HIPAA NPP Generator

Generate a provider notice of privacy practices draft.

For a HIPAA covered healthcare provider, enter your practice details, pick the optional statements that match how you operate, and get a ready-to-review draft based on 45 CFR 164.520 and HHS's February 2026 provider model. Copy or download it, then have counsel review it. Free, private, and no email required.

45 CFR164.520 elements
0data leaves your browser
Livedraft updates as you type

The generator

Build your notice of privacy practices

Fill in your organization and privacy contact, then toggle the optional statements. The notice updates live, and you can copy it or download it when it is ready.
1. Your organization

This generator is designed for a HIPAA covered healthcare provider. The notice must identify the organization and carry an effective date. The practice type tailors the treatment, payment, and operations examples to the selected setting.

2. Privacy contact

A provider notice must name a person or office and telephone number for questions. Enter the contact that will handle notice questions and complaints.

3. Optional statements

Include only descriptions that match how the organization operates. If the provider intends to contact individuals for fundraising, the notice must include the fundraising statement and opt-out right.

The draft always includes a conditional statement for substance use disorder records subject to 42 CFR part 2. That language applies only to the extent your organization has those records and reflects the HHS provider model revised in February 2026.

A current notice addresses one documentation and distribution duty. Staff still need role-relevant procedures and training to handle access, restrictions, confidential communications, complaints, and breach escalation.

This provider-focused draft is based on 45 CFR 164.520(b) and the HHS model notice revised in February 2026, including the conditional Part 2 proceeding statement. Health plans, clearinghouses, correctional institutions, group health plans, organized health care arrangements, and Part 2 programs can have different or additional notice requirements. Nothing you enter is sent anywhere. This template is educational, is not legal advice, and should be reviewed and adapted by qualified counsel before use.

What it does

Six things this NPP generator handles for you

The tool organizes a provider-focused draft around the federal content requirements. The output still needs review for your entity type, actual practices, state law, and any Part 2 program duties.

Rule-mapped

Built on 45 CFR 164.520

The provider-focused draft follows the federal content structure for uses and disclosures, individual rights, covered entity duties, complaints, contact information, and effective date.

Practice-aware

Examples written for your setting

Pick medical, dental, behavioral health, pharmacy, or therapy and the treatment, payment, and operations examples change for the selected provider setting.

Conditional statements

Toggle reminders, fundraising, and HIE

Appointment reminders, fundraising with the required opt-out, and health information exchange participation are switches to align with the provider's reviewed practices.

Current law

February 2026 Part 2 language included

The draft includes the conditional statement for substance use disorder records required by the surviving 2024 NPP amendments and reflected in HHS's February 2026 model.

Copy or download

Take it into your own letterhead

Copy the full notice to your clipboard or download it as a text file, then drop it into your document template and have counsel review it before you post it.

Private by design

Nothing leaves your browser

The notice is assembled entirely on your device. No account, no email, and none of the names or contact details you enter are sent anywhere.

The full picture

The HIPAA notice of privacy practices, explained

What the notice is, which covered entities have duties, the required content and distribution rules, and the Part 2 statement that became required on February 16, 2026.

What the notice of privacy practices actually is

The notice of privacy practices explains, in plain language, how a covered entity may use and disclose protected health information, the individual's rights, the covered entity's duties, and how to ask questions or complain. Section 164.520 specifies a required header, content elements, revision rules, and distribution methods. A covered entity must abide by the terms of the notice currently in effect.

The notice should describe the organization's actual practices without omitting required content or promising limits the organization cannot follow. Review its statements and contact details when practices or applicable law change, and keep the current version available through the delivery channels that apply to the entity.

Who must provide one, and which exceptions matter

Section 164.520 generally covers healthcare providers, health plans, and healthcare clearinghouses that are covered entities. A covered provider with a direct treatment relationship must provide the notice no later than first service delivery, subject to the emergency rule, make a good-faith effort to obtain acknowledgment, and satisfy applicable physical-site and website posting duties. Health plans have their own enrollment, revision, and three-year reminder rules.

The rule also includes exceptions and reduced duties. A healthcare clearinghouse whose only PHI is received as a business associate is excepted. A fully insured group health plan may have reduced or no notice duties depending on the PHI it creates or receives. Inmates do not have a right to notice from a covered correctional institution. Business associates generally do not issue an NPP solely because of their business associate role. This generator is designed for covered healthcare providers. Health plans, clearinghouses, group health plans, correctional institutions, organized healthcare arrangements, and Part 2 programs need entity-specific review.

The content the rule requires, element by element

The notice must contain this statement as a header or otherwise display it prominently: THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. The generator uses that required statement without alteration.

From there, the notice must describe how the organization may use and disclose protected health information for treatment, payment, and health care operations, with at least one example for each purpose. It must also describe other purposes for which the Privacy Rule permits or requires use or disclosure without authorization in enough detail to put the reader on notice. More protective law, including 42 CFR part 2 when applicable, must be reflected. The generator tailors treatment, payment, and operations examples to the selected provider setting, but counsel should confirm that every description matches the provider's actual practices and applicable law.

The 2013 Omnibus changes require the notice to state that most uses and disclosures of psychotherapy notes, uses and disclosures for marketing, and disclosures that amount to a sale of protected health information will occur only with written authorization. The covered entity's duties section must state that affected individuals will be notified following a breach of unsecured PHI. The rights section must describe the restriction that applies when an individual pays for a service in full out of pocket and asks that the information not be disclosed to a health plan for payment or healthcare operations, unless disclosure is required by law.

Current notices also need the surviving Part 2-related changes that became mandatory on February 16, 2026. The notice must state that, to the extent the covered entity has substance use disorder records subject to 42 CFR part 2, those records or testimony about them will not be used or disclosed in a civil, criminal, administrative, or legislative investigation or proceeding against the individual without written consent or the court-order process specified by Part 2. The generator includes that statement conditionally in its wording, following the HHS provider model revised in February 2026.

HHS also confirms that a federal court's June 18, 2025 order vacated the separate reproductive-health, attestation, and redisclosure NPP provisions formerly codified at 45 CFR 164.520(b)(1)(ii)(F), (G), and (H). This generator does not present those vacated provisions as current requirements. Review the current HHS fact sheet and the February 2026 HHS provider model before finalizing a notice.

The rights section must explain that individuals can inspect and copy their records, request amendments, receive an accounting of certain disclosures, request restrictions, request confidential communications, and obtain a paper copy of the notice on demand. The notice must describe the organization's legal duties, explain that it reserves the right to change its terms and how patients will learn of changes, tell patients how to complain both to the organization and to the Secretary of Health and Human Services with an assurance of no retaliation, name a contact person or office with a phone number, and carry an effective date. A fundraising statement is required if the entity intends to contact individuals for fundraising, including the right to opt out. The generator also offers optional practice-specific statements for reminders and electronic exchange.

Delivery, posting, and the acknowledgment signature

A direct-treatment provider must give the notice to each individual no later than the first service delivery, which in an emergency means as soon as reasonably practicable afterward. The full notice must be posted in a clear and prominent location at a physical service-delivery site and available there on request. A covered entity that maintains a website with information about customer services or benefits must prominently post the notice and make it available electronically. For a first service delivered electronically, the provider must provide electronic notice automatically and contemporaneously in response to the first request for service. Individuals retain the right to a paper copy.

Direct-treatment providers must make a good faith effort to obtain the patient's written acknowledgment that the notice was received, and when they cannot, they document the effort and the reason. A patient who declines to sign can still receive treatment. The acknowledgment is not a consent form; the patient is confirming receipt, not agreeing to the notice. Keep the signed acknowledgments, or the documentation of the attempts, for six years, the same retention period that applies to the notice itself and to your other HIPAA documentation.

When practices materially change their privacy practices, the notice must be revised first, because the organization may not implement a material change before the effective date of the notice that describes it. Providers then post the revised notice and make it available on request; they do not need to mail it to every past patient. Health plans have different website, annual-mailing, and distribution rules for material revisions.

How to review an older notice

An older notice should be compared element by element with the current rule and the organization's practices. Check the required header, uses and disclosures, rights, duties, complaint and contact information, effective date, the 2013 Omnibus changes, and the Part 2 statement required as of February 16, 2026. An old effective date alone does not prove a defect, and a new date alone does not make a notice accurate.

When a revision is needed, have counsel confirm the federal and state-law language, use an effective date that is not earlier than publication, update each required posting and distribution channel, retain the prior and revised notices, and brief the staff responsible for acknowledgments and individual-rights requests.

Notice, privacy policy, consent: three documents, three jobs

The notice of privacy practices has a different job from two neighboring documents. A website privacy policy describes what data a site collects from visitors, cookies included, and is governed by consumer protection and state privacy law, not by 45 CFR 164.520. A patient can be covered by both documents at once, and neither substitutes for the other; a healthcare website may also need a privacy policy under other applicable laws. Consent and authorization forms are different again. Treatment, payment, and operations require no signed permission under HIPAA, which is precisely what the notice explains. Written authorization is reserved for the uses the rule fences off, such as most marketing, sale of information, and most disclosures of psychotherapy notes. The notice describes the boundary; the authorization form is how a patient crosses it for a specific purpose.

State law sits on top of all of this. Several states require additional disclosures, shorter response deadlines for record requests, or stronger protections for categories like mental health, substance use, HIV, and genetic information, and federal rules at 42 CFR Part 2 add another layer for substance use disorder records. More stringent state privacy requirements can apply alongside HIPAA. That is one reason the draft should pass through counsel: this tool does not determine which federal or state requirements govern the organization.

Connect the notice to operational workflows

Each right described in the notice needs an operational workflow. Records access requires intake, identity verification, review, response, and fee controls. A self-pay restriction needs coordination between clinical and billing systems. Breach notification duties need an escalation path that reaches the people responsible for incident analysis and notice.

Generate the notice, have counsel adapt it, and train workforce members on the tasks that apply to their roles. USA HIPAA courses include a graded assessment and issue a dated certificate after a passing score. Organization plans provide seat management and completion records for team training. Training supports these workflows but does not replace policies, safeguards, legal review, or full compliance.

NPP FAQ

Common questions about the notice of privacy practices

Is this notice of privacy practices generator free?

Yes. The generator is completely free, runs entirely in your browser, and needs no account or email. Enter your organization details, toggle the statements that apply, and the notice is assembled instantly. You can copy it or download it as a text file. Nothing you type leaves your device.

What is a HIPAA notice of privacy practices?

The notice of privacy practices, often shortened to NPP, is a plain-language document that describes permitted uses and disclosures of protected health information, individual rights, the covered entity's duties, and complaint options. Section 164.520 sets content and distribution requirements. A covered healthcare provider with a direct treatment relationship generally provides it no later than first service delivery, subject to the emergency rule.

Who is required to have a notice of privacy practices?

Section 164.520 generally applies to covered healthcare providers, health plans, and healthcare clearinghouses, but the rule contains important qualifications. Direct-treatment providers have specific first-service, posting, and acknowledgment duties. Fully insured group health plans can have reduced or no notice duties depending on the PHI they receive. A clearinghouse whose only PHI is received as a business associate is excepted, and inmates do not have a right to notice from a covered correctional institution. This generator is designed for covered healthcare providers, not every covered entity type.

What must the notice contain?

The rule requires a specified header, examples for treatment, payment, and healthcare operations, descriptions of other permitted or required disclosures, authorization statements, individual rights, covered entity duties, complaint instructions, a contact, and an effective date. As of February 16, 2026, covered entities also must include the applicable statement about Part 2 substance use disorder records in investigations or proceedings. This generator is a provider-focused starting point and does not guarantee that the output addresses your entity type, state law, Part 2 program status, or actual practices.

Do patients have to sign the notice?

The signature is an acknowledgment of receipt, not agreement to the notice. Except in an emergency, a covered healthcare provider with a direct treatment relationship must make a good-faith effort to obtain written acknowledgment. If it is not obtained, document the effort and the reason. Retain the acknowledgment or documentation for six years. Counsel should review the acknowledgment workflow and any separate consent forms.

How often does the notice need to be updated?

Section 164.520 requires prompt revision and distribution when there is a material change to described uses, disclosures, rights, legal duties, or privacy practices. Review older notices against current requirements rather than assuming their date alone makes them deficient. In particular, confirm the 2013 Omnibus content and the surviving Part 2-related NPP changes required by February 16, 2026. Health plans have separate notice and reminder rules.

A posted notice is the start, not the finish. Back it up with HIPAA certification or plan a team rollout for your whole practice.

Paper plus people

Training helps staff carry out the notice.

Access requests, restrictions, confidential communications, and incident escalation all need role-relevant procedures. Train your team with a course that includes a graded assessment and produces dated certificates after a passing score. Keep those records with the policies behind your notice.