News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach
Beginnerfront deskpractice managerprovider

Notice of Privacy Practices: What Goes in It?

The handout patients receive explains how your organization uses health information. Here's what it is for.

TL;DR

The Notice tells patients their rights and your privacy practices. Post a summary in the office, give new patients a copy, and keep it current when practices change.

Updated 2026-04-21

The Notice of Privacy Practices (NPP) is not marketing material, it is a patient rights document. It explains how your organization may use and share health information and what choices patients have.

Where patients see it

  • Posted or available in the waiting area.
  • Offered to new patients (often with a signature line that they received it).
  • Updated when your uses of data materially change.

What staff should know

Front desk teams should be able to hand out the Notice and direct questions to the privacy officer. You do not need to memorize every paragraph, you need to know where the current version lives (paper + PDF).

If someone asks "why do I have to sign this?"

Explain simply: "It is how we show you the rules about your information. Signing means you got a copy, not that you gave up your rights." (Phrasing may vary, follow your script.)

Not legal advice. Educational overview only; consult qualified counsel for your situation.