Compliance

Cyber insurance for NEMT companies: what it covers and what insurers ask first

Updated 7 min read

Cyber insurance pays what a NEMT company faces after a data breach, ransomware attack, or email fraud: forensics, legal advice, rider notices, data restoration, lost income, extortion, and lawsuits. Insurers ask first about multifactor sign-in on email, remote access, and admin accounts, about tested backups, and about approval rules for payments. Read the exclusions for war and failure to maintain security, and the payment fraud limit.

On this page

Why a transportation company needs cyber coverage

A NEMT company holds the kind of data and money flows that criminals go after. Your system has riders’ names, home addresses, phone numbers, Medicaid IDs, and appointment details. Your staff log into broker portals, pay drivers and vendors, and take card payments.

The federal numbers show where the money goes. The FBI’s Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025, with reported losses of about $3.05 billion. It also received more than 3,600 ransomware complaints with more than $32 million in reported losses, a figure the FBI notes usually leaves out lost business, time, and equipment.

Health information adds legal duties on top of the cleanup. Under the HIPAA Breach Notification Rule, improper access to, use of, or disclosure of rider health information counts as a breach by default. The exception is a documented risk assessment finding only a low chance that the data was compromised. Then the notice clocks start:

Who must be toldDeadline
Each affected riderAs soon as reasonably possible, 60 calendar days after discovery at the latest
Prominent media outletsSame deadline, when more than 500 residents of one state or jurisdiction are affected
HHSAt the same time as riders for 500 or more people; within 60 days after the end of the calendar year for smaller breaches
The health plan, broker, or other covered entity you work for as a business associateAs soon as reasonably possible, 60 days after discovery at the latest

Every state also has a breach notification law of its own, according to the National Conference of State Legislatures. Broker agreements add their own reporting duties. MTM’s Pennsylvania agreement, for example, requires providers to report any breach of member information to MTM and to sign its business associate agreement. The HIPAA guide for NEMT explains which role your company plays.

What a cyber policy pays for

Cyber policies have two halves. The FTC’s guidance, written with the National Association of Insurance Commissioners, describes them this way.

PartWhat it typically paysA NEMT example (for illustration)
First-party coverageLegal counsel on notification duties, data recovery, rider notification and call center, lost income from business interruption, crisis management, cyber extortion and fraud, forensic investigation, and fees, fines, and penalties tied to the incidentRansomware locks the dispatch office for three days, trips go unassigned, and letters must go to every rider on file
Third-party coveragePayments to affected people, claims and settlements, defamation and infringement claims, litigation and regulatory response, other judgments, and accounting costsRiders sue after their Medicaid numbers appear online, and a regulator opens an inquiry

The FTC also suggests confirming that a policy covers attacks on your data held by vendors, attacks anywhere in the world, and terrorist acts, and that it includes a duty to defend and a breach hotline available at all hours. For a NEMT company, the vendor point matters: your trip data may sit with a dispatch software company, a broker portal, and a payment processor.

Most cyber cover comes in one of two forms. NAIC’s 2025 market report found that in 2024, 55.1 percent of U.S. cyber policies in force were endorsements attached to another policy, and 41.6 percent were stand-alone primary policies. Endorsements are high volume and low premium, so check the limit on any cyber endorsement already inside your package policy before relying on it.

Contracts that ask for it

Broker agreements such as MTM’s set HIPAA duties without naming a cyber policy, but some transportation contracts name the coverage and a limit. Community Care Plan, a Florida Medicaid health plan, issued a request for proposals for non-emergency transportation on March 25, 2026. Bidders had to agree to carry, if awarded:

  • $1 million general liability per occurrence
  • $5 million umbrella liability in the aggregate
  • $1 million auto liability, combined single limit
  • Workers’ compensation per statute
  • $1 million professional liability
  • $10 million cyber liability per occurrence and in the aggregate

The plan had to be named as an additional insured on all policies, with certificates submitted with the proposal. When a facility, county, or health plan contract names a cyber limit, send that page to your agent with your application. Our guide to professional liability and abuse coverage covers the other lines those contracts list.

What the application asks first

Cyber applications are short on business questions and long on security controls. One cyber application used by the wholesale broker CRC Group shows the pattern. It asks:

  1. Records and data. How many personal records you hold (in bands starting at 0 to 250,000), whether you handle HIPAA health information with procedures and encryption for transmitted records, and whether you take card payments.
  2. Multifactor sign-in. Whether it is required for all remote access to your network, all web-based email, administrator accounts, and access to cloud backups.
  3. Basic defenses. Firewall and antivirus, intrusion detection, email filtering for malicious attachments and links, and email authentication (SPF, DKIM, and DMARC).
  4. Patching. Whether you monitor vulnerabilities and apply security patches within 30 days of release.
  5. Backups. How often you back up, whether backups are protected by multifactor sign-in, tested in the last six months, and able to restore essential functions within three days of a ransomware attack, and whether you keep copies on two media with one off site.
  6. Encryption and monitoring. Encryption of sensitive data on your network, in the cloud, and on mobile devices, plus an endpoint detection and response tool with central monitoring.
  7. People and payments. Annual security training, and whether any wire or fund transfer over $25,000 needs approval and verification by two employees.
  8. Testing and history. A vulnerability assessment in the past 18 months, a tested continuity plan, and three years of claims, breach notices, extortion demands, outages, and wire transfer or phishing losses.

The FBI’s ransomware recommendations in its 2025 report cover much of the same ground: offline backups that are encrypted and cannot be altered, multifactor sign-in for webmail, VPNs, and accounts that reach critical systems, endpoint detection and response tools, and prompt patching.

The signature section matters as much as the questions. It states that the application forms the basis of the contract, becomes part of the policy if coverage is bound, and that you must report in writing any change before the effective date. Answer only what is true today. Our NEMT cybersecurity guide walks through putting those controls in place at a small fleet.

Exclusions and limits to read before you sign

The Maryland Insurance Administration describes cyber coverage as customized to each business, so read the exclusions and sublimits, not just the headline limit.

  • War and hostile acts. NAIC reports that U.S. cyber policies typically exclude losses from war, terrorism, or other hostile acts. Since March 31, 2023, Lloyd’s has required standalone cyber-attack policies written in its market, at inception or renewal, to carry a clause excluding losses from state backed cyber attacks that meet its criteria.
  • Failure to maintain security. Some carriers exclude claims that result from the insured’s failure to keep minimum or adequate security standards. Application answers therefore need to stay true for the whole policy term.
  • Deductibles and sublimits. NAIC found that insurers raised deductibles and added sublimits inside policies after the rise in ransomware. Ask for the limit on each part: ransomware, business interruption, notification, regulatory fines.
  • Payment fraud. Ask in writing whether a payment your staff send because of a fake email or a spoofed vendor is covered, and for how much. It may carry its own sublimit, so compare that number with your largest regular payments.
  • Vendors and downtime. Confirm that an outage or breach at your dispatch software or payment vendor counts, and when business interruption coverage starts paying.
  • Defense and hotline. Look for duty to defend wording and a breach hotline that answers every day at any hour, as the FTC recommends.

When something happens

Call the insurer’s breach hotline first, and check the policy’s rules on choosing lawyers and forensic firms before you hire anyone. Then:

  1. Stop the money. If a payment went to a fraudster, call your bank at once and ask for a recall. The FBI’s Recovery Asset Team handled 3,900 fraudulent transfer cases in 2025 and froze about $679 million of roughly $1.16 billion in attempted theft, and it asks victims to file at ic3.gov with full transaction details.
  2. Preserve evidence. Keep logs, emails, and affected devices as they are until the forensic firm says otherwise.
  3. Start the HIPAA clock. The 60-day notice period runs from the day of discovery, so record that date.
  4. Tell your brokers as their agreements require, and tell riders only what counsel approves.

Any decision about a ransom demand belongs with your insurer and counsel, never with a staff member acting alone. The FBI asks ransomware victims to file a report with IC3 as well.

Security built into HealthRide

HealthRide is HIPAA compliant. Sign-ins can use passkeys or two-step codes, each person sees only what their role allows, every change is recorded, and rider details stay off phone lock screens. Two-step sign-in is one of the first controls cyber applications ask about. The provider portal page explains how access works for your team.

Frequently asked questions

Does my general liability or business owner's policy cover a data breach?
Do not assume it does. The Maryland Insurance Administration lists cyber liability as its own type of coverage, separate from general liability, and NAIC data show that many cyber policies in force are endorsements added to another policy rather than stand-alone policies. Ask your agent whether your package includes a cyber endorsement, what it pays for, and its limit, then decide whether you need a stand-alone policy.
Do NEMT brokers require cyber insurance?
Some transportation contracts do. Community Care Plan, a Florida Medicaid health plan, told bidders on its March 2026 non-emergency transportation request for proposals that the winning vendor must carry $10 million in cyber liability per occurrence and in the aggregate, with the plan named as an additional insured. MTM's Pennsylvania provider agreement, by contrast, sets HIPAA duties instead: providers must report any breach of member information to MTM and sign a business associate agreement.
Will cyber insurance pay a ransom?
It may. The FTC lists cyber extortion among the typical first-party costs a cyber policy covers, but the policy wording decides what is paid and on what conditions. Call the insurer's breach hotline before anyone talks to the attackers, and read what the policy requires before any payment. Restoring from clean, offline backups, which the FBI recommends keeping, is the way out that does not depend on paying.
What happens if my application answers turn out to be wrong?
The claim can be disputed or the policy cancelled. On applications like CRC Group's, the signed application becomes part of the policy, and you agree to report changes before coverage starts. NAIC reports that some cyber policies carry a failure to maintain security exclusion, which denies claims when the insured did not keep the minimum security it promised. If you answered yes to multifactor sign-in on email, it has to be on for every account.
How fast do I have to notify riders after a breach?
Under HIPAA, a covered entity must tell each affected person promptly, and within 60 calendar days of discovering a breach of unsecured health information at the latest. A breach affecting more than 500 residents of a state also requires notice to prominent local media, and breaches of 500 or more go to HHS at the same time. If you are the broker's or plan's business associate, your notice to them is due within the same 60 days. Every state also has its own breach law.

Official resources

HealthRide plans the whole day in one click and bills every ride.