Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Notice of Privacy Practices — guide from Governance Docs

HIPAA Notice of Privacy Practices: What Changed in February 2026

The HIPAA notice of privacy practices is the document most covered entities wrote
once and have not revisited since. That is now a problem: a compliance deadline passed on
16 February 2026, and a separate 2024 requirement that many notices were updated for
has since been struck down. This guide covers what the notice must contain and what actually changed.

What a HIPAA notice of privacy practices must contain

Under 45 CFR §164.520 a HIPAA notice of privacy practices has to be written in plain language and cover:

  • How the entity may use and disclose protected health information, with examples
    for treatment, payment and health care operations.
  • Uses and disclosures that require authorisation, and the right to revoke it.
  • The individual’s rights: access, amendment, an accounting of disclosures,
    requests for restriction, confidential communications and a paper copy on request.
  • The entity’s legal duties, including the duty to notify affected individuals
    following a breach of unsecured PHI.
  • How to complain to the entity and to the Secretary of HHS, with an assurance of
    no retaliation.
  • A contact point and an effective date.

The HIPAA notice of privacy practices must be provided at first service delivery, made available on request, and posted prominently
— including on any website that describes services or benefits.

The HIPAA notice of privacy practices change that took effect on 16 February 2026

The 2024 final rule aligning 42 CFR Part 2 with HIPAA became effective on
16 April 2024 with a compliance date of 16 February 2026. It requires covered
entities to update the notice to address substance use disorder records, and it brings unified
consent, clearer redisclosure rules and explicit OCR enforcement with tiered civil monetary
penalties.

The trap is who it applies to. Any HIPAA covered entity that creates, receives,
maintains or transmits SUD records protected by Part 2 must update its notice —
even if it is not a substance use disorder treatment programme. General practices,
hospitals and health plans that receive Part 2 records from anywhere are in scope, and many assume
they are not. If your notice has not been reviewed since early 2026, this is the first thing to
check.

A notice of privacy practices template that is already current.

The HIPAA Toolkit includes the notice of privacy practices alongside 160+ policy templates and the security risk analysis workbook — every document carries a regulatory currency statement, so you can see what reflects current law and what is flagged as proposed.

Explore the HIPAA Toolkit →

The HIPAA notice of privacy practices requirement that no longer applies

The 2024 Privacy Rule amendment on reproductive health care required covered entities to revise
the notice and to obtain a signed attestation before certain disclosures. That rule
was vacated nationwide by the US District Court for the Northern District of Texas
in June 2025, and the appeal was dismissed in September 2025.

The practical consequence is awkward. Organisations that diligently updated their notice and built
an attestation workflow in 2024 are now maintaining a process with no legal basis, while template
packs and checklists across the industry still list it as a requirement. If your notice references
reproductive health care privacy protections under that amendment, that language should come out.

When to reissue a HIPAA notice of privacy practices

A material change requires you to revise the HIPAA notice of privacy practices promptly. For a health plan
that maintains a website, the revised notice goes on the site and is distributed at the next annual
mailing; a provider posts the revised notice and makes copies available, and provides it to new
patients — there is no obligation to re-paper every existing patient.

Both of the changes above are material. The Part 2 update requires new content; the vacated rule
requires content removed. Deal with them in one revision rather than two, and record the effective
date so the version history shows the notice tracked the law.

Where the HIPAA notice of privacy practices fits in the wider system

The HIPAA notice of privacy practices is the public face of your Privacy Rule obligations, and it makes promises that other
processes have to keep. If it says individuals can request restrictions, there must be a workflow for
that. If it says you will notify following a breach, the breach process must exist and be exercised.
Auditors and complainants both start from the notice and work inward, which is why an accurate one
matters beyond the document itself. See our guides to
the Security Rule versus the Privacy Rule,
HIPAA policies and the
HIPAA implementation plan.

References

More on HIPAA

All of these are covered by the HIPAA Toolkit, or start with the free HIPAA templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.