Cybersecurity for NEMT companies: stopping phishing, account takeovers, and data loss
HHS names five top threats to health care organizations, and four apply to NEMT companies: phishing and other social engineering, ransomware, lost or stolen devices, and insider data loss. A small provider blocks most of them with phishing-resistant sign-in on email, broker portals, and bank accounts, one login per person, same-day removal of former staff, updated and encrypted devices, offline backups, and a written response plan.
On this page
A NEMT company holds a lot that criminals want and very little security staff to protect it. Rider names, home addresses, and Medicaid numbers sit in the dispatch system. Trips and claims sit behind broker portal logins. Payroll and vendor payments run through one email inbox and one bank login. And when the dispatch system goes down at 5 AM, dialysis riders miss treatment.
Nothing here requires an IT department. It requires a handful of settings and habits, applied to every person and every device. This guide covers the attacks that actually hit small providers, the sign-in and device rules that stop most of them, the federal practices HHS recognizes, and what to do in the first hours of an incident. If your company is covered by HIPAA, the Security Rule makes much of this a legal duty, as our HIPAA guide for NEMT providers explains.
The threats that hit small providers
HHS’s Health Industry Cybersecurity Practices (HICP), 2023 edition, names five threats facing health care organizations. Four of them map directly onto a transportation company.
| Threat (HICP) | How it shows up in a NEMT company |
|---|---|
| Social engineering | A fake “broker portal” email asking a dispatcher to sign in, a text claiming to be the bank, a caller posing as IT |
| Ransomware | Dispatch computers and files locked, and a payment demanded before they are released |
| Loss or theft of equipment or data | A driver’s phone left at a pickup, a dispatch laptop taken from a van |
| Insider, accidental or malicious data loss | A former dispatcher still logged in, a manifest emailed to the wrong address |
The fifth, attacks on network-connected medical devices, rarely applies to transportation.
Money theft through email deserves its own mention. The FBI’s 2025 Internet Crime Report counted 24,768 business email compromise complaints with reported losses of $3,046,598,558. The FBI describes these scams as aimed at businesses that pay suppliers by wire, using compromised email accounts or other channels to push through an unauthorized transfer. A NEMT version, as an example: a message that appears to come from your fuel vendor or your accountant, asking you to send this month’s payment to a new bank account. Confirm any change of payment details by calling a number you already have on file.
Ransomware is a health care problem in particular. The same FBI report says the ten most reported ransomware variants in 2025 hit three critical sectors hardest, and Healthcare and Public Health was one of them.
Lock down the accounts that matter most
Three kinds of accounts carry most of the risk: email, broker portals, and anything that moves money.
- Email is the master key. Whoever controls an inbox can reset the password on almost every other account tied to it.
- Broker portals hold member details, trip assignments, and claims. MTM’s Rhode Island provider handbook (updated July 1, 2026) describes its MTM Link portal as the place providers manage trips, submit claims, and update driver profiles, and the same login works in its driver app.
- Bank, payroll, and card processing accounts move money directly.
Every one of those accounts needs multifactor sign-in. HHS lists multifactor authentication among its essential cybersecurity goals for health care, and the FBI recommends it for all services where possible, particularly webmail and accounts that reach critical systems. Some broker portals build it in. MTM Link, for example, asks for a six-digit code, delivered by text or email, each time a user signs in. The code expires after ten minutes, and users can choose to have the portal remember a device for 30 days. Leave that box unchecked on any shared office computer.
Not all second factors are equal
CISA ranks sign-in methods by how well they hold up against attack. Its guidance is that any form of multifactor sign-in beats a password alone, and that phishing-resistant sign-in is the gold standard.
| Sign-in method | Stands up to a fake login page | Main weakness |
|---|---|---|
| Passkey or hardware security key (FIDO/WebAuthn) | Yes | Needs a supported device and service |
| Authenticator app code or push with number matching | No | A fake page can relay a typed code |
| Push approval without number matching | No | Repeated prompts until someone taps Accept |
| Texted or voice code | No | SIM swaps and phone network weaknesses, plus relay |
| Password only | No | Stolen or guessed passwords |
NIST’s authentication guideline, revised in July 2025, explains why. Any code a person types in, whether it arrives by text or comes from an app, is not phishing-resistant, because a fake site can pass it straight to the real one. The guideline names WebAuthn as a standard that resists phishing by tying the sign-in to the real site’s name. It also classifies codes sent over the phone network as a restricted method. CISA’s November 2025 mobile guidance calls FIDO passkeys an acceptable alternative to hardware security keys. In practice: turn on passkeys wherever a service offers them, and use an authenticator app everywhere else.
Passwords that still matter
Passwords remain part of most sign-ins, and NIST’s current rules for them are simpler than most office habits. A password used on its own should be at least 15 characters, and one used with a second factor at least 8. NIST says systems should not force character mixes or periodic changes, but should force a change when there is evidence a password was compromised. A password manager makes long, unique passwords realistic for a dispatcher juggling six portals.
One person, one login
Shared logins make every other control useless, because nobody can tell who did what. The HIPAA Security Rule requires unique user identification (45 CFR 164.312(a)), and HHS’s performance goals list unique credentials and separate admin accounts among the essentials. The owner’s everyday account should not be the one that can delete users or change bank details.
Removing access is where small companies slip. HHS names prompt removal of access for departing employees, contractors, and volunteers as an essential goal, and the Security Rule calls for procedures to end access when employment ends (45 CFR 164.308(a)(3)). Build an offboarding checklist and run it the day someone leaves:
- Disable the person’s login in your dispatch and billing software.
- Remove them from each broker portal and its driver app.
- Close or suspend their company email and delete any forwarding rules they set.
- Change the passwords of any account they shared, including voicemail and Wi-Fi.
- Collect or wipe company devices, and remove company accounts from personal phones.
- Take them out of group chats and shared drives.
Phones, tablets, and the dispatch laptop
Lost and stolen devices are one of HICP’s five threats, and in a NEMT company every driver carries a phone that can open rider data. The Security Rule’s device and media controls call for policies on hardware that holds rider data, including how it is disposed of and reused (45 CFR 164.310(d)).
Set a short device standard:
- Screen lock and encryption on every device that opens rider data. HHS guidance says electronic PHI encrypted to its standard, with the key kept safe, does not count as unsecured, so losing an encrypted phone does not trigger breach notification.
- Automatic updates on. HHS lists fixing known vulnerabilities as its first essential goal, and the FBI ranks prompt patching among the cheapest and most effective protections a company has.
- Malware protection on. The FBI advises setting anti-virus and anti-malware tools to update themselves and scan on a regular schedule.
- Remote wipe ready before a phone goes missing, not after.
- No shared family devices signed in to work accounts.
- Lock-screen previews off for work apps, so a phone on the dashboard shows nothing about riders.
The HIPAA texting guide covers personal phones and group texts in more detail.
Ransomware and backups
Plan on the assumption that one day your files will be locked. HHS’s ransomware fact sheet says that when ransomware encrypts electronic PHI, the data has been acquired by unauthorized people, so a breach is presumed. Notification can be avoided only when a written risk assessment concludes the chance of compromise is low (45 CFR 164.402).
The HIPAA Security Rule already requires a contingency plan with three required parts: a data backup plan, a disaster recovery plan, and an emergency mode operation plan (45 CFR 164.308(a)(7)). For backups, HHS and the FBI give the same advice:
- Back up frequently, and confirm each backup finished.
- Test restoring from backup on a schedule, so you know it works.
- Keep at least one copy offline or otherwise disconnected, because some ransomware deletes connected backups. The FBI adds that backups should be encrypted and immutable.
HIPAA’s emergency mode plan is about keeping rider data protected while systems are down. Pair it with a plan for keeping rides moving: decide in advance who calls drivers, where the next day’s trip list comes from, and how riders on dialysis and chemotherapy schedules get priority.
One enforcement case shows the cost of skipping the basics. On May 30, 2025, HHS’s Office for Civil Rights announced a settlement with Comstar, LLC, a Massachusetts company that handles billing for nonprofit and municipal ambulance services. Attackers entered its servers on March 19, 2022, the company did not detect them until March 26, and ransomware encrypted data on about 585,621 people. OCR found that Comstar had failed to conduct an accurate and thorough risk analysis. The company paid $75,000 and accepted two years of monitored corrective action.
The practices HHS recognizes
Two HHS resources turn “be secure” into a list, and a 2021 law gives you a reason to follow them. Public Law 116-321 requires HHS, when it sets HIPAA fines, audit terms, or settlement remedies, to consider whether a company had recognized security practices in place for at least the previous 12 months. The law names NIST’s standards and the practices issued under section 405(d) of the Cybersecurity Act of 2015, which is where HICP comes from. It also says HHS cannot raise a penalty for not adopting them.
HHS’s voluntary healthcare cybersecurity performance goals set ten essentials:
| Essential goal | A NEMT company’s version |
|---|---|
| Mitigate known vulnerabilities | Automatic updates on every computer and phone |
| Email security | Filtering for spoofed and phishing mail, and staff who report it |
| Multifactor authentication | On email, broker portals, bank, payroll, and dispatch software |
| Basic cybersecurity training | A short session at hire and a refresher each year |
| Strong encryption | Encrypted devices and encrypted connections |
| Revoke credentials for departing workforce | The offboarding checklist, run the same day |
| Basic incident planning and preparedness | A one-page response plan with phone numbers |
| Unique credentials | One login per person, no shared passwords |
| Separate user and privileged accounts | Admin rights on a separate account |
| Vendor and supplier cybersecurity requirements | Security questions and a business associate agreement before signing |
The Security Rule itself may tighten. HHS proposed changes on January 6, 2025 that would, among other things, require multifactor authentication and written procedures for bringing critical systems and data back in 72 hours or less. As of September 2026, no final rule has been published, and HHS’s regulatory agenda lists final action for July 2027. Until then, the current rule is the one that applies. Building to the goals above now prepares you either way.
Choosing vendors that do not add risk
Every vendor with access to rider data extends your attack surface. Before signing, ask each one:
- Will you sign a business associate agreement?
- Do you support passkeys or other multifactor sign-in, and can we require it for every user?
- Can we limit what each user sees by role?
- Do you keep a record of who viewed or changed each record?
- Can we remove a user instantly, and export our data if we leave?
The guide to HIPAA-compliant NEMT software goes deeper on vendor questions.
The first hours of an incident
Write the response plan while nothing is on fire, keep it on paper, and make sure two people know where it is.
- Contain. Disconnect affected devices from the network. Do not wipe them, because investigators need what is on them.
- Call for help. Your IT support, your cyber insurer if you have one, and your attorney. Check your policy for its notice requirements.
- Secure accounts from a clean device. Change passwords, sign out all sessions, and check email for forwarding rules you did not create.
- Report the crime. File at ic3.gov or call your local FBI field office. For a stolen wire payment, speed matters: the FBI’s Recovery Asset Team works with banks to freeze fraudulent transfers, and it asks victims to file as quickly as possible.
- Keep rides running under the emergency mode plan.
- Assess the breach. Work through HIPAA’s four-factor risk assessment, and notify riders, HHS, and your broker as required.
- Close the gap that let it happen, and record each change you made.
Keep the plan with your other policies and procedures, and practice it once a year.
Account security in HealthRide
HealthRide is HIPAA compliant, and its security settings follow the same habits this guide recommends. In the provider portal, people can sign in with a passkey or a two-step code, access follows each person’s role, and every edit leaves a record. Drivers work in the driver app, which keeps rider details off the phone’s lock screen.
Frequently asked questions
- Would hackers bother with a small NEMT company?
- Yes. Most attacks are not aimed at a company because of its size. They go after anyone who opens a fake email, reuses a password, or leaves a device unlocked. A NEMT company holds rider names, addresses, and Medicaid details, logs into broker portals where trips and claims live, and pays drivers and vendors, which makes its email and payment accounts worth stealing.
- Are texted sign-in codes good enough?
- They are far better than a password alone, but they are the weakest form of multifactor sign-in. CISA notes that attackers can intercept texted codes through SIM swaps and phone network weaknesses, and NIST points out that a fake login page can relay any code a person types in. Use passkeys or security keys where the service offers them, and an authenticator app where it does not.
- Do we have to follow the HHS cybersecurity performance goals?
- No. HHS describes its healthcare cybersecurity performance goals as voluntary. The HIPAA Security Rule is the binding requirement for companies it covers. The goals are still a practical checklist, and under a 2021 law HHS must consider whether a company had recognized security practices in place for the previous 12 months when it sets HIPAA fines and audit terms.
- Should we pay a ransom to get our data back?
- The FBI does not support paying ransoms. It says payment does not guarantee you get your data back and encourages more attacks. Report the attack to your local FBI field office or at ic3.gov, call your cyber insurer and IT help, and restore from offline backups. Under HIPAA, data encrypted by ransomware is presumed breached unless a documented risk assessment finds the chance of compromise is low.
- A driver quit and still has the dispatch app and broker portal on his phone. What do we do?
- Remove his access to every system that day: your dispatch software, company email, the broker portal and its driver app, and any shared accounts, whose passwords you should change. HHS lists prompt removal of former workforce members' access as an essential cybersecurity goal, and the HIPAA Security Rule calls for procedures to end access when employment ends.
- What is the first thing to do after clicking a phishing link?
- Disconnect the device from the network, then change the password of the account involved from a different, clean device and sign out all other sessions. Tell whoever handles your IT and check the account for new forwarding rules or unfamiliar sign-ins. If rider information may have been exposed, start a HIPAA breach risk assessment and keep notes from the first minute.