route or flag records recreates exactly the disclosure the regulation prohibits, and it would be wrong even where it improved throughput. Protected records are identified by their source and by explicit designation rather than by inference from clinical content.
They carry re-disclosure restrictions your systems must honour, which many organisations have never implemented. We segment received records, attach the restriction, prevent onward disclosure through paths you control, and account for disclosures. This obligation is frequently the largest unrecognised exposure we find. Discovering it during an investigation is the worst sequence.
It has to, and that is what path enumeration and testing establish. Revoked consent must take effect at every enforcement point, not only in the system where it was recorded. We test each path with protected records to confirm exclusion, because assuming propagation works is how these positions fail.
Your email address will not be published. Required fields are marked *
Our expert reaches out shortly after receiving your request and analyzing your requirements.
If needed, we sign an NDA to protect your privacy.
We request additional information to better understand and analyze your project.
We schedule a call to discuss your project, goals. and priorities, and provide preliminary feedback.
If you're satisfied, we finalize the agreement and start your project.