HIPAA for NEMT providers: what applies to you and what to put in place
HIPAA reaches NEMT companies in two ways. A company that bills health plans electronically may be a covered entity itself, and one that handles rider information for a broker or health plan usually signs a business associate or subcontractor agreement. Either way you need a risk analysis, written policies, trained staff, safeguards for manifests and phones, vendor agreements, and breach notice within 60 days.
On this page
How HIPAA reaches an NEMT company
HIPAA applies to covered entities and their business associates. An NEMT company can land in either group, and brokers write HIPAA duties into their contracts either way. Knowing which role you hold tells you who you report to when something goes wrong.
| Your situation | Likely HIPAA role | Why |
|---|---|---|
| You bill Medicaid or health plans electronically for your own trips | Possibly a covered entity | HIPAA covers health care providers that transmit health information electronically in connection with a standard transaction, such as a claim |
| You run trips assigned by a broker or health plan | Business associate or subcontractor | You receive and create protected health information on their behalf |
| Private-pay or facility work with no electronic billing | Often outside HIPAA directly, but contracts may still require it | HIPAA turns on the definitions, not on the word “medical” |
HHS OCR links to a question-and-answer decision tool for covered entity status. If your answer is unclear, use it and ask a health care attorney. In practice the contract settles most of it. Virginia’s NEMT standards require drivers and attendants to comply with HIPAA, MTM’s provider handbook says it mandates that all transportation providers remain HIPAA compliant, and Modivcare’s annual attestation includes HIPAA privacy and security training.
What counts as protected health information in NEMT
Protected health information is individually identifiable health information, in any form. It includes demographic details tied to a person’s health, the care they receive, or payment for that care. In a transportation company, that covers a lot:
- Manifests with rider names, addresses, and phone numbers
- Destinations, because a dialysis center or a treatment clinic reveals a condition
- Mobility needs, oxygen, attendants, and notes about behavior
- Medicaid or member ID numbers and trip authorization numbers
- Signatures, trip logs, and billing records
A paper manifest on a dashboard is PHI. So is a driver’s phone showing tomorrow’s schedule.
The Privacy Rule in daily operations
The Privacy Rule’s minimum necessary standard is the one you apply most. When you use or share PHI, you must make reasonable efforts to limit it to the minimum needed for the purpose. A driver needs a pickup address, a time, and mobility needs. A driver does not need a diagnosis.
Broker manuals turn this into concrete driver rules. CareOregon’s provider manual tells drivers to leave no papers or devices with member information where others can see them, and not to discuss member information over the phone or radio in front of others. Virginia bars the words “Medicaid” or “FAMIS” from vehicles and business names, and requires that member identifying information not be visible to other passengers.
Good habits to write into policy:
- Keep manifests face down or on a locked phone, never on the dash.
- Confirm pickups with the rider by name only, not by appointment type.
- Use the rider’s first name and a pickup location on the radio, never a diagnosis.
- Shred printed manifests before the driver goes home.
The Security Rule starts with a risk analysis
If you are a covered entity or business associate and keep rider data electronically, the Security Rule applies to that data. Its first required step is a risk analysis: an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic PHI you hold. Risk management follows, meaning security measures that bring those risks down to a reasonable and appropriate level.
HHS OCR’s guidance says the risk analysis should be ongoing, and that small organizations usually have fewer systems and people to account for. The rule does not set a frequency. HHS notes that some organizations repeat it every year and others as needed, such as every two or three years. The Security Risk Assessment Tool from ONC and OCR is designed to help small and medium-sized practices and business associates.
For an NEMT company, the list of places PHI lives is usually short:
- Dispatch and billing software
- Driver phones and tablets
- Office computers and shared email inboxes
- Broker portals and downloaded trip files
- Paper files and the filing cabinet
The technical safeguards in 45 CFR 164.312 turn into a few concrete settings:
- Unique logins. Every user gets their own login. This one is required, so no shared dispatch passwords.
- Automatic logoff and encryption. Both are addressable. You adopt them, or you document why they are not reasonable and put an equivalent measure in place.
- Audit controls. Systems that hold rider data must record activity so you can review who opened or changed a record.
HHS proposed an update to the Security Rule on January 6, 2025. As of September 2026 it remains a proposal, so today’s rule is the one you must meet.
Business associate agreements with your vendors
Any vendor that creates, receives, maintains, or transmits PHI for you needs a business associate agreement. For an NEMT company that usually means dispatch software, a billing service, an answering service, and file storage.
Under 45 CFR 164.504(e), the agreement must:
- Limit how the vendor may use and disclose the information
- Require appropriate safeguards and compliance with the Security Rule
- Require the vendor to report misuse and breaches to you
- Bind the vendor’s own subcontractors to the same terms
- Require return or destruction of the data when the contract ends, if feasible
Ask for the agreement before you sign the order. Our guide to choosing NEMT software covers what else to check in a vendor. Modivcare’s 2025 attestation also has providers certify they do not receive, view, process, or store PHI outside the United States, so ask vendors where your data sits.
Training and documentation
Training duties depend on your role. A covered entity must train every workforce member on its privacy policies, as needed for their job. New staff must be trained within a reasonable time after they start, and everyone affected must be retrained when a policy changes materially. The training must be documented. Covered entities and business associates alike must also run a security awareness and training program for the whole workforce, management included.
Keep your HIPAA policies and required records for six years from creation or from the date they were last in effect, whichever is later. Broker contracts can go further. Modivcare’s 2025 attestation has providers certify that owners and drivers completed its compliance training, HIPAA included, for the calendar year. New employees must finish it within 30 days of hire, and training records must be kept for at least 10 years. MTM’s handbook lists fraud, waste and abuse and HIPAA training among its required courses. Our NEMT driver training guide puts these on one schedule.
When something goes wrong: breach notification
Any use or disclosure the Privacy Rule does not permit is presumed to be a breach unless a documented risk assessment shows a low probability the information was compromised. A lost, unlocked phone holding a day of manifests would likely qualify. Notice duties apply to unsecured PHI, and data encrypted to the standard in HHS guidance does not count as unsecured. That is one more reason to encrypt every phone and laptop. The clock starts on the day the breach is known, or would have been known with reasonable diligence.
| Who you notify | When |
|---|---|
| Each affected rider | Without unreasonable delay, no later than 60 calendar days after discovery |
| HHS, for 500 or more people | At the same time as the rider notices |
| Prominent media, for more than 500 residents of a state | Within the same 60 days |
| HHS, for fewer than 500 people | In a log reported within 60 days after the end of the calendar year |
| The covered entity, if you are its business associate | Without unreasonable delay, no later than 60 calendar days after discovery |
Your broker contract may set its own, shorter deadline for telling the broker. Check it before you need it.
HIPAA penalty amounts after the 2025 adjustment
HHS adjusts civil penalties for inflation every year. These are the 2025 figures in 45 CFR 102.3 for violations on or after February 18, 2009.
| Culpability | Per violation | Yearly cap |
|---|---|---|
| Did not know, and could not have known with reasonable diligence | $145 to $73,011 | $2,190,294 |
| Reasonable cause, not willful neglect | $1,461 to $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 to $73,011 | $2,190,294 |
| Willful neglect, not corrected within 30 days | $73,011 to $2,190,294 | $2,190,294 |
A HIPAA checklist for NEMT owners
- Decide your role for each line of business: covered entity, business associate, or subcontractor.
- Name a privacy and security officer, even if it is the owner.
- Complete and date a risk analysis, then fix the top risks first.
- Write short policies for manifests, phones, radio talk, texting, and records disposal.
- Sign business associate agreements with every vendor that touches rider data.
- Train every driver and dispatcher before their first shift, and keep sign-in sheets.
- Lock every device with a passcode and set screens to lock automatically.
- Write a breach response plan with the contacts and deadlines above.
- Review everything once a year and after any incident.
Protecting rider data in HealthRide
In HealthRide, patient information is encrypted and protected, and each person on your team only sees what their role allows. We sign business associate agreements with our providers. Drivers see their trips in the driver app instead of on printed manifests, and dispatch conversations stay in team chat instead of personal text threads.
Frequently asked questions
- Is an NEMT company a HIPAA covered entity?
- It depends on what you do. HIPAA covers health care providers that transmit health information electronically in connection with a standard transaction, such as a claim. A company that only runs trips for a broker usually handles rider information on the broker's behalf under a business associate or subcontractor agreement. HHS links to a decision tool that walks through the definitions, and your broker contract usually spells out your role.
- Can drivers text trip details to each other?
- Only through a channel your risk analysis says is safe, and only the minimum needed. Plain text messages on personal phones leave rider names and destinations on devices you do not control. Keep trip details inside your dispatch system or another tool covered by a business associate agreement, and train drivers not to forward screenshots of manifests.
- How long do I have to report a HIPAA breach?
- Notify affected riders without unreasonable delay and no later than 60 calendar days after you discover the breach. If 500 or more people are affected, notify HHS at the same time, and notify prominent media when more than 500 residents of one state are involved. Smaller breaches go in a log you report to HHS within 60 days after the end of the calendar year. If you are a business associate, you notify the covered entity instead, within the same 60 days.
- How much are HIPAA fines in 2026?
- The 2025 inflation adjustment in 45 CFR 102.3 sets per-violation penalties from $145 to $73,011 when the violator did not know, and from $73,011 up to $2,190,294 for willful neglect that is not corrected within 30 days. The yearly cap for identical violations is $2,190,294. HHS adjusts these amounts every year.
- Does HIPAA require annual training?
- No. A covered entity must train every workforce member, train new hires within a reasonable time after they start, and retrain people when a policy change affects their job. Covered entities and business associates both need an ongoing security awareness program. Neither rule names a yearly schedule. Broker contracts often do: Modivcare's 2025 attestation covers HIPAA privacy and security training for each calendar year, and new employees must finish it within 30 days of hire.