Skip to content
Artifisys
Menu
Start a conversation Talk to us

Behavioral health & substance use

One in four facilities still run on paper, and there is a reason

Why has no vendor built software that handles 42 CFR Part 2 properly?

Book a 20-minute call Free. No demo, no slides.

Figures and rules on this page apply to

United States

Working somewhere else? The shape of the problem usually travels. The deadlines do not.

What this looks like

A counsellor needs the medical record to treat someone safely. The rules say who may see what, and for which purpose, and for how long. So the safe answer becomes a locked cabinet and a paper chart, because paper cannot accidentally sync to somewhere it should not be.

The numbers

Every figure here is someone else’s. Check them.

  • 42 CFR Part 2consent rules that go well beyond HIPAA for any organisation treating substance use
  • 3+payer types in a typical mix: Medicaid managed care, commercial, county-funded
  • 2024the ONC data brief this paper-chart figure comes from

Why it happens

It is not a people problem.

This is not a technology gap. It is a consent-modelling gap. Part 2 asks who disclosed what, to whom, for what purpose, under whose signature, and for how long that permission lasts. Most record systems model a patient and a note. They have nowhere to put a question of that shape, so the workaround is to keep the sensitive part out of the system entirely.

Why your current software has not fixed it

Because it was never built to.

A generalist vendor can sell to the other three quarters of the market without touching Part 2. That is the rational choice for them. Building consent properly means rebuilding the permission model underneath everything, not adding a checkbox. That is why a quarter of this market has not been reached by any vendor, in 2026.

Intelligence, plumbed in

A consent form is a document. Its rules are not written in a field.

The build is a consent store other systems can query. Then a one-minute capture on a phone, and a kiosk for clients who arrive without one. Underneath it: a connector, one agreed meaning per field, and a test set scored on your own records.

How we make AI survive real data
  • Connectors
  • A semantic layer
  • Evals you can check

However hard, whatever it is

Consent is one example. Bring whatever is blocking the work.

Part 2 is one rule among many that shape this work. If yours is a different rule, or no rule at all and just a process that does not hold, we start the same way.

  1. 01

    We sit with you

    Days where the work happens, not a workshop in a meeting room. We watch the job get done and write down the shortcuts nobody wrote down.

  2. 02

    We read everything

    Your data, your rules, your vendors and their documentation, and the published research on your sector. We report what is actually in there.

  3. 03

    We break it to first principles

    Not which tool fixes this. What is actually causing it, taken apart until we reach the piece that cannot be divided further.

  4. 04

    Then we build

    Weeks, not quarters. By this point we are not guessing what to build, and guessing is the thing that makes projects long.

What we build

Specific enough to argue with.

Four mechanisms, not four features. Each one is a thing that happens on its own, every day, whether or not anyone remembers to run it.

  • Consent modelled as its own object: who, what, for what purpose, signed by whom, expiring when.

  • Every disclosure logged against the consent that permitted it, so an audit is a query rather than a search.

  • Billing that survives utilisation review across Medicaid managed care, commercial and county-funded contracts at the same time.

  • Group documentation and attendance-driven billing for day programmes, which is where that side of the business lives or dies.

How you would know it worked

Numbers in your own reporting, not ours.

  • Records still held on paper, which should fall to near zero.
  • Time to produce a disclosure history when somebody asks for one.
  • Claim denials caused by documentation rather than by clinical decisions.

Straight answers

Where a model is involved, it is scored against your own records first. Accuracy per source, not one flattering average.

The questions this raises

  • Have you done Part 2 work before?

    Yes, and we would rather show you than claim it. Ask on the call and we will walk through how the consent model works, including the parts that are awkward.

  • Can we keep our current EHR?

    Usually. The consent and disclosure layer can sit above it. Replacing a clinical record is a much bigger decision and rarely the thing actually causing the pain.

  • What if we treat both mental health and substance use?

    Then you already know the hard part. The rules differ by service, sometimes for the same person, and the system has to hold both without the clinician having to remember which applies.

The meaning is not in any schema

Two systems agree on the field and disagree on what it means.

The rule lives in a document, or in what one site has always called something, or in a habit nobody wrote down. Joining the data is the easy half; agreeing what it means is the half that is actually the work.

Consent rules, site vocabulary, what an hour counts as. Wherever two systems agree on a field and not on what it means.Describe the disagreement.

Consent is a records problem with a physical half.

The build is a consent store other systems can query. Then a one-minute capture on a phone, and a kiosk for clients who arrive without one.

See everything we build
  • Software
  • Hardware
  • Ways of working
  • Whole ventures

Is this happening to you? Tell us the size of it.

Twenty minutes. We will tell you honestly whether the numbers justify doing anything about it.