Business associate agreement template for NEMT vendors: billing services, answering services, and IT

Updated 8 min read

Overview

A business associate agreement template is the contract a NEMT company signs with an outside firm that handles rider information for it, such as a billing service, answering service, factoring company, or IT support. HIPAA requires clauses that limit the firm's use of the data, require safeguards and breach reports, bind its own subcontractors, and return or destroy the data at the end. Set its deadlines tighter than your broker's.

On this page

Which vendors need a business associate agreement

Any outside company or person that creates, receives, keeps, or sends rider information on your behalf needs one before it touches the data (45 CFR 160.103). Your own staff do not; they are workforce, covered by your HIPAA policy. HHS’s examples (its guidance was last reviewed July 30, 2026) and broker contracts translate into this NEMT list:

  • Billing services and clearinghouses. Billing is one of the activities HHS names, and so is a clearinghouse that converts claims into the standard format. The guide to hiring a NEMT billing service covers the rest of that relationship.
  • IT support and managed service providers that maintain computers or systems holding rider data, on site or remotely.
  • Cloud software and storage, such as dispatch, scheduling, email, and file services that keep rider data for you.
  • Answering services and outside dispatchers that take ride requests. The guide to outsourcing dispatch covers where that work can happen.
  • Factoring companies that receive trip logs or manifests to buy your receivables. WellTrans names them in its contract, as described below, and NEMT factoring explains the arrangement itself.
  • Accountants and lawyers whose work involves rider records.
  • Copier and device technicians when the repair exposes rider data stored on the machine.
  • Shredding companies that collect records to destroy them.

HHS also lists who does not need one. The Postal Service, couriers, and their electronic equivalents that only carry information pass under the conduit exception, which ends once a company looks at the data regularly to do its job. Cleaners and electricians need none either, as long as any contact with rider data is incidental at most and reasonable safeguards are in place. The same goes for a bank or card processor moving money for a payment, and for a health plan paying your claims.

Which side of the agreement you sign

Your HIPAA role decides who is on each side, and HIPAA for NEMT providers explains how to work out that role.

  • You are a covered entity (you bill health plans electronically for your own trips). You sign as the covered entity, and each vendor signs as your business associate.
  • You work for a broker as its business associate. Your vendors are then your subcontractors, and the same contract rules apply one level down (164.504(e)(5) and 164.314(a)(2)(iii)). Your agreement must hold the vendor to the same restrictions and conditions you accepted. WellTrans’s subcontractor business associate agreement (revised October 16, 2025) spells it out: any contract with a billing company, factoring company, or anyone else who gets the provider’s trip logs, trip manifests, or WellTrans billing documents must carry the same terms.
  • The broker sends its own form. Sign the broker’s. MTM’s Pennsylvania transportation provider services agreement (January 1, 2023) attaches its business associate agreement as Appendix A and says the provider must sign it. Then use the broker’s terms as the checklist for your vendor agreements.

A substance use disorder treatment center may give you a qualified service organization agreement that also serves as a business associate agreement; rehab center transportation explains it.

The template

This agreement follows the sample provisions HHS published on January 25, 2013, rewritten in plain words for a transportation company. HHS says its sample can be adapted for a business associate’s contract with a subcontractor. The rule behind each section is in parentheses. Choose one option in each set of brackets.

Business associate agreement

This agreement is between [Company name] (“Company”), a [covered entity / business associate of (broker or health plan)], and [Vendor name] (“Vendor”). It takes effect on [date] and covers the services in [name and date of service agreement].

1. Terms. Breach, protected health information, security incident, subcontractor, and unsecured protected health information mean what they mean in the HIPAA rules at 45 CFR parts 160 and 164. “Rider information” means protected health information that Vendor creates, receives, keeps, or sends for Company.

2. What Vendor may do with rider information (164.504(e)(2)(i) and (ii)(A)). Vendor uses and discloses rider information only to [prepare and send claims / answer ride request calls / maintain Company’s computers and accounts / buy and collect Company’s receivables / other], as described in the service agreement, or as the law requires. Vendor uses, discloses, and asks for the least rider information each task needs. Vendor [may / may not] use rider information to manage its own business and meet its legal duties. Vendor [may / may not] de-identify rider information under 45 CFR 164.514.

3. Safeguards (164.504(e)(2)(ii)(B), 164.314(a)(2)(i)(A)). Vendor uses appropriate safeguards for all rider information and follows the Security Rule, 45 CFR part 164, subpart C, for electronic rider information. [Optional: Vendor encrypts rider information when stored and when sent.] [Optional: Vendor does not receive, view, process, store, or reach rider information from outside the United States.]

4. Reports to Company (164.504(e)(2)(ii)(C), 164.314(a)(2)(i)(C), 164.410). Vendor tells [Company contact, phone, email] within [the same business day] after learning of any use or disclosure this agreement does not allow, or of any security incident. For a breach of unsecured rider information, Vendor reports within [the same business day] after discovery, names each affected rider as far as it can, and sends the facts Company needs for its own notices as they become known. [Company / Vendor] sends notices to riders, HHS, and the media. Vendor pays [the cost of notices and mitigation caused by its breach].

5. Vendor’s subcontractors (164.504(e)(2)(ii)(D), 164.314(a)(2)(i)(B)). Before any subcontractor receives rider information, Vendor signs a written agreement binding that subcontractor to the same limits and duties as this one. Vendor gives Company a list of those subcontractors on request.

6. Rider requests (164.504(e)(2)(ii)(E) to (G)). Within [2] business days of Company’s request, Vendor makes rider information available for a rider’s request to see or copy it, makes the corrections Company directs, and gives Company the record of disclosures it needs to answer a request for an accounting. If a rider contacts Vendor directly, Vendor forwards the request to Company within [1] business day.

7. Company duties Vendor carries out (164.504(e)(2)(ii)(H)). If Vendor performs a duty the Privacy Rule places on Company, Vendor follows the parts of that rule that apply to Company.

8. Access for HHS (164.504(e)(2)(ii)(I)). Vendor makes its practices, books, and records about rider information available to the Secretary of Health and Human Services for compliance reviews.

9. Ending the agreement (164.504(e)(2)(iii)). Company may end this agreement and the service agreement if Vendor violates a material term [and has not fixed the violation within (number) days after written notice].

10. When the work ends (164.504(e)(2)(ii)(J)). Vendor returns [or destroys] all rider information in any form, keeps no copies, and confirms it in writing [with a certificate of destruction]. If return or destruction is not feasible, Vendor explains why, keeps protecting what remains, and uses it only for the purpose that made return impossible.

11. Other terms. Sections 4, 10, and 11 survive the end of this agreement. A reference to a HIPAA rule means that rule as amended. The parties will amend this agreement when the law changes, and any unclear term is read in the way that complies with HIPAA. [Optional: Vendor indemnifies Company against claims caused by Vendor’s breach of this agreement.]

PartyName and titleSignatureDate
[Company name]
[Vendor name]

Setting the deadlines in the brackets

The federal deadline is the outer limit, not the one to write in. A business associate has up to 60 calendar days after discovering a breach to tell the covered entity (164.410). Broker contracts can allow far less. WellTrans’s subcontractor agreement requires reports of improper uses and disclosures, security incidents, and breaches within one business day. A billing service allowed 60 days, or even five, leaves you no chance of meeting that. Give each vendor less time than your broker gives you, which is why the template defaults to the same business day.

The clock can start before the vendor’s managers know. Under 164.410(a)(2), the discovery date is the first day the breach was known, or with reasonable diligence would have been known, to anyone working for the vendor as an employee, officer, or agent, other than the person who caused it. For example, if an answering service operator learns that a rider list was faxed to the wrong number, that day counts as the discovery date if the error turns out to be a breach.

Rider requests run on the same logic. WellTrans gives its providers five business days to make rider information available for a rider’s access or amendment request, so a vendor holding part of that record needs a shorter turnaround, such as two business days.

Where the data sits is a contract term too. Modivcare’s 2025 compliance attestation has each transportation provider certify that no one at the company stores, views, processes, or otherwise handles protected health information from outside the country. If you sign that attestation, put the optional offshore clause in section 3 of every vendor agreement. The guide to HIPAA-compliant NEMT software lists the other safeguards to ask a software vendor about.

Keeping track after you sign

List every vendor in one place: the service, the rider data it gets, the date the agreement was signed, its breach contact, and its subcontractors. Keep each signed agreement for six years after the last day it was in effect (164.316(b)(2)). The HIPAA policy template makes the privacy official responsible for that list.

A signed agreement does not end the job. If you know of a pattern of conduct by a vendor that materially breaches the agreement, HIPAA requires reasonable steps to fix it and, if they fail, ending the contract where feasible (164.504(e)(1)(ii) and (iii)). A business associate that skips agreements with its own subcontractors, or ignores a subcontractor’s known material breach, can face OCR enforcement directly, according to HHS’s fact sheet on business associate liability.

Missing agreements are expensive. In 2016, North Memorial Health Care of Minnesota paid $1,550,000 after OCR found it had given a contractor, Accretive Health, access to a hospital database holding electronic records of 289,904 patients without a business associate agreement. The investigation began with an unencrypted laptop stolen from a contractor employee’s car, which held data on 9,497 people.

If HealthRide is on your vendor list

HealthRide signs business associate agreements with its providers, so the system that holds your riders’ details is covered by the kind of agreement this page describes. HealthRide is HIPAA compliant, patient information is encrypted and protected, and in the provider portal each person on your team sees only what their role allows.

Frequently asked questions

Does my dispatch or scheduling software company need to sign one?
Yes, when it stores or processes rider information for you. HHS lists a cloud service provider that creates, receives, maintains, or transmits electronic health information for a covered entity or business associate among its examples of business associates. Get the signed agreement before you import riders, and ask the questions in the guide to choosing HIPAA-compliant software at the same time.
Does my bank or card processor need a business associate agreement?
Not for payment processing. HHS says a financial institution that processes card payments, clears checks, or moves electronic funds to pay for health care is giving its normal banking services to its customers, not acting for you, so no agreement is needed for that work. A vendor that reads trip records to build invoices or chase payments is doing more than moving money and does need one.
Do drivers and office staff sign a business associate agreement?
No. Employees, volunteers, and trainees whose work you directly control are your workforce, not business associates, so HIPAA reaches them through your policies, training, and sanctions. A one-page confidentiality pledge records their promise. The business associate agreement is for separate companies and outside professionals, such as an accounting firm whose work involves rider records.
Is the HHS sample business associate agreement enough on its own?
HHS calls its provisions sample language only. Using them is not required, and HHS warns that they alone may not make a binding contract under state law, because they leave out formalities and terms a contract usually needs. They are a sound base for the HIPAA clauses. Add the service terms, names, signatures, and deadlines, and have a lawyer read it if the contract is large.
What if a vendor will not sign?
Then it cannot handle rider data for you. The Security Rule lets a covered entity hand electronic health information to a business associate only after getting satisfactory assurances, documented in a written contract, and holds a business associate to the same rule with its subcontractors. If a vendor offers its own agreement instead, read it for the same clauses and deadlines before you accept it.
Does a shredding company need to sign one?
Yes, when its staff collect rider records to destroy them. HHS gives using a disposal vendor as a business associate to pick up and shred records as one example of proper disposal. Ask for a certificate after each pickup as well.

Official resources

Keep reading

HealthRide plans the whole day in one click and bills every ride.