HIPAA Privacy Notice (NPP & BAAs)

Covered group health plans must maintain and distribute a Notice of Privacy Practices and put a Business Associate Agreement in place with every vendor that handles PHI.

Heads up, who this actually applies to: A fully-insured plan whose sponsor creates or receives only (1) summary health information for limited purposes and (2) enrollment/disenrollment data falls under the "hands-off" exception: the carrier handles the NPP and the full privacy policies, and the plan sponsor is not required to maintain or distribute its own NPP. Self-insured and level-funded plans (and fully-insured plans whose sponsor touches more PHI than that) must maintain their own NPP, distribute it on schedule, and execute BAAs. Confirm your funding and how much PHI you handle before deciding this doesn't apply.
What Two related Privacy Rule duties: maintain and distribute a Notice of Privacy Practices (NPP), and execute Business Associate Agreements (BAAs) with vendors that create, receive, maintain, or transmit PHI for the plan.
Who Group health plans that are covered entities. Self-insured and level-funded plans carry the full obligation. Fully-insured plans whose sponsor handles only summary and enrollment data are largely exempt (the carrier handles the NPP).
When NPP must be provided at enrollment, within 60 days of a material revision, and, at least once every three years, the plan must remind individuals the NPP is available and how to get it. A BAA must be signed before a vendor handles PHI.
Risk Disclosing PHI to a vendor without a BAA, or failing to maintain/distribute the NPP, is itself a Privacy Rule violation. Civil monetary penalties are tiered by culpability, with OCR corrective action plans a common outcome.
60
Days after a material revision

A material change to uses, disclosures, individual rights, or plan duties requires a revised NPP distributed within 60 days.

3
Years, availability reminder

At least once every 3 years, remind covered individuals that the NPP is available and how to obtain a copy.

Trigger Timing Notes
NPP to new enrollees At time of enrollment Provide to individuals covered by the plan when they enroll.
NPP after a material revision Within 60 days of the material change A material change to uses, disclosures, individual rights, or the plan's duties requires a revised NPP.
Three-year availability reminder At least once every 3 years Notify covered individuals that the NPP is available and how to obtain a copy.
NPP on request Promptly, on demand Any individual may request a copy at any time. If the plan maintains a website, the current NPP must be posted there.
BAA before vendor access Before PHI is shared A signed BAA must be in place before a business associate handles the plan's PHI.
Trigger: NPP to new enrollees
Timing: At time of enrollment
Notes: Provide to individuals covered by the plan when they enroll.
Trigger: NPP after a material revision
Timing: Within 60 days of the change
Notes: Required for changes to uses, disclosures, rights, or duties.
Trigger: Three-year availability reminder
Timing: At least once every 3 years
Notes: Remind individuals the NPP is available and how to get it.
Trigger: NPP on request
Timing: Promptly, on demand
Notes: Post the current NPP on the plan website if one exists.
Trigger: BAA before vendor access
Timing: Before PHI is shared
Notes: The signed BAA must precede any PHI handling.
  • Funding and PHI assessment: Confirm whether the plan is self-insured or fully insured, and how much PHI the plan sponsor actually creates or receives; this determines whether the hands-off exception applies.
  • NPP content elements: How the plan uses and discloses PHI (treatment, payment, health-care operations, and other permitted disclosures); individuals' rights (access, amendment, accounting of disclosures, request restrictions, confidential communications); the plan's legal duties; how to complain; a contact; and the effective date.
  • Vendor inventory: A list of every vendor that touches plan PHI: TPA/claims administrator, PBM, COBRA administrator, FSA/HRA administrator, wellness vendor, brokers/consultants that receive PHI, and IT/cloud providers that store it.
  • BAA templates: Each BAA must contain the provisions required by 45 CFR 164.504(e) (permitted uses, safeguards, breach reporting, subcontractor flow-down, return/destruction at termination). Most vendors provide their own; review for the required terms and adequate breach-notification timing.
  • Plan-document privacy language: For self-insured plans, plan-document provisions describing the permitted disclosures of PHI to the plan sponsor and the certifications required under 45 CFR 164.504(f).
1
Determine whether you're in scopeIf the plan is fully insured and the sponsor receives only summary and enrollment data, the carrier maintains and distributes the NPP; confirm this with the carrier and stop here for the NPP. Otherwise, proceed.
2
Draft or update the NPPInclude all required content elements. Use HHS's model notices as a starting point and tailor them to your plan. Set an effective date.
3
Distribute the NPP on scheduleProvide it at enrollment, within 60 days of any material revision, and send the availability reminder at least every three years. Post the current NPP on the plan/benefits website if one exists.
4
Inventory PHI-handling vendorsIdentify every business associate and confirm a current, signed BAA is on file for each. No BAA should ever lag behind PHI access.
5
Review each BAA for required termsConfirm it includes the 164.504(e) provisions and a breach-notification timeline that supports your own 60-day obligations (see the HIPAA Breach Notification page). Push for a specific, short BA-to-plan reporting window.
6
Document plan-sponsor accessFor self-insured plans, ensure the plan document authorizes PHI disclosures to the sponsor and that the sponsor has certified to the required safeguards.
7
Refresh as things changeUpdate the NPP for material changes and add a BAA whenever you onboard a new PHI-handling vendor.
  • Paper or electronic: The NPP may be delivered on paper or, if the individual agrees to electronic delivery, by email. A health plan that maintains a website providing information about benefits must post the current NPP there.
  • To whom: The plan must provide the NPP to the named insured/covered participant; it is not required to send a separate copy to each dependent.
  • Three-year reminder: Rather than redistributing the full NPP, the plan may simply notify individuals that the NPP is available and explain how to obtain a copy, at least once every three years.
  • Revisions: When a material change is made, distribute the revised NPP (or information about the change and how to get the revised notice) within 60 days.
  • NPP versions and distributionEach version of the NPP, with its effective date, and records of when and how it was distributed (enrollment packets, revision mailings, three-year reminders, website postings).
  • Signed BAAsSigned BAAs for every business associate, plus any subcontractor flow-down agreements provided by the BA.
  • Inventory and certificationsYour vendor/PHI inventory and the plan-document privacy provisions and sponsor certifications (self-insured plans).
  • Policies and requestsPrivacy policies and procedures and any individual-rights requests received and how they were handled.
  • RetentionAt least 6 years from creation or last effective date, HIPAA's general documentation standard.

Common traps

Sharing PHI with a vendor before the BAA is signed: The BAA must be in place before the vendor receives PHI. A late BAA doesn't cure the earlier impermissible disclosure.
Forgetting the three-year reminder: Even with a stable NPP, the plan must remind participants at least every three years that the notice is available. This is the most-missed NPP step.
Assuming fully-insured means "nothing to do": The hands-off exception only holds if the sponsor receives just summary and enrollment data. The moment the sponsor handles more PHI (for example, to administer an FSA/HRA or assist with claims), full obligations attach.
Missing a business associate: Brokers, wellness vendors, cloud storage providers, and COBRA/FSA administrators are often business associates. Map every vendor that touches PHI, not just the medical TPA.
Relying on an outdated NPP template: Confirm your NPP reflects current requirements (see the FAQ below on recent rule changes) before distributing it.

FAQs

What is a business associate, and who are mine?
A person or entity that creates, receives, maintains, or transmits PHI to perform a function on the plan's behalf. Common examples for a health plan: the TPA/claims administrator, PBM, COBRA administrator, FSA/HRA administrator, wellness program vendor, brokers/consultants that receive PHI, and IT/cloud vendors storing PHI.

We're fully insured, do we need our own NPP?
Generally no, if the plan sponsor receives only summary health information and enrollment/disenrollment data. The insurer maintains and distributes the NPP. If the sponsor handles more PHI than that, the plan must maintain and distribute its own NPP and follow the full privacy rules.

Did the 2024 reproductive-health HIPAA changes affect our NPP?
The 2024 rule's reproductive-health provisions, including the related NPP changes, were vacated nationwide by a federal court in Purl v. HHS (June 2025), so those specific NPP modifications are not in effect. Separately, NPP content updates tied to the 2024 Part 2 rule on substance-use-disorder confidentiality carry a compliance date of February 16, 2026. Because this area is in flux, confirm current HHS guidance before finalizing your NPP.

What are the penalties?
Civil monetary penalties under HIPAA/HITECH are tiered by culpability, with annual caps per violation category; OCR corrective action plans are common. Disclosing PHI to a vendor without a BAA, or failing to provide the NPP, are each enforceable Privacy Rule violations.

How does this relate to breach notification?
They're connected: your BAAs should require business associates to report breaches to the plan quickly enough to meet your own 60-day notification deadlines. See the HIPAA Breach Notification page for the response process.

  • Fully-insured "hands-off" plans: If the sponsor receives only summary and enrollment data, the carrier handles the NPP and most privacy policies; the sponsor still may not use that data for employment purposes.
  • Self-insured and level-funded plans: Full obligations apply: NPP, distribution timing, privacy policies, plan-document amendments authorizing PHI disclosure to the sponsor, and BAAs with all PHI-handling vendors.
  • Account-based plans (health FSA, HRA): These are typically covered entities subject to the Privacy Rule. If administered by a vendor, a BAA is required; if administered in-house, the sponsor handles PHI and full obligations apply.
  • Subcontractors: A business associate's subcontractors that handle PHI must themselves be bound by BAA terms (flow-down). Confirm your BAAs require this.
  • State privacy laws: Some states impose additional health-privacy or data-breach requirements that can apply alongside HIPAA. Check state law where your participants reside.

HHS publishes a model Notice of Privacy Practices and the required BAA provisions; start from these and tailor them to your plan rather than drafting from scratch.

Vendor BAA / PHI inventory check (drop-in language); send to any vendor that may touch plan PHI:

"Does your organization create, receive, maintain, or transmit protected health information on behalf of our group health plan? If so, please confirm a current, signed Business Associate Agreement is in place, and that it includes the provisions required by 45 CFR 164.504(e), including a breach-notification timeline that allows the plan to meet its own 60-day obligation and flow-down terms binding any subcontractors that handle PHI."