HIPAA privacy and security policy template for NEMT companies: fill-in sections staff sign
Overview
A HIPAA policy template gives a transportation company the written rules HIPAA expects it to follow and train on: who the privacy and security officials are, which rider details each job may see, how phones and printed manifests are handled, how logins start and end, sanctions, breach reporting, and six-year record keeping. Every company HIPAA reaches needs the security rules; covered entities need the privacy rules too.
On this page
Which HIPAA rules require written policies
Two sections of the HIPAA rules make you put policies in writing. The Security Rule’s documentation standard (45 CFR 164.316) applies to covered entities and business associates alike: keep the policies that protect electronic rider data in written form (electronic is fine), make them available to the people who carry them out, and review them periodically. The Privacy Rule’s version (164.530(i)) applies to covered entities and reaches rider information in every form, paper included. Both let you size the policy to the business, so a five-van company writes a short document, not a hospital binder.
Which sections you need depends on your HIPAA role, and HIPAA for NEMT providers explains how billing and broker work decide it. In short:
- Covered entity. You bill Medicaid or a health plan electronically, yourself or through a billing service. CMS’s covered entity decision tool treats claims a provider sends through another company as the provider’s own electronic transactions. Use every section below.
- Business associate only. You run trips for a broker and never bill electronically. The Security Rule sections apply by law, and so does the minimum necessary rule in 164.502(b). Keep the privacy sections anyway, because broker agreements demand them: the subcontractor business associate agreement in WellTrans’s provider agreement (revised October 16, 2025) requires a system of sanctions, HIPAA training for employees, and proof of training on request.
The policy records who your privacy and security officials are; the two officer roles explains who can hold them and what they do. It also sits on top of your HIPAA risk analysis: every High row on that fix list should turn into a rule here that someone follows.
The template
Fill in the brackets, delete the options you do not use, and keep the rule line under each section so an auditor can trace it. Every workforce member signs Section 12 after training.
[Company name] HIPAA privacy and security policy
Version: [number] | Effective date: [date] | Approved by: [owner name and title] | Last reviewed: [date]
1. Scope
[Company name] protects the health information of the riders it carries. This policy applies to the whole workforce: employees, drivers, attendants, dispatchers, office staff, trainees, volunteers, and family members who help in the business, paid or not. It covers rider information on paper, on screens, in conversation, and in stored files.
Our HIPAA role: [covered entity for trips we bill to (payers)] / [business associate of (brokers or health plans)] / [both].
Rule: 45 CFR 160.103 (workforce), 164.530(i), 164.316(a).
2. Officials
- Privacy official: [name, title, phone, email]
- Security official: [name, title, phone, email] (may be the same person)
- Complaint contact: [name or office, phone]
The officials keep this policy current, run training, take every report made under Section 9, and keep the records in Section 11.
Rule: 164.530(a), 164.308(a)(2).
3. Who sees which rider details
Each job gets the rider information it needs and no more. Access to dispatch software, broker portals, and shared files follows this table.
| Role | Rider details the job needs | Details the job does not need |
|---|---|---|
| Driver and attendant | Example: name, pickup and drop-off addresses, times, phone, mobility and oxygen needs, escort | Example: diagnosis, billing history |
| Dispatcher | [fill in] | [fill in] |
| Biller | [fill in] | [fill in] |
| Owner or manager | [fill in] | [fill in] |
| [Other role] | [fill in] | [fill in] |
The limit does not apply to information given to the rider, or to a doctor, clinic, or other health care provider for the rider’s treatment.
Rule: 164.502(b), 164.514(d).
4. Phones, paper manifests, and email
- Rider details stay in [dispatch software and driver app]. Staff do not text, email, or message them from personal accounts.
- Every phone, tablet, and computer that shows rider details locks after [1 to 5] minutes idle and hides message previews on the lock screen.
- Printed manifests stay face down or out of sight in the vehicle, never stay in a parked van, and go back to [the office shred bin] at the end of the shift.
- Email with rider details goes only through [encrypted email or the broker’s secure portal].
- A lost or stolen phone, tablet, laptop, or manifest is reported under Section 9 at once.
- Paper is shredded and old devices are wiped or destroyed under [disposal procedure].
Rule: 164.530(c), 164.310(b) to (d), 164.312.
5. Logins and ending access
- Every person has their own login to every system that holds rider data. Nobody shares a login.
- [Security official] grants access by role under Section 3, reviews the user list every [quarter], and reviews login and activity records every [month].
- When someone leaves or changes jobs, on the same day [Company name]:
- turns off their dispatch, driver app, email, and shared drive accounts;
- asks each broker to remove them from its portal and roster;
- changes the password on any administrator account they used;
- collects company phones, tablets, keys, badges, and fuel cards;
- has them delete rider details from any personal phone used for work, and confirms it.
- [Security official] signs the exit checklist and files it.
Rule: 164.308(a)(1)(ii)(D), 164.308(a)(3)(ii)(C), 164.308(a)(4), 164.312(a)(2)(i).
6. Training
- New workforce members finish HIPAA training before their first trip or first login, and no later than [30] days after hire.
- Staff whose work is affected by a change in this policy are retrained within [30] days of the change.
- [Security official] sends a security reminder at least every [quarter]: phishing calls and emails, lost phones, passwords.
- Each session is logged with the date, the topic, and who attended.
Rule: 164.530(b), 164.308(a)(5).
7. Sanctions
Breaking this policy leads to action matched to the harm and the intent.
| Level | Examples | Action |
|---|---|---|
| 1 | Manifest left in view, screen lock turned off | Retraining and written warning |
| 2 | Rider details sent by personal text, login shared | Final warning, off [broker] trips pending review |
| 3 | Looking up a rider out of curiosity, posting about a rider, a second level 2 | [Suspension or termination] |
| 4 | Selling or deliberately exposing rider information | Termination and referral to law enforcement |
Every sanction is written down, dated, and kept under Section 11. Nobody is disciplined for reporting a problem in good faith, for filing a complaint with HHS or taking part in an investigation, or for a disclosure HIPAA protects, such as a good-faith report of wrongdoing to a health oversight agency or to the person’s own lawyer.
Rule: 164.530(e) and (g), 164.308(a)(1)(ii)(C), 164.502(j), 160.316.
8. Complaints
[Complaint contact] logs every privacy complaint, looks into it, answers within [30] days, and records the outcome. Nobody is treated differently for complaining. [Covered entities only.]
Rule: 164.530(d) and (g).
9. Incidents and breaches
- Anyone who thinks rider information went where it should not (a lost phone, a manifest left at a clinic, a text to the wrong number, a login that should not have worked) tells [privacy official] within [1 hour], even when unsure.
- [Privacy official] logs it, limits the harm (recovers the paper, locks or wipes the device, resets the password), and records each step.
- [Privacy official] decides whether it is a breach. Any use or disclosure the Privacy Rule does not allow counts as one unless a written assessment shows a low probability the information was compromised, weighing the kind of information and identifiers, the person who received it, whether anyone actually saw or took it, and how much of the risk has been reduced.
- Brokers and health plans are told within their contract deadlines: [broker and deadline] / [broker and deadline].
- As a covered entity, [Company name] sends rider, HHS, and media notices on the federal schedule. As a business associate, it notifies the covered entity.
Rule: 164.308(a)(6), 164.402, 164.404 to 164.410, 164.530(f).
10. Vendors
Rider information goes to an outside company only after that company signs a business associate agreement. [Privacy official] keeps the list of vendors and their signed agreements.
Rule: 164.308(b), 164.502(e), 164.504(e).
11. Records and review
- This policy and its earlier versions, training logs, sanctions, complaints, incident files, risk analyses, and vendor agreements are kept six years, counted from when each was written or from its last day in effect if that is later, or [longer period] where a contract requires it.
- [Security official] reviews this policy every [12] months and after any new system, new broker contract, incident, or change in the law, and writes the date on page one.
Rule: 164.316(b)(2), 164.530(i) and (j).
12. Acknowledgment
I have received and read the [Company name] HIPAA privacy and security policy, had my questions answered, and completed training on [date]. I understand that breaking it can lead to the sanctions in Section 7.
| Name | Role | Signature | Date |
|---|---|---|---|
Choosing the numbers in the brackets
The rules leave most numbers to you, so set each one from your strictest contract rather than from HIPAA’s outer limit.
- Reporting time (Section 9). A business associate has up to 60 calendar days to tell the covered entity about a breach (164.410). Broker contracts are much shorter. CareOregon’s NEMT provider manual (version 1.3, February 2024) says suspicious activity or a breach of member information goes to the brokerage at once, and no more than 24 hours later. A one-hour internal limit leaves time to gather facts before that call.
- Training deadline (Section 6). HIPAA says new staff are trained “within a reasonable period of time.” Modivcare’s 2025 compliance attestation requires new employees to finish its training, HIPAA privacy and security included, within 30 days of hire. Texas law gives covered entities 90 days and adds a signed statement, as the guide to state privacy laws stricter than HIPAA explains.
- Email (Section 4). CareOregon’s manual says any email or correspondence with member information goes through a secure email portal, and a provider without one can ask the brokerage to send encrypted email instead.
- Retention (Section 11). Six years is the HIPAA floor. The same Modivcare attestation has providers keep training records, such as employee acknowledgments and rosters, for at least 10 years.
Ending access on the last day
Shut off a departing person’s access on their last day, and work from a written exit checklist. OCR calls breaches caused by current and former workforce members a recurring problem across industries, health care included. Its November 2017 cybersecurity newsletter on insider threats recommends a standard set of exit steps, which can be kept as a checklist, and tells covered entities and business associates to take back laptops, phones, keys, and badges, clear rider data from personal devices that were allowed to hold it, shut off remote access and outside accounts such as cloud services, and change passwords on administrator accounts the person used. NIST SP 800-66 Revision 2 (February 2024), the federal guide to putting the Security Rule into practice, adds a question small companies tend to skip: whether other organizations need to close accounts the person used for the job. In NEMT that means every broker portal and roster. The guide to letting a driver go puts those steps in order for the day itself.
The rule may get stricter. Under the Security Rule changes HHS proposed on January 6, 2025, access would have to end within one hour after a job ends, and other regulated entities would have to hear within 24 hours when a person’s access to their systems changes or ends. As of October 6, 2026, the Federal Register still lists only that proposal for the rulemaking. Writing “same day” into Section 5 now puts you most of the way to the proposed standard.
Sanctions staff can predict
Tier the sanctions, so a dispatcher knows a visible manifest and a deliberate leak are not handled the same way. NIST’s guide asks whether a sanctions policy has tiers that account for the size of the harm and the type of disclosure, and gives reprimand and termination as examples of sanctions. Section 7 uses four levels. Pair it with the one-page confidentiality agreement, which points each signer to these levels.
Keep the protected-disclosure sentence. HIPAA’s sanctions standard expressly does not apply to a good-faith whistleblower disclosure that meets 164.502(j), and 45 CFR 160.316 bars retaliation against anyone who files a complaint with HHS or takes part in an investigation. Both exceptions belong in the document staff sign.
Section 10 needs a signed agreement for each vendor before rider data moves. The business associate agreement template has the clauses and the deadlines to set.
Policies the software backs up
Sections 3 and 5 are easier to keep when the software enforces them. HealthRide is HIPAA compliant. In the provider portal you create a separate account for every dispatcher, biller, and office worker, each person sees only what their role allows, and every change is recorded. Sign-ins can use passkeys or two-step codes.
Frequently asked questions
- Does a small NEMT company really need written HIPAA policies?
- Yes, if HIPAA reaches it at all. The Security Rule requires every covered entity and business associate to keep its security policies in writing, and electronic copies count. The Privacy Rule requires covered entities to adopt privacy policies sized to the business. Size changes the length, not the duty. In 2015 OCR settled with Cornell Prescription Pharmacy, a single-location pharmacy in Denver, for $125,000 after finding it had no written Privacy Rule policies and had not trained its staff on privacy.
- Does the policy cover paper manifests or only electronic records?
- Both, if you are a covered entity. The Privacy Rule tells covered entities to safeguard protected health information in any form, which takes in printed manifests, trip sheets, and signature logs. The Security Rule covers electronic data only. A business associate still has to use appropriate safeguards for all the rider information it handles, paper included, because 164.504(e) writes that duty into its business associate agreement. One policy that covers both media is simpler to train on.
- Do drivers have to sign the HIPAA policy?
- HIPAA does not require a signature on the policy. It requires training on the policies, a record that the training happened, and a sanctions policy the workforce knows about. A signed acknowledgment page proves all three at once, which is why the template ends with one. Brokers check for it: Modivcare's 2025 attestation lists employee acknowledgments among the training records a provider must produce on request.
- How often should the HIPAA policy be reviewed?
- The Security Rule calls for periodic review and an update whenever operational or environmental changes affect the security of rider data. The Privacy Rule requires prompt revision when the law changes. Neither sets a calendar. A yearly review, plus one after any new software, new broker contract, incident, or change of official, meets both. Write each review date on the first page, because the six-year retention clock runs from the last day each version was in effect.
- What happens to the policy if HHS finalizes the Security Rule update?
- It would need tighter numbers. The January 6, 2025 proposal would require ending a departing worker's access within one hour, telling other regulated entities within 24 hours when someone's access to their systems changes, and security training within 30 days of first access and every 12 months. As of October 6, 2026 only the proposal had been published, so the current rule still applies.