Skip to content
Baldwin Bulletin

HIPAA Notice of Privacy Practices Update Deadline

The Baldwin Group
|
Updated: January 28, 2026
|
2 minute read

January 2026

Natashia Wright, Associate Director Benefits Compliance

Employers that sponsor self-funded group health plans, considered “covered entities” under the Health Insurance Portability and Accountability Act (“HIPAA”), are required to update their Notice of Privacy Practices (“NOPP”). A final rule issued by the U.S. Department of Health and Human Services (HHS) in April 2024 requires covered entities to update their Privacy Notices if they receive or maintain patient records regarding substance use disorder (SUD) treatment provided by a federally assisted treatment program. While many organizations have not revised their NOPP since the HITECH Act in 2013, federal authorities have established February 16, 2026, as the deadline for mandatory revisions. This notice must be accessible to plan participants, as well as on applicable employer or plan websites.

The requirements outlined in 45 C.F.R. Section 164.520 of the HIPAA rule are now considered outdated. Notably, the existing regulations do not address recent legal developments, particularly those impacting reproductive health information. Although certain HIPAA modifications regarding reproductive health were vacated by courts in June, all covered entities must update their NOPP to comply with new regulatory directives related to SUD records. For organizations that create or maintain SUD records protected under 42 C.F.R. part 2, the revised NOPP must provide individuals with clear notice regarding the potential uses and disclosures of their records, as well as inform them of their rights and the entity’s legal obligations concerning such sensitive information.

Under the new regulation, the NOPP is required to explicitly state that SUD treatment records from programs governed by 42 C.F.R. part 2 may not be used or disclosed in civil, criminal, administrative, or legislative proceedings without written consent or a court order following due process. Any judicial authorization for use or disclosure must also be accompanied by a subpoena or other valid legal requirement.

The revised rule emphasizes that if other laws impose stricter limitations than HIPAA—especially those governing SUD records—these requirements must be reflected in the NOPP. Additionally, where other legislation permits or requires disclosure, the revised NOPP must clearly communicate the circumstances under which individuals’ information may be shared. Covered entities maintaining SUD records should clarify that, unlike most protected health information, the use or disclosure of SUD records for treatment, payment, or healthcare operations typically requires explicit patient consent.

A further significant amendment stipulates that the NOPP must notify individuals that information released pursuant to the Privacy Rule may be subject to redisclosure by the receiving party and, consequently, may no longer be safeguarded by the Privacy Rule. This redisclosure warning, previously limited to authorizations, now extends to the NOPP itself. Moreover, if an entity proposes to use or release SUD records for fundraising purposes, it must offer individuals a clear and prominent method to opt out of any related communications.

The Department of Health and Human Services’ Office for Civil Rights is anticipated to issue further guidance, and additional regulatory changes may be forthcoming if proposed rules designed to improve care delivery and reduce administrative complexities are finalized later this year.

  • Review Process and Procedures and ensure that enhanced privacy protections for SUD records are included.
  • Review and update NOPPs, to include the suggested SUD-related language, regardless of whether the plan handles SUD records, and have posted by February 16, 2026.

Related Insights

Stay in the know

Our experts monitor your industry and global events to provide meaningful insights and help break down what you need to know, potential impacts, and how you should respond.

Baldwin Bulletin
RxDC Reporting Office Hours
March 2026 Deanna Sizemore, Associate Director, Benefits Compliance The Baldwin Group is excited to host RxDC Reporting Open Office Hours sessions. During these sessions, attendees...
Baldwin Bulletin
White House Launches TrumpRx Website
March 2026 Caitlin Hillenbrand, Associate Director Benefits Compliance On February 5, 2026, President Donald Trump announced the launch of TrumpRx.gov, a federally run website...
Baldwin Bulletin
DOL Publishes Informational Videos about the FMLA
March 2026 Tony Nelson, State & Leave Compliance Specialist Enacted in 1993, the Family and Medical Leave Act (“FMLA”) provides eligible employees...
Baldwin Bulletin
2026 Increased Penalty Amounts Issued
March 2026 Diana Craig, Director, Benefits Compliance On January 28, 2026, the U.S. Department of Health and Human Services (“HHS”) released annual...
Baldwin Bulletin
2026 Federal Poverty Levels and Non-Calendar Year Plans
March 2026 Deanna Sizemore, Associate Director, Benefits Compliance On January 13, 2026, the Department of Health and Human Services (“HHS”) issued the 2026 federal poverty...
Let's make it possible

Partner with us to build solutions that align with your business, individual, or employee needs and open new possibilities for your future.

Connect with us