Compliance risk assessment template for NEMT companies: rank billing, driver, and privacy risks once a year

Updated 11 min read

Overview

A compliance risk assessment template for a NEMT company lists the ways it could break a payer's rules, scores each by likelihood and impact, names an owner and a control, and sets the next check. HHS-OIG's guidance asks small entities to run an assessment every year and use the results to pick what to audit.

On this page

What does OIG expect from a small company’s yearly risk assessment?

OIG expects a small company to look for ways it could break program rules at least once a year, rank what it finds, and decide what to do about the biggest items. Its General Compliance Program Guidance (November 2023) defines a risk assessment as “a process for identifying, analyzing, and responding to risk,” asks small entities for one assessment every year, and says it can be simple and need not use many resources (OIG guidance, small entity section).

This page is the form for that exercise. The NEMT compliance program guide explains where the assessment sits among OIG’s seven elements and what the yearly audit and monitoring should look like. The monthly trip audit checklist is the recurring work the top rows turn into. The HIPAA risk analysis template is a separate Security Rule exercise about electronic rider data, and the privacy rows below point to it.

The template

Part A: Set up the review

ItemEntry
Period covered (the last 12 months)
Date of the review
People in the room: owner, compliance contact, dispatcher, biller, lead driver
Data pulled: monthly trip audit findings, denied or rejected trips, rider and facility complaints, incident reports, payer or broker audit letters
Law and payer changes since the last review (new manuals, new contracts, new state rules)
Last year’s register and what became of its top rows
OIG Work Plan checked for NEMT items (date)

Part B: Scoring key

Score every row, not only the ones that worry you. Multiply likelihood by impact.

ScoreLikelihood (from your own records)Impact (what a payer could do)
1No finding on this in the last 12 monthsFix it, and no money or payer action follows
2One or two findings, correctedMoney to repay, or a warning from a payer
3Repeated findings, or any finding from a payer or auditorSuspension, termination, repayment across many trips, or a referral

Levels: a score of 1 or 2 is Low, 3 or 4 is Medium, and 6 or 9 is High. Audit every High row this year.

Part C: Risk register

The first 14 rows come from OIG audit findings and payer rules for NEMT. Delete any that cannot apply, and add your own at the bottom. The next section explains each one.

No.RiskLikelihoodImpactScoreOwnerControl in place nowNext check (date)
R1Billed trips with no proof of a medical visit that day
R2Trip records incomplete or unsigned
R3Billed miles above GPS-recorded miles
R4Level of service or night charge billed above what was provided
R5Overpayment found and not returned within 60 days
R6Gifts to riders above a nominal amount
R7Driver checks or training not proven for the trip date
R8Vehicle registration, inspection, or identity not proven
R9Insurance not in force on the trip date
R10Excluded owner, employee, or contractor
R11Minor riders carried against a state or payer rule
R12Privacy incident not logged or not reported on time
R13Vendor that handles rider data without a signed agreement
R14Records lost when you close, move, or leave a program
R15
R16
R17

Part D: The year’s audit and actions

One line for each High row and any Medium row you choose to work on.

Risk no.What you will do (audit, monitoring, process change, training)Scope and sampleOwnerDueDone

Part E: Sign-off

ItemEntry
Reviewed with the owner on (date)
Compliance contact (name)
Next review (no later than 12 months from this date)
Reviews added since this one for a new contract, service, or state

What auditors have found behind each risk

The facts below come from HHS-OIG audits of state Medicaid NEMT programs. Those audits look at what the state paid, but each failure they list is something a provider has to be able to prove. The dates and sample sizes are the audits’ own. Our guide to NEMT fraud prevention covers the enforcement cases, so this section sticks to audit findings.

Billing and trip proof

  • R1, no medical visit that day. In OIG’s New Jersey audit (July 2016), the medical provider confirmed for 6 of 100 sampled claims that the rider had no Medicaid-covered service on the date of the trip. In Massachusetts (January 2021), OIG found 48 of 100 sampled lines had no qualifying medical service on the transport date. Control: confirm the appointment or destination for standing orders, and keep each facility’s name and address on the trip.
  • R2, incomplete records. In California (January 2015), 2 of 100 sampled services lacked enough documentation to support payment. In Massachusetts, the broker could not document that the trip was provided for 62 of 100 lines. Control: every leg closes with times, a signature or the payer’s accepted substitute, and a reason when either is missing.
  • R3, miles. North Carolina’s audit (November 2016) found counties paying vendors for miles driven before a pickup, after a drop-off, or between stops with no rider aboard. State policy pays the direct cost of a trip only while the rider is aboard, and tells counties to fold empty miles into the vendor’s mileage rate. OIG’s guidance also tells small entities to track their own risk indicators, such as unusual changes in code utilization and in the number or type of claim rejections, and billed miles per trip is an easy one to add. Control: compare billed miles with GPS-recorded miles each month, by driver, and chase outliers. The mileage billing guide lists the checks payers run.
  • R4, level of service and night charges. California’s audit found 2 of 100 services billed as ambulance transfers when the records supported only a wheelchair or litter van, and 1 improperly billed as a night call, an extra charge for trips from 7 p.m. to 7 a.m. In New Jersey, the broker could not produce a medical necessity form for 17 of 30 claims for riders in mobility-assistance vehicles. Control: match the vehicle and any time-based charge to the authorization, and keep the form behind every wheelchair or stretcher trip.
  • R5, late repayment. The statute OIG quotes makes a Medicaid overpayment due 60 days after it is identified, or the date a cost report is due if that is later. Control: write down the date you identify any overpayment, and use the 60-day rule guide.
  • R6, rider gifts. OIG’s guidance describes the nominal-value limit for gifts to beneficiaries as no more than $15 per item or $75 a year in total. Control: a written rule for drivers and dispatchers, and the anti-kickback guide.

Drivers and vehicles

  • R7, driver checks. New Jersey’s audit found 26 of 100 sampled claims where driver background check and training requirements were not met: 16 where the driver had not finished the approved training before the trip, 8 where the background check showed a disqualifying conviction, and 2 where the check was done after the trip date. Texas’s audit (October 2014, fiscal year 2011 claims) found 18 of 90 claims where the provider could not verify background checks, drug testing, and driver history checks. A training certificate dated after the first trip is a finding. Control: no first trip until each check is dated and filed.
  • R8, vehicles. In the Texas audit, 51 of 90 claims could not show that the vehicle had current registration and inspection or could not identify the vehicle used. In Massachusetts, none of the 100 sampled items had adequate driver and vehicle records. For 89 of them the state had some papers but not the identifying details, such as driver names and vehicle descriptions, to tie them to the trip. Control: the driver and vehicle on each trip are named, and both files are current on that date.
  • R9, insurance. New Jersey found 8 of 100 claims where the provider had no workers’ compensation, general liability, or auto coverage on the trip date. Michigan’s audit (June 2018) found insurance papers that had expired before the trip date. North Carolina’s (November 2016) found vendors with $1 million of liability coverage where $1.5 million was required. Control: one dated record per policy, kept in the certificate tracker. MTM’s standard provider agreement (the January 2023 copy Pennsylvania posts) ends the contract immediately if insurance lapses.
  • R10, exclusions. OIG updates its exclusion list monthly and says screening monthly keeps exposure lowest. It also notes that an excluded employee, or one with a lapsed license, can have a significant impact on a small entity. Control: the exclusion screening log.
  • R11, minors. Texas’s audit found 19 of 90 claims where children were carried without a parent or guardian, and OIG recommended no rides for children under 15 without one. North Carolina’s found a county carrying a 13-year-old alone against state policy. Rules differ by state and payer. Control: a booking question about age and a stated rule for the dispatcher.

Privacy, vendors, and records

  • R12, privacy incidents. A covered entity or business associate must be able to show every required notice was made, or that an incident was not a breach (164.414). Control: the breach log, with the HIPAA risk analysis as the wider review.
  • R13, vendors. Any outside company that handles rider information for you needs a business associate agreement. Control: the vendor list and agreements in your business associate agreement template.
  • R14, records gone. In Indiana’s audit (August 2020), 17 of 120 sampled claims came from 4 providers who kept no records: some had closed, some had left the program, some had moved, and some could not find them. Indiana’s rule is seven years from the date of service. Control: a retention rule that says where records go when the company closes or a contract ends, in the record retention schedule.

A worked example: scoring a twelve-van company’s first three rows

A row scores as likelihood times impact, so a repeat finding with money at stake outranks a one-off. This is an invented example. A twelve-van company pulls 15 paid trips a month for its own audit, so it has 180 samples for the year.

  • R2, trip records. 14 of the 180 sampled trips had no rider signature and no reason written. Likelihood 3, because the finding repeats. Impact 2, because unsigned trips can mean money to repay. Score 6, High.
  • R9, insurance. One van’s policy renewed 6 days after it expired, and no trip was found in the gap. Likelihood 2, because it happened once and was caught. Impact 3, because a payer can end a contract for a lapse. Score 6, High.
  • R3, miles. Billed miles stayed within tolerance of GPS miles in every month. Likelihood 1, impact 2. Score 2, Low.

Two rows tie at 6. The company starts with R2, because its findings repeat, and puts a check on the van’s renewal date for R9. R3 stays on the register with a monthly check and no further work.

How do you turn the scores into the year’s audit?

Pick the audit from the top of the register, then write it down in Part D.

  1. Take every High row. Add any row where a payer or auditor has already found something, even if its score is lower.
  2. Choose what each gets. OIG names three responses: an audit, routine monitoring, or a process change. Use a sample audit for proof problems such as R1, R2, R7, and R8. Use monitoring for lists and dates, such as R9 and R10. Use a process change when the same finding repeats.
  3. Write the scope. The period, the number of trips or files, and who looks. The person who bills the trips should not mark them.
  4. Report to the owner. OIG suggests a compliance contact reports to the owner at least quarterly when there is no board.
  5. Act on what you find. OIG’s remediation list is repaying overpayments, changing processes, and educating staff. If an audit finds money owed, the 60-day clock starts when you identify it.

Put the audit dates and each next-check date on the compliance calendar so they do not depend on memory.

How do you keep the register current between reviews?

Score a new risk the day you learn of it, using the same key. OIG’s guidance tells the compliance officer to keep scanning between assessments for legal and regulatory changes, enforcement actions, OIG Work Plan developments, and new initiatives, and to assess anything new by the same method.

OIG’s Work Plan has an active series on this industry: audits of whether selected states met Medicaid payment requirements for NEMT, announced May 28, 2026, with an estimated completion in fiscal year 2028. The announcement says NEMT providers must be lawfully authorized to provide transportation and must keep records supporting the services they bill, which maps to R2, R7, R8, and R14. Add a row when you sign a new broker contract, add a service level, or start work in a new state.

Checking the rows against your records in HealthRide

Several rows in Part C come down to records HealthRide already keeps. Each trip holds GPS-recorded miles, pickup and drop-off times, and the signature captured on screen, and the trip log exports from reports for the monthly sample behind R1 to R4. Licenses, van insurance, registrations, and training certifications sit in the fleet and credentials registry with their expiration dates. That covers the expiry side of R7 to R9: reminders go out ahead of time, and an expired one is flagged when a trip is assigned.

Frequently asked questions

Is a yearly compliance risk assessment required for a NEMT company?
OIG's General Compliance Program Guidance (November 2023) is voluntary, and it asks small entities for a compliance risk assessment every year. Whether you must do one depends on your contracts, since some payers write a compliance program into their agreements. Our compliance program guide lists who requires one. Either way, the yearly assessment is how you decide what to audit.
How is this different from a HIPAA risk assessment?
A HIPAA risk analysis is a Security Rule requirement about electronic rider information: where it lives and how it could leak. A compliance risk assessment is wider. It asks where you could break the rules of a payer or a program, such as billing, driver and vehicle records, and gifts. The privacy rows here point to the HIPAA exercise rather than repeating it.
How do I score likelihood without guessing?
Use your own records. OIG tells small entities to review their own data for risks, such as claim denials and complaints, and says brainstorming at a staff meeting also works. Count findings from your monthly trip audit, rejected or denied trips, rider complaints, and payer letters over the last 12 months. No findings is a 1, a few corrected ones is a 2, and repeated ones or any payer finding is a 3.
How many risks should the register hold?
Start with the 14 listed here and delete any that cannot apply to you. Add rows from your payer manuals and from audit letters you have received. OIG says the assessment can be simple and need not use many resources, and a short register that is scored honestly and reviewed every year beats a long one that is never read.
What do I do with the highest scores?
Audit them first. OIG asks small entities for at least one audit a year, and the risk assessment is how you pick what to audit. What the audit finds can lead to repaying overpayments, changing a process, or retraining staff. A Medicaid overpayment must be reported and returned within 60 days after it is identified. The statute does not define identified, so write down the date a finding surfaces and read the 60-day guide before you decide when the clock started.
Who should score the register?
The owner and the compliance contact, with input from dispatch, billing, and a lead driver. OIG suggests that a small company name one person as its compliance contact who is not involved in billing, coding, or submitting claims whenever possible, and who reports to the owner at least quarterly. The person who bills the trips should supply the numbers, but should not decide how risky they are.
When do I add a risk between yearly reviews?
When something new appears. OIG says to keep scanning between assessments for legal and regulatory changes, enforcement actions, OIG Work Plan developments, and new initiatives, and to score a new risk with the same method. A new broker contract, a new service level, and a new state are all good moments to add a row and score it.

Official resources

Keep reading

HealthRide plans the whole day in one click and bills every ride.