Skip to main content
Category: Uses and Disclosures

Notice of Privacy Practices

Also known as: NPP, Notice of Privacy Practices for Protected Health Information, HIPAA Privacy Notice
Simply put

A Notice of Privacy Practices is a document that a healthcare provider or health plan gives to individuals explaining how their protected health information (PHI) may be used and disclosed. It also informs individuals of their privacy rights and how to raise concerns or file complaints. Providers typically give the notice at first contact with a patient, and health plans generally provide it to members on enrollment.

Formal definition

The Notice of Privacy Practices (NPP) is a document that covered entities are generally required under the HIPAA Privacy Rule to develop and distribute to describe how they may use and disclose an individual's protected health information (PHI), the individual's rights with respect to that information, and the entity's legal duties regarding PHI. Distribution requirements typically differ by entity type: covered health care providers with a direct treatment relationship generally provide the notice at the date of first service delivery, while health plans generally furnish it to members at or around enrollment. HHS publishes model notices as one option for meeting the requirement, and, where applicable, separate patient notices (such as those associated with Part 2 substance use disorder records) may impose additional or distinct obligations. Because the NPP is a Privacy Rule obligation, its scope covers PHI in all forms rather than being limited to electronic PHI; readers should verify specific content, timing, and acknowledgment requirements against the current regulatory text, and note that state law or other frameworks may impose additional requirements.

Why it matters

The Notice of Privacy Practices is one of the most visible and patient-facing obligations under the HIPAA Privacy Rule. It operationalizes the principle of transparency by giving individuals a plain description of how their protected health information may be used and disclosed, what rights they hold over that information, and how to raise concerns or file a complaint. For covered entities, a compliant and current NPP is a foundational element of a broader privacy program; a missing, outdated, or inaccurate notice can signal deeper gaps in how an organization manages PHI.

Because the NPP is a Privacy Rule requirement rather than a Security Rule one, its scope extends to PHI in all forms, including oral, paper, and electronic. This distinguishes it from safeguards that apply only to electronic PHI. The notice also serves an accountability function: by publicly stating an entity's legal duties and the individual's rights, it creates an expectation against which the entity's actual practices can be measured. HHS OCR enforces the HIPAA rules, and distribution or content failures can factor into enforcement outcomes; however, specific findings, penalty tiers, and figures are adjusted over time and should be confirmed against current OCR guidance.

It is important to recognize the limits of what an NPP accomplishes. Providing a notice does not by itself establish overall HIPAA compliance, nor does it guarantee that an entity's underlying uses and disclosures are lawful. Where substance use disorder records subject to Part 2 or other frameworks are involved, separate or additional patient notice obligations may apply, and state law may impose further requirements. Entities should verify the specific content, timing, and acknowledgment expectations against the current regulatory text.

Who it's relevant to

Covered health care providers
Providers with a direct treatment relationship are generally required to distribute the NPP at or around the date of first service delivery and to make it available thereafter. They should ensure the notice accurately reflects their actual uses and disclosures of PHI and is updated when material changes occur.
Health plans
Health plans generally furnish the NPP to members at or around enrollment and provide it on request. Because the notice reflects the plan's legal duties and members' rights, plans should confirm content and timing align with current regulatory requirements.
Privacy officers and compliance staff
Those responsible for HIPAA privacy programs typically own the drafting, distribution, revision, and posting of the NPP. They should treat the notice as one component of a broader compliance effort rather than as evidence of overall compliance, and should track any additional obligations arising from Part 2 records or state law.
Patients and health plan members
Individuals receive the NPP to understand how their health information may be used and shared, what rights they have over that information, and how to file a complaint or raise a concern. The notice is intended to prompt discussions with providers and health plans about privacy issues.
Legal counsel and auditors
Attorneys and auditors reviewing an entity's privacy posture examine the NPP for accuracy, timely distribution, and consistency with actual practices. They should verify content and timing against the current regulatory text and flag areas where Part 2, HITECH, or state law may impose additional requirements.

Inside NPP

Description of Uses and Disclosures
An explanation of how the covered entity may use and disclose protected health information (PHI), generally including uses for treatment, payment, and health care operations, as well as other permitted or required uses and disclosures under the Privacy Rule.
Individual Rights
A statement of the individual's rights with respect to their PHI, which typically include the right to access and obtain a copy of records, request amendments, request an accounting of certain disclosures, request restrictions, and request confidential communications, subject to the conditions and limitations in the Privacy Rule.
Covered Entity's Duties
A description of the covered entity's legal duties regarding PHI, generally including its obligation to maintain the privacy of PHI and to provide notice of its privacy practices.
Complaint Procedures
Information on how an individual may file a complaint with the covered entity and with the Secretary of HHS (through HHS OCR) if they believe their privacy rights have been violated, along with a statement that the individual will not be retaliated against for filing a complaint.
Contact Information
The name or title and telephone number of a person or office the individual can contact for further information about the notice or the covered entity's privacy practices.
Effective Date and Revision Rights
The date on which the notice is first in effect, and a statement that the covered entity reserves the right to change its privacy practices and the terms of the notice, and to apply revised terms as permitted under the Privacy Rule.
Header or Required Statement
A prominent statement, often set apart at the top of the notice, that alerts individuals that the notice describes how medical information about them may be used and disclosed and how they can get access to this information.

Common questions

Answers to the questions practitioners most commonly ask about NPP.

Does providing a Notice of Privacy Practices require obtaining a patient's signed consent before using their information?
No. The NPP is a notice, not a consent form. Under the HIPAA Privacy Rule, covered entities with a direct treatment relationship must make a good faith effort to obtain a written acknowledgment that the individual received the NPP, but this acknowledgment is distinct from authorization or consent. Providing the notice and obtaining acknowledgment of receipt does not by itself authorize uses and disclosures beyond those permitted or required by the Privacy Rule; certain uses (such as many marketing activities or disclosures of psychotherapy notes) generally require a separate, specific authorization. Readers should verify current requirements against the applicable regulatory text.
If a patient refuses to sign the acknowledgment, can we refuse to treat them or withhold services?
No. The requirement is generally to make a good faith effort to obtain a written acknowledgment of receipt, not to secure a signature as a condition of treatment. If an individual declines to sign, the covered entity should document its good faith effort and the reason acknowledgment was not obtained, and may still proceed with treatment. The acknowledgment requirement applies to covered entities with a direct treatment relationship; note that the NPP is a Privacy Rule obligation and does not itself govern electronic protected health information safeguards, which fall under the Security Rule.
Who is responsible for providing the Notice of Privacy Practices, the covered entity or its business associates?
The obligation to develop and distribute the NPP generally rests with the covered entity, not with business associates. Business associates are bound by the terms of their business associate agreements and by applicable provisions of the Privacy and Security Rules, but the duty to provide the NPP to individuals typically flows to the covered entity. A business associate that performs functions on a covered entity's behalf should follow the covered entity's notice and the terms of the applicable agreement rather than issuing its own NPP to the covered entity's patients. Confirm specific allocation of responsibilities in the governing agreement.
How and when must the NPP be provided to individuals?
In most cases, a covered entity with a direct treatment relationship must provide the NPP no later than the date of first service delivery, including service delivered electronically, and must make a good faith effort to obtain a written acknowledgment of receipt at that time. The notice generally must also be posted in a clear and prominent location where individuals are able to read it, made available to anyone who asks, and posted on any website the covered entity maintains that describes its services. Specific timing and delivery mechanics should be verified against the current regulatory text, and state law may impose additional requirements.
What must we do when we make a material change to our privacy practices?
When a covered entity makes a material change to the NPP, it must generally revise the notice and make the updated version available. For providers who post their notice, the updated notice typically must be posted and made available upon request, and copies of the current notice must be provided going forward. Health plans generally have distinct notification obligations to enrollees. Because the exact mechanics differ by type of covered entity and may be affected by the HITECH Act and state law, confirm the applicable requirements against current guidance before implementing changes.
How long should we retain acknowledgments and prior versions of the NPP?
The Privacy Rule generally requires covered entities to retain documentation related to their compliance, including copies of notices issued and, where applicable, signed acknowledgments or documentation of good faith efforts to obtain them, for a period specified by the regulation. Because retention periods and documentation requirements are set by regulation and may be supplemented by state law, verify the current required retention period against the applicable regulatory text rather than relying on a fixed figure. Maintaining prior versions supports the ability to demonstrate what notice was in effect at a given time.

Common misconceptions

The Notice of Privacy Practices is a Security Rule requirement covering electronic protected health information.
The NPP is a HIPAA Privacy Rule requirement. The Privacy Rule covers PHI in all forms, including oral, paper, and electronic, and is distinct from the Security Rule, which governs only ePHI and does not itself impose the NPP requirement.
An individual's signed acknowledgment of the NPP constitutes their consent authorizing all uses and disclosures of their PHI.
Acknowledgment of receipt is generally not the same as authorization. The NPP informs individuals of practices, but many uses beyond treatment, payment, and health care operations typically require a separate, specific authorization under the Privacy Rule. Readers should verify specific requirements against the current regulation.
Providing an NPP by itself demonstrates HIPAA compliance.
The NPP addresses only certain notice obligations under the Privacy Rule. It does not by itself establish overall HIPAA compliance, which involves additional Privacy Rule, Security Rule, and Breach Notification Rule obligations. Frameworks such as the HITRUST CSF are not legal requirements and do not by themselves establish HIPAA compliance.

Best practices

Ensure the NPP includes all required components, generally covering uses and disclosures, individual rights, the covered entity's duties, complaint procedures, contact information, and the effective date, and verify content against the current Privacy Rule text.
Make the notice available as required, including posting it prominently where individuals can see it and, in most cases, providing it at the date of first service delivery for direct treatment providers; confirm the applicable delivery and posting requirements against current guidance.
Document good-faith efforts to obtain written acknowledgment of receipt where applicable, and retain those records, while recognizing that acknowledgment is generally distinct from authorization for uses and disclosures.
Review and update the NPP whenever privacy practices or applicable requirements change, and follow the Privacy Rule's provisions for revising and re-distributing the notice.
Write the notice in plain, accessible language and consider making it available in formats and languages appropriate to the population served.
Coordinate the NPP with applicable state law and other frameworks, since state privacy laws or other requirements may impose obligations beyond those in HIPAA; confirm any additional requirements against current legal guidance.