A material change to uses, disclosures, individual rights, or plan duties requires a revised NPP distributed within 60 days.
At least once every 3 years, remind covered individuals that the NPP is available and how to obtain a copy.
| Trigger | Timing | Notes |
|---|---|---|
| NPP to new enrollees | At time of enrollment | Provide to individuals covered by the plan when they enroll. |
| NPP after a material revision | Within 60 days of the material change | A material change to uses, disclosures, individual rights, or the plan's duties requires a revised NPP. |
| Three-year availability reminder | At least once every 3 years | Notify covered individuals that the NPP is available and how to obtain a copy. |
| NPP on request | Promptly, on demand | Any individual may request a copy at any time. If the plan maintains a website, the current NPP must be posted there. |
| BAA before vendor access | Before PHI is shared | A signed BAA must be in place before a business associate handles the plan's PHI. |
- Funding and PHI assessment: Confirm whether the plan is self-insured or fully insured, and how much PHI the plan sponsor actually creates or receives; this determines whether the hands-off exception applies.
- NPP content elements: How the plan uses and discloses PHI (treatment, payment, health-care operations, and other permitted disclosures); individuals' rights (access, amendment, accounting of disclosures, request restrictions, confidential communications); the plan's legal duties; how to complain; a contact; and the effective date.
- Vendor inventory: A list of every vendor that touches plan PHI: TPA/claims administrator, PBM, COBRA administrator, FSA/HRA administrator, wellness vendor, brokers/consultants that receive PHI, and IT/cloud providers that store it.
- BAA templates: Each BAA must contain the provisions required by 45 CFR 164.504(e) (permitted uses, safeguards, breach reporting, subcontractor flow-down, return/destruction at termination). Most vendors provide their own; review for the required terms and adequate breach-notification timing.
- Plan-document privacy language: For self-insured plans, plan-document provisions describing the permitted disclosures of PHI to the plan sponsor and the certifications required under 45 CFR 164.504(f).
- Paper or electronic: The NPP may be delivered on paper or, if the individual agrees to electronic delivery, by email. A health plan that maintains a website providing information about benefits must post the current NPP there.
- To whom: The plan must provide the NPP to the named insured/covered participant; it is not required to send a separate copy to each dependent.
- Three-year reminder: Rather than redistributing the full NPP, the plan may simply notify individuals that the NPP is available and explain how to obtain a copy, at least once every three years.
- Revisions: When a material change is made, distribute the revised NPP (or information about the change and how to get the revised notice) within 60 days.
- NPP versions and distributionEach version of the NPP, with its effective date, and records of when and how it was distributed (enrollment packets, revision mailings, three-year reminders, website postings).
- Signed BAAsSigned BAAs for every business associate, plus any subcontractor flow-down agreements provided by the BA.
- Inventory and certificationsYour vendor/PHI inventory and the plan-document privacy provisions and sponsor certifications (self-insured plans).
- Policies and requestsPrivacy policies and procedures and any individual-rights requests received and how they were handled.
- RetentionAt least 6 years from creation or last effective date, HIPAA's general documentation standard.
Common traps
FAQs
What is a business associate, and who are mine?
A person or entity that creates, receives, maintains, or transmits PHI to perform a function on the plan's behalf. Common examples for a health plan: the TPA/claims administrator, PBM, COBRA administrator, FSA/HRA administrator, wellness program vendor, brokers/consultants that receive PHI, and IT/cloud vendors storing PHI.
We're fully insured, do we need our own NPP?
Generally no, if the plan sponsor receives only summary health information and enrollment/disenrollment data. The insurer maintains and distributes the NPP. If the sponsor handles more PHI than that, the plan must maintain and distribute its own NPP and follow the full privacy rules.
Did the 2024 reproductive-health HIPAA changes affect our NPP?
The 2024 rule's reproductive-health provisions, including the related NPP changes, were vacated nationwide by a federal court in Purl v. HHS (June 2025), so those specific NPP modifications are not in effect. Separately, NPP content updates tied to the 2024 Part 2 rule on substance-use-disorder confidentiality carry a compliance date of February 16, 2026. Because this area is in flux, confirm current HHS guidance before finalizing your NPP.
What are the penalties?
Civil monetary penalties under HIPAA/HITECH are tiered by culpability, with annual caps per violation category; OCR corrective action plans are common. Disclosing PHI to a vendor without a BAA, or failing to provide the NPP, are each enforceable Privacy Rule violations.
How does this relate to breach notification?
They're connected: your BAAs should require business associates to report breaches to the plan quickly enough to meet your own 60-day notification deadlines. See the HIPAA Breach Notification page for the response process.
- 45 CFR 164.520: the NPP requirement, including content and distribution rules.
- HHS: HIPAA Privacy Rule: the overarching rule governing PHI use, disclosure, and individual rights.
- HHS: HIPAA and Reproductive Health: current status of the reproductive-health rule following the 2025 court vacatur.
- Fully-insured "hands-off" plans: If the sponsor receives only summary and enrollment data, the carrier handles the NPP and most privacy policies; the sponsor still may not use that data for employment purposes.
- Self-insured and level-funded plans: Full obligations apply: NPP, distribution timing, privacy policies, plan-document amendments authorizing PHI disclosure to the sponsor, and BAAs with all PHI-handling vendors.
- Account-based plans (health FSA, HRA): These are typically covered entities subject to the Privacy Rule. If administered by a vendor, a BAA is required; if administered in-house, the sponsor handles PHI and full obligations apply.
- Subcontractors: A business associate's subcontractors that handle PHI must themselves be bound by BAA terms (flow-down). Confirm your BAAs require this.
- State privacy laws: Some states impose additional health-privacy or data-breach requirements that can apply alongside HIPAA. Check state law where your participants reside.
HHS publishes a model Notice of Privacy Practices and the required BAA provisions; start from these and tailor them to your plan rather than drafting from scratch.
- HHS Model Notices of Privacy Practices: customizable NPP templates (full and summary versions) from HHS/OCR.
- HHS Sample Business Associate Agreement Provisions: the contract language a compliant BAA must contain; use it to draft or to check a vendor's BAA.
- HHS Business Associates guidance: who qualifies as a business associate and what the relationship requires.
Vendor BAA / PHI inventory check (drop-in language); send to any vendor that may touch plan PHI: