
Running a rehabilitation or any other healthcare practice across several locations means the same patient records move between sites every working day, whether physically or digitally. Each additional location you manage will inherently have to maintain its own network, its own devices and local staff who will need access to electronic protected health information (ePHI). Yet HIPAA requirements do not scale down for a satellite office or a leased suite inside a larger medical building.
However, rehab facilities specifically have a new recordkeeping compliance burden as of 2026 that demands an extra layer of diligence when handling the PHI of patients that have or are receiving treatment or other services related to a substance use disorder (SUD). The deadline for updated confidentiality requirements under the Final Rule of 42 CFR Part 2 and the Coronavirus Aid, Relief, and Economic Security (CARES) Act passed in February 2026, which both allows parties to file complaints and for regulators to apply civil and criminal enforcement penalties under HIPAA for violations of Part 2 regarding the records of SUD patients, as well as obligates covered entities to update their Notice of Privacy Practices (NPP) to be compliant with the updated law. A further overhaul of the cybersecurity regulations under the HIPAA Security Rule is also expected in 2027 after being delayed by the Office for Civil Rights (OCR) under the U.S. Department of Health and Human Services (HHS), which will also bring additional sweeping changes for medical facilities that manage data between multiple locations.
Continue reading below to learn which obligations affect multi-site rehab facilities and what additional documentation those obligations require:
What Changes When Medical Care Spans Several Sites
The Security Rule applies to the regulated entity rather than to any individual building, so a practice with six locations answers for safeguards at all six. Every site that stores, receives or transmits ePHI needs the same administrative, physical and technical protections applied and documented. Workforce access adds a second layer of difficulty, because clinical staff who float between sites accumulate credentials at each one. Offboarding a floating employee requires termination of access at every location rather than at a single home office.
Where 42 CFR Part 2 Applies to Multi-Site Rehab Facilities
The term “rehab” covers two separate medical facility categories under regulatory oversight. Physical therapy, occupational therapy and general rehabilitation practices answer to HIPAA alone, while facilities that treat substance use disorder may also fall under Part 2, a federal regulation imposing stricter consent requirements than HIPAA provides on its own.
However, the regulation only technically applies to federally assisted programs that both hold themselves out as providing SUD diagnosis, treatment or referral for treatment and actually provide those services, and not strictly all healthcare facilities that treat addiction conditions. Federal assistance is defined broadly, covering participation as a Medicare provider, registration to dispense controlled substances used in substance use disorder treatment, receipt of federal financial assistance in any form and tax-exempt status granted by the IRS.
Coverage applies to multi-site rehab facilities under several conditions, including:
- Treatment and rehabilitation programs – Standalone facilities that publicly present themselves as substance use disorder providers
- Identified units inside a general medical facility – A dedicated wing or department, rather than the whole hospital
- Designated clinical personnel – Staff whose primary work is substance use disorder diagnosis, treatment or referral, and who are identified as such
- Employee assistance and school-based programs – Arrangements outside the traditional outpatient clinic model
Where a patient receives substance use disorder treatment from a provider that is not a federally assisted program, that record falls outside Part 2 even when the patient benefits from federal support elsewhere.
Consent and Redisclosure Across Rehabilitation Locations
Compliance with the amended Part 2 requirements began February 16, 2026, with enforcement authority delegated to the Office for Civil Rights in August 2025 and complaints accepted from the compliance date forward. Enforcement provisions mirror those applied to HIPAA violations, including civil money penalties.
The amended regulation permits a single written consent covering all future uses and disclosures for treatment, payment and health care operations. When a covered entity or business associate receives a record under that consent, it may redisclose the record as HIPAA otherwise permits, excepting use in proceedings against the patient. Each disclosure still requires the accompanying notice the regulation specifies.
One provision applies unevenly across locations. At a facility or a component of a facility publicly identified as a place where only substance use disorder services are provided, the presence of an identified patient may be acknowledged only with written consent or a court order. A general outpatient site carries no equivalent restriction, so two locations under the same practice hold different obligations at the front desk.
Vendor Agreements at Every Rehab Location
Any vendor that creates, receives, maintains or transmits ePHI on your behalf is a business associate, and that relationship requires a written agreement. Multi-site practices accumulate these relationships unevenly, particularly when individual locations sign their own contracts for imaging, transcription, billing or backup. Vendors providing data processing, billing, laboratory analysis or professional services to an entity covered by Part 2 must enter a written agreement acknowledging that they are bound by the regulation and will resist attempts to obtain patient identifying information.
The Proposed Security Rule Update and Its Status
The proposed Security Rule overhaul has not been finalized. The proposal reached the Federal Register in January 2025 at 90 FR 898, the comment period closed that March, and the rulemaking now sits on the long-term actions agenda with a final action target of July 2027. The current Security Rule remains in effect while that rulemaking proceeds.
Several provisions in the proposal scale with the number of locations a practice operates. Under the proposal, every implementation specification would become mandatory, ending the split between required items and addressable ones:
- Technology asset inventory and network map – Maintained at least annually and updated when the environment changes, covering every location and the data paths between them
- Multi-factor authentication and encryption – Applied to ePHI at rest and in transit, with narrow exceptions
- Network segmentation – A design question answered per site rather than once at the practice level
- Vulnerability scanning and penetration testing – Scanning at six-month intervals and testing annually
- Annual compliance audit – Documented confirmation that Security Rule requirements are met
- Access change notification within 24 hours – Triggered whenever a workforce member’s access is modified or terminated
- Written restoration procedures – Recovery of affected information technology assets and data within 72 hours
- Annual business associate verification – Written analysis by a subject matter expert confirming technical safeguards are deployed
IT Support for Rehab HIPAA Compliance
Rehab facilities manage the exact type of protected health information that makes healthcare a standing target of hackers and each additional location multiplies the entry points available to an attacker. Phishing reaches staff at every site, unpatched workstations sit in every treatment room, and vendors handling billing or records often connect into more than one network. Regulators and cyber insurance carriers assess documented proof that controls work, not the presence of tools on a purchase order.
Managed support for a distributed practice generally works across three layers. Hygiene closes the openings attackers use most often, visibility surfaces activity at every location rather than the main office alone, and response determines how much of an incident turns into downtime. Applying the same three layers site by site is what yields one evidence set instead of several partial records.
What a Managed IT Service Provider Covers Across Locations
The IT support categories every healthcare facility needs apply per site rather than per practice. Working with a managed service provider (MSP) will help you protect each location and ensure both cybersecurity and helpdesk coverage for when an incident occurs. Here are some of the services that SWK Technologies, an award-winning MSP, provides for rehab practices and other medical organizations:
- Security awareness training – Delivered to staff at every location rather than the primary site only
- Multi-factor authentication and access administration – Enforced on all accounts, with credentials documented and revoked at every site an employee worked
- Patch management and endpoint detection and response – Applied to workstations, servers and personal devices used across sites
- Email and web filtering – Spam and virus filtering applied to email accounts and web browsers at the user level
- Security monitoring and managed detection and response – Continuous coverage, so tools deployed at a satellite location do not run unwatched
- Server and network monitoring – Performance, availability and configuration tracked location by location
- Backup and disaster recovery – Segmented, tested backups paired with written restoration procedures
- Dark web monitoring – Surfacing exposed credentials tied to practice accounts
- Vulnerability assessment and penetration testing – Scanning and validation producing documentation auditors and carriers accept
- Cyber risk assessment – Evaluation of existing policies and controls against HIPAA readiness using NIST-aligned methodology
- Virtual CIO and vendor risk management – Third-party access held to the same standard applied to internal controls
Evaluating Infrastructure at Each Rehab Location
Downtime at a multi-location practice often traces to two separate causes, even if occurring simultaneously or consequentially of each other: network disruption or security incidents. The effects of both are virtually similar on the user side, which often makes it difficult for local staff to identify and isolate the issue without an expert evaluation at each and every site. A practice operating distinct facility types, such as a procedure suite, an overnight recovery area and outpatient clinics in separate towns also must measure their uptime and connectivity requirements at each location.
Strengthen Your HIPAA Compliance with SWK Technologies
SWK Technologies provides managed IT services and cybersecurity support to healthcare providers, including Compliance as a Service for practices working to stay aligned with data privacy requirements. Coverage extends from evaluation of existing infrastructure at each location through standardization of security controls and the documentation that both HIPAA and Part 2 require.
Contact SWK here to discuss bringing every location in your practice onto a single compliance standard.
