TL;DR: Fax triage software doesn't change what a practice is permitted to disclose under 42 CFR Part 2 or the psychotherapy-note provisions of HIPAA. What it changes is how consistently those rules get applied: classification and routing rules can identify protected document types and hold them for authorized staff, rather than enforcement depending on whoever opened the fax that morning. The tradeoff worth understanding is that automation adds a per-document audit trail you didn't have before, and it still can't make a consent determination for you.
What automation changes, and what it doesn't
Start with the part that causes the most confusion in a compliance review.
Automating your inbound fax queue does not alter your regulatory obligations. The rules governing substance use disorder records under 42 CFR Part 2 and the heightened protection HIPAA applies to psychotherapy notes apply identically whether a person opens each document or a system classifies it first. Software isn't a covered entity's judgment; it's a covered entity's tooling.
What changes is the reliability of enforcement. In a shared cloud fax inbox, the person who happens to open a document decides in that moment whether it's sensitive, whether it can be filed, and who should see it. That decision is made hundreds of times a week, by different people, under time pressure, with no record of the reasoning.
A classification layer makes that decision by rule instead. Rules are auditable, consistent across staff, and reviewable when they're wrong. They're also visible — you can show a compliance officer the routing matrix, which is not something you can do with a coordinator's instincts.
That's the honest case for automation in a behavioral health setting. It's a control improvement, not a compliance shortcut.
What the February 2026 Part 2 enforcement date changed
SAMHSA's final rule revising 42 CFR Part 2 took effect in April 2024 with a two-year implementation period, and compliance enforcement began February 16, 2026. Two changes matter for document workflow.
Single consent for treatment, payment, and operations. Part 2 programs may now use one patient consent covering all TPO purposes, rather than obtaining separate consent for each disclosure. Recipients who receive records under a valid TPO consent may redisclose consistent with HIPAA — with the significant exception that records can't be used in civil, criminal, administrative, or legislative proceedings against the patient absent written consent or a court order.
Alignment with HIPAA on breach notification and enforcement. Part 2 now carries HIPAA-style penalties and breach notification obligations, which raises the stakes on a misrouted document meaningfully.
The American Psychiatric Association's practice guidance is a reasonable starting point for the clinical-practice reading of these changes. The operational consequence is straightforward: whether a given record is covered, and whether the consent on file authorizes a given disclosure, is now a determination with more downside if it's made carelessly.
That determination is also exactly the kind of thing that gets made carelessly when it's buried in a queue of 200 undifferentiated PDFs.
Why records requests are the riskiest document class in your queue
Most inbound documents create risk only if they're misfiled. Records requests create risk if they're acted on incorrectly, which is a larger surface.
A records request arriving by fax triggers an outbound disclosure. The chain of judgments behind that disclosure is where practices get into trouble:
- Is this patient's record subject to Part 2, or does the practice hold Part 2 records for them?
- Do the requested materials include psychotherapy notes, which require separate specific authorization and shouldn't ride along with a general release?
- Is the authorization on file valid, current, and scoped to what's being requested?
- Is the requester who they say they are, and is the fax number they've asked you to send to verified?
None of those are classification questions. All of them are judgment questions. What automation can do is make sure the judgment happens — by identifying the document as a records request, flagging that the patient has records in a protected category, and routing it to a person credentialed to decide rather than into a general work queue.
The failure mode automation prevents is not "the software made the wrong call." It's "nobody realized this needed a call."
What should never file on an automated path
Set these as categorical rules that override confidence scores entirely. A system that's 99% confident about a psychotherapy note should still stop.
- Anything identified as a psychotherapy note. Heightened HIPAA protection, separate authorization required, and no legitimate reason to move it unattended.
- Documents implicating Part 2 records — records from a Part 2 program, or documents about a patient the practice knows has a Part 2 episode.
- Inbound records requests, without exception. The document can be classified and routed automatically; the response cannot be.
- Court orders, subpoenas, and legal correspondence, which need a named owner and often counsel.
- Anything where the patient match is below your confidence threshold. In a behavioral health chart, a misfile is a disclosure risk, not just a data-quality issue.
Then set the escalation rules for the other direction. Crisis and urgent referrals should route to a named person on a short clock rather than joining a general queue — that's a patient-safety control, and it belongs in the same routing matrix.
Write all of this down before configuration. A routing matrix with a named owner in every cell is the artifact a compliance review actually wants to see.
What audit trail to require from a vendor
This is where evaluation should get specific, because "we're HIPAA compliant" is table stakes and tells you nothing about document-level accountability.
Ask to see, per document:
- What the system classified it as, and the confidence score attached
- What fields it extracted, and from where on the page
- What routing decision it made, and which rule produced that decision
- Every user who viewed, downloaded, or acted on it, with timestamps
- Every human override, with the before and after values
That last item matters more than people expect. When a coordinator reclassifies a document, that's either a system error worth correcting or a policy question worth surfacing — and you can't tell which without the record.
On the vendor-side controls, ask the ordinary questions and expect ordinary answers: a signed BAA, encryption in transit and at rest, role-based access control, documented breach notification procedures, and third-party security attestation. Vendors serving healthcare should have these; a vendor that gets vague about them is answering the question.
Configuring role-based routing so protected records reach only authorized staff
Rule-based routing is the mechanism that turns policy into behavior, and it's worth designing deliberately rather than accepting a default configuration.
Three principles hold up:
- Route by document class, not by sender. A county behavioral health authority sends you referrals, records requests, and billing correspondence from the same number. Sender-based rules can't separate them; content classification can.
- Give protected classes their own destination with a restricted access list. Part 2 records and psychotherapy notes should land in a queue that general intake staff cannot see. This is the capability a shared fax inbox structurally cannot provide, and it's usually the strongest argument for the whole project.
- Make the default restrictive. Anything the system can't classify with confidence should route to review, not to a general queue. An unclassified document in a behavioral health practice is more likely to be sensitive than average, because the hard-to-classify documents tend to be the unusual ones from courts, agencies, and attorneys.
Honey Health's Fax Triage agent is built around this shape — classify each document, confidence-score the patient match, apply routing rules you define, file into the EHR with the task attached, and log the classification, extraction, and routing decision for every document. The design intent is that protected classes are handled by rule rather than by whoever is working the queue, and that every decision is reconstructable afterward.
Where automation genuinely cannot help
Being specific here is what makes the rest of the argument credible.
It cannot determine whether a disclosure is permitted. Reading a signed authorization and deciding whether it covers a given request is a judgment involving the patient's record, the scope of the request, and often state law. Software flags; people decide.
It cannot verify a requester's identity. A fax cover sheet claiming to be from a law firm is a claim. Verification is a phone call to a known number, and that stays human.
It cannot resolve conflicts between federal and state rules. Some states impose stricter mental health confidentiality standards than federal law. Your routing rules have to encode whichever is stricter, and knowing which that is requires counsel, not classification.
It cannot fix an authorization process that isn't working. If your practice doesn't have a reliable way to know which patients have valid authorizations on file, triage will surface that gap rather than close it. That's useful, but it's a finding, not a fix.
Frequently Asked Questions
Does using AI to read faxes create a new HIPAA obligation?
It creates a business associate relationship with the vendor, which means a signed BAA and the usual diligence on their security controls. It doesn't change your obligations to patients. Treat the vendor evaluation the way you'd treat any vendor processing PHI at volume, with particular attention to access controls and audit logging.
Can classification software identify a psychotherapy note reliably?
Reliably enough to flag and hold, which is the correct design — the rule should be conservative and stop on anything plausibly in that category. Test it with your own documents during evaluation, and confirm the system errs toward flagging rather than filing when uncertain. False positives in this category cost a review; false negatives cost more.
What happens if the system misroutes a protected document?
That's what the audit log is for. You should be able to see what it classified the document as, which rule routed it, and every user who accessed it — which tells you both the scope of any exposure and the rule change needed. Confirm during evaluation that you can pull this per document, not just as an aggregate report.
Do we need patient consent to run faxes through a vendor's system?
No. A business associate processing PHI on your behalf for treatment, payment, or operations operates under the BAA rather than requiring separate patient consent. Part 2 records carry their own disclosure framework, so it's worth confirming with counsel that your BAA and your Part 2 posture are aligned before go-live.
How does this interact with state confidentiality laws?
Wherever state law is stricter than federal, state law controls. Practically, that means your routing rules should encode the stricter standard. Identify the applicable state rules with counsel before configuration, since retrofitting a routing matrix after go-live is more disruptive than getting it right the first time.
Will an auditor accept automated routing as a control?
Controls are generally evaluated on whether they're documented, consistently applied, and evidenced. Rule-based routing with per-document logging tends to be easier to demonstrate than a manual process resting on staff training, but the deciding factor is whether you can produce the routing matrix, the access lists, and the logs on request.

