The updated 42 CFR Part 2 rule (compliance required by Feb 16, 2026) requires more than updated patient consent forms. Every disclosure of SUD-related information must include a no-redisclosure notice, and organizations must maintain auditable disclosure logs....
Cybersecurity
42 CFR Part 2’s New Consent Rules: What They Mean and How to Get Started
The 2024 update to 42 CFR Part 2 finally resolves one of the biggest friction points in substance use disorder (SUD) care: patient consent. Effective February 16, 2026, providers can use a single consent for Treatment, Payment, and Operations (TPO). That’s...
42 CFR Part 2 Is Now Aligned with HIPAA: What Changed, What’s at Stake, and What to Do First
The U.S. Department of Health and Human Services finalized updates to 42 CFR Part 2 aligning Substance Use Disorder (SUD) confidentiality requirements with HIPAA. For SUD programs and adjacent providers (pain management, HHA, DME, assisted living/SNF), this is a...
The Q4 Tighten-Up – Where Resilience Fades (And How to Stay Ahead)
It’s Q4. You’re closing the year strong. But don’t mistake momentum for security. Resilience isn’t built once and left alone. It’s tuned, tested, and reinforced—especially when things are busy. This week, we’re looking at where resilience fades fast in Q4—and how to...
What Fades, Fails, or Fractures When You Don’t Follow Through
Last week, we laid out six simple ways to keep your resilience real: → Review your drills → Update your call tree → Clean up shared access → And a few more easy wins... But here’s the hard truth: The biggest risks don’t come from what you didn’t do. They come from...
Resilience 2025 – More Ways to Stay Sharp, Ready, and Resilient
Resilience isn’t a one-time milestone—it’s a system that gets stronger with steady effort. Last week, we outlined monthly and quarterly habits that help keep your resilience plan alive.This week, we’re going deeper—into the areas teams often postpone or underestimate...
The Tactics That Keep Cyber Resilience Alive All Year
Resilience isn’t about big quarterly drills or a binder review once a year. It’s about what you do in the day-to-day—when things are calm, when nothing is on fire, and when it’s easiest to say “we’ll deal with it later.” Week 5 of our Resilience 2025 series is about...
From Operational to Ongoing—How to Sustain What You’ve Built
You’ve done the hard part: Built the fallback plans Assigned the owners Practiced the drills Scored the systems But now the real question is: Will it still work 6 months from now? Most resilience programs lose effectiveness after they’re operationalized. Not because...
How to Operationalize What You Know About Your Security Posture
You’ve seen the patterns. You’ve read the blogs. You’ve felt the pressure. Cyber threats aren’t new. But the urgency to act on what we already know? That’s rising. This week is all about the handoff—from insight to implementation. Because most companies don’t fail...