Skip to content

Privacy Practices Guide

Reviewed by Jack Forbush, DO · last verified 2026-09-22 · what this means

Overview

Privacy practices are fundamental to healthcare compliance and patient trust. This guide covers implementing privacy protections in your DPC practice, from policies to daily operations.

Caution

Consult Compliance Professionals: Privacy requirements under HIPAA and state laws are complex and carry significant penalties for violations. While this guide provides practical orientation, consider consulting a healthcare compliance specialist for your initial policy development and Notice of Privacy Practices. State-specific requirements may also apply.

Prerequisites

  • Understanding of HIPAA basics (see HIPAA Compliance Basics)
  • Business entity established
  • Basic understanding of your practice workflows

Starting Lean: Privacy by Stage

Stage 1: Just Starting (0-25 Patients)

Essential privacy measures: - Notice of Privacy Practices (NPP) - Basic access controls (passwords, locks) - Secure communication method - HIPAA-compliant storage

Reality: Simple practices need simple privacy measures. Don't overcomplicate.


Stage 2: Growing (25-75 Patients)

Add: - Formal privacy policies - Staff training (if applicable) - Audit procedures - Incident response plan


Stage 3: Established (75+ Patients)

Systematize: - Regular privacy audits - Documented training programs - Vendor management - Ongoing compliance monitoring


Notice of Privacy Practices (NPP)

What It Is

A document explaining how you use and protect patient health information. HIPAA requires it of every covered entity (45 CFR 164.520). Whether a cash-only DPC practice is a covered entity depends on whether it sends HIPAA standard electronic transactions—see Are You a Covered Entity?. Provide an NPP either way: patients and vendors expect it, state law may require similar notice, and it costs little.

Required Content

Your NPP must include (45 CFR 164.520(b)(1)): - The header sentence, verbatim: "THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY." - How you use and disclose PHI for treatment, payment and operations, with at least one example of each, and each other purpose permitted or required without authorization - A statement that any other use or disclosure will be made only with the patient's written authorization, and that the patient may revoke it - If you create, receive or maintain substance use disorder treatment records subject to 42 CFR Part 2: the Part 2 statements required since 2026-02-16, including that those records will not be used or disclosed in civil, criminal, administrative or legislative proceedings against the patient without written consent or a court order - Patient rights regarding their information (listed below) - Your duties: to protect PHI, to abide by the current notice, and to notify affected patients after a breach of unsecured PHI - How to file a complaint with you and with HHS, and that there will be no retaliation - The name or title and telephone number of the person to contact for more information - Effective date

Start from the HHS model notices for health care providers (2026). Do not copy the reproductive-health statements at 164.520(b)(1)(ii)(F)–(H) that eCFR still prints; that rule was vacated in Purl v. HHS (2025) and those paragraphs are void.

Patient Rights to Include

  1. Right to access - Review and obtain copies of their records
  2. Right to amend - Request corrections to their records
  3. Right to accounting - Know who you've disclosed PHI to
  4. Right to restrict - Request limits on uses/disclosures. You are not required to agree, except that you must honor a request not to disclose an item or service to a health plan when the patient paid for it in full out of pocket (164.522(a)(1)(vi))
  5. Right to confidential communications - Request alternative contact methods
  6. Right to a paper copy - Receive paper NPP on request

Distribution Requirements

When to provide: - No later than the date of first service delivery for new patients; in an emergency, as soon as reasonably practicable afterward. If the first service is delivered electronically, such as a telehealth visit, send the notice electronically at the same time (164.520©(2)(i)) - When requested - After a material change: revise the notice promptly, make the revised notice available on request and at your office, and re-post it. You are not required to mail or hand the revised notice to existing patients (164.520(b)(3), ©(2)(iv))

How to provide: - Give paper copy at enrollment - At any physical service site, keep copies available for patients to take and post the notice in a clear and prominent location. This is required, not optional (164.520©(2)(iii)) - Post on your website if the site describes your services or benefits (164.520©(3)(i)) - Obtain acknowledgment signature

Sample NPP Acknowledgment

I acknowledge that I have received a copy of [Practice Name]'s Notice of Privacy Practices, which describes how my health information may be used and disclosed and how I can access this information.

Signature: ___________________ Date: ___________

If patient refuses to sign: [ ] Patient refused to sign acknowledgment Staff initials: _____ Date: _____


Privacy Policies

Core Policies Needed

1. Minimum Necessary Standard - Access only the PHI needed for the task - Don't browse records unnecessarily - Limit disclosures to what's required

2. Access Control Policy - Who can access what information - Password requirements - Physical access to records

3. Disclosure Policy - When PHI can be disclosed without authorization - When authorization is required - How to document disclosures

4. Patient Rights Policy - How to handle access requests - Amendment request procedures - Complaint procedures

5. Breach Response Policy - How to identify breaches - Notification procedures - Documentation requirements


Physical Privacy Protections

Office Space

Reception/waiting area: - Sign-in sheets that don't reveal reason for visit - Conversations not overheard by waiting patients - Computer screens not visible to patients

Exam rooms: - Doors close fully - Conversations not overheard - Charts not visible through windows

Work areas: - Screens positioned away from patient view - Papers face-down when not in use - Secure storage for records

Paper Records

If using paper records: - Locked file cabinets - Access limited to authorized personnel - Secure disposal (shredding) - No records left unattended

Mail and Fax

Mail: - Secure mailbox - Prompt retrieval - Consider PO Box for practice

Fax (if used): - Cover sheets with confidentiality notice - Confirm fax numbers before sending - Machine in secure location - Prompt retrieval of received faxes


Electronic Privacy Protections

Computer Security

Basic requirements: - Strong, unique passwords - Automatic screen lock (2-5 minutes) - Encrypted storage - Automatic logoff - Antivirus/antimalware - Regular updates

Email

For patient communication: - Encrypted email service, OR - Patient consent to unencrypted (with understanding of risks) - No PHI in subject lines - Verify recipient before sending

Mobile Devices

If using phones/tablets: - Password/biometric lock - Remote wipe capability - Encrypted storage - Avoid storing PHI on personal devices - HIPAA-compliant apps only

Cloud Storage

Requirements: - BAA with provider - Encryption in transit and at rest - Access controls - Audit logging


Patient Communication Privacy

Phone Calls

Best practices: - Verify patient identity before discussing PHI - Be aware of surroundings when calling - Leave minimal information in voicemails - Document patient's communication preferences

Sample voicemail:

"This is [Your Name] from [Practice Name] calling for [Patient Name]. Please call us back at [number] at your convenience."

(Don't leave specific health information in voicemails unless patient has consented.)

Text Messages

If texting patients: - Get consent for text communication - Understand risks of texting PHI - Use minimal PHI (appointment reminders OK) - Consider HIPAA-compliant texting platforms

Patient Portal

Privacy features: - Secure login required - Encrypted transmission - Audit trails - Timeout settings


Handling Patient Requests

Access Requests

When patients want their records:

  1. Accept request (written preferred)
  2. Verify identity
  3. Provide within 30 days (one 30-day extension allowed)
  4. Provide in requested format if feasible
  5. May charge a reasonable, cost-based fee covering only labor for copying, supplies, postage, and preparing a summary if the patient agreed to one (164.524©(4)). HHS's optional $6.50 flat fee for electronic copies is a safe harbor, not a cap
  6. Document request and response

What to provide: - Medical records - Billing records - Any PHI you maintain

Exceptions (can deny): - Psychotherapy notes - Information compiled for legal proceedings - Certain research information - Information a licensed professional determines is reasonably likely to endanger the life or physical safety of the patient or another person. This denial is reviewable: the patient may have it reviewed by a different licensed professional (164.524(a)(3)-(4))

Amendment Requests

When patients want corrections:

  1. Accept written request
  2. Respond within 60 days (one 30-day extension allowed if you give the patient written notice of the reason and the expected date, 164.526(b)(2))
  3. If granting: make amendment, inform patient, notify others who received incorrect info
  4. If denying: provide written denial with reason, and tell the patient they may file a statement of disagreement and a complaint with you and with HHS (164.526(d)). There is no appeal

Can deny if: - Information is accurate - You didn't create the record (unless the patient shows the originator is no longer available to act on the request) - Information not part of designated record set

Restriction Requests

Patients can request restrictions on uses/disclosures.

  • You're not required to agree (with one exception)
  • Must agree if patient pays out of pocket in full and requests you not disclose to their health plan
  • If you agree to any restriction, you must honor it
  • Document all requests and your response

Disclosures Without Authorization

When Authorization NOT Required

Treatment, Payment, Healthcare Operations (TPO): - Sharing with consultants/specialists for treatment - Billing (if applicable) - Quality improvement activities

Required by law: - Public health reporting - Abuse/neglect reporting - Court orders

Other permitted purposes: - Health and safety threats - Organ donation - Workers' compensation - Law enforcement (limited circumstances)

When Authorization IS Required

  • Marketing
  • Sale of PHI
  • Most research
  • Psychotherapy notes
  • Anything not otherwise permitted

Workforce Training

Solo Practice

Even if you're the only "workforce member," document your own training: - Initial HIPAA training (self-study counts) - Periodic review (annual is best practice, not a rule) - Updates when policies change

With Staff

Training requirements (164.530(b)): - All workforce members trained - Training within a reasonable time after hire - Retraining within a reasonable time after a material change in policies that affects their work - Periodic refreshers (annual is best practice, not a rule) - Document all training

Training topics: - Privacy basics - Your practice policies - Patient rights - Breach identification and reporting - Sanctions for violations


Documentation Requirements

What to Document

  • Notice of Privacy Practices (and acknowledgments)
  • Privacy policies
  • Training records
  • Patient requests and your responses
  • Disclosures (accounting of disclosures)
  • Complaints and resolutions
  • Incidents and responses

Retention

  • Retain HIPAA compliance documentation (policies, NPP versions, training records, requests and responses) for 6 years from the later of creation or the date last in effect (164.530(j)). This is not a chart-retention rule: how long you keep medical records is set by state law and your medical board
  • Longer if state law requires
  • Secure storage and disposal

Common Privacy Scenarios

Scenario 1: Family Member Asks for Information

Situation: Spouse calls asking about patient's test results.

Response: Written authorization is not required. Under 45 CFR 164.510(b) you may share information with a family member or friend involved in the patient's care if the patient agrees, or was given the chance to object and did not, or if your professional judgment reasonably infers the patient would not object. If the patient is not present, use professional judgment about whether sharing is in the patient's best interest, and share only what is directly relevant to that person's involvement.

  • Verify the caller's identity
  • Check the patient's documented preferences: has the patient named the spouse as involved in their care, or asked you not to share with them?
  • If sharing is appropriate, share only what is relevant to the spouse's involvement
  • If the patient has objected, or you have no basis to infer agreement: "I'm not able to discuss that without [patient]'s okay. Please have [patient] call us, or we can talk when [patient] is with you."
  • Document what you shared and why

Scenario 2: Employer Requests Records

Situation: Employer calls asking if employee was seen.

Response: - Don't confirm or deny patient relationship without authorization - "We cannot release patient information without authorization. Please have your employee contact us if they wish to release information."

Scenario 3: Law Enforcement Request

Situation: Police officer asks about a patient.

Response: - Don't automatically disclose - Ask for written request or court order - Consult attorney if unsure - Limited exceptions for emergencies

Scenario 4: Patient Wants Records Sent to Attorney

Situation: Patient asks you to send records to their lawyer.

Response: Two routes, and the choice affects what you may charge.

  • Patient-signed access request directing a copy to the attorney: this is the patient's own right of access (164.524©(3)(ii)). Send it within 30 days, and the access-fee limits above apply (cost-based labor, supplies, postage)
  • HIPAA authorization signed by the patient: verify it is valid and send only what it covers. Fees under an authorization are governed by state law, not the HIPAA access-fee limits

Checklist: Privacy Practices

Documents

  • Notice of Privacy Practices created
  • NPP acknowledgment form ready
  • Privacy policies documented
  • Authorization form available
  • Access request form available

Physical Safeguards

  • Secure storage for records
  • Computer screens positioned appropriately
  • Conversations can be private
  • Secure disposal method in place

Electronic Safeguards

  • Password protection on all systems
  • Encryption for electronic PHI
  • Automatic screen lock enabled
  • BAAs with electronic service providers

Ongoing

  • Training documented
  • Patient requests tracked
  • Disclosures logged
  • Regular policy review scheduled

Resources

Sources checked against primary law and agency guidance on 2026-09-22.


Next Steps

After establishing privacy practices: - BAA Requirements - Vendor management - Incident Response Plan - Preparing for problems