The NPP must include language that a ???Covered Entity is required to notify affected individuals following a breach of unsecured PHI??? and if the entity is a health plan, the NPP must be updated within 60 days of a material revision to the privacy policy and provided to the individual.16According to 45 CFR ??164.520 of the Megarule, the NPP must also include ???a statement that other uses and di