Notice of Privacy Practices
A Notice of Privacy Practices is a document that a healthcare provider or health plan gives to individuals explaining how their protected health information (PHI) may be used and disclosed. It also informs individuals of their privacy rights and how to raise concerns or file complaints. Providers typically give the notice at first contact with a patient, and health plans generally provide it to members on enrollment.
The Notice of Privacy Practices (NPP) is a document that covered entities are generally required under the HIPAA Privacy Rule to develop and distribute to describe how they may use and disclose an individual's protected health information (PHI), the individual's rights with respect to that information, and the entity's legal duties regarding PHI. Distribution requirements typically differ by entity type: covered health care providers with a direct treatment relationship generally provide the notice at the date of first service delivery, while health plans generally furnish it to members at or around enrollment. HHS publishes model notices as one option for meeting the requirement, and, where applicable, separate patient notices (such as those associated with Part 2 substance use disorder records) may impose additional or distinct obligations. Because the NPP is a Privacy Rule obligation, its scope covers PHI in all forms rather than being limited to electronic PHI; readers should verify specific content, timing, and acknowledgment requirements against the current regulatory text, and note that state law or other frameworks may impose additional requirements.
Why it matters
The Notice of Privacy Practices is one of the most visible and patient-facing obligations under the HIPAA Privacy Rule. It operationalizes the principle of transparency by giving individuals a plain description of how their protected health information may be used and disclosed, what rights they hold over that information, and how to raise concerns or file a complaint. For covered entities, a compliant and current NPP is a foundational element of a broader privacy program; a missing, outdated, or inaccurate notice can signal deeper gaps in how an organization manages PHI.
Because the NPP is a Privacy Rule requirement rather than a Security Rule one, its scope extends to PHI in all forms, including oral, paper, and electronic. This distinguishes it from safeguards that apply only to electronic PHI. The notice also serves an accountability function: by publicly stating an entity's legal duties and the individual's rights, it creates an expectation against which the entity's actual practices can be measured. HHS OCR enforces the HIPAA rules, and distribution or content failures can factor into enforcement outcomes; however, specific findings, penalty tiers, and figures are adjusted over time and should be confirmed against current OCR guidance.
It is important to recognize the limits of what an NPP accomplishes. Providing a notice does not by itself establish overall HIPAA compliance, nor does it guarantee that an entity's underlying uses and disclosures are lawful. Where substance use disorder records subject to Part 2 or other frameworks are involved, separate or additional patient notice obligations may apply, and state law may impose further requirements. Entities should verify the specific content, timing, and acknowledgment expectations against the current regulatory text.
Who it's relevant to
Inside NPP
Common questions
Answers to the questions practitioners most commonly ask about NPP.