Background
The Health Insurance Portability and Accountability Act (HIPAA), requires patients have the right to be informed about the privacy practices of their health plans and healthcare providers (covered entities”), as well as their privacy rights concerning their personal health information. This fundamental right requires covered entities to develop and distribute a clear, user-friendly Notice of Privacy Practices (NPP).
Notice Requirements and Accessibility
All covered entities, are required to create and provide an NPP. This notice must be comprehensible and in plain language, detailing:
- How the entity may use and disclose protected health information.
- The individual’s rights and how to exercise them.
- The entity’s legal duties regarding the protection of health information.
- Contact information for further inquiries about the entity’s privacy policies.
An NPP must be made available upon request and must be prominently posted and accessible both in the provider’s office and on any website maintained by the entity that provides information about services or benefits. It should be noted that health plans are also required to distribute the notice to new enrollees at enrollment and following any significant changes to the privacy practices.