Compliance and safety

What Is a Business Associate Agreement (BAA)? When NEMT Companies Need One and What It Must Say

A business associate agreement (BAA) is the written contract HIPAA requires before a company creates, receives, keeps, or sends protected health information for a covered entity or another business associate. In NEMT, you usually sign one with each broker or health plan that sends you trip manifests, and you get one from every vendor that handles rider information for you, such as a billing service, scheduling software, or cloud storage.

  • Brokers that send you manifests usually have you sign their agreement, as MTM Health and WellTrans do.
  • Get a signed agreement from every vendor that handles rider information before any data moves.
  • HIPAA sets ten required clauses. A broker's agreement often adds much shorter deadlines.
  • HIPAA allows up to 60 days to report a breach, but WellTrans's agreement allows one business day.
  • Keep every signed agreement for 6 years after it was last in effect.

What a business associate agreement is

HIPAA protects health information held by covered entities: health plans, clearinghouses, and health care providers that send standard electronic transactions such as claims. A business associate is a person or company, other than a member of the covered entity’s workforce, that creates, receives, maintains, or transmits protected health information on its behalf. HIPAA names billing, claims processing, data analysis, and practice management as examples, along with legal, accounting, consulting, and management services (45 CFR 160.103).

A subcontractor that does the same work for a business associate is a business associate too. That is where most NEMT companies fit. A state or health plan hires a broker, and the broker hands you member names, addresses, phone numbers, and appointment details to run the ride.

The business associate agreement is the written proof that the other side will protect that information. HIPAA lets a covered entity or business associate share health information with a vendor only after getting that assurance in writing (45 CFR 164.502(e)). HHS says a business associate is directly liable for uses and disclosures its agreement does not allow, and for failing to protect electronic health information under the Security Rule.

When a NEMT company signs or asks for one

Two directions matter. You sign the agreement your broker or plan gives you, and you get agreements from your own vendors.

Situation Who signs Why
You run trips for a broker or plan that sends manifests You sign the broker’s agreement Brokers are business associates of the state or plan. Washington’s Health Care Authority says its contracts name its NEMT brokers as business associates (May 2025). You are their subcontractor.
A billing service sends your claims The billing service signs yours HIPAA names billing and claims processing as business associate work
Scheduling, GPS, or cloud software stores trip data The vendor signs HHS lists cloud service providers as business associates, even for encrypted data they cannot read
An IT company supports your computers and systems The IT company signs HHS lists IT vendors whose support work gives them access to electronic health information
An accountant or attorney sees trip records The firm signs HHS lists CPA firms and attorneys whose work involves health information
A factoring company buys your broker invoices The factoring company signs WellTrans’s agreement names factoring and billing companies that get your trip logs, manifests, or billing documents

Whether your own company is a covered entity depends on whether your rides count as health care and how you bill. See HIPAA for NEMT providers and HIPAA covered entity. Either way, a broker that sends you member data will ask you to sign.

When you do not need one

HHS’s business associate guidance, last reviewed July 30, 2026, lists cases where no agreement is needed:

  • Your employees. Drivers, dispatchers, and office staff on your payroll are workforce members, not business associates.
  • Billing a plan for your own trips. HHS says that when a provider submits a claim to a health plan, each side acts for itself, so neither is the other’s business associate.
  • Incidental access. A janitor or electrician who might see a manifest by chance does not need one, as long as you keep reasonable safeguards.
  • Pure carriers. The Postal Service, some couriers, and their electronic equivalents only pass information along. A company that reaches into the data regularly to do a job for you is not a carrier.
  • Banks. Processing card payments, checks, and transfers is normal banking work.

What HIPAA requires the agreement to say

Every agreement must contain these terms (45 CFR 164.504(e) and 164.314(a)). The same rules apply to an agreement between a business associate and its subcontractor.

Clause What it requires
1. Permitted uses Lists what the business associate may do with the information
2. No other uses No use or disclosure beyond the agreement or what the law requires
3. Safeguards Appropriate safeguards and compliance with the Security Rule for electronic information
4. Reporting Reports of any use or disclosure the agreement does not allow, security incidents, and breaches (164.410)
5. Subcontractors Every subcontractor agrees to the same restrictions in writing
6. Rider rights Information made available for access, amendment, and an accounting of disclosures
7. Privacy Rule duties Follows the Privacy Rule when doing a task the covered entity owes
8. HHS access Internal practices, books, and records open to HHS
9. End of contract Returns or destroys all information if feasible, and keeps no copies
10. Termination Lets the covered entity end the contract for a material violation

HHS publishes sample language for each clause, dated January 25, 2013. HHS says it is only sample language, may not make a binding contract under state law, and does not replace a lawyer. Use the business associate agreement checklist to check any draft against this list.

What broker agreements add

A broker’s agreement can be much stricter than HIPAA. HIPAA gives a business associate up to 60 calendar days after discovery to report a breach of unsecured information (164.410). WellTrans’s Subcontractor Business Associate Agreement, revised October 16, 2025, shows how far a broker can go:

Term HIPAA floor WellTrans agreement
Improper use or a security incident Report it Report it within one business day
Breach of unsecured information Report within 60 calendar days Written notice within one business day
A rider’s request to see or correct records Make the information available Within five business days of WellTrans’s request
Your own vendors Same restrictions in writing An agreement with billing and factoring companies and anyone who gets trip logs, manifests, or billing papers
Training Security training for your whole workforce Train staff on the agreement and HIPAA, and give proof on request
End of contract Return or destroy if feasible Return or destroy, and certify the destruction

WellTrans’s agreement also has you indemnify WellTrans and its clients for HIPAA violations, and lets it ask you for a privacy and security survey, audit, or attestation. See WellTrans.

MTM Health’s standard agreement, in the January 1, 2023 version Pennsylvania posts, requires you to sign its business associate agreement (Appendix A) and to report any breach of member information to MTM (section 2.I). It also bars you from sharing member information with anyone outside your company, or subcontracting any services, without MTM’s written consent (sections 21.B and 12.A). So ask MTM in writing before a billing service logs in for you. See MTM Health.

What a missing agreement costs

On April 20, 2017, HHS announced that the Center for Children’s Digestive Health, a small pediatric practice with seven Illinois clinics, paid $31,000 and agreed to a corrective action plan. It had sent records to a storage company since 2003, and neither side could produce a signed agreement dated before October 12, 2015. HHS also lists a business associate’s failure to sign agreements with its subcontractors among the violations it can enforce directly.

How to handle business associate agreements, step by step

  1. List every outside company that touches rider names, addresses, trip logs, or claims.
  2. Read each broker agreement before signing. Write down its breach and incident deadlines.
  3. Get a signed agreement from each vendor before it sees any rider information. Your billing service comes first.
  4. Set vendor deadlines shorter than your broker’s. If your broker wants one business day, your vendors need to tell you faster. HHS’s sample invites a stricter timeframe.
  5. Keep every signed agreement for 6 years from when it was made or last in effect, whichever is later (45 CFR 164.316).
  6. Add it to your policy. Your HIPAA policy should say no vendor gets rider information without a signed agreement.
  7. Watch for the Security Rule update. HHS proposed on January 6, 2025 to require written verification from each business associate, at least every 12 months, that required technical safeguards are in place. As of September 2026 it is still a proposal.

Frequently asked questions

Do I need a business associate agreement with my NEMT broker?

Usually yes, and the broker writes it. MTM Health's standard agreement, in the January 1, 2023 version Pennsylvania posts, requires providers to sign its business associate agreement (Appendix A). WellTrans attaches a Subcontractor Business Associate Agreement to its provider agreement, revised October 16, 2025. Read the reporting deadlines and the subcontractor rules before you sign.

Do my drivers need to sign a business associate agreement?

No. HIPAA's definition of a business associate leaves out members of your own workforce, so employees do not sign one. Train them instead. The Security Rule requires security awareness training for your whole workforce, and brokers such as WellTrans require HIPAA training and proof of it. A driver who works as an outside contractor is a different question for your attorney.

Does my scheduling or GPS software company need to sign one?

Yes, if it stores, receives, or sends rider information for you. HHS lists cloud service providers and IT vendors that maintain health information as business associates. Its cloud computing guidance, last reviewed December 23, 2022, says that is true even when the vendor stores only encrypted data and has no key to read it.

Can I use a free business associate agreement template?

You can start from HHS's sample provisions, published January 25, 2013. HHS says they are sample language only, may not be enough for a binding contract under state law, and do not replace a lawyer. Brokers use their own agreements, so the template is for your vendors. Check any template against the ten clauses HIPAA requires.

What happens if I share rider information without a business associate agreement?

You can face HIPAA enforcement, and so can the vendor. On April 20, 2017, HHS announced that a small Illinois pediatric practice paid $31,000 because it had sent records to a storage company since 2003 with no signed agreement. HHS also says a business associate is directly liable for failing to sign agreements with its own subcontractors.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter