Does Epic EHR Provide an NPP for Your Practice?
By NPP Generator Research Team · Published Apr 25, 2026 · Last reviewed Apr 28, 2026 · 3 min read
Epic is the dominant enterprise EHR for hospitals and health systems. A common assumption among new Epic customers is that the platform's HIPAA-compliant infrastructure or BAA covers the NPP requirement. It does not. The NPP is a covered-entity-side document — your practice produces it, distributes it, and posts it.
What Epic does provide for HIPAA compliance
Epic provides HIPAA-compliant infrastructure and contractual protections, but none of them are an NPP:
- Enterprise-grade HIPAA-compliant infrastructure (encryption, audit logs, access controls)
- BAA executed during implementation contract (not provided as a separate downloadable PDF for self-service customers, since Epic doesn't have self-service customers)
- MyChart patient portal with patient-facing HIPAA notices customizable per organization
- Epic-supplied template patient documents (consent forms, etc.) — customizable but not pre-built NPPs
Plan tiers and BAA availability
Epic licenses to enterprise customers (hospitals and large health systems). The BAA is part of the standard enterprise contract. Epic does not have a SaaS-tier or self-service onboarding; BAA execution happens during the implementation contract.
How to request the BAA from Epic
Epic's BAA is negotiated as part of the enterprise implementation contract. Healthcare-system legal teams handle this directly with Epic's legal team. There is no self-service BAA portal.
What the Epic BAA covers (and doesn't)
The Epic BAA binds Epic to HIPAA's safeguard obligations for PHI it handles on your behalf. It does not produce an NPP, fulfill your NPP-distribution obligation, or substitute for any patient-facing HIPAA documentation. The BAA covers vendor-side responsibilities; the NPP covers practice-side patient communications.
Alternatives if you need NPP support
Hospital systems using Epic typically have legal/compliance teams that produce the system's NPP. For smaller organizations or entities that haven't built their own NPP, NPP Generator's tool produces a HHS-Feb-2026-aligned NPP in 5 minutes for $49 — Epic-customizable: upload as a MyChart shared document or distribute via your existing patient-engagement workflow.
Setup after enabling Epic's HIPAA features
Once the NPP is produced, configure MyChart to surface it during patient onboarding and post it on the practice/system's public website. Distribute to existing patients on next encounter or via the portal.
Common patient-facing scenarios with Epic
In day-to-day operations using Epic, several scenarios commonly surface NPP-related questions:
- New patient onboarding — present the practice's NPP at first encounter; capture acknowledgment electronically through the practice-management workflow
- Returning patients post-NPP-update — when the NPP materially changes, surface the updated NPP at the next encounter or via the patient portal
- Patient-portal NPP availability — make the NPP downloadable from the patient-portal documents area
- Right of Access requests — patients may request electronic copies of their records; the NPP describes this right and the practice's response process
- Vendor-relationship changes — if you switch from Epic to another EHR, the NPP may need updating to reflect the new vendor relationship
Audit-readiness with Epic
When OCR or a state regulator audits a practice using Epic, expect the auditor to request:
- Signed BAA between the practice and Epic
- Practice-issued NPP (current version)
- Acknowledgment-tracking documentation
- Evidence of patient-portal NPP availability
- Documentation of any data exchanges between the practice and other vendors (each requires its own BAA)
What changed in the HHS February 2026 model
The HHS February 2026 final rule introduced several NPP content updates that affect every covered entity, including practices using Epic: clarified Right of Access language, updated breach-notification provisions, refined marketing-communication requirements, and explicit safeguards-against-AI language. Practices issuing or updating NPPs after February 16, 2026 should align to the new model. Epic's patient-portal infrastructure typically supports either model; the document content is the practice's responsibility.
More EHR & vendor guides
Generate a compliant NPP in 5 minutes
HHS Feb 2026 model · Part 2 SUD language · Section 1557 taglines · whether you're updating or starting fresh.
No subscription · PDF + Word · Free watermarked preview · See sample →
Related: EHR & practice-management vendors