Whether your company provides health benefits or qualifies as a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), it is important to update your Notice of Privacy Practices (NPP) by February 16, 2026, to remain HIPAA compliant.
The updated requirements focus on how substance use disorder information may be used or disclosed and remove reproductive health language that was previously added but has since been revoked.
Required Updates to the Notice of Privacy Practices
Covered entities, including health plans and employers subject to HIPAA, must revise their NPP to include new and more restrictive requirements related to protected health information (PHI). Specifically, the NPP must:
- Describe stricter limitations on the use and disclosure of substance use disorder records.
- State that an individual’s written consent or a court order is required to use substance use disorder records in civil, criminal, administrative, or legislative proceedings against the individual.
- Explain that PHI disclosed in accordance with HIPAA may be redisclosed by the recipient and may no longer be protected by HIPAA.
- Clarify that if PHI is used or disclosed for fundraising purposes, individuals will be given a clear and conspicuous opportunity to opt out of future fundraising communications.
- Remove reproductive health language that was added under prior rules that have since been withdrawn.
As part of this update, covered entities should also consider whether other NPP language should be revised in light of operational or legal changes since the document was last updated.
Other HIPAA Documentation to Review
Revisions to the NPP may require corresponding updates to other elements of your HIPAA compliance program, including:
- Policies and procedures: Internal HIPAA policies should be amended to reflect the NPP.
- Training: HIPAA training programs should be updated to address the new requirements.
- Business Associate Agreements (BAAs): BAAs should be reviewed and revised as needed to ensure consistency with HIPAA and the updated NPP.
Next Steps
- Review and update your Notice of Privacy Practices to comply with the new HIPAA requirements.
- Assess related policies, training, materials, and BAAs for consistency.
- Distribute the revised NPP in a timely manner, as required by HIPAA.
For questions or assistance with HIPAA compliance, including updating your NPP, contact a member of Varnum’s employee benefits team.






