HIPAA Privacy Notice: Requirements, Content, and Delivery
What a HIPAA privacy notice must contain, who has to issue one, how to distribute it, and how it differs from your website privacy policy. Full 2026 guide.
If you handle patient health information in the United States, a HIPAA privacy notice is not optional paperwork. It is a specific, federally mandated document, formally called the Notice of Privacy Practices, and 45 CFR 164.520 dictates much of what it says and how you deliver it. This guide walks through what the notice must contain, who has to issue one, and where it fits alongside the privacy policy on your website. It is educational rather than legal advice, so bring your specific circumstances to a health care attorney before finalizing anything.
What Is a HIPAA Privacy Notice?
A HIPAA privacy notice is a written statement that tells individuals how a covered entity may use and disclose their protected health information (PHI), what rights they have over that information, and what legal duties the entity has to protect it. It is required by the HIPAA Privacy Rule at 45 CFR 164.520 and applies to every covered entity except correctional institutions and certain group health plans that neither create nor receive PHI beyond summary data.
The document goes by several names in practice. You will see it called a Notice of Privacy Practices, an NPP, a HIPAA privacy statement, or informally a HIPAA privacy policy. They all refer to the same regulatory requirement. Internally, your written policies and procedures under 45 CFR 164.530(i) are a separate thing: those are the operational rules your staff follows, while the notice is the public-facing summary patients receive.
One point causes more confusion than any other. The notice is a disclosure document, not a consent form. Signing it does not authorize any use of PHI. Authorizations for uses that require permission, such as marketing or the sale of PHI, are governed separately by 45 CFR 164.508.
Who Must Provide a HIPAA Privacy Notice
The obligation attaches to covered entities, a term with a precise definition in 45 CFR 160.103:
- Health plans, including group health plans, health insurance issuers, HMOs, Medicare, and Medicaid.
- Health care clearinghouses, which process nonstandard health information into standard formats.
- Health care providers who transmit any health information electronically in connection with a HIPAA covered transaction, such as claims, eligibility checks, or referral authorizations.
That last category catches far more organizations than people expect. A solo therapist who bills insurance electronically is a covered entity. A cash-only practice that never submits an electronic claim generally is not, though state law may still impose confidentiality duties.
Business associates, the vendors that handle PHI on a covered entity's behalf, do not issue their own notice. Their obligations flow from the business associate agreement required by 45 CFR 164.504(e) and from the Security Rule. If you run a scheduling platform, a billing service, or a cloud EHR, your compliance work sits there, not in an NPP.
What Must Be Included in a HIPAA Privacy Notice
The content requirements in 45 CFR 164.520(b)(1) are unusually prescriptive. A compliant notice must include all of the following:
- The header, in plain language, that reads: "THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY."
- A description of permitted uses and disclosures for treatment, payment, and health care operations, each with at least one specific example.
- A description of other categories of uses and disclosures you may make without authorization, such as public health reporting, judicial proceedings, or law enforcement requests.
- Separate statements for uses that require special handling, including psychotherapy notes, marketing communications, the sale of PHI, and fundraising, along with the individual's right to opt out of fundraising.
- A statement that all other uses require written authorization and that the individual may revoke that authorization.
- A description of individual rights and how to exercise them.
- A statement of the covered entity's legal duties, including the duty to notify affected individuals following a breach of unsecured PHI under 45 CFR 164.404.
- Complaint procedures, telling individuals they may complain to you and to the Secretary of HHS, with an assurance of no retaliation.
- A named contact or office and phone number for questions.
- The effective date of the notice.
Two structural rules trip people up. If you want the flexibility to change your practices and apply the new terms to PHI you already hold, 45 CFR 164.520(b)(1)(v)(C) requires you to reserve that right explicitly in the notice. And where state law is more protective, for example around HIV status, genetic testing, or substance use disorder records, the notice must reflect the stricter standard rather than the federal floor.
Individual Rights Your HIPAA Privacy Statement Must Describe
Your HIPAA privacy statement has to spell out the rights individuals hold over their records. At minimum:
- Right of access to inspect and obtain a copy of PHI in a designated record set, in the form and format requested if readily producible (45 CFR 164.524). Response is due within 30 days.
- Right to amend records the individual believes are inaccurate or incomplete (45 CFR 164.526).
- Right to an accounting of disclosures made in the six years prior to the request, with the exceptions listed in 45 CFR 164.528.
- Right to request restrictions on uses and disclosures (45 CFR 164.522(a)). Most restriction requests may be denied, but one may not: where the individual pays in full out of pocket, you must honor a request not to disclose that item to their health plan.
- Right to confidential communications at an alternative address or by an alternative method (45 CFR 164.522(b)).
- Right to a paper copy of the notice, even if the individual already received it electronically.
- Right to notification if their unsecured PHI is breached.
Write these in language a patient can act on. The Office for Civil Rights (OCR) has run a Right of Access Initiative since 2019 that has produced dozens of settlements, most in the $3,500 to $240,000 range, almost all for failing to hand over records on time. A notice that buries the access right does not cause those violations, but it correlates with practices that do.
How and When to Distribute Your HIPAA Privacy Notice
Distribution rules in 45 CFR 164.520(c) differ by entity type, and this is where small practices most often fall short.
Providers with a direct treatment relationship must:
- Give the notice no later than the date of first service delivery, including service delivered electronically.
- Make a good faith effort to obtain a written acknowledgment of receipt, and if that fails, document the attempt and the reason.
- Post the notice in a clear and prominent location at every physical service delivery site, where it is reasonable to expect patients to read it.
- Provide a copy to anyone who asks for one.
- In an emergency treatment situation, deliver the notice as soon as reasonably practicable afterward.
Health plans must provide the notice to new enrollees at enrollment, then notify enrollees at least once every three years that the notice is available and how to obtain it.
Every covered entity that maintains a website describing its services or benefits must post the notice prominently on that site and make it available electronically, per 45 CFR 164.520(c)(3)(i). Email delivery is permitted where the individual agrees to electronic notice, though they retain the right to request paper.
Electronic acknowledgment through a patient portal counts, provided you retain the record. Under 45 CFR 164.530(j), you must keep the notice and any acknowledgments for six years from the later of the creation date or the date it was last in effect.
HIPAA Privacy Notice vs Website Privacy Policy
These are different documents serving different laws, and publishing one does not satisfy the other. Confusing them is the single most common compliance gap for health care organizations with a public web presence.
| HIPAA privacy notice | Website privacy policy | |
|---|---|---|
| Legal basis | 45 CFR 164.520 | GDPR, CCPA/CPRA, CalOPPA, state laws |
| Covers | PHI held by a covered entity | Site visitor data: IP addresses, cookies, analytics, forms |
| Audience | Patients, members, enrollees | Anyone visiting the website |
| Content | Fixed regulatory elements | Data categories, purposes, sharing, retention, user rights |
| Enforced by | HHS Office for Civil Rights | FTC, state attorneys general, EU supervisory authorities |
A dermatology clinic running Google Analytics, a Meta Pixel, and a chat widget is collecting data from people who are not yet patients. That processing sits outside the notice of privacy practices and inside consumer privacy law. Building a privacy policy for the website itself is a separate task from drafting the HIPAA notice, and both belong in your footer.
Cookies deserve their own attention here. If your site serves visitors in the EU or UK, Article 5(3) of the ePrivacy Directive requires consent before non-essential cookies are set, and a cookie policy plus a consent banner is the standard answer. California's CCPA exempts PHI covered by HIPAA under Section 1798.146, but it does not exempt the marketing data your website collects from prospective patients.
Online Tracking Technologies and PHI
OCR issued a bulletin in December 2022, revised in March 2024, taking the position that tracking technologies on covered entity webpages can transmit PHI to third parties, and that doing so without a business associate agreement or valid authorization violates the Privacy Rule. In June 2024, a federal court in the Northern District of Texas vacated the portion of that guidance addressing unauthenticated public webpages in American Hospital Association v. Becerra.
The practical takeaway survives the litigation. Trackers on authenticated pages such as patient portals, appointment histories, and test results still handle PHI, and OCR continues to investigate. Several hospital systems have paid multimillion dollar settlements in private class actions over pixel-based disclosures. Auditing what actually loads on your pages, rather than what your marketing team believes loads, is the only reliable check.
Updating and Retaining Your HIPAA Privacy Notice
You must revise the notice promptly whenever there is a material change to your uses and disclosures, individual rights, legal duties, or other practices described in it. Under 45 CFR 164.520(b)(3), a covered entity may not implement a material change before the revised notice takes effect, unless the change is required by law.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowDelivery of a revision depends on entity type:
- Providers must post the revised notice at their service sites and on their website, make copies available at the site, and provide it to anyone who requests it, all by the effective date. There is no obligation to mail it to every existing patient.
- Health plans that post the notice on a website must post the material revision there by its effective date and send it, or information about it and how to obtain it, in the next annual mailing. Plans without a website must send it within 60 days of the material revision.
Two regulatory changes are worth tracking right now. The 2024 final rule aligning 42 CFR Part 2 (substance use disorder records) with HIPAA added new NPP content requirements with a compliance date of February 16, 2026. Separately, the 2024 HIPAA Privacy Rule to Support Reproductive Health Care Privacy was vacated nationwide by a Texas federal court in June 2025, with the Part 2 related notice provisions left standing. Because this area keeps moving, confirm the current state of both rules with counsel before you finalize a revision.
Common HIPAA Privacy Notice Mistakes
- Treating the notice as a consent form. Acknowledgment of receipt authorizes nothing. Uses beyond treatment, payment, and operations still require an authorization under 45 CFR 164.508.
- Copying another organization's notice verbatim. The notice must describe your actual practices, your contact, and any stricter state law that applies to your records.
- Omitting the required header. The all-caps statement is prescribed text, not a suggestion.
- Failing to post it on the website. A covered entity with a services website must make the notice prominently available there. Auditors check this first because it takes 10 seconds.
- Never updating the effective date. A notice dated 2013 signals to a regulator that no one has reviewed privacy practices in over a decade.
- Leaving no acknowledgment trail. Good faith effort means documented effort. An undocumented attempt is indistinguishable from no attempt during an investigation.
Penalties for a Deficient HIPAA Privacy Notice
Privacy Rule violations, including failure to provide or post the notice, fall under the tiered civil monetary penalty structure created by the HITECH Act and codified at 45 CFR 160.404. The four tiers turn on culpability:
- No knowledge, where the entity did not know and would not have known by exercising reasonable diligence.
- Reasonable cause, where the violation was due to a cause other than willful neglect.
- Willful neglect, corrected within 30 days.
- Willful neglect, not corrected.
Amounts are adjusted annually for inflation. Minimums begin around $141 per violation in the lowest tier, and the top tier exceeds $71,000 per violation, with annual caps per identical provision ranging from roughly $2.1 million down to about $35,000 depending on tier. Criminal penalties under 42 U.S.C. 1320d-6 reach $50,000 and one year of imprisonment for knowing disclosure, rising to $250,000 and 10 years where PHI is used for commercial advantage or malicious harm.
In practice, OCR resolves most notice deficiencies through corrective action plans rather than headline fines. The reputational cost of a public resolution agreement, and the multiyear monitoring that comes with it, usually exceeds the check.
Building the Rest of Your Compliance Stack
The HIPAA privacy notice covers PHI. Your website still needs its own set of documents for everything else it collects, and those are governed by consumer privacy law rather than HIPAA. Most health care sites need a privacy policy, terms of service, and a cookie policy with a functioning consent banner.
TermsBox generates those website documents and scans your pages to detect the cookies, trackers, and third-party services actually running on them, which is the same audit that surfaces pixel problems on patient-facing pages. It does not produce a Notice of Privacy Practices, since that document has to be drafted against your specific PHI practices and reviewed by health care counsel. Treat the two workstreams as parallel, not interchangeable.
State laws add a third layer. Washington's My Health My Data Act requires a separate consumer health data privacy policy for health data collected outside HIPAA, and it carries a private right of action. Nevada's SB 370 imposes comparable duties. A wellness app, a symptom checker, or a lead generation page for a clinic can fall under these laws even when HIPAA does not reach it.
Frequently Asked Questions
Is a HIPAA privacy notice the same as a website privacy policy?
No. A HIPAA privacy notice is a specific document required by 45 CFR 164.520 that describes how a covered entity uses and discloses protected health information. A website privacy policy covers the data your site collects from visitors, such as analytics identifiers, cookies, and contact form submissions, and it is required by laws like GDPR and CCPA rather than HIPAA.
Do patients have to sign the HIPAA privacy notice?
Patients do not have to sign it, and their signature is not consent to anything. Under 45 CFR 164.520(c)(2)(ii), a provider with a direct treatment relationship must make a good faith effort to obtain a written acknowledgment that the patient received the notice, and if the patient declines, the provider simply documents the attempt and the reason it failed.
How often does a HIPAA privacy notice need to be updated?
There is no fixed schedule, but you must revise the notice whenever there is a material change to your privacy practices, your legal duties, or individual rights. Providers must post the revised notice and make it available by its effective date, while health plans that post the notice on a website must distribute a material revision within 60 days.
Do business associates need their own HIPAA privacy notice?
No. The notice of privacy practices obligation in 45 CFR 164.520 applies to covered entities, meaning health plans, health care clearinghouses, and providers who transmit health information electronically in covered transactions. Business associates are bound by their business associate agreement and by the Security Rule, but they do not issue their own notice.
Does a HIPAA privacy notice have to be posted on my website?
Yes, if you maintain a website that provides information about your services or benefits. 45 CFR 164.520(c)(3)(i) requires covered entities with such a site to make the notice prominently available there, and providers must also post it in a clear and prominent location at every physical service delivery site.
What are the penalties for not providing a HIPAA privacy notice?
Failure to provide the notice is a Privacy Rule violation subject to tiered civil monetary penalties that start around $141 per violation for unknowing violations and rise past $71,000 per violation for uncorrected willful neglect, with annual caps adjusted for inflation each year. The HHS Office for Civil Rights has resolved multiple cases specifically over missing or unposted notices, often with corrective action plans attached.