There is a decent chance your Notice of Privacy Practices currently describes a federal rule that no longer exists.
Not a rule that changed. One that a court struck down nationwide, in June of last year, and that has not applied to anyone since.
The Clause That Outlived Its Rule
In 2024 a federal rule added special protections for reproductive health information, and a lot of us updated our privacy notices to match. Form vendors did too. It was the responsible thing to do at the time.
Then a federal court vacated that rule nationwide in Purl v. HHS.
Nothing arrived in your inbox when that happened. No vendor emailed you. The PDF on your hard drive did not change. It just quietly became a document describing a legal obligation that had been erased, handed to patients at intake, with your practice name on it.
That is the whole problem with compliance forms in one example. They do not fail loudly.
A form pack does not expire. It just keeps printing.
New York Moved in the Other Direction
While that federal rule was being struck down, New York was expanding.
The state's breach notification law now carries a 30-day deadline for notifying affected individuals, and the definition of "private information" was widened to expressly include medical information and health insurance information. That change came through an amendment to General Business Law 899-aa.
Read those two together. One obligation vanished and another got broader and faster, inside the same stretch of months. If your forms were written before both, they are wrong in two directions at once, and nothing on the page tells you so.
"So Who Would Even Notice?"
Fair question, and I asked it myself for a long time. The honest answer is that it is probably not an auditor. It is you.
HIPAA requires a practice to abide by the terms of the notice it currently has in effect. A privacy notice is not a filing. It is a promise, in writing, handed to a patient with your name on it. If yours still promises heightened handling of reproductive health information, that is now the standard you have told your patients you will meet, whether or not any rule still requires it of you. You are held to the document you gave them, not the document you meant to give them.
The New York side is worse, because it does not require anyone to catch you at all. If your breach template still says 60 days and the law now says 30, you will do everything right. You will follow your own procedure, on your own timeline, and be a month late.
That is the part that changed my thinking. A stale form is not a filing error sitting quietly in a drawer. It is an instruction you will follow at the worst possible moment.
So How Would You Know?
Honestly, most practices would not. You would find out during an audit, or from a patient's attorney, or from a colleague who happened to read the right thing.
The usual answer is a static PDF. You buy a compliance form pack, you file it, and it slowly drifts away from the law it was built on. The document looks exactly as authoritative on year three as it did on day one, which is precisely what makes it dangerous.
So I built the boring fix.
The Vault is now monitored by a system I call Compliance Watch. Every two weeks it checks authoritative government sources for each law a Vault form actually depends on. HIPAA notice requirements. New York breach notification. 42 CFR Part 2. The Medicare ABN. New York records access law. When something material is enacted or newly proposed, it flags it.
Here is the part that matters, and the part I will not automate. Compliance Watch does not touch a form. It raises a flag. I read the flag, go to the primary source myself, and decide whether the form genuinely needs to change. Only then does anything ship.
That human step is not a bottleneck I am apologizing for. It is the product. An automated system that edited legal documents on its own would be worse than a stale PDF, because you would trust it more.
What It Actually Found This Cycle
Five flags. Here is every one, and what happened to it.
The reproductive health clause in the Notice of Privacy Practices. Removed, because the rule it implemented was vacated. Real change.
The New York breach notification template. Updated for the 30-day deadline and the broader definition of private information. Real change.
The 42 CFR Part 2 consent. Checked against the 2024 single-consent rule. Already compliant. No change.
The Medicare ABN, form CMS-R-131. A 2026 refresh, cosmetic only. No change needed.
New York records access fees under Public Health Law 18. Already covered. One mammogram-specific nuance noted for a future primary care and OB-GYN edition.
Two real updates out of five flags. Three verified as already fine.
That ratio is the point. An unsupervised system would have "updated" all five and handed you three rounds of pointless churn, new version numbers, and re-reading you did not need. A static PDF would have caught none of them. What you want is somebody checking, and then mostly telling you that you are fine.
What You Need To Do
If you own the Vault: nothing. Version 2.3 is live and it is already yours. Your access link always returns the current version, so the updated Notice of Privacy Practices and the updated New York breach template are sitting there right now, at no additional cost. Open the link you were sent and you have them.
If you do not: go look at your Notice of Privacy Practices right now, today, before you do anything else. If it contains reproductive health privacy language added in 2024, it is describing a rule that no longer exists, and it is the document you hand patients at intake.
A note on what these are. The Vault is a set of templates and internal policies that a practice reads, adapts, and adopts for its own circumstances. Review anything you adopt with counsel licensed in your jurisdiction before it goes in front of a patient. It is not legal advice and it is not a compliance guarantee, and anyone selling you either of those is selling you something they cannot deliver. What it is: current, verified against the actual statutes and rules it is built on, by a person, on a schedule.
A New York chiropractic edition is in final review. If that is your practice, reply and I will tell you when it is out.
Version 2.3 is live. Owners already have it.
The Private Practice Protection Vault is a stamped, personalized set of HIPAA and state compliance forms plus 35 internal practice policies, monitored by Compliance Watch and updated by hand when the law actually moves. Your access link always returns the current version. National edition $299. New York edition $349 (adds SHIELD Act and state-specific addenda).
With security,
Brad
Brad Lieberman, JD (retired), MSN, PMHNP-BC
Founder, The Encrypted Chart
www.encryptedchart.com · Vault: store.encryptedchart.com/l/binder
[email protected]
Sources
Purl v. U.S. Department of Health and Human Services, vacating the 2024 HIPAA reproductive health care privacy rule nationwide, June 2025.
Uses and disclosures consistent with notice, 45 CFR § 164.502(i), requiring a covered entity to abide by the terms of the notice of privacy practices it currently has in effect.
New York General Business Law § 899-aa, as amended by Chapter 647 of the Laws of 2024.
42 CFR Part 2, as revised by the 2024 final rule permitting a single patient consent for treatment, payment, and health care operations.
Centers for Medicare and Medicaid Services, Advance Beneficiary Notice of Noncoverage, form CMS-R-131.
New York Public Health Law § 18, governing patient access to records and permitted fees.
