U.S. Department of Health and Human Services, Office for Civil Rights 2026 HHS.gov

Summary of the HIPAA Privacy Rule (HHS.gov)

HHS’s own official summary of the HIPAA Privacy Rule. Most of the page is legal/regulatory scope detail (covered-entity classification, business-associate contract terms, permitted-disclosure categories) rather than design guidance; only the Notice-of-Privacy-Practices provisions are design-relevant and extracted below.

License: Public domain — U.S. federal government work (17 U.S.C. § 105), the same basis as NASA Task Load Index (TLX).

Key points

  • A covered health care provider with a direct treatment relationship must deliver the Notice of Privacy Practices no later than the first service encounter, post it at each service delivery site “in a clear and prominent place where people seeking service may reasonably be expected to be able to read” it, and make it “electronically available on any web site it maintains for customer service or benefits information.”
  • A covered health care provider with a direct treatment relationship must make a good-faith effort to obtain a patient’s written acknowledgement that they received the notice, and must document the reason for any failure to obtain it.
  • A health plan must give its notice to each new enrollee at enrollment, then send a reminder at least once every three years that the notice remains available on request — a recurring-disclosure cadence, not a one-time delivery.

Cited In

Standards

Source Links

Created Thu Aug 27 2026 00:00:00 GMT+0000 (Coordinated Universal Time) Updated Thu Aug 27 2026 00:00:00 GMT+0000 (Coordinated Universal Time)