Key Takeaways
A notice of privacy practices is the HIPAA-required legal notice informing patients how covered entities use, disclose, and protect protected health information (PHI).
HIPAA mandates that all covered health care providers, health plans, and clearinghouses provide an NPP in plain language to every patient at their first service or enrollment.
The NPP must include 12 required elements: header, uses and disclosures, patient rights (access, amendment, accounting), covered entity duties, minimum necessary standard, and complaint process.
Pabau’s compliance tools automate NPP acknowledgement tracking, digital distribution, and version control – eliminating manual signature collection errors and audit gaps.
Download Your Free Notice of Privacy Practices Template
Notice of Privacy Practices
A ready-to-use, HIPAA-compliant notice covering patient details, privacy practices, patient rights disclosures, uses and disclosures, covered entity duties, minimum necessary procedures, complaint procedures, and acknowledgement of receipt signature block.
Download templateMost practice owners assume their patient intake forms handle privacy disclosures. They don’t. Healthcare law requires a specific legal document – the notice of privacy practices – that describes how your clinic uses patient information, what rights patients have, and how complaints are filed. Missing it exposes your practice to HIPAA penalties of $100-$50,000 per violation.
This guide explains what a notice of privacy practices is, what HIPAA requires, when and how to distribute it, and how to keep it current as regulations change. We’ve also provided a downloadable template you can customize for your clinic today.
What is a Notice of Privacy Practices?
A notice of privacy practices is the formal legal document that healthcare providers use to explain their privacy policies to patients. Under the HIPAA Privacy Rule (45 CFR Part 164), every covered entity – including healthcare providers, health plans, and health care clearinghouses – must provide an NPP to individuals whose information they handle.
The notice of privacy practices satisfies three legal requirements: (1) transparency – patients must know how their protected health information (PHI) is used before treatment, (2) accuracy – the NPP documents your clinic’s actual privacy practices, and (3) rights disclosure – patients learn their rights under HIPAA, including access to records, requesting amendments, and filing complaints with the Office for Civil Rights (OCR).
Most practices customize an HHS model NPP to reflect their actual practices. This customization is critical – the model is a template, not a one-size-fits-all document. Your notice of privacy practices must accurately describe YOUR clinic’s privacy procedures.
How to Use and Implement Your Notice of Privacy Practices
Implementing a notice of privacy practices follows a five-step workflow that ensures HIPAA compliance and maintains audit trails.
- Customise the template: Review the downloaded PDF and modify the disclosures section to match your actual practices. Remove any disclosures that don’t apply to your clinic. Ensure plain language – assume the average patient can understand it.
- Add state-specific disclosures: If operating in California, add California Confidentiality of Medical Information Act (CMIA) notices. If in Texas or New York, add those state privacy law disclosures. State laws often impose stricter requirements than HIPAA.
- Designate a Privacy Officer: Name a contact (person or department) for patient privacy questions or complaints. Enter their phone and email in the designated section.
- Set up acknowledgement collection: Print the template or distribute it digitally via patient portal. Require patients to sign or electronically acknowledge receipt. Retain the signed copy in the patient’s record – this creates your audit trail proving good-faith effort at acknowledgement.
- Post the notice visibly: Display the notice in a clear, prominent location (waiting room, reception desk) and on your website. Current and prospective patients must be able to access it.
Once distributed, keep the notice of privacy practices current. If privacy practices change – new disclosures, a merger, a breach, or state law changes – revise and redistribute the NPP. Practices using digital forms for patient intake can version-control the NPP automatically.

Automate Privacy Acknowledgement with Pabau
Track NPP acknowledgements, digital signatures, and version control in one compliance hub.
Who is Required to Provide a Notice of Privacy Practices?
Any healthcare entity that holds or processes patient information must provide a notice of privacy practices. This includes:
- Covered health care providers: Solo practitioners, group practices, clinics, hospitals, urgent care, dental offices, mental health therapists, and medical spas with clinical staff that treat patients.
- Health plans: Insurance companies, HMOs, PPOs, and employer-sponsored plans.
- Health care clearinghouses: Billing services, coding companies, and intermediaries processing health information on behalf of covered entities.
The key question: Are you a healthcare provider with a direct patient relationship, do you bill insurance, or do you maintain medical records? If yes, you’re a covered entity and must provide an NPP. Medical spas with nurses or physicians are covered entities. Mental health practices are always covered entities. Consult a healthcare attorney if unclear.
Benefits of a Current Notice of Privacy Practices
Legal compliance: An NPP is mandatory. Failure to provide one triggers HIPAA civil monetary penalties (currently $100-$50,000 per violation, adjusted annually). The Office for Civil Rights prioritises NPP enforcement.
Patient trust: A clear NPP in plain language demonstrates that your practice respects privacy and patient autonomy. This builds reputation and improves retention.
Audit defense: A signed acknowledgement of receipt is your proof that notice was provided. If a patient claims unawareness, the signed NPP is your evidence. Digital acknowledgements add timestamps and IP-address logging for stronger audit trails.
Operational clarity: Writing the notice of privacy practices forces you to document actual privacy practices and surfaces gaps: inconsistent disclosure procedures, missing state law notices, or undefined data retention policies.
Pro Tip
Update your notice of privacy practices immediately if your clinic merges, you add new data uses (e.g. research partnership), your state passes a privacy law, or you experience a breach. Document the revision date in the footer so staff know which version is current. Use digital forms to version-control automatically.
State-Specific Privacy Requirements: Going Beyond HIPAA
HIPAA is a federal floor, not a ceiling. Several states have enacted laws imposing stricter confidentiality requirements. Your notice of privacy practices MUST disclose these state duties – failure to do so is a state law violation alongside potential HIPAA non-compliance.
California Confidentiality of Medical Information Act (CMIA): California practices must comply with CMIA (Cal. Civ. Code § 56 et seq.), which is stricter than HIPAA. CMIA requires prior written authorisation for nearly all disclosures except those related to direct treatment, payment, or healthcare operations. Your NPP must explicitly state: “California law requires our authorisation before we disclose your medical information, except in specific circumstances related to your care.” Privacy regulation checklists for your jurisdiction can help identify all applicable state laws.
If you operate in multiple states, your notice of privacy practices should include a state-specific section disclosing the stricter laws. Consult your state health department or a healthcare attorney to confirm which state privacy laws apply to your practice.
Conclusion: Protect Your Practice With a Current Notice
The notice of privacy practices is your foundation for HIPAA compliance. A clear, updated NPP signed and dated by every patient proves your clinic is transparent about privacy – reducing regulatory risk and building patient trust.
Use the template above to draft your clinic’s NPP today, customise it for your actual practices and state laws, and integrate it into your patient intake workflow. Practice management software with built-in compliance tools can automate NPP distribution, acknowledgement capture, and version control, reducing administrative burden while maintaining audit-ready documentation.
Continue your research
Need a framework for required NPP content? HIPAA compliance checklist for primary care walks through all required content elements in a single checklist.
Curious about security safeguards alongside privacy? HIPAA Security Rule requirements covers the parallel safeguards your NPP should reference when describing how you protect patient data.
Want to automate digital acknowledgements? Medical forms at your healthcare practice explains how to capture, store, and audit patient form signatures digitally whilst maintaining HIPAA compliance.
Frequently Asked Questions
What is a notice of privacy practices?
A notice of privacy practices is a HIPAA-required legal document that healthcare providers must give to patients explaining how the clinic uses and discloses protected health information (PHI), what patient rights exist, and how to file complaints with the Office for Civil Rights. It must be provided at the patient’s first service delivery.
When must a notice of privacy practices be provided?
For healthcare providers with direct patient relationships, the NPP must be provided at the time of first service or as soon as practicable thereafter. For health plans, it must be provided by the date of enrollment. If materially revised, it must be re-distributed to all patients within 60 days.
What if a patient refuses to sign the acknowledgement?
Under HIPAA, you must make a good-faith effort to obtain written acknowledgement, but a patient’s refusal to sign does not violate the rule. Document your good-faith effort (e.g. “Patient offered NPP; declined to sign on [date]”) and proceed with treatment.
What are the penalties for not providing a notice of privacy practices?
HIPAA civil monetary penalties for NPP violations range from $100 to $50,000 per violation, adjusted annually for inflation. The Office for Civil Rights (OCR) determines penalties based on the violation’s nature, severity, and whether corrective action was taken.