Skip to main content
WarningScams & fraud

Fake 42 CFR Part 2 substance-use-disorder (SUD) record consent-revocation lure — "Patient consent revocation — purge SUD records within 30 days" targets behavioral-health EHR admins. 42 CFR Part 2 Final Rule (effective Apr 16, 2024 / compliance Feb 16, 2026) harmonized SUD-record consent with HIPAA, lending the lure narrative immediate credibility. Drainer harvests behavioral-health admin credentials + SUD-record PHI exfil (irreversible HIPAA + 42-CFR-Part-2 + SUD-stigma exposure). Real 42-CFR-Part-2 / SAMHSA / SUD-record notifications come through samhsa.gov / hhs.gov / ocr.hhs.gov / EHR-vendor (Netsmart / Epic / Cerner) portals, never via inbound email link demanding 30-day purge of SUD records from an unfamiliar domain. PHI +0.05% budget; SUD-stigma scope flag; B2B-behavioral-health scope. Source: GC1 R9 multiagent council P1 (S2 healthcare specialist).

fake-42-cfr-part-2-sud-record-consent-revocation-spoof

What this tier means

Warning signal — bulk / marketing / mild spam. Contributes to the trash score but is not by itself sufficient.

How Gorganizer detects this

Fake 42 CFR Part 2 substance-use-disorder (SUD) record consent-revocation lure targeting behavioral-health EHR (Electronic Health Record) admins, opioid-treatment-program (OTP) compliance staff, and SAMHSA-registered methadone / buprenorphine providers. The phish narrative arrives as: "Patient consent revocation — purge SUD records within 30 days," or "42 CFR Part 2 patient consent revocation request — your facility must purge or destroy substance-use-disorder treatment records within 30 days under the 2024 Final Rule HIPAA-harmonization compliance deadline." 42 CFR Part 2 Final Rule (effective Apr 16, 2024 / compliance Feb 16, 2026) harmonized SUD-record consent with HIPAA — the compliance deadline of Feb 16, 2026 created a recent regulatory pivot point that compliance staff are still digesting, lending the lure narrative immediate credibility especially because the Final Rule did genuinely modify when records can be re-disclosed and when consent must be re-acquired. Lookalike portals harvest behavioral-health admin credentials (post-compromise the attacker can read every SUD treatment record in the EHR — irreversible HIPAA + 42-CFR-Part-2 + SUD-stigma exposure for every treated patient) plus SUD-record PHI exfil through the fake "consent revocation purge" upload form (the attacker collects the patient's SUD record material as it is being prepared for purge, retaining evidentiary copies for downstream extortion and identity fraud against an extremely vulnerable population). Real 42-CFR-Part-2 / SAMHSA / SUD-record notifications come through samhsa.gov / hhs.gov / ocr.hhs.gov / EHR-vendor (Netsmart / Epic / Cerner) portals using credentials provisioned via the EHR-vendor onboarding process, never via inbound email link demanding 30-day purge of SUD records from an unfamiliar domain. PHI +0.05% budget; SUD-stigma scope flag; B2B-behavioral-health scope. Fires when body references 42 CFR Part 2 / substance use disorder / SUD record-treatment / SAMHSA / consent revocation / harmoniz / methadone / MAT / opioid treatment program / OTP AND contains purge / delete / destroy / 30-days / verify / comply / action-required / submit / deadline urgency. Excludes samhsa.gov, hhs.gov, ocr.hhs.gov, netsmartcloud.com, epic.com, cerner.com, and the broader .gov umbrella. Auto-classified as danger via the `-spoof` suffix. Source: GC1 R9 multi-agent council P1 (S2 healthcare specialist).

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a warning-tier signal — bulk / marketing / mild spam. It contributes to the trash score but never triggers deletion on its own. Gorganizer requires multiple signals + a margin over the safety floor before any email is moved to trash.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started