Skip to content
Baldwin Bulletin

HIPAA Notice of Privacy Practices Update Deadline

The Baldwin Group
|
Updated: January 28, 2026
|
2 minute read

January 2026

Natashia Wright, Associate Director Benefits Compliance

Employers that sponsor self-funded group health plans, considered “covered entities” under the Health Insurance Portability and Accountability Act (“HIPAA”), are required to update their Notice of Privacy Practices (“NOPP”). A final rule issued by the U.S. Department of Health and Human Services (HHS) in April 2024 requires covered entities to update their Privacy Notices if they receive or maintain patient records regarding substance use disorder (SUD) treatment provided by a federally assisted treatment program. While many organizations have not revised their NOPP since the HITECH Act in 2013, federal authorities have established February 16, 2026, as the deadline for mandatory revisions. This notice must be accessible to plan participants, as well as on applicable employer or plan websites.

The requirements outlined in 45 C.F.R. Section 164.520 of the HIPAA rule are now considered outdated. Notably, the existing regulations do not address recent legal developments, particularly those impacting reproductive health information. Although certain HIPAA modifications regarding reproductive health were vacated by courts in June, all covered entities must update their NOPP to comply with new regulatory directives related to SUD records. For organizations that create or maintain SUD records protected under 42 C.F.R. part 2, the revised NOPP must provide individuals with clear notice regarding the potential uses and disclosures of their records, as well as inform them of their rights and the entity’s legal obligations concerning such sensitive information.

Under the new regulation, the NOPP is required to explicitly state that SUD treatment records from programs governed by 42 C.F.R. part 2 may not be used or disclosed in civil, criminal, administrative, or legislative proceedings without written consent or a court order following due process. Any judicial authorization for use or disclosure must also be accompanied by a subpoena or other valid legal requirement.

The revised rule emphasizes that if other laws impose stricter limitations than HIPAA—especially those governing SUD records—these requirements must be reflected in the NOPP. Additionally, where other legislation permits or requires disclosure, the revised NOPP must clearly communicate the circumstances under which individuals’ information may be shared. Covered entities maintaining SUD records should clarify that, unlike most protected health information, the use or disclosure of SUD records for treatment, payment, or healthcare operations typically requires explicit patient consent.

A further significant amendment stipulates that the NOPP must notify individuals that information released pursuant to the Privacy Rule may be subject to redisclosure by the receiving party and, consequently, may no longer be safeguarded by the Privacy Rule. This redisclosure warning, previously limited to authorizations, now extends to the NOPP itself. Moreover, if an entity proposes to use or release SUD records for fundraising purposes, it must offer individuals a clear and prominent method to opt out of any related communications.

The Department of Health and Human Services’ Office for Civil Rights is anticipated to issue further guidance, and additional regulatory changes may be forthcoming if proposed rules designed to improve care delivery and reduce administrative complexities are finalized later this year.

  • Review Process and Procedures and ensure that enhanced privacy protections for SUD records are included.
  • Review and update NOPPs, to include the suggested SUD-related language, regardless of whether the plan handles SUD records, and have posted by February 16, 2026.

Related Insights

Stay in the know

Our experts monitor your industry and global events to provide meaningful insights and help break down what you need to know, potential impacts, and how you should respond.

Baldwin Bulletin
Baldwin Bulletin FAQ of the Month
January's FAQ of the month Question: Is an Applicable Large Employer (ALE) required to continue to offer medical coverage to...
Baldwin Bulletin
2025 Compliance Year in Review
January 2026 Daniel Finnegan, Compliance Specialist Several regulatory changes and updates occurred last year in connection with the One Big Beautiful Bill Act (“OBBBA”) as well as significant agency non-enforcement...
Baldwin Bulletin
2025 ACA Reporting and Filing Deadlines 
January 2026 Stephanie Hall, Associate Director Benefits Compliance The IRS has released the final 2025 forms and instructions for reporting under...
Baldwin Bulletin
CMS Medicare Part D Reporting Deadline 
January 2026 Paul Van Brunt, Associate Director Benefits Compliance Employers that offer any prescription drug coverage under a group health plan...
Baldwin Bulletin
IRS FAQ Addresses OBBBA Flexibilities for HSA-Compatible Telehealth and Direct Primary Care
January 2026 Diana Craig, Director Benefits Compliance In December 2025, the IRS issued Notice 2026-5, which offered additional guidance about Health Savings Account (“HSA”) flexibilities included in the One Big Beautiful Bill Act...
Let's make it possible

Partner with us to build solutions that align with your business, individual, or employee needs and open new possibilities for your future.

Connect with us