{"@context":"https://schema.org","@type":"Article","headline":"Notice of amendment","description":"Learn who may need notice after a HIPAA amendment is accepted and how covered entities should track scope, recipient agreement, delivery, and downstream action.","url":"https://finnihealth.com/resources/glossary/notice-of-amendment","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Notice of amendment","item":"https://finnihealth.com/resources/glossary/notice-of-amendment"}]}}
Glossary term

Notice of amendment

Learn who may need notice after a HIPAA amendment is accepted and how covered entities should track scope, recipient agreement, delivery, and downstream action.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

downstream PHI amendment notice amendment notification

A notice of amendment communicates an accepted HIPAA amendment to relevant people or entities. The covered entity makes reasonable efforts to inform people identified by the individual as having received the PHI and needing the amendment, plus people, including business associates, that the entity knows possess the information and may have relied or could foreseeably rely on it to the individual's detriment. The notice is scoped to the accepted change.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Recipient selection has two sources

45 CFR 164.526 uses the individual's identification and agreement for relevant recipients and the covered entity's knowledge of others with potentially detrimental reliance. Record which basis applies to each recipient and why the amendment matters.

After accepting an amendment, explain the recipient process to the individual and request names, organizations, destinations, and relevant disclosures. Capture agreement to notify the identified people. Then conduct the entity's own review of disclosure logs, referrals, claims, business-associate workflows, and other known uses. A recipient can qualify through either workstream, and the final ledger should merge duplicates while preserving the basis.

The detrimental-reliance analysis is fact specific. Ask whether the person or organization has the PHI and whether prior or foreseeable reliance could disadvantage the individual. Focus on the accepted change and actual distribution path. Sending every amendment to every historical contact creates unnecessary disclosure and still may miss a current relying recipient.

Design a notice that can be applied

Identify the individual, accepted amendment, affected record or field, relevant original information, decision date, and a contact for questions. Provide enough context for the recipient to connect the amendment to the right record without disclosing unrelated PHI. Preserve the exact content transmitted. When the recipient is a business associate, follow the contract, approved channel, and operating procedure for record changes.

The notice workflow should specify what counts as reasonable effort. Delivery may be shown by a secure-message receipt, interface acknowledgment, confirmed fax, tracked mail, or another approved record. A bounce, invalid fax, or rejected interface message is evidence of failure, not completion. Assign retries and escalation, and document the final disposition when current contact information cannot be found.

Network notice requires reasonable effort

HHS guidance explains the network responsibility. Use current contact information, an approved secure route, delivery evidence, retry ownership, and a record of any source that could not be reached.

Shared networks require ownership boundaries. Decide whether a central privacy office, local practice, health information exchange, or business associate sends and applies the notice. Contract language can allocate work, while the covered entity still needs evidence that its obligations were carried out. Test whether a notice updates the source record, cached views, extracts, and future decision surfaces rather than merely entering a queue.

Incoming notices deserve the same discipline. Verify sender and individual match, route the amendment to the affected designated record set, apply or link it, and record completion. Raise conflicting notices or technically unchangeable systems to privacy and records leadership instead of discarding them.

Example by recipient

A practice identifies seven recipients. Five receive the amendment, one message fails, and one recipient is still under legal review. Delivery completion is 5 of 7 recipients. Both unresolved recipients remain in the denominator.

If the five completed notices include three confirmed receipts and two validated interface acknowledgments, the practice can show its reasonable efforts. The failed message receives a corrected address and retry. The legally reviewed recipient remains open until the route is approved or a documented decision explains why notice is outside the accepted amendment workflow. Reporting only the five successful sends would hide the two unresolved obligations.

Notice checklist

  • Confirm that the amendment was accepted and identify its exact scope.
  • Capture recipients identified by the individual and the individual's agreement.
  • Search for other known holders with actual or foreseeable detrimental reliance.
  • Merge duplicates while preserving the basis for including each recipient.
  • Send only the amendment and context needed to apply it through an approved route.
  • Record destination, sent date, delivery evidence, failures, and retries.
  • Route incoming notices to each affected designated-record-set owner.
  • Close the ledger only after all recipients have a supported final disposition.

Owner controls

Keep the accepted amendment, affected PHI, recipient basis, agreement, disclosure route, sent date, receipt evidence, retries, and final outcome together. When another covered entity sends a notice, route it to the office responsible for updating designated record sets.

Measure recipients identified, notices attempted, notices delivered, failures resolved, unresolved cases, and incoming notices applied. Sample business-associate and network paths, where proof often sits outside the primary record system. A strong audit trail shows both why each recipient was selected and how the notice reached a system that can use it.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni