HHS Releases Model Notices of Privacy Practices
Time 1 Minute Read
Categories: Health Privacy

This week, the Department of Health and Human Services’ Office for Civil Rights (“OCR”), in conjunction with the Office of the National Coordinator for Health Information Technology, released model Notices of Privacy Practices. The notices, which have been developed for use by health care providers and health plans, come in different formats:

  • an 8-page booklet;
  • a 5-page layered notice that summarizes key details on the first page and includes the full content of the booklet on the remaining four pages;
  • a 5-page condensed version of the 8-page booklet; and
  • a 6-page text-only version of the booklet.

The model notices contain the new content requirements set forth in the Omnibus Rule issued in January 2013. OCR provides instructions for using the model notices on its website, and notes that health care providers and health plans can simply input their entity-specific information into the model and then print the notices for distribution or post them on their websites.

View the model notices.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page