Confidentiality pledge for NEMT staff: the one-page HIPAA agreement drivers and office staff sign

Updated 7 min read

Overview

A HIPAA confidentiality agreement is a one-page pledge each driver, attendant, dispatcher, and biller signs before seeing rider information. HIPAA never requires the signature itself, but it requires trained staff and a sanctions policy, and Texas law and broker contracts ask for signed proof of training. The pledge covers using only what the job needs, phones and paper, no posts about riders, and returning devices on the last day.

On this page

Does HIPAA require staff to sign a confidentiality agreement?

No. Nothing in the HIPAA Privacy, Security, or Breach Notification Rules (45 CFR part 164) tells a company to have its workforce sign a confidentiality agreement. What the rules do require is harder to prove without one:

  • Training, with a record. A covered entity must train every workforce member on its privacy policies, train new people within a reasonable time after they start, and document that the training happened (45 CFR 164.530(b)). Covered entities and business associates alike must run a security awareness and training program for all staff, management included (164.308(a)(5)).
  • Sanctions, applied and recorded. Both kinds of company must apply sanctions to staff who break the security policies, and covered entities must document every privacy sanction they apply.

A signed page that says “I was trained on this date, I know the rules, and I know what happens if I break them” covers both. The full rules belong in your HIPAA privacy and security policy; the pledge is the one-page version each person signs, and its clauses point back to that policy. HIPAA for NEMT drivers explains what each clause means in the van, the lobby, and on the phone.

Others expect proof that each person knows the rules:

  • Texas. A covered entity under Texas law must have each employee it trains sign a statement, electronic or written, verifying the training was completed, and keep it until the sixth anniversary of signing (Texas Health and Safety Code 181.101(d)). Texas defines covered entity more broadly than HIPAA, as the guide to state privacy laws stricter than HIPAA explains.
  • Virginia. Its fee-for-service NEMT standards (updated May 26, 2026) require drivers and attendants to comply with HIPAA by keeping members’ identifying information confidential and out of other passengers’ view, and by keeping it out of conversations with anyone not involved in the member’s treatment or other care.
  • Brokers. Modivcare’s 2025 compliance attestation has providers keep records, such as employee acknowledgments and training rosters, showing that owners and drivers finished its training, HIPAA privacy and security included, and hand them over on request. WellTrans’s subcontractor business associate agreement requires HIPAA training with proof available on request.

Who signs it

Everyone in your workforce, before their first trip or first login. HIPAA’s definition of workforce turns on direct control: employees, trainees, volunteers, and anyone else you direct while they work for you, paid or unpaid (45 CFR 160.103). In a NEMT company that means drivers, attendants, dispatchers, schedulers, billers, office staff, and managers, plus the relative who covers the phones on Saturdays and the trainee on a ride-along. Owners should sign too, because brokers such as Modivcare expect owners to finish the same training as drivers. The test is direct control, not payroll, so a contract driver whose work you direct can count too.

Separate companies are different. A billing service, answering service, or IT firm that handles rider data for you signs a business associate agreement instead.

The agreement

Fill in the brackets, print it on one page, and keep the signed original. Give the signer a copy.

[Company name] rider information confidentiality agreement

Name: ____________ Role: ____________ Start date: ____________

At [Company name] I will see information about the people we drive. Federal law and our contracts require us to protect it. By signing, I agree to the following.

1. What I protect. Anything that ties a rider to their trips or health: name, address, phone number, pickup and drop-off places, appointment times, mobility, oxygen, or escort needs, Medicaid or member numbers, trip numbers, signatures, and notes. It does not matter whether it is on paper, on a screen, or said out loud.

2. Only what my job needs. I look up, use, and share rider information only for the trips and tasks assigned to me. I never look up a rider, or my own family, friends, neighbors, or anyone in the news, out of curiosity.

3. Who I may tell. The rider; a caregiver or representative the rider has allowed; staff at the clinic or facility caring for the rider; and coworkers who need it for the trip. I send every other request, including from police, lawyers, reporters, and callers I cannot identify, to [privacy official].

4. Phones, paper, and the van. I keep rider details in [driver app or approved system] only. I do not text them from a personal account, take screenshots, or photograph or record riders, their homes, or their papers. My phone locks when I put it down. Printed manifests stay face down and go back to [office] at the end of my shift. I do not discuss riders on speaker, on the radio, or in front of other riders.

5. Online. I do not post, comment, review, or reply about riders, facilities, or trips on any website or app, even without names.

6. Reporting mistakes. If a phone or manifest is lost, a message goes to the wrong person, or someone sees rider information they should not, I tell [privacy official] within [1 hour]. I will not be punished for reporting in good faith.

7. When I leave. On my last day I return company phones, tablets, keys, badges, fuel cards, and any paper with rider information, and I delete rider information from any personal device I used for work and show [privacy official] that it is gone. My logins end that day. My duty to keep rider information confidential does not end.

8. If I break this agreement. I may face the sanctions in Section 7 of the [Company name] HIPAA policy, from retraining up to termination. The company may have to report the problem to brokers, riders, and the government. Knowingly obtaining or disclosing health information in violation of HIPAA can also be a federal crime.

9. What this agreement does not limit. Nothing here stops me from discussing my own pay, hours, or working conditions, from reporting a concern to a government agency or my own lawyer as the law allows, or from filing a complaint with HHS.

NameSignatureDate
Employee
Privacy official

HIPAA training completed on: ____________ Copy given to employee: yes / no

What each clause rests on

  • Clause 2. The minimum necessary rule limits staff to the information their job requires (164.502(b)). Criminal law can reach the worst cases. For information a covered entity holds, 42 U.S.C. 1320d-6 treats an employee who knowingly obtains or discloses it without authorization as committing an offense: up to a $50,000 fine, a year in prison, or both, rising to $250,000 and ten years when the aim is to sell the information or use it for personal gain or malicious harm.
  • Clauses 4 and 5. These are the everyday habits. The pledge only records the promise; the habits themselves come from training.
  • Clause 6. Speed matters because of how HIPAA counts time. The clock starts on the first day any workforce member or agent, apart from the one responsible, knew of the breach or should have known (164.404(a)(2) for covered entities, 164.410(a)(2) for business associates). If a lost phone turns out to be a breach, a driver who kept quiet about it for three days has already used three days of your deadline, and broker deadlines can be as short as a day.
  • Clause 7. Ending access is a Security Rule procedure (164.308(a)(3)(ii)(C)). Section 5 of the policy template lists the exit steps the office takes on its side.
  • Clause 8. Covered entities must document every sanction they apply (164.530(e)(2)). In 2017, Memorial Hermann Health System in Texas paid $2.4 million to settle with OCR after senior managers approved a press release that named a patient, and OCR also found the system had not documented the sanctions against the workforce members involved in time.
  • Clause 9. The National Labor Relations Board treats work rules that reasonably tend to stop employees from exercising their Section 7 rights, such as acting together over pay and conditions, as unlawful, so keep confidentiality aimed at rider information. The driver handbook makes the same point for its own confidentiality section. HIPAA also protects good-faith reports of wrongdoing to a health oversight agency or the person’s own lawyer (164.502(j)) and complaints to HHS (160.316).

When to collect signatures

  1. Before the first trip or login. Sign at the end of HIPAA training and write the training date on the form.
  2. After a policy change that affects the job. HIPAA calls for retraining within a reasonable time after a material change, so collect a fresh signature at that session.
  3. Every year if a broker trains yearly. Modivcare’s attestation covers training for each calendar year, so a yearly signature keeps the file current.
  4. Log each signature in your training log so you can show a broker the whole roster on one page.

Fewer places for rider details to leak

The pledge is easier to keep when rider details never reach personal phones in the first place. HealthRide’s team chat keeps dispatch conversations inside the company instead of in personal text threads, and in the driver app rider details stay off the lock screen. HealthRide is HIPAA compliant: every change is recorded, and each person sees only what their role allows.

Frequently asked questions

Do volunteers and family members who help out need to sign it?
Yes, if they handle rider information for you. Under HIPAA, workforce means anyone you directly control while they work for you, paid or unpaid, so it takes in trainees and volunteers as well as employees. A spouse who answers the phone on weekends or a trainee riding along for a shift is workforce. Train them and have them sign before they see a manifest.
Does a signed pledge replace HIPAA training?
No. The pledge records a promise; training teaches the rules behind it. Covered entities must train every workforce member on their privacy policies and document it, and covered entities and business associates must both run a security awareness program for all staff, management included. Have people sign at the end of the training session, with the training date on the form, so one page proves both.
Can the agreement be signed electronically?
Yes. The Security Rule accepts documentation in electronic form, and Texas, which requires a signed statement that each employee finished privacy training, allows that signature to be electronic or written. Store the signed files where the privacy official can produce them quickly for a broker or an auditor.
How long do we keep signed agreements?
Keep each one at least six years, counted from when it was signed or, if later, the last day it applied. That is HIPAA's retention period for required documentation. Texas requires its signed training statement to be kept until the sixth anniversary of signing. Broker contracts can ask for more: Modivcare's 2025 attestation asks providers to keep training records, employee acknowledgments included, for at least 10 years.
Should our billing service or IT company sign this pledge?
No. A separate company that handles rider data for you signs a business associate agreement, which carries the clauses HIPAA requires for vendors. The pledge is for your own workforce. A contract driver whose work you direct day to day may still fall within HIPAA's definition of workforce, so have that driver sign the pledge too.

Official resources

HealthRide plans the whole day in one click and bills every ride.