Compliance and safety

What Is Protected Health Information (PHI)? What Counts on a NEMT Trip

Protected health information (PHI) is information that identifies a person and relates to their health, their care, or payment for it, held by a HIPAA covered entity or business associate in any form. On a NEMT trip, a rider's name with a pickup address, a dialysis appointment, a Medicaid ID, or a wheelchair need is PHI, whether it sits on a manifest, in a text, or is said out loud.

  • PHI is identifiable health, care, or payment information, on paper, on a screen, or spoken.
  • A trip manifest is PHI: it ties names and addresses to appointments, member numbers, and assistance needs.
  • Your drivers' employment records are not PHI under HIPAA, but keep them confidential anyway.
  • Give drivers the minimum they need: pickup, drop-off, time, and assistance level, not the diagnosis.
  • Broker agreements often require HIPAA training before a driver carries members, and fast breach reports.

What makes information PHI

HIPAA builds the term in layers, all in 45 CFR 160.103. Information is protected health information when it passes three tests:

  1. It is about health, care, or payment. It relates to a person’s past, present, or future physical or mental health or condition, the care they receive, or payment for that care. It includes demographic information collected from the person, such as an address or date of birth.
  2. It identifies the person. It names them, or there is a reasonable basis to believe it could be used to identify them.
  3. It is held or sent in any form. Electronic, paper, and spoken information all count. A dispatcher reading a pickup over the radio handles PHI just as a printed manifest does.

The HIPAA rules protect PHI in the hands of covered entities and their business associates. Many NEMT companies are one or both: a covered entity if your rides count as health care and you bill health plans electronically, or a business associate if a broker or plan hands you member information to run its rides. Whether your rides count as health care is the hard part of that test, and states classify NEMT differently. The HIPAA guide for NEMT providers walks through it, and the business associate agreement page covers the broker contract.

Some records are never PHI: education and student treatment records covered by the federal student records law, employment records a covered entity holds as an employer, and records about a person who died more than 50 years ago.

Which NEMT trip details are PHI

Detail PHI? Why
Rider name with pickup address and destination Yes Identifies the rider and shows where they get care
Medicaid ID or health plan member number Yes A health plan beneficiary number is a listed identifier
Appointment date and time Yes, when tied to the rider Dates directly related to a person are identifiers
Level of service: wheelchair, stretcher, escort, oxygen, weight with chair Yes Reveals the rider’s condition
Reason for the trip or a diagnosis in the notes Yes Health information in plain words
Signed trip log Yes Names the rider and records the care trip
GPS history of a van while a named rider is aboard Yes Links the rider to places and times of care
Broker trip number Yes, while it links to a rider Any unique identifying number is a listed identifier
Claims and remittance advice Yes Payment for care, tied to a member
A photo of a rider or of a manifest Yes Full-face photos are identifiers, and a manifest shows every name on it
Monthly count of trips by service level, with no names or dates Usually not Counts that identify no one are not individually identifiable
Your drivers’ files, drug tests, and background checks Not under HIPAA Employment records held as an employer are excluded
Your own vans’ plates and VINs Not by themselves The identifier list covers the rider’s vehicle, not your fleet

The last rows matter for your office. A driver’s drug test result is private, but it is an employment record, not PHI. Keep driver files locked anyway, because other laws and broker contracts protect them.

The 18 identifiers that make trip data identifiable

HIPAA’s safe harbor method says health information is de-identified only when all 18 kinds of identifiers are removed, for the person and for their relatives, employers, and household members, and the company has no actual knowledge that what is left could identify anyone (45 CFR 164.514(b)). The list shows what to strip before you share any trip data outside the job:

Identifier Where it shows up in NEMT
Names Manifests, trip logs, dispatch notes
Geographic units smaller than a state, including street address, city, county, and zip code Pickup and drop-off addresses. Only the first 3 digits of a zip code may stay, and only for areas of more than 20,000 people.
Every part of a date except the year, such as birth, admission, discharge, and death dates, and ages over 89 Trip dates, appointment times, dates of birth
Phone numbers and fax numbers Rider and caregiver contacts, facility fax requests
Email addresses Trip confirmations
Social Security numbers Old intake forms
Medical record numbers Facility trip requests
Health plan beneficiary numbers Medicaid and plan member IDs
Account numbers Private pay invoices
Certificate and license numbers A rider’s ID shown at pickup
Vehicle identifiers and license plates A rider’s or family member’s own car
Device identifiers and serial numbers A power chair’s serial number
Web addresses and IP addresses Online booking forms
Biometric identifiers, such as fingerprints and voice prints Voice recordings of calls
Full-face photos and similar images Dash camera and door camera footage
Any other unique number, characteristic, or code Broker trip numbers, rider numbers in your own system

Everyday habits that protect PHI

Most of the rules come down to a few habits in the van and at the desk.

  • Share the minimum. HIPAA requires reasonable efforts to limit each use or disclosure of PHI to the minimum needed (45 CFR 164.502(b)). A driver needs the pickup, the drop-off, the time, and the assistance level, not the diagnosis. Disclosures to a health care provider for treatment are an exception. See minimum necessary.
  • Keep rides private from each other. MTM Health’s Virginia handbook (approved August 10, 2026) bars drivers from showing or discussing PHI with unauthorized people, including other members on the same ride.
  • Keep paper out of sight. Keep manifests in a folder or face down, never on the dashboard, and lock the van when you walk a rider to the door.
  • Lock every phone and tablet. Use a passcode and auto-lock, and remove a driver’s logins the day they leave.
  • Say less at the door. “I’m here for your 9:30 ride” tells a neighbor nothing. HIPAA accepts incidental disclosures, such as being overheard, only when you use reasonable safeguards and share the minimum (45 CFR 164.502(a)(1)(iii) and 164.530(c)).
  • Talk to family with care. A covered entity may share information directly relevant to a family member’s or friend’s involvement in the rider’s care when the rider agrees or does not object (45 CFR 164.510(b)). Under a broker, follow its rule on who you may speak with.
  • Never post, share, or keep photos. No pictures of manifests, riders, or addresses on personal phones or social media.
  • Destroy it properly. Shred old manifests and trip logs once your retention period ends, and wipe phones before you sell or reassign them.

Training is required, not optional. A covered entity must train its whole workforce on its privacy policies and train new members within a reasonable time after they join (45 CFR 164.530(b)). Covered entities and business associates alike must run a security awareness program for everyone, managers included (45 CFR 164.308(a)(5)). Brokers go further: MTM Health’s Virginia handbook requires HIPAA training before a driver transports members, and its standard agreement, in the version Pennsylvania posts dated January 1, 2023, requires fraud, waste, and abuse and HIPAA in driver training. The NEMT HIPAA policy template puts these habits in writing.

When PHI gets out

A breach is an access, use, or disclosure of PHI the rules do not allow that compromises it. It is presumed unless a risk assessment of the factors the rule lists shows a low probability the information was compromised (45 CFR 164.402). Three situations are not breaches:

  • A workforce member opens PHI by mistake, in good faith and within their job, and does nothing more with it.
  • One authorized person at your company sends PHI to another authorized person there by mistake, such as a manifest emailed to the wrong dispatcher.
  • You believe in good faith that the person who received it could not have kept it, such as a manifest handed to the wrong clinic desk and returned unread.

Anything else is presumed a breach and starts the clock. MTM’s standard agreement requires you to report any breach of PHI or personal information to MTM. WellTrans’s subcontractor business associate agreement, revised October 16, 2025, allows one business day from discovery. For the notice steps and deadlines, see NEMT data breach.

Frequently asked questions

Is a rider's name and address protected health information?

On its own, a name and address in a phone book is not. Once your company holds it as a covered entity or business associate, in connection with a ride to care, it is. HIPAA's definition covers demographic information collected from a person when it relates to their health, their care, or payment for it and identifies them (45 CFR 160.103). A name and address on a Medicaid trip manifest tells anyone who reads it that the person gets care there.

Is a NEMT trip manifest PHI?

Yes. A manifest links each rider's name, address, and phone number to an appointment, a destination such as a clinic, a member number, and often a level of service such as wheelchair or stretcher. Each of those is either a HIPAA identifier or health information. Treat every copy, printed or on a phone, as PHI.

Are my drivers' background checks and drug test results PHI?

Not under HIPAA. The definition of PHI leaves out employment records a covered entity holds in its role as employer (45 CFR 160.103). Other laws and your broker's rules can still require you to keep driver files confidential, so store them locked and limit who sees them.

Does HIPAA apply to PHI if I only carry private pay riders?

The HIPAA rules apply to covered entities and their business associates. A company that bills no health plan electronically and handles no rider information for a broker, plan, or provider may fall outside them. State privacy laws, facility contracts, and your riders' trust still apply, and one broker contract changes the answer. See HIPAA for NEMT providers for the full test.

How long does PHI stay protected after a rider dies?

For 50 years. A covered entity must keep following the privacy rules for a deceased person's information for 50 years after death (45 CFR 164.502(f)), and information about someone who died more than 50 years ago is no longer PHI.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter