Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

2026 HIPAA Deadline: How to Update Your Notice of Privacy Practices (NPP) for SUD Records (42 CFR Part 2)

February 16, 2026

The latest HIPAA change is the latest updates to the Notice of Privacy Practices (NPP).        As of February 16, 2026, the newest version of the NPP must include further information about how Substance Use Disorder (SUD) Protected Health Information (PHI) is handled and secured.

While this was initially ruled under the Biden administration in 2024, the updated content has seen significant changes, including the removal of proposed legislation that would treat reproductive healthcare PHI differently. However, while some states still have additional requirements for handling reproductive care PHI, those requirements were struck down at the federal level by a court ruling in 2025.

Now that the deadline is here, it’s essential to understand what these changes actually mean for your practice.

What’s Actually Changing in the Document?

The Final Rule requires practices to update this document for patients (posted on the website and provided in-person) by February 16, 2026. Your practice must also review whether your state has additional legislation regarding reproductive healthcare PHI.

  • Expanded Scope for SUD Information: SUD records must now be included in the NPP for all Covered Entities, regardless of whether the practice focuses specifically on SUD treatment.
  • Standard Disclosure Language: The notice must explicitly state how the practice discloses SUD records for Treatment, Payment, and Healthcare Operations (TPO).
  • Legal Proceeding Protections: The NPP must state that SUD records cannot be disclosed in legal proceedings without specific written patient consent or a formal court order.
  • Single consent for TPO: The rule does allow patients to sign one consent for all future uses/disclosures of TPO. Previously, SUD records were discussed in a separate document for patients to review.
  • Fundraising Opt-Outs: If your practice uses SUD records for fundraising communications, the NPP must clearly provide patients with the opportunity to opt out. For example, if a rehabilitation center is seeking to raise money for a new facility, it cannot reach out to former patients who have clearly opted out.
  • Redisclosure Warning: The notice must highlight that once PHI (including SUD records) is shared with an outside party, it may be subject to redisclosure by the recipient. In other words, once it’s shared, it’s tough to control how it is shared again by third parties.
  • Universal Accessibility: To remain compliant, practices must ensure the NPP is accessible to all patients, which includes providing translated copies.
  • State-Specific Requirements: Depending on your state, additional protections for reproductive health PHI may still be in place.

Where do I start?

First, ensure your Notice of Privacy Practices (NPP) is already specific to your practice. Your final notice must be specific, include your office address, and provide clear contact information for your Compliance or Privacy Officer. To remain compliant, this notice must also be prominently displayed on your website so patients can easily access and understand their rights.

Your NPP should now include a section that addresses these SUD records directly. The federal government provides model language similar to this:

  • When applicable, we may use or disclose 42 CFR Part 2 substance use disorder records for treatment, payment, and health care operations as permitted by law. Part 2 records will not be used or disclosed in legal or administrative proceedings against you without your specific written consent or a court order.

Your NPP should now include a section that mentions fundraising as well. The federal government provides model language similar to this:

  • If we were to use or disclose substance use disorder records protected by 42 CFR Part 2 in connection with fundraising, you have the right to opt out of receiving fundraising communications in advance, before any such communications are sent.

Simplify Compliance

Updating your NPP can feel like just another complicated task on an already full plate. For practices where you’re wearing many hats, finding the resources for a legal deep-dive is tough.

The simplest way to handle the February 16, 2026, deadline is to lean on experts. Abyde has already done the heavy lifting, automating the necessary HIPAA and SUD record updates so you can focus on what you do best: take care of patients.

Reach out to our team of experts to learn more about HIPAA updates affecting your practice.

Disclaimer: This post is for informational purposes only and does not constitute legal advice. Health care privacy laws are subject to frequent change and vary by state. Consult with a qualified health care attorney or compliance officer to ensure your Notice of Privacy Practices meets all current federal and state requirements.

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
PrevPrevious“We Have IT”: Why That Doesn’t Mean You’re HIPAA Compliant
Next2026 HIPAA Compliance Alert: $103,000 Settlement for Risk Analysis FailureNext

Related posts

2025 OSHA Healthcare Updates
Abyde News, Legislation, OSHA

OSHA 2025: What Healthcare Professionals Need to Know

February 3, 2025 Penelope Schweitzer No comments yet

February 3, 2025 We’ve already seen that 2025 will be a year of major healthcare compliance changes, with the OCR releasing the long-awaited updates to the Security Rule proposal. Similar to how HIPAA laws are being updated, OSHA will likely update key legislation for healthcare workers. Healthcare workers experience the highest rates of workplace injuries, with an average of 3.6 injuries for every 100 employees. Healthcare environments can present many hazards, so it is essential that your staff knows how to prevent and mitigate dangerous situations. While some OSHA initiatives have not been finalized, OSHA has already started the year with legislation that impacts healthcare workers. Increased Penalty Costs As seen in previous years, OSHA has once again increased its fine cost. OSHA has increased the penalty for serious and other-than-serious violations from $16,131 to $16,550 per violation due to inflation. The maximum penalty for repeated and willful violations also has been increased from $161,323 to $165,514 per violation. This highlights that OSHA is dedicated to setting an example with monetary punishment. It’s safe to say that this adjustment will continue to be an annual increase. Consolidating COVID-19 Regulations It’s an understatement to say that COVID-19 devastated and transformed healthcare. Nearly five years since it was classified as a pandemic, proposed healthcare OSHA COVID-19 regulations were officially scrapped as of early January. Over the past years, COVID-19 regulations have been altered. Emergency Temporary Standards required distinctive protocols to follow, which expired. A proposed rule for COVID-19 mitigation in healthcare settings was waiting to be passed for years. Now, specific OSHA COVID-19 legislation in healthcare will be rolled into a broader infectious disease rule, which is expected to be finalized in 2025. This comprehensive rule is expected to require COVID-19 recordkeeping log, but not much else focused on specifically COVID-19. The anticipated comprehensive rule will likely mandate a COVID-19 recordkeeping log. Federal Workplace Violence Legislation Healthcare workers are five times more likely to be attacked at work than workers in any other industry. We’ve seen state-level legislation announced requiring specific logs, training, heightened penalties, and more to mitigate workplace violence in healthcare, but federal legislation is still being drafted. Currently, workplace violence falls under OSHA’s General Duty Clause, requiring organizations to maintain “a place of employment which are free from recognized hazards.” This federal legislation is expected to be announced in 2025. It will likely mirror what state legislation requires, so please review your state’s legislation regarding workplace violence prevention in your practice. What’s Next? As new legislation is announced, it’s vital for your practice to maintain an organized OSHA program. New laws, especially focused on workplace violence prevention, will require additional training, logs, and more. Turning to smart software can allow for your practice to simplify and streamline compliance. Cloud-based software automatically updates with the latest legislation, providing your practice with a clear path to compliance. To learn more about how your practice can achieve OSHA compliance, meet with our experts today.

HIPAA Security Rule Updates
HIPAA, Legislation

The HIPAA Security Rule is Changing: Is Your Practice Ready?

January 23, 2025 Penelope Schweitzer No comments yet

January 23, 2025 The HIPAA Security Rule went into effect in 2003, and it’s an understatement to say that technology has changed quite a bit since then. The Office for Civil Rights has released proposed updates for the HIPAA Security Rule. After a historic year of breaches, this legislation comprehensively strengthens the current Rule. This is the first update of the legislation in a decade. Many of the new requirements simply reinforce existing recommendations within the Security Rule, which now makes best practices mandatory. This legislation is the result of the significant rise in cyber attacks and the OCR’s continuous noncompliant findings when investigating Covered Entities and Business Associates. Although the proposed rule has not yet been finalized, legislation will likely be enacted within the next year, given bipartisan support for protecting patient data. What is the HIPAA Security Rule? The Security Rule, a critical component of HIPAA, centers on stringent guidelines for managing electronic Protected Health Information (ePHI). These guidelines encompass a wide range of safeguards—including physical, administrative, and technical—all designed to ensure the protection of sensitive patient data. One of the most significant components of the Security Rule is completing a Security Risk Analysis (SRA). The SRA sets a benchmark for your practice and assesses what your practice currently does to protect patient data. This analysis includes safeguards ranging from physical measures, like door alarms, to technical precautions, like properly encrypting files. This analysis is a yearly procedure for the OCR and continues to be emphasized in this proposal. In this new proposal, the OCR strictly defines the SRA as a yearly requirement with more guidelines on specific questions. The OCR has introduced eight implementation specifications for risk analysis. This also includes a thorough analysis of potential natural disasters and the consequences if a Business Associate was breached. In fact, the government has introduced a Risk Analysis Initiative, fining practices and businesses that do not complete this analysis. While this assessment is a major component of this rule, once vulnerabilities are identified, it’s up to your practice to implement these safeguards to protect your patients. What’s Changing? This proposed rule mandates that Covered Entities and their Business Associates implement certain proactive measures that were previously only strongly recommended, such as multi-factor authentication. As technology has greatly advanced since the introduction of this rule, there are also more requirements focused on system management, including required anti-malware protection, disabling unused network ports, and a network map, highlighting what devices are connected to specific networks in an organization. Network segmentation is another advancement of the rule, requiring practices to use different networks based on access to specific information. New policies and procedures will also be required if this proposal goes into effect. For instance, contingency plans will be required, showing what a practice or business plans to do if it is breached within 72 hours. Additionally, practices need to have a transition plan when staff leaves, and they need to notify other regulated entities when a staff member’s access to ePHI is changed or terminated. Business Associates (BAs) will also face stricter requirements when working with Covered Entities. If breached, BAs must notify their Covered Entities within 24 hours. BAs will also now have to have their compliance program certified by a Subject Matter Expert in cybersecurity on a yearly basis, ensuring that the business is taking the right steps to protect patient data. What Can I Do? While this rule is still within its comment period until early March, it could be enacted this year. Being aware of upcoming HIPAA legislation and preparing your practice is vital. Working with a smart compliance solution can take the pressure off, with compliance experts updating their systems to ensure their users will be compliant with new laws. Looking to understand HIPAA compliance for your practice before new laws take effect? Schedule a consultation with one of our experts today.

HIPAA, Legislation

The Breach Notification Rule: What to Do in Case of a Data Breach

April 17, 2024 Gaurav Modi Comments Off on The Breach Notification Rule: What to Do in Case of a Data Breach

April 17, 2024 Imagine this: it’s a quiet Wednesday morning at the practice. As you’re watching the clock tick criminally slow to lunch hour, you check your email. It looks like your boss sent you an email!  He wants you to print out the attached file. You absent-mindedly click on the file, and your once quiet morning is completely flipped on its head.  The email was a phishing scam! If you looked a bit harder, you would have noticed it didn’t actually come from your boss, but an unknown suspicious email.  The malware begins to infect your computer, starting to wreak havoc. What are you going to do?  Email phishing scams are a common example of a breach, exposing patient data. Other forms of breaches include: stolen laptops, improper disposal of PHI, and overall, any time unauthorized access to sensitive patient data. Breaches, unfortunately, happen pretty often, affecting millions of patients. In 2023, over 133 MILLION patients’ information was exposed in breaches.  What’s the HIPAA Breach Notification Rule?  Now that we’ve painted a scary picture, let’s talk about what you can do. This is where HIPAA’s Breach Notification Rule comes in. The Breach Notification Rule is one of the pillars of HIPAA and guides Covered Entities (CEs) and Business Associates (BAs) when it comes to breaches. It mandates required information about a breach and how patients need to be notified of their exposed data. What Should I Do?  Well, first, don’t panic! Time is of the essence when it comes to a breach.  Here’s a step-by-step guide on what to do if you suspect a data breach: 1.Contain the Breach: First things first, stop the attack! If dealing with a cyber attack, like an email phishing scheme, disconnect the infected computer immediately, so it can’t spread the nasty virus to other computers on the network. Report the incident to your IT department or IT partner immediately. 2. Investigate the Breach: Time to play a bit of Sherlock Holmes and investigate the attack. What data was accessed or potentially accessed? How many individuals are potentially affected? How did the breach occur?  All of these questions are vital when it comes to reporting this breach and notifying patients. In the Abyde software, we have our breach log, a quick questionnaire for you to organize your investigation.Notification Requirements: Depending on the severity of the breach, notifications may need to be sent to several parties: 3. Notification Requirements: Depending on the severity of the breach, notifications may need to be sent to several parties: 4. Mitigation and Prevention: Well, hopefully, that never happens again! Now, it’s time to take steps to prevent similar breaches in the future. This involves:  How Abyde Can Help Mitigating breaches and protecting patient privacy can be daunting. Abyde can help! We offer a plethora of resources on compliance and data security best practices. As discussed above, Abyde assists with every step of the breach process, from proactively identifying risks and vulnerabilities with the Security Risk Analysis, to training, to breach logs.  Want to learn more about how Abyde can help you Never Stress Over Compliance Again? Email info@abyde.com, and schedule a compliance consultation here and here for Business Associates.   

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS