Introduction: Privacy Policies in Medical Assisting
Most medical offices now use patient portals, but staff still blur the line between an internal HIPAA privacy policy and a patient-facing Notice of Privacy Practices, a mistake that surfaces at check-in and records release. The HIPAA Privacy Rule has required both documents since 2003.
Medical assistants need more than generic yearly training; access to charts, phones, faxes, and portals makes them the first line of minimum necessary decisions.
The practical question is whether the sample policy template matches front desk reality, where an MA decides if a request falls under treatment, payment, or a signed release.
What Is a HIPAA Privacy Policy? (And How It’s Different From a Notice)
45 CFR 164.502 sets a baseline rule that medical assistants working in any covered health care setting must follow: when you use or share protected health information, you limit it to the minimum necessary to get the job done.1 That single standard is a useful starting point for understanding why an internal HIPAA privacy policy and a patient-facing Notice of Privacy Practices are not the same document.
Covered Entity, PHI, and Minimum Necessary
A covered entity includes health plans, health care clearinghouses, and health care providers that transmit health information electronically in standard transactions such as insurance claims.2 If your clinic sends electronic claims or checks eligibility, it is generally a covered entity regardless of size.
Protected health information, or PHI, means individually identifiable health information in any form: electronic, paper, or oral. A name attached to a lab result, a voicemail about a prescription, even a handwritten sign-in sheet can be PHI.1
The minimum necessary standard requires reasonable efforts to share only what is needed for the task. For example, when an administrative medical assistant confirms an appointment, they do not need to read the full chart. When a clinical medical assistant hands a provider the day's vitals, they should not also hand over billing notes unless those are required for the task.
Internal Privacy Policy vs Notice of Privacy Practices
A HIPAA privacy policy in the operational sense is an internal set of rules and procedures.3 It tells staff who may access which records, how to log certain disclosures, how training is handled, and what happens if a privacy rule is violated. It is not written for patients and is not required to be posted or handed out.
The Notice of Privacy Practices is different. It is a patient-facing document required by the HIPAA Privacy Rule to be written in plain language.3 Practices must make it available on request, post it on a website if the practice has one, and offer it to patients at their first service delivery with a good-faith effort to obtain written acknowledgment. It explains how the practice may use and disclose PHI, patient rights, the practice's legal duties, and who to contact, including a contact for the practice's internal privacy policies.
Where They Overlap
The two documents overlap in subject matter but not in depth. The notice summarizes rights and duties. The internal policy operationalizes them with role-based access, specific procedures for common tasks, complaint handling, and sanctions. If a patient asks what the office does with their emergency contact information, the notice says it may be used for treatment and health care operations. The internal policy says which staff members may update that information and how the change should be documented. Both documents reflect the same legal obligations, but only one is designed for the front desk or clinical workstation.
At a Glance: Privacy Policy vs Notice of Privacy Practices
A medical office uses two related but distinct documents to protect patient information. The internal privacy policy guides staff behavior, while the Notice of Privacy Practices tells patients how their information is handled.

Key Sections Every Medical Office Privacy Policy Should Include
A complete medical office privacy policy does more than list rules. It gives staff clear direction on protected health information and gives patients a way to understand their rights. The sections below reflect HIPAA Privacy Rule expectations and the gaps that often show up in compliance reviews.
| Policy Section | Required Elements | Common Compliance Gaps |
|---|---|---|
| Uses and disclosures of PHI | Set limits and conditions on permitted uses and disclosures of protected health information without individual authorization, including treatment, payment, health care operations, and other allowed disclosures. | Many policies do not clearly define permissible uses and disclosures, apply the minimum necessary standard, or describe authorization, marketing, and fundraising limits, leaving staff unsure when explicit authorization is required. |
| Patient rights related to PHI | Describe patient rights to access, inspect, amend, and obtain a copy of PHI; receive an accounting of disclosures; request restrictions and confidential communications; and file complaints with the covered entity. | Covered entities often do not fully implement inspection, amendment, and accounting of disclosures processes, or do not clearly explain to patients how to exercise these rights. |
| Safeguards for protecting PHI | Require appropriate administrative, technical, and physical safeguards to protect PHI from unauthorized access, use, or disclosure. | Compliance programs often lack clearly documented physical, administrative, and technical safeguard procedures, or fail to tie workforce responsibilities to those safeguards. |
| Workforce training on privacy policies | Require workforce members to be trained on written privacy policies and procedures as necessary and appropriate for their job functions. | A common gap is insufficient or inconsistent training on privacy and breach notification policies, especially failure to train all workforce members on adopted procedures. |
| Sanctions for privacy violations | Have and apply appropriate sanctions against workforce members who fail to comply with privacy policies, procedures, the Privacy Rule, or Breach Notification Rule. | Organizations often lack clearly developed, documented, and approved sanction guidelines, or do not communicate them and include them in workforce training. |
| Breach notification procedures | Outline procedures for identifying breaches of unsecured PHI, notifying affected individuals without unreasonable delay and no later than 60 calendar days after discovery, and documenting the breach and response. | Frequent gaps include untimely notifications, incomplete breach notices lacking required content, and inadequate documentation of breach response policies. |
| Written privacy policies and procedures | Maintain written policies and procedures necessary to implement Privacy Rule standards, including how PHI is handled and how workforce members are trained to perform their functions. | Many medical offices omit key elements such as minimum necessary standards, workforce responsibilities, complaint procedures, and policy update requirements. |
| Notice of privacy practices content alignment | Align internal policies with the Notice of Privacy Practices by covering uses and disclosures of PHI, individual rights and how to exercise them, legal duties to maintain privacy, and contact information for privacy questions. | Common issues include not updating notices to reflect new federal requirements, such as substance use disorder patient records, and failing to keep the internal policy synchronized with the public notice. |
| Complaint handling and mitigation | Include procedures for receiving and handling complaints, imposing sanctions, and mitigating harm resulting from privacy violations. | Entities often fail to document complaint processes, mitigation steps, and incident response procedures, even though documentation is essential to meet administrative requirements. |
Medical Assistant Responsibilities Under the Privacy Policy
The core challenge for medical assistants is balancing efficient patient care with strict privacy protection. Every interaction with patient information requires judgment about what you need to access, who should receive it, and how to document your actions. Understanding your specific duties under the privacy policy transforms abstract rules into practical daily habits.
Verifying Identity and Safeguarding PHI
Before releasing any protected health information, confirm you are speaking with the right person. For in-person visits, check a photo ID against the patient record. On phone calls, use established verification questions such as date of birth and address before discussing appointment details or test results. Never leave patient charts visible on desks or computer screens unattended, and position monitors away from waiting areas.
When pulling physical or electronic records, access only the information needed for the task at hand. This "minimum necessary" standard means that scheduling an appointment requires the patient's name and contact information, not their full medical history. Chart pulls for billing involve specific visit codes, not unrelated diagnoses.
Logging Disclosures and Handling Requests
Every time protected health information leaves the office for purposes beyond treatment, payment, or operations, you may need to log the disclosure. Track the date, recipient, and purpose so the practice can provide an accounting if a patient requests one. When patients ask for copies of their records, amendments, or restrictions on how their information is shared, follow the office protocol for routing these requests to the designated privacy officer.
Consequences of Non-Compliance
Violating privacy policies can result in disciplinary action, termination, or civil penalties for both you and the practice. Fines for privacy breaches can reach thousands of dollars per incident, and repeated violations can cost a practice millions. For medical assistants, losing a position over a privacy lapse can also affect future employment references and professional standing.
Training and Certification Expectations
Most accredited medical assistant certificate and diploma programs include privacy and confidentiality modules, and employers typically require annual refresher training. Certification exams from organizations like AAMA and AMT, such as the CMA exam, test your understanding of privacy principles. Documenting your training completion protects both you and your employer by demonstrating ongoing compliance efforts.
Related Articles
Privacy Policy in Daily Practice: Charts, Calls, and Digital Tools
A paper chart left on a desk and an unencrypted text about a patient's lab result can cause the same kind of privacy breach, but one feels low-tech while the other feels instant. Medical assistants are often the first line of privacy protection across every chart, call, fax, and screen.
Paper Charts and Phone/Fax Workflows
Paper charts require strict habits. Never leave them unattended where other patients or visitors can see them. Use a cover sheet or folder when carrying records through hallways, and return charts to locked storage immediately after use. For phone calls, verify the caller's identity before discussing protected health information, and avoid speaking about patient details where others can overhear. Faxes should include a confidentiality notice on the cover page and be sent to confirmed numbers. Routine care calls are generally HIPAA-related, so treat the information you share as sensitive even when the conversation feels casual. The office privacy policy should spell out exactly how charts are checked out, logged, and returned.
Patient Portals, Email, and Personal Devices
Patient portals used for care are typically covered by HIPAA when they handle protected health information as part of the treatment workflow.3 Routine email about a patient's care is also protected health information, but email tracking, newsletters, appointment reminders, or marketing emails may collect personal data outside HIPAA's protected scope.3 Medical assistants should use encrypted email when available, avoid forwarding patient information to personal accounts, and never send PHI from a personal phone unless the office has approved secure messaging. Texting and personal device use are risky because messages can sync to personal backups and remain outside office controls.
State Privacy Laws Add Another Layer
HIPAA is the floor, not the ceiling. In 2026, about 20 states have comprehensive privacy laws in effect, including California, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, and others.1 California's CCPA/CPRA generally does not apply to HIPAA-covered PHI held by a covered entity or business associate, but it can apply to personal data collected by digital tools outside the HIPAA-covered workflow, such as web analytics, marketing pixels, or patient engagement tools.3 Indiana, Kentucky, and Rhode Island take effect in 2026.2 The practical rule is simple: if a tool collects data outside treatment or operations, state privacy law may apply.3 Integrated privacy coverage means the same care and caution should extend across in-office and online workflows, not just paper or phone. Because many state laws exempt PHI but details vary, ask your privacy officer how state rules affect tools you use every day.3
Do's and Don'ts for Medical Assistants
- Do log out of your workstation and lock screens before walking away.
- Do verify patient identity before sharing information by phone, fax, or portal.
- Don't text PHI from a personal phone or use personal email for patient care.
- Don't leave paper charts or printed lab results face-up on counters.
- Do ask your supervisor whether a new digital tool has been reviewed for privacy compliance before using it with patient data.
How Do HIPAA, CCPA/CPRA, and WA My Health Data Compare?
HIPAA sets the federal privacy floor, but California and Washington layer on extra protections for health-related data. This side-by-side view highlights the differences medical assistants are most likely to encounter in daily practice.

Sample HIPAA Privacy Policy Template for a Medical Office
A HIPAA-compliant privacy policy template structures the Notice of Privacy Practices into clear sections so patients can review their rights and the practice's duties. Use the required header language verbatim, then adapt each section below to match your office's actual workflows and state requirements.
| Template Section | What to Include | Customization Notes |
|---|---|---|
| Header / Introductory Statement | Display the required HIPAA header: "THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY." | Keep the header wording verbatim to comply with 45 CFR 164.520(b)(1)(i). Font, formatting, and placement may vary, but the language itself may not. |
| Effective Date | Include the date on which the Notice of Privacy Practices is first in effect, displayed on the notice. | Place the effective date prominently, typically at the top. Update it whenever the notice is materially revised to match current practices. |
| Uses and Disclosures of PHI | Provide specific statements describing how the physician will use and disclose protected health information, including routine uses and situations where the patient's authorization is required. | Tailor examples for treatment, payment, and health care operations, and list other permitted uses such as public health or legal requirements that actually apply to your practice. |
| Individual / Patient Rights | Include a statement of individuals' rights with respect to protected health information and a brief description of how the individual may exercise those rights. | List all HIPAA rights, including access, amendments, accounting of disclosures, restrictions, confidential communications, and copies of the notice. Explain the office's specific request process. |
| Covered Entity / Physician Duties | Describe the physician's duties under the HIPAA Privacy Rule, including the duty to abide by the current Notice of Privacy Practices. | State that the practice is required to maintain the privacy of protected health information, provide notice of legal duties and privacy practices, and notify patients if terms change. |
| Complaint Process | Include a statement that patients may complain to the physician or to the Secretary of HHS if they believe their privacy rights have been violated, along with filing instructions and a no-retaliation statement. | Provide specific instructions for filing a complaint with your privacy officer, including contact details, and note that complaints can also be filed with HHS. Align wording with your actual complaint-handling process. |
| Contact / Privacy Officer Information | Include the name or title and telephone number of the person to contact for further information about privacy practices, generally the designated privacy officer. | List the privacy officer's name, title, phone, email, and mailing address for written requests. Ensure these details match your current privacy office structure. |
| Scope: Who Follows This Notice | Explain whose privacy practices are covered, such as the practice, its employees, clinical and administrative staff, and any other parties who follow the notice. | Customize the scope statement to include all organizational units, workforce members, and affiliated providers that operate under your joint notice of privacy practices. |
| Uses and Disclosures Requiring Authorization | Identify categories of uses and disclosures that require the patient's written authorization, such as most uses of psychotherapy notes, marketing communications with payment, and sale of protected health information. | Add specific statements detailing when authorization is required and describe how patients may revoke an authorization, consistent with your practice's procedures. |
| Optional / Voluntary Limitations | You may include additional, voluntary limitations on use and disclosure of protected health information. If included, the practice will be bound by them. | Only add optional promises that the practice can operationally support, since any voluntary limits become enforceable obligations. |
| Substance Use Disorder (Part 2) Section | If the practice creates or maintains substance use disorder records subject to 42 CFR Part 2, add a section explaining additional privacy protections and Part 2-specific rules. | Include Part 2 language only if applicable to your services. Adapt the template so it accurately describes handling of substance use disorder records and any consent requirements under 42 CFR Part 2. |
Special Situations: Family Access, Minors, and Substance Use Records
Can a spouse, parent, or caregiver view a patient's protected health information without the patient's written permission? The short answer is usually not automatically. These special situations require medical assistants to know exactly when authorization is needed and when disclosure is permitted.
Family Access: No Automatic Right
Family relationships alone do not grant access to a patient's health records. A spouse, adult child, or caregiver generally cannot obtain PHI unless:
- The patient provides written authorization: This is the clearest path and always the safest default.
- The patient verbally agrees or does not object: When a patient is present and capable, they can give or withhold permission on the spot.
- An exception applies: Emergency situations, incapacity, or specific legal authority (such as a healthcare power of attorney) may permit limited disclosure.
As a medical assistant, your safest practice is to ask patients directly who may access their information and document their preferences in the record.
Minors: State Laws Shape the Rules
Disclosure rules for minors depend heavily on state law and who has legal authority to consent to treatment. In some states, parents can access all of a minor's records. In others, minors who consent to their own care for specific services (such as reproductive health or mental health) may control access to those records.
Before sharing a minor's information with a parent or guardian, confirm your state's rules and check whether the minor consented to care independently. When in doubt, consult your supervisor or compliance officer.
Substance Use Disorder Records: 2026 Part 2 Changes
As of February 16, 2026, the Part 2 final rule compliance deadline changed how substance use disorder (SUD) records are handled. Key points for medical assistants:
- Single consent now allowed: Patients can sign one consent form covering all future uses and disclosures for treatment, payment, and healthcare operations.
- Records remain protected: Even though segregation is no longer required, the new Substance Use Disorder Record Rules confirm that SUD records still carry stricter protections than general health information.
- Redisclosure follows HIPAA: If your office receives SUD records under the new consent rules, you may redisclose them under HIPAA, but you must follow any limits attached to the records.
- Legal proceedings restricted: Under the HHS fact sheet on 42 CFR Part 2, SUD records cannot be used against a patient in civil, criminal, or administrative proceedings without specific consent or a court order.
Medical assistants should never treat SUD records as routine. Copying, faxing, scanning, or sharing these records requires following your office's specific workflow and any notice attached to the records.1 HIPAA breach notification rules also apply to SUD information, so handle these records with extra care.
When written authorization is required, do not proceed without it. When disclosure is permitted by law or patient direction, document the basis clearly.2
How to Stay Current: Policy Updates, Training, and Documentation
Staying compliant is less about reacting to every headline than about separating what triggers a required update from what benefits from a periodic refresh. For a medical office, the cost of putting this off is not just a possible fine; it is staff drifting into inconsistent habits around protected health information.
Update Frequency: Required vs Recommended
HIPAA requires an update after a material change to privacy practices, policies, or procedures.2 That may include a new EHR, a redesigned patient portal, a new release-of-information workflow, or a change in who has access to records. No federal rule prescribes an exact routine review schedule, but an annual review is a common practice, with a quicker targeted review after any major operational change. A good rule of thumb is to review the policy when you change the workflow and to put it on a calendar at least once a year. As of 2026, the federal six-year retention standard for privacy documentation has not changed.3
Staff Training and Documentation
Train each new hire on the current privacy policy before they handle protected health information. Retrain current staff whenever a material policy change affects their duties, and consider brief refreshers at least annually. Documentation should capture the policy version, training date, delivery method, and attendees. A sign-in sheet alone is thin; note which version staff reviewed so an auditor can see that training matched the policy in force at that time. If training is online, keep completion timestamps. A paper or electronic record should list attendees and the policy version they acknowledge.
The Six-Year Retention Rule
Keep privacy policies and procedures, notices of privacy practices, complaints and their dispositions, and signed patient authorizations for six years from the later of the date they were created or last effective.1 For signed patient authorizations, the six-year period starts from the date the authorization was last in effect, not necessarily the date it was signed.2 Amendments to privacy policies follow that same six-year rule.1 This applies to policy documentation; HIPAA does not set a federal retention period for the medical record itself, and medical record retention is generally state law, so keep the two timelines separate in the office manual.1
Version Control and Change Logs
Give each version a number, effective date, and a short description of what changed. Do not simply overwrite the prior draft; archive it. Retain the change log for the same six-year period, including what was revised, who approved it, and when it took effect. For material changes, confirm whether the notice of privacy practices also needs updating, then retrain and redistribute as needed.
Common Questions About HIPAA Privacy Policies
A HIPAA privacy policy is the internal rulebook your medical office follows to protect patient health information. These are the questions medical assistants ask most often once they start working with the policy day to day.
Policy Basics
- What is the difference between a privacy policy and a notice of privacy practices? The privacy policy is the internal document that tells staff how to handle protected health information. The notice of privacy practices is the patient-facing summary explaining how the office uses and shares that information, and what rights patients have.
- What should a HIPAA privacy policy include? At minimum: definitions of protected health information, permitted uses and disclosures, patient rights, staff responsibilities, safeguards for paper and digital records, breach response steps, authorization procedures, and training requirements.
Your Role and Daily Use
- Do medical assistants have to follow the privacy policy? Yes. Every workforce member with access to patient information is bound by the policy, regardless of role or hours. Violations can lead to discipline, termination, and, in serious cases, civil or criminal penalties.
- Can I see a sample HIPAA privacy policy for a medical office? Yes. The template section earlier in this guide walks through each required element with sample language you can adapt. Always have a compliance officer or attorney review the policy before adopting it.
Updates and Documentation
- How often should a medical office update its privacy policy? Review it at least annually, and any time regulations change, new technology is introduced, or a breach reveals a gap. Document each review with dates and signatures.
- What are the documentation requirements for patient authorization under HIPAA? A valid authorization must be in writing, describe the information to be disclosed, name who is releasing and receiving it, state the purpose, include an expiration date or event, and be signed and dated by the patient. Keep the signed form in the record for at least six years.






