A HIPAA notice of privacy practices tells patients how a covered healthcare provider uses, discloses, and safeguards their protected health information (PHI). It also lists patients’ rights over their records and your practice’s legal duties under the HIPAA Privacy Rule.
You hand it over at the first visit, post it in your office and on your website, and ask each patient to acknowledge receipt. The free template below gives you the core wording. This guide covers the details you must add before it’s compliant, including the February 2026 update for substance use disorder records.
Download your free HIPAA notice of privacy practices template
A fillable notice with the required header, uses and disclosures of PHI, uses that need authorization, patient rights, breach notification, and an acknowledgment signature block. Add your contact person, complaint process, and effective date before you use it.
Download templateKey takeaways
A HIPAA notice of privacy practices tells patients how their PHI is used and disclosed, what rights they hold, and how to complain.
Healthcare providers give it at the first service encounter, post it on site and online, and make a good-faith effort to get written acknowledgment.
The notice needs a prescribed header, uses and disclosures, patient rights, your legal duties, a complaint process, a contact person, and an effective date.
The one live 2026 update applies to practices holding 42 CFR Part 2 substance use disorder records, with a February 16, 2026 deadline. The 2024 reproductive health amendments were vacated by a federal court in 2025.
Practice management software like Pabau sends the notice with digital intake forms and files each signed acknowledgment in the patient record.
What is a HIPAA notice of privacy practices?
The notice is a plain-language document explaining how a covered entity uses and discloses protected health information (PHI) and what control patients have over it. 45 CFR §164.520 sets out its required content for every healthcare provider that meets HIPAA’s covered-entity definition.
It does two jobs. It tells patients how their information supports treatment, payment, and health care operations. It also spells out their rights, from getting a copy of their records to filing a complaint with the HHS Office for Civil Rights (OCR). The notice is not a consent form, and patients don’t have to agree to it. Getting this notice delivered and acknowledged is one of the first jobs HIPAA compliance software takes off your front desk.
Who has to provide the notice?
Every covered entity under HIPAA must provide a notice of privacy practices. Covered entities include:
- Healthcare providers that transmit health information electronically, such as for insurance claims (physicians, nurse practitioners, therapists, mental health professionals, medical spas, hospitals)
- Health plans (insurance companies, HMOs, employer health plans)
- Healthcare clearinghouses
Mental health practices, aesthetic practices, and small specialty offices are covered once they send claims or eligibility checks electronically. Solo practitioners aren’t exempt. A cash-only med spa that never bills insurance electronically may fall outside HIPAA, although state privacy laws can still apply.
What must a HIPAA notice of privacy practices include?
The Privacy Rule lists the content every notice must carry. These are the mandatory elements:
Check the downloaded template against this table before you use it. As the checklist below shows, it carries the header, uses and disclosures, patient rights, and breach notification wording. You add the contact person, complaint process, duties statement, and effective date for your own practice. Many practices also add state-specific privacy language where state law is stricter than HIPAA.

The February 2026 notice update for substance use disorder records
The one live 2026 change to the notice affects practices that create or receive substance use disorder (SUD) records under 42 CFR Part 2. Those practices had to update their notice by February 16, 2026.
The deadline comes from the 2024 HHS rulemaking that brought HIPAA notices into line with Part 2. If you hold Part 2 records, your notice must now:
- Explain that Part 2 records need the patient’s written consent for treatment, payment, and health care operations, and where Part 2 is stricter than HIPAA
- Describe patients’ rights over Part 2 records, including the limits on redisclosure
- State that Part 2 records can’t be used in civil, criminal, administrative, or legislative proceedings against the patient without consent or a court order
- Give patients a clear opportunity to opt out of fundraising communications, if you plan to use Part 2 records for fundraising
Practices that never create or receive Part 2 records don’t need this language. The rest of the notice is unchanged.
What happened to the reproductive health amendments?
The same 2024 rule also added reproductive health privacy language to the notice. A federal court in Texas vacated those provisions nationwide on June 18, 2025, in Purl v. HHS. HHS didn’t appeal, and the Fifth Circuit dismissed an intervenor appeal in September 2025. No reproductive health notice requirement applies in 2026.
If your practice added that language in 2024 or 2025, review it with counsel. HIPAA bars you from using or disclosing PHI in a way that contradicts your own notice, so a promise left in place still binds you. Some state laws also protect reproductive health information on their own terms.
Patient rights you must list in the notice
The notice must summarize six individual rights under HIPAA. Every patient has the right to:
- Access and obtain a copy of their PHI within 30 days of a request
- Request amendments to inaccurate or incomplete information in their record
- Request restrictions on uses and disclosures of their PHI
- Receive an accounting of disclosures made during the prior six years
- Request confidential communications, such as contact at a different phone number or address
- Receive a paper copy of the notice on request
Leaving out even one of these rights is a common compliance failure. Compliance management software can track when each notice goes out and comes back signed, which shortens audit preparation.
How and when to deliver the notice
Healthcare providers with a direct treatment relationship must deliver the notice in these ways:
- At the first service encounter: no later than the first appointment, or as soon as practicable after an emergency
- In writing: on paper by default, or electronically if the patient agrees, and patients can still ask for paper
- With an acknowledgment: make a good-faith effort to get written acknowledgment, and document why if the patient won’t sign
- Posted on site: displayed in a clear, prominent spot such as your waiting room
- On your website: posted prominently if you maintain a site describing your services
- After material changes: revise the notice, repost it, and have new copies available on request
Health plans follow different rules. They give the notice at enrollment and remind members of its availability at least once every three years.
Patient portals let you deliver the notice electronically and collect acknowledgments online, leaving a dated record for audits. Train your staff on the notice too, since front-desk teams answer most patient questions about it.
How to customize the template
The template gives you the core regulatory wording. Fill in these details before you hand it to patients:
- Add your practice details: legal business name, physical address, phone number, and website
- Name your contact person: the privacy officer’s name or title, phone number, and email
- Add the complaint process: how patients complain to your office and to OCR, plus a statement that you won’t retaliate
- State your legal duties: that you must protect PHI, follow this notice, and notify patients of a breach
- Match uses and disclosures to your operations: add uses the template doesn’t cover, such as research. Remove examples that don’t apply, like sign-in sheets or medical student training
- Add Part 2 language if you hold SUD records: use the four points in the February 2026 section above
- Add state-specific language: some states go further than HIPAA, such as California’s Confidentiality of Medical Information Act
- Set an effective date: the date you first distribute this version
- Have legal counsel review it: a healthcare attorney can confirm the notice fits your state’s laws and your services
Common mistakes to avoid
OCR complaint investigations often turn up notices that fall short of the rule. These are the most frequent failures:
- Outdated effective date: update it whenever you make a material change
- Missing patient rights: every notice must list all six rights
- No complaint process: patients need to know how to complain to you and to OCR
- Old version left online: the website copy must match the notice you hand out
- No acknowledgment record: without a signed or digital acknowledgment on file, you can’t show a good-faith effort
- Missing contact person: patients need a named privacy contact for questions
- Generic uses and disclosures: the notice must describe how your practice handles PHI, not how a template author imagined it
- Vacated reproductive health wording: a notice still carrying the 2024 language commits you to terms the law no longer requires
HHS adjusts HIPAA violation penalties for inflation each year. OCR’s enforcement program can also require a corrective action plan with years of monitoring.
How Pabau handles notice delivery and acknowledgments
Many practices still print the notice, collect a signature at the front desk, and scan the page into a patient file. Acknowledgments go missing, and nobody can prove which version a patient received.
Practice management software like Pabau sends the notice with digital intake forms before the first appointment. Patients read and sign on their own device. The signed acknowledgment then files straight into the patient record.

When you revise the notice, you update the form once and every new patient receives the current version. You can see from each patient record who has signed, so missing acknowledgments get chased before an audit.
Send and track privacy notices automatically
Pabau sends your notice of privacy practices with intake forms, collects e-signed acknowledgments, and stores each one in the patient record for audits.
Conclusion
A notice of privacy practices only protects you if it matches how your practice handles PHI. Start from the template, then add your contact person, complaint process, duties statement, and effective date.
Check whether you hold Part 2 substance use disorder records, and remove any vacated reproductive health wording unless counsel advises keeping it. Then build delivery and acknowledgment into intake so every new patient is covered.
Book a demo to see how Pabau delivers your privacy notice and files every acknowledgment automatically.
Continue your research
Looking for broader HIPAA compliance guidance? HIPAA compliance software covers the safeguards that sit around your notice, from access controls to audit trails.
Need a form for disclosures the notice doesn’t cover? Authorization to use and disclose health information gives you a template for patient-signed authorizations.
Need help with privacy training for your team? HIPAA training for employees explains what front-desk and clinical staff must learn, and how often.
Running a small office? HIPAA compliance for medical offices walks through the day-to-day privacy duties a practice carries beyond the notice.
Frequently asked questions
What is a HIPAA notice of privacy practices?
A HIPAA notice of privacy practices is a mandatory document that healthcare providers must give patients. It explains how their protected health information is used, disclosed, and protected under 45 CFR §164.520. It also describes patient rights and the provider’s legal duties.
Which providers have to give patients the notice?
Any covered entity under HIPAA must provide a notice. Covered entities include health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically, such as when billing insurance. Solo practitioners and small practices are not exempt.
When must the notice be provided?
At the patient’s first service encounter, before or at the time treatment begins. The notice must also be posted in your facility, on your website if you have one, and made available on request. Health plans give it at enrollment and remind members of it at least every three years.
Can patients refuse to sign the acknowledgment?
Yes. Patients have the right to refuse to acknowledge receipt. You should still provide the notice and document that you offered it and the patient declined. A patient’s refusal does not affect their privacy rights under HIPAA.