The NPP duties statement explains that the covered entity must maintain the privacy of PHI, provide notice of its legal duties and privacy practices, notify affected individuals after a breach of unsecured PHI, and follow the notice currently in effect. If the entity reserves the right to apply future notice changes to previously maintained PHI, it also states that reservation and explains how revised notices will be provided.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
The statement includes current and future duties
45 CFR 164.520 requires the privacy, notice, breach-notification, and current-terms statements. A change-reservation statement has additional content. Align it with the practice's actual revision policy and 45 CFR 164.530 rather than inserting boilerplate automatically.
Map each clause to the policy and operational evidence that supports it. The privacy statement should align with safeguards and workforce responsibilities. The duty to provide notice needs current distribution and availability processes. Breach-notification language should match the entity's incident assessment and notification procedure. The commitment to follow the notice currently in effect requires version control across every public and delivered format.
The current notice governs real practice
Treat the NPP as an operational commitment, not solely a publication artifact. Review policies, training, intake scripts, disclosure workflows, complaint handling, individual-right processes, and vendor instructions against the active notice. When the notice voluntarily promises a narrower practice, the entity needs a supported process to follow it or a reviewed revision. A template cannot cure a conflict between public language and daily operations.
Create a clause register with source, approved wording, entity, effective period, related policy, system control, training owner, evidence, and review trigger. Use it during acquisitions, service changes, new data uses, vendor onboarding, litigation developments, and state-law updates. Preserve prior records so later reviewers can determine which duties statement applied at the time of an event.
A notice cannot create authority the law withholds
Optional limits can describe more protective practices, but the entity must follow what it states. The notice cannot limit a required-by-law disclosure or the specified serious-threat pathway. Route promises beyond the federal minimum through legal and operations review.
Separate an aspirational privacy statement from a binding operational promise. Plain language can be reassuring without making absolute commitments that conflict with current law or emergency procedures. Qualified reviewers should examine words such as “always,” “never,” and “only,” then trace each promise into policy and system behavior. If more protective state or program law governs, identify its scope instead of applying it broadly to unrelated records.
Govern breach and revision language together
The breach-notification statement should point to an incident process that can assess unsecured PHI, applicable definitions, affected individuals, timing, and required communications. The NPP does not decide whether a particular incident is a reportable breach. Staff should route suspected incidents promptly rather than giving a legal conclusion from the notice.
If the entity reserves the right to change the notice and apply revised terms to PHI already maintained, document that policy and the required method for providing a revised notice. Coordinate the reservation with effective dates, website and physical posting, health-plan routes, first-service delivery, paper availability, and joint-notice participants. A reservation clause cannot replace the actual revision process.
Example with duty fields
Six notice variants are reviewed. Five contain current duty language and a usable revision route; one old translation omits breach notification. Duty completeness is 5 of 6 variants.
The owner withdraws the affected translation, commissions qualified correction, compares the entire translated notice with the approved source, and assesses deliveries made during the defect period. Release evidence includes reviewer approval, version identifier, publication time, replaced stock, and a follow-up test. The incident team also confirms that language-support staff know how to route a reported privacy incident.
Duties-statement checklist
- Map every duty clause to current authority, policy, and evidence.
- Confirm the statement fits the correct covered entity and notice version.
- Align breach language with incident intake and assessment procedures.
- Review optional promises for operational and legal consequences.
- Govern any future-change reservation through the release process.
- Check translations, websites, portals, paper stock, and joint notices.
- Archive effective periods, approvals, defects, and remediation.
Owner controls
HHS model notices provide current examples. Use approved clauses, source mapping, translation parity, effective-date controls, breach-policy alignment, and revision-release testing. Archive every notice version and its applicable period.
Monitor clause-to-policy coverage, active-format parity, obsolete copies, open legal questions, release exceptions, and reported conflicts between the notice and practice. Audit from policies into the active notice and from notice promises into operational evidence. Escalate conflicts while qualified owners can still prevent a broader distribution or practice gap.
Include the duties statement in incident and change-management reviews. A breach, complaint, new service, or privacy exception may expose a mismatch between the public promise and the implemented control. Record the applicable notice version before choosing corrective action.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni