News
TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data Breach
Beginnerfront deskpractice managerprovider

Notice of Privacy Practices: What Goes in It?

The handout patients receive explains how your organization uses health information. Here's what it is for.

TL;DR

The Notice tells patients their rights and your privacy practices. Post a summary in the office, give new patients a copy, and keep it current when practices change.

Updated 2026-04-21

The Notice of Privacy Practices (NPP) is not marketing material, it is a patient rights document. It explains how your organization may use and share health information and what choices patients have.

Where patients see it

  • Posted or available in the waiting area.
  • Offered to new patients (often with a signature line that they received it).
  • Updated when your uses of data materially change.

What staff should know

Front desk teams should be able to hand out the Notice and direct questions to the privacy officer. You do not need to memorize every paragraph, you need to know where the current version lives (paper + PDF).

If someone asks "why do I have to sign this?"

Explain simply: "It is how we show you the rules about your information. Signing means you got a copy, not that you gave up your rights." (Phrasing may vary, follow your script.)

Not legal advice. Educational overview only; consult qualified counsel for your situation.