The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#236 Don't Miss It: HIPAA NPP Changes Due Feb. 16th
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This episode discusses the upcoming deadline for dental practices to update their Notice of Privacy Practices on Feb. 16, 2026. Learn what needs to change and why, how to make the NPP available to patients, and where to find a template for the updated NPP.
Resources:
- American Dental Association - members access
- The Compliance Divas resources https://www.thecompliancedivas.com/resources
I wish we have it. I'm Mary Gavoni. I'm Olive Long, and together we are the Compliance Divas. Welcome to the Compliance Divas podcast. I'm Mary Gavoni and I am flying solo on this podcast today because the divas wanted to bring you some important information about a deadline with relationship to HIPAA. On Monday, February 16th, you are required to have an updated notice of privacy practices, referred to as the NPP. And there's some information that needs to be included into the notice of privacy practices that you should already have in your practice. And I'll give the details on that in a bit. But how do you use the notice of privacy practices? Well, the notice of privacy practices is a detailed description of all the ways that you record, use, and transmit patients' protected health information in the course of treating them. And it lists the patient's rights to have that information restricted if they choose to, and your rights or and your obligations to that patient with respect to protecting that information. So you are not required to give a patient a copy of that notice of privacy practices. Everybody doesn't need to get one, but you are required to have it available for a patient to look at, to read, or to have a copy to take with them if they want it. So a great way to do that is to number one, put a copy on your website so patients could view it or download it from your website, and then have a copy available at the check-in area in your practice. I like to print the pages and laminate them so that they don't get all dog eared over time so patients can look at that. Some people put it on the wall. It's up to you if you want to frame it and put it up on the wall. I've also seen practices print them and make them into a brochure that they can put in a little brochure holder and set somewhere in the check-in area or in the reception area. In any event, it needs to be available to patients who want to see it. So we had the original NPP that was presented to us back in 2003 when the HIPAA rules first took effect. And then there was an update to it when the rules were updated in 2013. And now again, we have the 2026 update that must be available in your practice on February 16th. So, what's new? What do you need to add in or amend your notice of privacy practices? Well, the first thing is adding in a statement about how you would manage if you had any patient records that related to substance abuse disorder and treatment. This is not typical in a dental practice. You most likely will never have those, but you need to have a statement in there that says that you will protect those records and not disclose them to anyone who's not authorized to have that information. The second thing is to add a statement that clarifies that you may be transmitting the patient's confidential or protected health information to other entities like insurance clearinghouse or maybe to a uh specialist that you're referring to. And in that clarification statement, you need to say that once you have transmitted that information, it's no longer in your control. In other words, you don't have a say over what happens to that. Now, I need to qualify that when you are sharing that information with another entity, it has to be done in a HIPAA-compliant way, meaning through an encryption portal, through a HIPAA compliant portal, for example, when you submit your electronic claims. And you may remember a couple of years ago, there was a huge HIPAA security breach with a company called Change Healthcare that processed electronic claims for a number of practice management software entities. And in the grand scheme of things, the breach may have exposed some of your patient data, but because it wasn't in your control and it had been transmitted in a HIPAA-compliant way, the clearinghouse was the one that had to take care of notifying the patients and providing credit protection for those patients that were affected if their records were breached. So that's an important risk management tool statement, if you will, that you need to have in your notice of privacy practices. And then finally, as we are now adapting to using more and more artificial intelligence or AI in practices for record keeping or recording calls for training and so forth, you need to make sure that you have a statement in your notice of privacy practices that you may use artificial intelligence in relation to recording information about their treatment and about their communications with you. That also falls under the Federal Wiretap Act. And there was a lawsuit against a large DSO last year that violated that by using a recording software for telephone calls that they did not inform their patients that they were being recorded. So if you're using some AI app for voice charting, period charting, or clinical notes, that involves the use of a recording device. You're speaking to your computer to record that information. You need to let your patient know ahead of time that they are being recorded because, of course, you interact with them during that time. So, again, just to summarize, the changes are making sure that you have a statement about the storage of any kind of information about substance abuse disorder treatment, a statement about the information not being in your control once it's been transmitted to another covered entity, and last, a statement that you may be using artificial intelligence to assist in your record keeping. So, where do you get a template? Where do you get a new notice of privacy practices that you can use in your practice? Well, we have a couple of options for you. If you or your doctor is a member of the American Dental Association, the ADA has done a great job of creating an updated template and you can download it through the members section of the ADA website, and there's no cost to doing that. And that's a great service that the ADA has done. If for some reason you don't have access to that ADA statement, you can go to the ComplianceDivas website, thecompliancedivas.com, and you can click on resources, and we have a copy of a template that you are free to use. And you also can access that template through the link on the show notes for the podcast on your podcast app. If you have any questions about the podcast, you can submit them to support at thecompliancedevas.com, and we'll be happy to answer those questions for you. We hope that you give us a review on your podcast app. Thanks for your attention to this timely information, and we'll see you next time.