Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Aesthetics & Beauty

Notice of privacy practices

Key takeaways

Key takeaways

A notice of privacy practices is the notice HIPAA requires you to give patients, explaining how you use, disclose, and protect their health information.

Every covered provider, health plan, and clearinghouse must hand it over in plain language, at or before the first service or enrollment.

45 CFR 164.520 fixes the content: the header, uses and disclosures, patient rights, your duties, changes to the notice, and the complaint process.

Covered entities that receive substance use disorder records under 42 CFR Part 2 had to revise their notice by February 16, 2026.

Keep the signed acknowledgment in the patient record, because it is your evidence that the notice was offered before treatment began.

Download your free notice of privacy practices template

The template is a four-page notice built on 45 CFR 164.520. It covers the required header, uses and disclosures, patient rights, covered entity duties, and the Office for Civil Rights complaint process. Page four is a signed acknowledgment of receipt, with a good faith effort box for patients who decline to sign.

Download template

A notice of privacy practices is the separate document HIPAA requires you to hand every patient. Your intake and consent forms don’t cover it. The notice explains how you use their health information, what rights they hold, and how to complain.

Not having one is a violation in its own right. Civil monetary penalties now start at $145 per violation and reach $73,011, after the inflation adjustment that took effect on January 28, 2026. Willful neglect that goes uncorrected carries a calendar-year cap of $2,190,294.

This guide covers what the notice has to contain, who is required to issue one, and how to distribute and document it. It also covers the substance use disorder update that fell due in February 2026. The template above is yours to customize.

What is a notice of privacy practices?

A notice of privacy practices is the document a covered entity uses to tell patients, in plain language, how it handles their protected health information. The HIPAA Privacy Rule requires one from every healthcare provider, health plan, and clearinghouse it covers. The governing section is 45 CFR 164.520.

The notice does three jobs at once. It makes your handling of patient data transparent before treatment starts. It documents what your practice does with that data. And it tells patients what rights they hold and how to enforce them.

Most practices start from an HHS model notice and edit from there. Skipping that edit is a costly mistake. A notice that describes practices you don’t follow is worse than no notice. It commits you in writing to a standard you are already missing.

What HIPAA requires your notice to include

Section 164.520(b) sets out the content, and an auditor will look for each piece. The template above is organized in the same order, so you can work through it section by section.

  • The header: the exact wording prescribed by the rule, displayed prominently at the top of the notice.
  • Uses and disclosures: how you use information for treatment, payment, and health care operations, with an example of each. It also covers the disclosures the law permits or requires without authorization.
  • Authorization statements: confirmation that marketing, the sale of health information, and most psychotherapy notes need written authorization, and that the patient can revoke it.
  • Patient rights: access, amendment, an accounting of disclosures, requested restrictions, confidential communications, a paper copy, and breach notification.
  • Your duties: a statement that you protect the information, abide by the current notice, and notify patients after a breach.
  • Changes to the notice: your right to revise the notice, and how patients will get the revised version.
  • Complaints and contact: how patients complain to you and to the Office for Civil Rights, with a promise of no retaliation. The notice also names a contact and gives an effective date.

Two extras are easy to forget. If you fundraise using patient information, the notice has to say so and offer an opt-out. If your state or specialty imposes a stricter rule, the notice has to describe that limit rather than the looser federal one. Our HIPAA compliance checklist covers the policies that sit behind both.

Who has to provide a notice of privacy practices

Any covered entity that holds or processes patient information has to issue one. That falls into three groups.

  • Covered health care providers: solo practitioners, group practices, hospitals, urgent care, dental offices, mental health therapists, and medical spas with clinical staff.
  • Health plans: insurers, HMOs, PPOs, and employer-sponsored plans.
  • Health care clearinghouses: billing services, coding companies, and other intermediaries that process health information for covered entities.

One test settles most cases. If you treat patients and transmit health information electronically for a covered transaction, you are a covered entity. Claims and eligibility checks both count. Medical spas with nurses or physicians usually qualify, and mental health practices almost always do. Ask a healthcare attorney if your situation is borderline.

How to distribute and document your notice

Getting the wording right is half the job. The other half is proving that every patient received it.

  1. Customize the template. Open the downloaded PDF and edit the disclosures section so it matches what your practice does. Delete anything that doesn’t apply. Keep the language plain enough for an average patient to follow.
  2. Add the laws that bind you. Layer in your state requirements, and the 42 CFR Part 2 language if you handle substance use disorder records. Section 11 of the template is set aside for this.
  3. Name a Privacy Officer. Give a person or department that patients can contact with privacy questions or complaints. Their phone number, email, and mailing address go in section 10.
  4. Collect the acknowledgment. Hand out the notice at or before the first service, on paper or through the patient portal, and ask the patient to sign for it. File the signed page in the patient record.
  5. Post it where patients can see it. Display the current notice in your waiting room and on your website, and keep paper copies at reception for anyone who asks.

Then keep it alive. A merger, a new data use, a breach, or a change in state law all mean the notice needs revising. Providers then have to post the revised version promptly and keep copies available. Practices running digital patient intake forms can re-issue the notice to their list instead of chasing signatures at the front desk.

Digital consent and intake forms with a patient signature panel
Practice management software like Pabau ends each form with a signature panel, so the acknowledgment is filed before the visit.

The February 2026 substance use disorder update

Covered entities that receive or maintain 42 CFR Part 2 records had to update their notice of privacy practices by February 16, 2026. That deadline came out of the 2024 final rule aligning Part 2 with HIPAA, and it has already passed. A notice written before then is out of date for any practice that touches these records.

Two rules arrived together, which is where the confusion starts. The Part 2 notice amendments came alongside the 2024 reproductive health privacy rule. In June 2025, a federal court in Texas vacated that reproductive health rule nationwide. The Part 2 notice provisions survived the ruling. Practices that treated the whole package as dead are now non-compliant.

If you receive Part 2 records, four things belong in your notice.

  • A description of how you may use and disclose Part 2 records. This includes where written patient consent is needed for treatment, payment, and health care operations.
  • A statement that other law materially limits those uses and disclosures, and what the limits on redisclosure are.
  • A statement that Part 2 records cannot be used in civil, criminal, administrative, or legislative proceedings without patient consent or a court order.
  • An opt-out from fundraising communications, if you use Part 2 records for fundraising.

If you never receive or hold Part 2 records, this requirement doesn’t reach you and your existing notice stands. Section 11 of the template flags Part 2 so you can decide either way and record the decision.

State privacy laws that go beyond HIPAA

HIPAA sets a federal floor. States are free to go further. Where a state law protects patient information more strictly, that stricter law governs and your notice has to describe it. Getting this wrong is a state violation on top of any federal exposure.

  • California: the Confidentiality of Medical Information Act, at Cal. Civ. Code section 56 and following, requires written authorization for most disclosures outside direct treatment, payment, and operations.
  • Texas: the Medical Records Privacy Act, at Tex. Health and Safety Code chapter 181, applies to a wider set of businesses than HIPAA does and adds its own training and consent duties.
  • New York: Public Health Law section 18 governs patient access to records, and article 27-F sets separate rules for HIV-related information.

Operating across state lines makes this harder. Write a state-specific section into the notice rather than issuing different versions per location, since one document is easier to keep current. Your state health department or a healthcare attorney can confirm which statutes apply to your specialty.

Why a current notice is worth the effort

It closes off an easy enforcement finding. A missing or stale notice is simple for an investigator to establish, and it needs no patient harm to support a penalty.

It gives you an audit defense. A signed acknowledgment, dated and filed, answers a patient who later says they were never told. A digital signature adds a timestamp and an audit log to that record.

It builds patient trust. A notice a patient can actually read signals that you take their privacy seriously, which matters in specialties where the record itself is sensitive.

It forces you to write down what you do. Drafting the notice surfaces the parts of your privacy program that were never documented, such as inconsistent disclosure steps or an undefined retention policy.

Pro Tip

Put the revision date in the footer of your notice and keep a dated archive of superseded versions. If an investigator asks what your policy was on the date of an incident, that archive is the answer. Set a calendar reminder to review the notice once a year and after any merger, breach, or change in state law.

How Pabau handles notice delivery and acknowledgment

At most practices the notice lives in a printer tray. Reception hands it over at check-in, the patient signs a page, and someone scans the page into the chart later that week. Signatures go missing, revisions reach only the patients who happen to book, and nobody can say who holds which version.

Pabau, our practice management software, moves the whole exchange into the patient record. You build the notice and its acknowledgment as a digital intake form. Then you attach it to the appointment types that need it and send it with the booking confirmation.

The patient signs on their phone before they arrive. The signed form files itself against their record with a timestamp, so nobody has to scan anything later.

That changes the follow-up too. You can see which patients still have the form outstanding before the day starts. When you revise the notice, you re-issue it to the affected patients in one action rather than one visit at a time. The signed versions stay in the record as your compliance documentation, ready to produce if anyone asks.

Collect every privacy acknowledgment before the visit

Send your notice of privacy practices with the booking confirmation, capture the signature digitally, and file it against the patient record automatically. No chasing paper at the front desk.

Pabau clinic management dashboard

Conclusion

Treat the notice of privacy practices as a live document rather than a form you produced once. The wording only protects you while it describes what your practice does. The February 2026 Part 2 deadline shows how quickly that stops being true.

Download the template, edit it against your own disclosures and state law, and decide today whether Part 2 reaches you. Then turn to delivery, which is the harder half of the job. A signed, dated acknowledgment in every record is what turns a good notice into a defensible one.

Book a demo to see how Pabau delivers your notice with every booking and files the signed acknowledgment for you.

Continue your research

Continue your research

Need a framework for the wider privacy program? HIPAA compliance checklist walks through the policies your notice has to describe accurately.

Want to automate digital acknowledgments? Our guide to medical forms explains how to capture, store, and audit patient signatures while staying HIPAA compliant.

Building out the rest of your patient paperwork? Our medical power of attorney template covers another document patients sign, with its own consent and storage rules.

Run a behavioral health practice? The thought record worksheet is a printable form you can send in the same digital intake packet.

Not sure the rules reach you? The personal trainer liability waiver shows what patient paperwork looks like when HIPAA does not apply.

Frequently asked questions

What is a notice of privacy practices?

A notice of privacy practices is the HIPAA-required document that tells patients how your practice uses and discloses protected health information. It also sets out their rights and how to complain to the Office for Civil Rights. Providers must give it at or before the first service delivery.

When must patients receive the notice?

Providers with a direct treatment relationship must give it no later than the first service delivery. Health plans must give it by the date of enrollment. After a material revision, a provider posts the new notice promptly and makes copies available, while a health plan has 60 days to notify enrollees.

What if a patient refuses to sign the acknowledgment?

You must make a good faith effort to obtain a written acknowledgment, but a refusal does not put you in violation. Record the effort in the patient record, with the date offered and the reason it was not signed, then go ahead with treatment. The template has a box for this.

Did the notice of privacy practices requirement change in 2026?

Yes, for practices that receive or maintain 42 CFR Part 2 substance use disorder records. Those entities had to revise their notice by February 16, 2026. The additions cover Part 2 uses and disclosures, redisclosure limits, and the bar on use in legal proceedings. Practices with no Part 2 records were not affected.

What are the penalties for not issuing the notice?

Civil monetary penalties run from $145 to $73,011 per violation as of the inflation adjustment effective January 28, 2026. The calendar-year cap for repeated violations of one provision is $2,190,294. The Office for Civil Rights sets the amount by culpability, severity, and whether you corrected the problem.

×