Establishing secure connection…Loading editor…Preparing document…

Notice of Privacy Practices

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HIPPA NOTICE OF PRIVACY PRACTICES

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW THIS INFORMATION CAREFULLY.

Note: If you have questions about this notice, please contact

WHO WILL FOLLOW THIS NOTICE:

This notice describes the privacy practices of . All of our staff may have access to information in your chart for treatment, payment and health care operations, which are described below, and may use and disclose information as described in this Notice. This Notice also applies to any volunteer or trainee we allow to help you while seeking services from us.

OUR PLEDGE REGARDING THE PRIVACY OF YOUR MEDICAL INFORMATION:

Your medical information includes information about your physical and mental health. We understand that information about your physical and mental health is personal. We are committed to protecting medical information about you. We create a record of the care and services you receive from us. We need his record to provide you with quality care and services and to comply with certain legal requirements. This notice applies to any and all of the records of your care generated by us.

This notice will tell you about the ways in which we may use and disclose medical information about you. We also describe your rights and certain obligations we have regarding the use and disclosure of medical information.

We reserve the right to revise or amend our notice of privacy practices without additional notice to you. Any revision or amendment to this notice will be effective for all of your records our practice has created or maintained in the past, and for any of your records we may create or maintain in the future. We will post a copy of our current notice in our offices in a prominent place and will post the notice on our website.

OUR OBLIGATIONS TO YOU:

We are required by law to:

• make sure that medical information that identifies you is kept private except as otherwise provided by state or federal law;

• give you this notice of our legal duties and privacy practices with respect to medical information about you; and

• follow the terms of the notice that is currently in effect.

HOW WE MAY USE AND DISCLOSE MEDICAL INFORMATION ABOUT YOU:

The following categories describe different ways that we may use and disclose medical information. For each category of uses or disclosures we will explain what we mean and try to give some examples. Not every use or disclosure in a category will be listed. This notice covers treatment, payment, and what are called health care operations, as discussed below. It also covers other uses and disclosures for which a consent or authorization are not necessary. Where law is more protective of your medical information, we will follow state law, as explained below.

For Treatment:

We may use medical information about you to provide you with medical treatment or services without consent or authorization unless otherwise required by applicable state law. We may disclose medical information about you to doctors, pharmacists, laboratories, or other health care providers or case managers or case coordinators or other service providers who are involved in taking care of you whether or not they are affiliated with us. For example, we may disclose medical information concerning you to the local hospital, or physicians or counselors who care for you as well as to any other entity that has provided or will provide care to you.

We will disclose any mental health information, including psychotherapy notes, AIDS or HIV-related information, or drug treatment information, that we may have about you only with written authorization as required by law, HIPAA and other federal regulations.

During the course of your treatment, we may refer you to other health care providers with which you may not have direct contact. These providers are called "indirect treatment providers." "Indirect treatment providers" are required to comply with the privacy requirements of state and federal law and keep your medical information confidential. These providers will be bound by the HIPAA privacy rule.

For Payment:

We may use and disclose medical information about you without consent or authorization so that the treatment and services you receive from us may be billed to and payment may be collected from you, an insurance company or a third party. For example, we may need to give your health plan information about treatment received so your health plan will pay us or reimburse you for the treatment. We may also tell your health plan or insurance company about a treatment you are going to receive to obtain prior approval or to determine whether it will cover the treatment. We may also provide your information to case coordinators or case managers for payment purposes as well.

For Health Care Operations:

We may use and disclose medical information about you without consent or authorization for "health care operations." These uses and disclosures are necessary to operate and make sure that all individuals receive quality care. For example, we may use medical information or mental health treatment information to review our treatment and services and to evaluate the performance of our staff in caring for you. We may also disclose your protected health information to doctors or staff or consultants for review and learning purposes. We may also use your protected health information in preparing for litigation.

Appointment Reminders:

We may use and disclose medical information to contact you by mail or phone to remind you that you have an appointment for treatment, unless you tell us otherwise in writing.

Treatment Alternatives:

We may use and disclose medical information to tell you about or recommend possible treatment options or alternatives that may be of interest to you. However, we will not use or disclose medical information to market other products and services, either ours or those of third parties, without your authorization.

Health-Related Benefits and Services:

We may use and disclose medical information to tell you about health-related benefits or services that may be of interest to you.

Individuals Involved in Your Care or Payment for Your Care:

We may release medical information, including mental health information, about you to a family member who is involved in your medical care without consent or authorization. We may also give medical information, including prescription information or information concerning your appointments to other individuals who are involved in your care. We may also give such information to someone who helps pay for your care. In addition, we may disclose medical information about you to an entity assisting in a disaster relief effort so that your family can be notified about your condition, status and location. If law requires specific authorization for such disclosures, we will obtain an authorization from you prior to such disclosures.

As Required By Law:

We will disclose medical information about you when required to do so by federal, state or local law without your consent or authorization.

To Avert a Serious Threat to Health or Safety:

We may disclose medical information about you when necessary to prevent a serious threat to your health and safety or the health and safety of the public or another person. Any disclosure, however, would only be to someone able to help prevent the threat.

To Business Associates:

from time to time will hire consultants called "business associates," who render services to us. We may disclose your medical information to such business associates without your consent or authorization. Business associates are required to maintain and comply with the privacy requirements of state and federal law and keep your medical information confidential. Examples of "business associates" are accounting firms that we hire to perform audits of billing and payment information, and computer software vendors who assist us in maintaining and processing medical information.

Military and Veterans:

If you are a member of the armed forces, we may release medical information about you as required by military command authorities. We may also release medical information about foreign military personnel to the appropriate foreign military authority.

Worker’s Compensation:

We may release medical information about you for workers’ compensation or similar programs without consent or authorization. These programs provide benefits for work-related injuries or illnesses. For example, if you are injured on the job, we may release information regarding that specific injury.

Public Health Risks:

We may disclose medical information about you for public health activities without your consent or authorization. These activities generally include the following:

• to prevent or control disease, injury or disability;

• to report reactions to medications or problems with products;

• to notify people of recalls of products they may be using;

• to notify a person who may have been exposed to a disease or may be at risk for contracting or spreading a disease or condition;

• to notify the appropriate government authority if we believe a individual has been the victim of abuse, neglect or domestic violence. We will only make this disclosure if you agree or when required or authorized by law.

Health Oversight Activities:

We may disclose medical information to a health oversight agency, such as the Department of Health and Human Services, for activities authorized by law. These oversight activities include, for example, audits, investigations, inspections, and licensure. These activities are necessary for the government to monitor the health care system, government programs, and compliance with civil rights laws.

Lawsuits and Administrative Proceedings:

If you are involved in a lawsuit or dispute as a party, we may disclose medical information about you in response to a court or administrative order. We may also disclose medical information about you in response to a subpoena, discovery request, or other lawful process by someone else involved in the dispute. Similarly we may disclose medical information about you in proceedings where you are not a party, but only if efforts have been made to tell you or your attorney about the request or to obtain an order protecting the information requested. In addition, we may disclose medical information, including mental health treatment information, to the opposing party in any lawsuit or administrative proceeding where you have put your physical or mental condition at issue if you have signed a valid release.

Law Enforcement:

We may release medical information if asked to do so by a law enforcement official:

• in response to a court order, subpoena, warrant, summons or similar process;

• to identify or locate a suspect, fugitive, material witness, or missing person;

• about the victim of a crime if, under certain limited circumstances, we are unable to obtain the person’s agreement;

• about a death we believe may be the result of criminal conduct;

• about criminal conduct at ; and

• in emergency circumstances to report a crime; the location of the crime or victims; or the identity, description or location of the person who committed the crime.

Coroners, Medical Examiners and Funeral Directors:

We may release medical information including mental health information to a coroner or medical examiner. This may be necessary, for example, to identify a deceased person or determine the cause of death.

National Security and Intelligence Activities:

We may release medical information about you to authorized federal officials for intelligence, counterintelligence, and other national security activities authorized by law.

Protective Services for the President and Others:

We may disclose medical information about you to authorized federal officials so they may provide protection to the President, other authorized persons or foreign heads of state or conduct special investigations.

Inmates:

If you are an inmate of a correctional institution or under the custody of a law enforcement official, we may release medical information about you to the correctional institution or law enforcement official. This release would be necessary (1) for the institution to provide you with health care; (2) to protect your health and safety or the health and safety of others; or (3) for the safety and security of the correctional institution.

YOUR RIGHTS REGARDING MEDICAL INFORMATION ABOUT YOU.

You or your personal representative have the following rights regarding medical information we maintain about you (when we say "you" this also means your personal representative, which may be your parent or legal guardian or other individual who is authorized to care for you):

Right to Inspect and Copy:

You have the right to inspect and copy medical information that may be used to make decisions about your care. If you wish to be provided a copy of medical information that may be used to make decisions about you, you must submit your request in writing to the Privacy Officer at . If you request a copy of the information, we may charge a reasonable fee for the costs of copying, mailing and or other supplies associated with your request.

We may deny your request to inspect and/or obtain a copy in certain very limited circumstances. If you are denied access to medical information, you may request that the denial be reviewed. Another licensed health care professional chosen by us will review your request and the denial. The person conducting the review will not be the person who denied your request. We will comply with the outcome of the review.

Right to Request an Amendment:

If you feel that medical information we have about you is incorrect or incomplete, you may ask us to amend the information. You have the right to request an amendment for as long as the information is kept by or for us. To request an amendment, your request must be made in writing and submitted to the Privacy Officer at . In addition, you must provide a reason that supports your request.

We may deny your request for an amendment if it is not in writing or does not include a reason to support the request. In addition, we may deny your request if you ask us to amend information that:

• Was not created by us, unless the person or entity that created the information is no longer available to make that amendment;

• Is not part of the medical information kept by us;

• Is not part of the information which you would be permitted to inspect and copy; or

• Is accurate and complete.

Right to an Accounting of Disclosures:

You have the right to request an “accounting of disclosures.” This is a list of some of the disclosures we made of medical information about you.

To request this list or accounting of disclosures, you must submit your request in writing to the Privacy Officer at . Your request must state a time period which may not be longer than six years starting with .Your request will be provided to you on paper. The first list you request within a 12-month period will be free. For additional lists, we may charge you for the costs of providing the list. We will notify you of the cost involved and you may choose to withdraw or modify your request at that time before any costs are incurred.

Right to Request Restrictions:

You have the right to request a restriction or limitation on the medical information we use or disclose about you for treatment, payment or health care operations. You also have the right to request a limit on the medical information we disclose about you to someone who is involved in your care or the payment for your care, like a family member or friend. However, you will need to make alternative arrangements for payment if you restrict access of individuals responsible for the payment of your care.

We are not required to agree to your request. If we do agree, we will comply with your request unless the information is needed to provide you emergency treatment.

To request restrictions, you must make your request in writing to the Privacy Officer at . In your request, you must tell us (1) what information you want to limit; (2) whether you want to limit our use, disclosure or both; and (3) to whom you want the limits to apply, for example, disclosures to your spouse.

Right to Request Confidential Communications:

You have the right to request that we communicate with you about medical matters in a certain way or at a certain location. For example, you can ask that we only contact you at work or by mail.

To request confidential communications, you must make your request in writing to the Privacy Officer at . We will not ask the reason for your request. We will accommodate all reasonable requests. Your request must specify how or where you wish to be contacted.

Right to a Paper Copy of This Notice:

You have the right to a paper copy of this notice. You may ask us to give you a copy of this notice at any time. Even if you have agreed to receive this notice electronically, you are still entitled to a paper copy of this notice.

COMPLAINTS:

If you believe your privacy rights have been violated, you may file a complaint with us or with the Secretary of the Department of Health and Human Services. To file a complaint with us, submit your complaint in writing to the Privacy Officer at . You will not be penalized for filing a complaint.

OTHER USES OF MEDICAL INFORMATION:

Other uses and disclosures of medical information not covered by this notice or the laws that apply to us will be made only with your written permission as set out in an authorization signed by you. If you provide us permission to use or disclose medical information about you, you may revoke that permission, in writing, at any time. If you revoke your permission, we will no longer use or disclose medical information about you for the reasons covered by your written authorization. You understand that we are unable to take back any disclosures we have already made with your permission, and that we are required to retain our records of the care that we provided to you.

Authorized Signature:

Date:

Printed Name:

Title:

Additional Acknowledgements:

Enter text✕

What the Notice of Privacy Practices Is and When It Applies

The Notice of Privacy Practices explains how a covered entity or business associate uses and discloses protected health information (PHI), and describes individuals' rights regarding that information. Under HIPAA, covered entities must make a Notice available to patients, include an effective date, and describe permitted uses (treatment, payment, operations), authorized disclosures, and rights such as access, amendment, and accounting of disclosures. The Notice also names a privacy contact, explains complaint procedures, and describes how to obtain copies or request restrictions on PHI.

Why a Clear Notice Matters for Compliance and Trust

A compliant Notice reduces regulatory risk by documenting PHI practices under HIPAA, informs patients of their statutory rights, and supports transparent handling of sensitive information for audits and patient inquiries.

Why a Clear Notice Matters for Compliance and Trust

Who Prepares and Receives the Notice

Covered entities and business associates prepare Notices to document PHI practices and communicate them to patients, clients, and members.

  • Hospitals and clinics — provide at first visit, post in waiting areas, and supply written copies on request.
  • Health plans and insurers — include Notice with enrollment materials and member communications.
  • Third-party administrators and vendors — distribute Notices when they handle PHI on behalf of a covered entity.

Keep the Notice available at intake, on patient portals, and as part of onboarding for new business relationships to ensure ongoing transparency and compliance.

Core Elements to Include in a Professional Notice

A professional Notice of Privacy Practices groups legal requirements into readable sections so individuals can quickly find rights, uses, contacts, and change history.

Purpose

Explain why PHI is collected and how it supports care, payment, and healthcare operations while noting limited exceptions that permit disclosure without authorization.

Uses & Disclosures

List routine permitted uses (treatment, payment, operations), examples of other disclosures, and any required disclosures such as those for public health or law enforcement.

Individual Rights

Describe rights to access, amend, request an accounting of disclosures, request restrictions, request confidential communications, and obtain a paper copy of the Notice.

Privacy Contact

Provide the name, phone, and mailing address of the person responsible for privacy inquiries and complaints within the covered entity.

Effective Date

State the date the Notice takes effect and explain that it applies to PHI created or received after that date; indicate how patients will be informed of material changes.

Complaint Process

Explain how to file an internal complaint and note the right to file with the HHS Office for Civil Rights if they believe their HIPAA rights were violated.

Required Identification and Contact Details

Covered Entity Name: Full legal entity name used for official notices
Privacy Official: Name and title of the privacy officer or responsible person
Effective Date: MM/DD/YYYY effective date shown on the Notice
Primary Uses: Short list: treatment, payment, healthcare operations
Patient Rights: Access, amendment, accounting, restriction, confidential communications
Contact Info: Phone, mailing address, and email for privacy inquiries

Step-by-Step: Prepare and Deliver the Notice

Follow a concise sequence to draft, approve, publish, and document delivery of the Notice to meet HIPAA expectations and maintain a defensible record.

  • 01
    Gather Requirements: Collect PHI practices, policy owners, and regulatory obligations
  • 02
    Draft Text: Write clear, nontechnical explanations of uses, rights, and contacts
  • 03
    Legal Review: Have counsel or compliance officer review for accuracy and state nuances
  • 04
    Distribute: Provide to patients, post publicly, and retain delivery evidence

How to Configure an Electronic Distribution Workflow

Configure delivery, authentication, and retention settings to ensure Notices are accessible, auditable, and securely stored.

Field Configuration
Delivery Method Email delivery and printed copies at intake
Authentication Email link or SMS code for recipient verification
Acknowledgement Capture signed acknowledgement or checkbox consent
Retention Store signed copies according to retention policy

Typical Routing: Where and How to Provide the Notice

Notices are delivered through multiple channels so individuals can access them in person, online, or during enrollment and treatment interactions.

  • In-Person: Hand copy at first service and collect acknowledgement
  • Mail: Send a paper copy upon request or with enrollment materials
  • Patient Portal: Post Notice and enable download from secure portal
  • Public Posting: Display a copy in reception and common public areas

Technical Requirements for Electronic Notices and eSubmission

Use platforms that support secure delivery, data protection, and audit logging when distributing Notices electronically.

  • Integrations: Salesforce, NetSuite, Google Workspace integrations supported
  • Formats: PDF and DOCX export with audit trail
  • Security: TLS 1.2/1.3 and AES-256 encryption

Ensure any vendor handling PHI signs a BAA, provides role-based access, maintains immutable audit trails, and offers simple export for regulatory review and patient requests.

Timing and Update Expectations for the Notice

Key timing rules govern when to give the Notice, how to handle material changes, and the timelines for responding to related patient requests.

Initial Delivery Requirement:

Provide at first service and upon first delivery of services

Material Changes:

Post revised Notice and distribute when privacy practices materially change

Patient Access:

Respond to access requests per HIPAA timelines (45 CFR §164.524)

Document Versioning:

Record effective date and retain prior versions for audit trail

On-Request Copies:

Provide paper or electronic copies promptly upon request

Common Mistakes When Preparing a Notice

  • Using technical legal jargon that patients cannot easily understand, which undermines informed consent and increases inquiry volume.
  • Failing to include an accurate effective date or to record version history, making it difficult to determine which Notice applied at a given time.
  • Not capturing or retaining signed acknowledgements or electronic delivery receipts, leaving the entity without proof of distribution.
  • Neglecting to obtain a BAA with vendors handling PHI, which exposes the entity to avoidable HIPAA compliance risk.

Key Penalties and Compliance Risks to Watch

HIPAA Civil Penalties: 45 CFR §160.404: $100–$50,000 per violation
HIPAA Criminal Penalties: Up to $250,000 and 10 years imprisonment
Failure to Distribute: State enforcement actions and fines possible
Loss of BAA Protections: Contracts invalidated; increased liability risk
Civil Litigation: Potential patient lawsuits and reputational harm
Data Breach Exposure: Breach notifications and corrective action plans required

Real-World Examples of Notices in Practice

These short examples show how different organizations present Notices to patients and clients while preserving compliance and accessibility.

Fertility Centers of Illinois

A clinic implemented a clear online Notice with a designated privacy contact and effective date.

  • The Notice emphasized access and amendment rights.
  • John Butler, Founder, said the team valued the platform's responsiveness and compliance features when integrating signed acknowledgements into patient records.

Martin Properties

A small real-estate practice posted a tailored Notice at offices and on the client portal.

  • Staff collected acknowledgements at first contact.
  • Tim Martin, Founder, reported that using electronic delivery and stored receipts helped maintain consistent proof of distribution across mobile and in-office workflows.

Who Is Authorized to Approve or Sign the Notice

Privacy Officer

Chief compliance or privacy officer — typically responsible for drafting, approving, and responding to complaints; signs off on Notice language and oversees updates and staff training.

Authorized Representative

Executive or practice owner — legally approves policy adoption, executes BAAs with vendors, and ensures organizational procedures are implemented and documented.

FAQs and Troubleshooting for Notice of Privacy Practices

Answers to common questions about delivery, updates, electronic acknowledgement, and interactions with HIPAA requirements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users