N NPP Generator
EHR & Vendor

Does Tebra (Kareo + PatientPop) Provide an NPP?

By NPP Generator Research Team  ·  Published Apr 25, 2026  ·  Last reviewed Apr 28, 2026  ·  3 min read

Need to update your NPP?

Update → Generate new →
Quick answer: No. Tebra does not provide a HIPAA-compliant Notice of Privacy Practices for your practice. Tebra provides HIPAA-compliant infrastructure and signs a BAA on appropriate plans — but does not produce a HIPAA-compliant NPP. The NPP — the patient-facing HIPAA document required by 45 CFR § 164.520 — is the covered entity's responsibility to produce and maintain.

Tebra (formed from the Kareo + PatientPop merger) provides EHR, practice management, and patient-engagement tools for small practices. A common assumption among new Tebra customers is that the platform's HIPAA-compliant infrastructure or BAA covers the NPP requirement. It does not. The NPP is a covered-entity-side document — your practice produces it, distributes it, and posts it.

What Tebra does provide for HIPAA compliance

Tebra provides HIPAA-compliant infrastructure and contractual protections, but none of them are an NPP:

Plan tiers and BAA availability

Tebra offers tiered plans. The BAA is included on Professional and higher tiers and executed during onboarding.

How to request the BAA from Tebra

Tebra's BAA is executed during onboarding. The BAA portal is accessible to admin users; legal-team review is recommended before execution.

What the Tebra BAA covers (and doesn't)

The Tebra BAA binds Tebra to HIPAA's safeguard obligations for PHI it handles on your behalf. It does not produce an NPP, fulfill your NPP-distribution obligation, or substitute for any patient-facing HIPAA documentation. The BAA covers vendor-side responsibilities; the NPP covers practice-side patient communications.

Alternatives if you need NPP support

Tebra is well-suited to small practices that need a turnkey EHR + marketing stack. For the NPP itself, use NPP Generator's tool ($49) and upload to Tebra's patient portal as a shared intake document.

Setup after enabling Tebra's HIPAA features

Configure Tebra patient portal to deliver NPP at intake, post on practice website, and at physical office locations.

Common patient-facing scenarios with Tebra

In day-to-day operations using Tebra, several scenarios commonly surface NPP-related questions:

Audit-readiness with Tebra

When OCR or a state regulator audits a practice using Tebra, expect the auditor to request:

What changed in the HHS February 2026 model

The HHS February 2026 final rule introduced several NPP content updates that affect every covered entity, including practices using Tebra: clarified Right of Access language, updated breach-notification provisions, refined marketing-communication requirements, and explicit safeguards-against-AI language. Practices issuing or updating NPPs after February 16, 2026 should align to the new model. Tebra's patient-portal infrastructure typically supports either model; the document content is the practice's responsibility.

More EHR & vendor guides

Generate a compliant NPP in 5 minutes

HHS Feb 2026 model · Part 2 SUD language · Section 1557 taglines · whether you're updating or starting fresh.

No subscription · PDF + Word · Free watermarked preview · See sample →

Related: EHR & practice-management vendors

Frequently Asked Questions

Does Tebra provide a Notice of Privacy Practices?
No. Tebra provides HIPAA-compliant infrastructure and signs a BAA on appropriate plans, but does not produce a HIPAA-compliant NPP. The NPP is the covered entity's responsibility under 45 CFR § 164.520.
Does Tebra sign a BAA?
Yes, on appropriate enterprise/healthcare-tier plans. Tebra offers tiered plans. The BAA is included on Professional and higher tiers and executed during onboarding.
What's the cheapest way to get an NPP for my practice?
The HHS model notices are free and can be adapted manually, but they require you to fill in practice-specific fields (entity name, Privacy Officer, website, effective date) and add Part 2 SUD language if applicable. Tools like NPP Generator take the HHS model, capture practice information via a guided intake, and produce a formatted PDF and Word file for $49.
If I switch from Tebra to another EHR, do I need to update my NPP?
Possibly. The NPP describes uses and disclosures; if changing EHR materially changes data flows or vendor relationships, the NPP may need updating. Re-distribute on material change.
Does HIPAA-compliant infrastructure satisfy the NPP requirement?
No. HIPAA-compliant data hosting, encryption, and audit logging are Security Rule safeguards. The NPP is a Privacy Rule requirement under § 164.520 — distinct and not satisfied by infrastructure.