Purpose
Explain why PHI is collected and how it supports care, payment, and healthcare operations while noting limited exceptions that permit disclosure without authorization.
A compliant Notice reduces regulatory risk by documenting PHI practices under HIPAA, informs patients of their statutory rights, and supports transparent handling of sensitive information for audits and patient inquiries.
Covered entities and business associates prepare Notices to document PHI practices and communicate them to patients, clients, and members.
Keep the Notice available at intake, on patient portals, and as part of onboarding for new business relationships to ensure ongoing transparency and compliance.
Explain why PHI is collected and how it supports care, payment, and healthcare operations while noting limited exceptions that permit disclosure without authorization.
List routine permitted uses (treatment, payment, operations), examples of other disclosures, and any required disclosures such as those for public health or law enforcement.
Describe rights to access, amend, request an accounting of disclosures, request restrictions, request confidential communications, and obtain a paper copy of the Notice.
Provide the name, phone, and mailing address of the person responsible for privacy inquiries and complaints within the covered entity.
State the date the Notice takes effect and explain that it applies to PHI created or received after that date; indicate how patients will be informed of material changes.
Explain how to file an internal complaint and note the right to file with the HHS Office for Civil Rights if they believe their HIPAA rights were violated.
| Field | Configuration |
|---|---|
| Delivery Method | Email delivery and printed copies at intake |
| Authentication | Email link or SMS code for recipient verification |
| Acknowledgement | Capture signed acknowledgement or checkbox consent |
| Retention | Store signed copies according to retention policy |
Use platforms that support secure delivery, data protection, and audit logging when distributing Notices electronically.
Ensure any vendor handling PHI signs a BAA, provides role-based access, maintains immutable audit trails, and offers simple export for regulatory review and patient requests.
Provide at first service and upon first delivery of services
Post revised Notice and distribute when privacy practices materially change
Respond to access requests per HIPAA timelines (45 CFR §164.524)
Record effective date and retain prior versions for audit trail
Provide paper or electronic copies promptly upon request
A clinic implemented a clear online Notice with a designated privacy contact and effective date.
A small real-estate practice posted a tailored Notice at offices and on the client portal.
Chief compliance or privacy officer — typically responsible for drafting, approving, and responding to complaints; signs off on Notice language and oversees updates and staff training.
Executive or practice owner — legally approves policy adoption, executes BAAs with vendors, and ensures organizational procedures are implemented and documented.