Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Model Notices of Privacy Practices

The HIPAA Privacy Rule requires health plans and covered health care providers to develop and distribute a notice that provides a clear, user friendly explanation of individuals’ rights with respect to their personal health information and the privacy practices of health plans and health care providers.

As of February 16, 2026, these HIPAA covered entities are required to include information about substance use disorder (SUD) patient records (described in 42 U.S.C. 290dd-2(a) and 42 CFR part 2 (“Part 2”)) in their Notice of Privacy Practices (NPP). Additionally, federally assisted SUD treatment programs are required to provide a new patient notice by February 16, 2026, that is aligned more closely with the HIPAA NPP.

Part 2 programs that are also Covered Entities under HIPAA are allowed to create a combined notice that meets the requirements of both the HIPAA NPP and the Part 2 Privacy Notice.

HIPAA Privacy Rule and the Notice Requirements

Part 2 Final Rule and Requirements

Revised February 2026 Model Notices of Privacy Practices (NPPs)

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.