Glossary · Health Privacy

Notice of Privacy Practices (NOPP): The HIPAA Form You Sign and What It Actually Does

By Steve Levine · Updated August 21, 2026 · 9 min read

Quick Answer

A Notice of Privacy Practices — NOPP, sometimes written NPP — is the privacy document the HIPAA Privacy Rule requires health plans and most health care providers to hand you, at 45 C.F.R. § 164.520. It has to describe how your protected health information may be used and disclosed, list your rights over it, state the entity's own duties including its duty to tell you after a breach, explain how to complain, and carry an effective date. The signature the front desk asks for is an acknowledgment that you received it — not consent to anything. It matters to class action readers for one reason: HIPAA gives individuals no right to sue, so when health data leaks, plaintiffs' firms quote the NOPP back to the defendant as a promise it made and broke.

On this page

What a Notice of Privacy Practices is

The Notice of Privacy Practices is a creature of one regulation: 45 C.F.R. § 164.520, part of the HIPAA Privacy Rule. It says that an individual has a right to adequate notice of how a covered entity may use and disclose protected health information, and of the rights and duties that attach to that information — and then it spends several thousand words specifying what that notice must contain and how it must be delivered.

Who has to produce one is narrower than most people assume. The obligation falls on covered entities: health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with a covered transaction. That sweeps in essentially every doctor, hospital, dentist, pharmacy, therapist, and insurer you deal with. It does not sweep in the vendors sitting behind them — a billing company, a records-scanning service, or a cloud host is a business associate, bound by contract and by parts of the rules, but it does not issue its own notice to you. And it does not reach companies that hold health information without being in the health care system at all. A period tracker, a fitness wearable, a sleep app, an ad network that infers a condition from your browsing: none of them owe you a NOPP, because HIPAA does not apply to them.

That gap is worth holding onto, because it explains why some of the largest health privacy settlements on this site have nothing to do with HIPAA. The $59.5 million Flo period tracker settlement was built on state wiretap and privacy law, not the Privacy Rule, for exactly this reason.

What has to be in one

Section 164.520(b) sets out required content, and the notice has to be written in plain language. Six blocks do the work.

The header comes first, and the regulation dictates the words. Prominently displayed at the top, the notice must say that it describes how medical information about you may be used and disclosed and how you can get access to this information, and ask you to review it carefully. If you have ever wondered why every one of these forms opens with the same all-caps sentence, that is why — it is quoted from the rule.

Then the uses and disclosures. The notice has to describe, with enough detail for you to understand, the types of uses and disclosures the entity may make for treatment, payment, and health care operations, with at least one example of each. It also has to describe the other purposes for which the entity may use or disclose your information without asking you first — public health reporting, health oversight, judicial proceedings, law enforcement in defined circumstances, and the rest of the permitted list. If a more stringent state or federal law limits any of those, the description has to reflect the stricter rule rather than the federal floor. Separate statements are required for things like appointment reminders, treatment alternatives, and fundraising, and the notice must say that most uses of psychotherapy notes, uses for marketing, and disclosures that amount to a sale of your information require your written authorization, which you can revoke.

Third, your rights. The notice must describe the right to request restrictions on uses and disclosures, including the right added by the HITECH Act to bar a disclosure to your health plan when you pay for the service out of pocket in full; the right to receive confidential communications by alternative means or at an alternative address; the right to inspect and get a copy of your records; the right to request an amendment; the right to an accounting of certain disclosures; and the right to a paper copy of the notice itself, even if you agreed to get it electronically.

Fourth, the entity's own duties — and this is the block that ends up in complaints. The notice has to state that the entity is required by law to maintain the privacy of protected health information, to provide individuals with notice of its legal duties and privacy practices, and to notify affected individuals following a breach of unsecured protected health information. It also has to say that the entity is required to abide by the terms of the notice currently in effect, and, if it reserves the right to change those terms, say so and explain how it will communicate a revision.

Fifth, complaints: a statement that you may complain to the entity and to the Secretary of Health and Human Services if you believe your privacy rights were violated, a brief description of how to file with the entity, and a statement that you will not be retaliated against for filing.

Sixth, a contact — the name or title, and telephone number, of a person or office to reach for more information — and an effective date, which the notice cannot predate.

When you get it, and what signing means

Delivery rules in § 164.520(c) split by who you are dealing with.

A provider with a direct treatment relationship has to give you the notice no later than the date of first service delivery, post it in a clear and prominent location at the site where patients can read it, and keep copies available for you to take. In an emergency treatment situation the notice comes as soon as reasonably practicable afterward. If the entity maintains a website that describes its services or benefits, the notice has to be prominently posted there and available electronically through the site.

Health plans work on a different clock. New enrollees get the notice at enrollment. After that, the plan must notify people covered by it, at least once every three years, that the notice is available and how to get a copy. And when a plan materially revises its notice, it has to get the revised version to covered individuals within 60 days.

Now the part everyone asks about. A direct treatment provider must make a good faith effort to obtain your written acknowledgment that you received the notice, and if it cannot, it documents the effort and the reason. That signature is a receipt. It is not consent to a disclosure, not an authorization, not an arbitration agreement, and not a waiver of any claim. The uses the notice describes for treatment, payment, and operations are ones the Privacy Rule already permits — your signature neither enables nor blocks them. Declining to sign is allowed, is documented, and does not entitle anyone to refuse you care.

What a NOPP does not do

It is easy to read the document as a privacy guarantee. It is closer to a disclosure of how much sharing the law already allows.

It does not narrow the entity's permitted disclosures — it describes them. It does not require your permission for treatment, payment, and operations uses. It does not follow your records to every company that touches them; business associates are governed by their contracts, not by a notice they never issued. It does not apply to health data held outside the health care system. And on its own terms it is not a document you negotiated: the content is set by regulation, the entity has no choice about issuing it, and you were handed it on a clipboard while checking in.

That last point is the whole fight described in the next section.

Why a NOPP shows up in class actions

Start with the obstacle. Federal courts have consistently held that HIPAA creates no private right of action — that the statute regulates entities handling medical information rather than conferring enforceable rights on individuals. The Fifth Circuit said so in Acara v. Banks, 470 F.3d 569 (5th Cir. 2006), affirming dismissal for lack of jurisdiction where the plaintiff's only asserted basis was a HIPAA violation, and other circuits have reached the same result. So when a hospital system is breached and millions of records are exposed, nobody can sue for the HIPAA violation as such.

Plaintiffs' firms route around it. A typical health data breach class action complaint pleads negligence and negligence per se, breach of express contract, breach of implied contract, breach of fiduciary duty or confidence, unjust enrichment, and state consumer protection or medical confidentiality statutes. HIPAA still appears in those counts, but as a borrowed standard of care rather than as the claim itself — the argument being that the Privacy and Security Rules define what reasonable data protection looks like for a health care entity, so falling below them is evidence of negligence.

The Notice of Privacy Practices does something more specific. It supplies the promise. Because the notice is required to state that the entity will maintain the privacy of protected health information, will abide by the terms of the notice currently in effect, and will notify individuals following a breach, complaints quote it back and argue those are express undertakings the entity made to every patient — undertakings that a breach, or a delayed notification, broke. The theory converts a compliance document into contract terms.

Defendants argue the opposite, and their argument is not weak: that a NOPP is a regulatory disclosure the government compels, not a bargained-for agreement supported by consideration; that patients do not read it, negotiate it, or exchange anything for it; and that treating it as a contract is an end run around the very rule that HIPAA gives individuals no private claim. Courts have gone both ways on motions to dismiss, and the outcome tends to turn on the specific wording of the specific notice and on the contract law of the state in play. There is no settled national answer.

You can watch the whole exchange in a live case. The complaint in the Devereux Advanced Behavioral Health data breach class action pleads breach of express contract on the theory that Devereux's Notice of Privacy Practices became part of the agreement for services, and our page on that case sets out the notice-is-a-regulatory-disclosure response a defendant in that posture would be expected to raise. Nothing in that case has been decided, and Devereux has not been found liable for anything.

The notice also turns up in the web tracking wave. When complaints allege that a hospital ran a Meta Pixel or a similar advertising tracker on a patient portal, the NOPP is often quoted for the proposition that the health system told patients it would not use their information for marketing without authorization. Those cases are usually pleaded under state wiretap statutes such as California's CIPA rather than under HIPAA, but the notice is the document that makes the alleged mismatch concrete. Several of the resulting settlements are listed on this site, among them Mount Sinai, Banner Health, Bayhealth and LifeStance.

One more thing worth knowing if you follow these cases: even a well-pleaded complaint has to clear Article III standing, and after TransUnion LLC v. Ramirez, showing that a health record was exposed is not automatically the same as showing a concrete injury. That question has ended more health privacy cases than the contract fight has.

If you think a provider broke its notice

There are two paths, and they do different things.

The first is the entity itself. Every notice has to explain how to complain to the covered entity and has to state that you will not be retaliated against for doing so. It also has to name a contact office. For a records access problem, an amendment request, or a disclosure you think should not have happened, that is usually where to begin.

The second is the HHS Office for Civil Rights, which enforces the Privacy, Security, and Breach Notification Rules. Filing is free, can be done through the OCR complaint portal, and generally must happen within 180 days of when you knew or should have known of the act complained of — OCR can extend that period for good cause. Understand what the process is and is not: OCR can investigate, require corrective action, and impose civil money penalties on the entity, but it does not award you money, and most complaints resolve without a penalty.

State law can go further than federal law, and sometimes does. Some states give patients their own claim for unauthorized disclosure of medical information with statutory damages attached, and state attorneys general have independent authority over HIPAA violations affecting their residents. Whether any of that applies to your situation is a question for a lawyer licensed in your state.

If what brought you here is a letter saying your information was involved in an incident, that is a different track again. A breach notification letter is not a lawsuit, but it is usually what precedes one, and it is also the document that will eventually carry the identifiers a settlement claim form asks for. Our explainer on why you got a class action notice covers what those mailings mean, and the data breach settlement tracker lists the ones currently taking claims.

The February 2026 update, and the rule that was struck down

If you received a fresh Notice of Privacy Practices in late 2025 or early 2026, there is a specific reason.

February 16, 2026 was the compliance date for notice changes flowing from the 2024 federal rulemaking that aligned 42 C.F.R. Part 2 — the separate, stricter confidentiality regulation covering substance use disorder treatment records — with HIPAA. Covered entities that create or receive Part 2 records had to revise their notices to describe how those records may be used and disclosed, including which disclosures need patient consent, to identify the patient rights that attach to Part 2 records, and to state the Part 2 program's duties. A notice that was fully HIPAA-compliant did not automatically satisfy that, because Part 2 is more stringent in places where HIPAA is permissive.

The same February 16, 2026 date originally applied to a second set of notice changes, under the Privacy Rule to Support Reproductive Health Care Privacy that HHS finalized in April 2024. That rule barred certain uses and disclosures of reproductive health information and added an attestation requirement for particular requests. On June 18, 2025, in Purl v. U.S. Department of Health and Human Services, a judge in the U.S. District Court for the Northern District of Texas held the rule unlawful and vacated it nationwide. Reporting on the decision describes the court as severing the Part 2 notice provisions from that vacatur, leaving them in force with their February 2026 date intact, and appeals of the decision were subsequently dropped.

The practical upshot for a reader: notices updated in this cycle should address substance use disorder records, and the reproductive-health attestation framework that was announced in 2024 is not in effect. For anyone reading a notice to see what a provider committed to, the effective date on the last page is the first thing to check — the entity's duty runs to the terms of the notice currently in effect, not to a version you were handed years earlier.

Frequently asked questions

Does signing the form at the front desk mean I agreed to share my records?

No. What you sign is an acknowledgment that you received the notice, and 45 C.F.R. § 164.520(c)(2)(ii) requires a provider with a direct treatment relationship to make a good faith effort to obtain it. It is a receipt, not consent, not an authorization, and not a waiver of anything. The disclosures the notice describes for treatment, payment, and health care operations are permitted by the Privacy Rule itself whether or not you sign. If you decline to sign, the provider documents its good faith effort and the reason the acknowledgment was not obtained, and you still get treated.

Can I sue a provider for violating its Notice of Privacy Practices?

Not under HIPAA itself. Federal courts have held that HIPAA creates no private right of action, so an individual cannot bring a federal claim for a HIPAA violation — the Fifth Circuit said so in Acara v. Banks, 470 F.3d 569 (2006), and other circuits have reached the same conclusion. That is why plaintiffs' firms build health privacy cases on state-law theories instead, and why the notice itself gets quoted as the source of a promise in breach of contract counts. Whether a court will treat a NOPP as a contract is contested and has come out both ways.

What can I actually do if I think a provider broke its privacy notice?

Two routes exist and they do different things. The notice must tell you how to complain to the entity itself and must state that you will not be retaliated against for complaining. You can also file a complaint with the HHS Office for Civil Rights, which is free and generally must be filed within 180 days of when you knew or should have known of the act, a period OCR can extend for good cause. OCR enforcement can produce corrective action and civil money penalties against the entity, but it does not pay money to the person who complained. Whether you have a claim of your own is a question for a lawyer licensed in your state.

Why did my doctor or health plan send me an updated privacy notice in early 2026?

February 16, 2026 was the compliance date for notice changes tied to the 2024 federal rule aligning 42 C.F.R. Part 2, the confidentiality regulation for substance use disorder treatment records, with HIPAA. Covered entities that create or receive Part 2 records had to revise their notices to describe how those records may be used and disclosed, the patient rights that attach to them, and the program's duties. The same February 2026 date originally applied to notice changes under the 2024 Reproductive Health Care Privacy Rule, but a federal court in the Northern District of Texas vacated that rule nationwide on June 18, 2025 while leaving the Part 2 notice provisions in place.

Is a Notice of Privacy Practices the same as a website privacy policy?

No, and the difference matters. A NOPP is a specific document the HIPAA Privacy Rule requires of covered entities, with content dictated by regulation. A website privacy policy is a general disclosure a company writes for itself. A hospital typically has both, and they can say different things — which is exactly the tension in the patient portal tracking cases, where complaints allege the notice promised information would not be used for marketing while advertising trackers were running on the same site.

Does the notice have to say anything about data breaches?

Yes. Since the 2013 Omnibus Rule, the duties section of a Notice of Privacy Practices has to state that the entity is required to notify affected individuals following a breach of unsecured protected health information. That single sentence is doing a lot of work in litigation: it is the promise plaintiffs point to when they argue a delayed breach notification broke an express undertaking rather than merely a regulation.

Does a health app or wearable have to give me a NOPP?

Usually not. HIPAA reaches covered entities — health plans, health care clearinghouses, and providers that transmit health information electronically in connection with covered transactions — plus their business associates. Most period trackers, fitness apps, wearables, and direct-to-consumer health platforms are none of those, so no NOPP is required and the Privacy Rule does not govern what they do with your data. Cases against those companies are built on state wiretap, consumer protection, and common law privacy claims instead.



Sources


More on Health Privacy & Data Breach Claims