The 42 CFR Part 2 compliance date landed on February 16, 2026 — six days ago. If your practice bills any substance use disorder treatment and your billing workflow has not changed since last year, you are already behind. Billing for behavioral health services is the one revenue cycle in healthcare where the claim form, the consent form, and the privacy notice all have to agree with each other, and where getting the documentation wrong exposes a category of record HIPAA treats as more sensitive than anything else in the chart.

This guide is for the administrator, billing lead, or privacy officer who owns that workflow. It covers how practices document code selection for behavioral health encounters, which parts of the mental health record may lawfully travel to a payer, what the 2026 Part 2 changes mean for your clearinghouse and RCM contracts, and how to handle the patient who pays cash and asks you to keep it off their insurance. No clinical advice — operational mechanics and records handling only.

The Three Record Sets Your Billing Staff Actually Touch

Most billing errors in behavioral health start as a records-classification error. Your staff are working with three distinct sets, and only two of them are billable inputs.

The designated record set. Progress notes, assessments, treatment plans, medication records, discharge summaries. This is the chart. Patients have a right of access to it under 45 CFR 164.524, and payers can receive relevant portions for payment purposes under the treatment, payment, and operations permission.

Psychotherapy notes. HIPAA defines these narrowly at 45 CFR 164.501: notes recorded by a mental health professional documenting or analyzing the contents of a counseling session, maintained separately from the rest of the record. If your clinicians keep process notes inside the general chart, they are not psychotherapy notes under the rule — separation is part of the definition. Psychotherapy notes are excluded from the right of access, and disclosing them generally requires a specific authorization, including disclosure to a health plan for payment.

Claim and eligibility data. Diagnosis codes, procedure codes, units, dates and times of service, place of service, rendering provider NPI, modifiers. This is what leaves your building.

Train your billers to work from set one and set three, and never set two. Then confirm that your EHR configuration actually enforces the separation your policy claims.

Can You Send Psychotherapy Notes to a Payer?

No — not without a specific, separate authorization from the patient. Under 45 CFR 164.508(a)(2), psychotherapy notes require an authorization that covers only those notes, even when the purpose is payment.

What payers legitimately need is already carved out of the psychotherapy notes definition. The regulation excludes, and therefore treats as ordinary protected health information: medication prescription and monitoring, counseling session start and stop times, the modalities and frequencies of treatment furnished, results of clinical tests, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. Those elements support a clean claim on their own. HHS explains the distinction in its guidance on HIPAA and mental health information.

Operationally: if a payer's records request asks for "all notes," your response is a curated packet of the excluded elements — not a chart dump. Document what you sent and why.

How Practices Document Code Selection for Behavioral Health Encounters

Code selection is the clinician's determination. Your job is to build the workflow that captures the facts the code depends on, before the claim goes out.

Time-based psychotherapy codes need real start and stop times

The individual psychotherapy family (the 30-, 45-, and 60-minute codes) is time-defined. Practices that survive payer audits do three things: require documented start and stop times in the note template, make the field non-optional, and reconcile the documented duration against the code selected before submission rather than after a denial.

Build a pre-submission edit that flags any time-based code where start/stop times are missing or where the documented duration sits outside the range the clinician's selection implies. Route the flag back to the clinician for correction — never let a biller change a code to match a time, or a time to match a code. That is the single clearest line in your billing policy.

Diagnostic evaluations, group services, and add-ons

Psychiatric diagnostic evaluations, group psychotherapy, family services, crisis codes, and interactive complexity add-ons each depend on facts your intake and scheduling systems can capture: who was present, whether an initial evaluation had already occurred, group size, and whether a medical evaluation and management component was part of the encounter. Put those fields on the encounter form. Ambiguity at the front end becomes a denial at the back end.

Integrated and collaborative care models

If your primary care practice bills behavioral health integration or collaborative care management, you are billing a monthly service with time thresholds, a designated care manager, and consulting psychiatric involvement. That means time logs per patient per calendar month, a documented patient consent to the arrangement including cost-sharing, and a registry. Assign one person to own the monthly reconciliation. Check the current Medicare Physician Fee Schedule each year — CMS has been adding behavioral health codes and adjusting requirements in recent rules, including codes for digital mental health treatment devices and safety planning services.

Telehealth place of service and modifiers

Behavioral health is the most telehealth-heavy specialty in most practices, and place of service is where claims break. Your scheduling template should record the patient's physical location at the time of service, because that drives place-of-service coding and, for some payers, state licensure questions. Modifier and POS conventions vary by payer and change with congressional extensions of Medicare telehealth authority — verify current requirements rather than relying on last year's cheat sheet, and keep a dated payer matrix so you can prove what the rules were when you billed.

What the February 2026 Part 2 Compliance Date Changed for Billing Vendors

If any part of your practice is a Part 2 program — federally assisted substance use disorder treatment — the 2024 final rule aligning 42 CFR Part 2 with HIPAA became enforceable on February 16, 2026. Several changes hit billing directly.

Single consent for TPO. A patient can now give one written consent covering all future uses and disclosures for treatment, payment, and health care operations. That simplifies claim submission, but only if your consent form has been rewritten to match and your staff know which version to use. Legacy consents scoped to a single payer or a single disclosure do not carry the new permission.

Redisclosure by HIPAA-regulated recipients. A covered entity or business associate that receives Part 2 records under a TPO consent may generally redisclose them as HIPAA permits. Practically, that changes what your clearinghouse and payers may do downstream — and it does not relieve you of minimum necessary obligations upstream.

Breach notification applies. Part 2 records are now within the HIPAA breach notification framework. A misdirected SUD billing statement is a reportable-analysis event, not just an apology call.

Notice requirements. Your Notice of Privacy Practices needs Part 2 content. If yours has not been revised, that is a documentation gap an investigator will find in ten minutes.

The Self-Pay Restriction Request Your Front Desk Will Fumble

Under 45 CFR 164.522(a)(1)(vi), when a patient pays out of pocket in full for a service and asks you not to disclose it to their health plan for payment or operations, you must honor the request. Behavioral health patients invoke this more than any other population — a counseling session they do not want appearing on a family plan's explanation of benefits.

The failure mode is mechanical: the front desk agrees, collects cash, and the claim goes out anyway because nobody flagged the encounter in the practice management system. Fix it with three controls.

  • A written request form, signed at check-in, that names the specific date and service.
  • A hard hold flag on that encounter that blocks claim generation until a biller clears it manually.
  • A weekly report of held encounters, reviewed by the billing lead, so nothing sits unresolved past your payer filing deadlines.

Also decide in advance how you handle a bundled encounter where one component was self-pay and another was billed. Write the answer down before a patient asks.

Your Vendor List Is Longer Than You Think

Count the vendors that touch a behavioral health claim: clearinghouse, RCM or outsourced billing company, eligibility verification service, statement and print-mail vendor, patient payment processor, telehealth platform, appointment reminder system, transcription or AI documentation assistant, collections agency, and whoever hosts your EHR. Each one that creates, receives, maintains, or transmits PHI on your behalf needs a business associate agreement in place before the first record moves.

For behavioral health specifically, push three additional terms into those agreements:

  1. Part 2 acknowledgment. If the vendor will handle SUD treatment records, the contract should reflect the Part 2 obligations that now travel with them.
  2. Minimum necessary scope. Specify the data elements the vendor receives. An appointment reminder vendor does not need diagnosis codes. HHS's minimum necessary guidance is the standard your auditor will apply.
  3. Subcontractor disclosure. Offshore coding subcontractors and model-training use of your notes are both live issues. Get the list, in writing, and re-request it annually.

If you have vendors operating on a handshake or an expired agreement, close that gap first. You can produce a signature-ready business associate agreement through a guided six-step wizard and export it as PDF or DOCX — faster than routing a redline through counsel for a $200-a-month statement vendor.

Minimum Necessary in Denials, Appeals, and Payer Audits

Appeals are where behavioral health practices over-disclose. A denial arrives, someone wants it overturned, and the fastest path feels like sending everything. Resist that.

Build a standard appeal packet: the claim, the relevant excluded-element summary (diagnosis, treatment plan, modality, frequency, progress, start/stop times), and the specific medical-necessity criteria the payer cited. Log every disclosure. If a payer demands psychotherapy notes as a condition of payment, escalate to your privacy officer rather than complying at the biller's desk — that request needs a documented decision, not a reflex.

The same discipline applies to records subpoenas, which behavioral health practices receive at a higher rate because of custody and disability proceedings. Part 2 records carry additional restrictions on use in legal proceedings. Route every legal request to one named person.

Documenting All of This So It Survives an Audit

Every control above needs a written policy, an assigned owner, and evidence it operates. That is the Security Rule administrative safeguard requirement and it is where most behavioral health practices are thinnest — strong clinical documentation, no current risk analysis, policies dated 2019.

Your risk analysis should specifically address the flows described here: claim transmission, self-pay holds, psychotherapy note segregation, and each vendor's data scope. If building that from scratch is what has kept it undone for three years, automated HIPAA risk analysis and policy generation will produce the full document set — risk assessment, policies, procedures — in a form you can hand to an auditor or a payer's credentialing team. No compliance product is government-certified, and none should claim to be; what you want is a defensible, dated, complete record of the work.

A 30-Day Cleanup Sequence

Week 1. Inventory vendors touching behavioral health claims. Confirm a signed, current BAA for each. Flag gaps.

Week 2. Verify psychotherapy notes are stored separately in the EHR and that billing roles cannot open them. Pull an access report to prove it.

Week 3. Rewrite the self-pay restriction workflow. Test it with a dummy encounter and confirm the claim does not generate.

Week 4. If you are a Part 2 program, confirm the new single-consent form is in use, the Notice of Privacy Practices includes Part 2 content, and staff have been retrained. Update your risk analysis to reflect all four changes.

Billing for behavioral health services rewards practices that treat the privacy controls as part of the revenue cycle rather than a separate department. The claim goes out clean because the record was handled correctly first.

Start with the vendor inventory and the risk analysis — those two documents determine how every other decision in this article gets defended. Generate your risk analysis and compliance document set, then work the 30-day sequence against it.