Compliance and safety
What Is Protected Health Information (PHI)? What Counts on a NEMT Trip
Protected health information (PHI) is information that identifies a person and relates to their health, their care, or payment for it, held by a HIPAA covered entity or business associate in any form. On a NEMT trip, a rider's name with a pickup address, a dialysis appointment, a Medicaid ID, or a wheelchair need is PHI, whether it sits on a manifest, in a text, or is said out loud.
- PHI is identifiable health, care, or payment information, on paper, on a screen, or spoken.
- A trip manifest is PHI: it ties names and addresses to appointments, member numbers, and assistance needs.
- Your drivers' employment records are not PHI under HIPAA, but keep them confidential anyway.
- Give drivers the minimum they need: pickup, drop-off, time, and assistance level, not the diagnosis.
- Broker agreements often require HIPAA training before a driver carries members, and fast breach reports.
What makes information PHI
HIPAA builds the term in layers, all in 45 CFR 160.103. Information is protected health information when it passes three tests:
- It is about health, care, or payment. It relates to a person’s past, present, or future physical or mental health or condition, the care they receive, or payment for that care. It includes demographic information collected from the person, such as an address or date of birth.
- It identifies the person. It names them, or there is a reasonable basis to believe it could be used to identify them.
- It is held or sent in any form. Electronic, paper, and spoken information all count. A dispatcher reading a pickup over the radio handles PHI just as a printed manifest does.
The HIPAA rules protect PHI in the hands of covered entities and their business associates. Many NEMT companies are one or both: a covered entity if your rides count as health care and you bill health plans electronically, or a business associate if a broker or plan hands you member information to run its rides. Whether your rides count as health care is the hard part of that test, and states classify NEMT differently. The HIPAA guide for NEMT providers walks through it, and the business associate agreement page covers the broker contract.
Some records are never PHI: education and student treatment records covered by the federal student records law, employment records a covered entity holds as an employer, and records about a person who died more than 50 years ago.
Which NEMT trip details are PHI
| Detail | PHI? | Why |
|---|---|---|
| Rider name with pickup address and destination | Yes | Identifies the rider and shows where they get care |
| Medicaid ID or health plan member number | Yes | A health plan beneficiary number is a listed identifier |
| Appointment date and time | Yes, when tied to the rider | Dates directly related to a person are identifiers |
| Level of service: wheelchair, stretcher, escort, oxygen, weight with chair | Yes | Reveals the rider’s condition |
| Reason for the trip or a diagnosis in the notes | Yes | Health information in plain words |
| Signed trip log | Yes | Names the rider and records the care trip |
| GPS history of a van while a named rider is aboard | Yes | Links the rider to places and times of care |
| Broker trip number | Yes, while it links to a rider | Any unique identifying number is a listed identifier |
| Claims and remittance advice | Yes | Payment for care, tied to a member |
| A photo of a rider or of a manifest | Yes | Full-face photos are identifiers, and a manifest shows every name on it |
| Monthly count of trips by service level, with no names or dates | Usually not | Counts that identify no one are not individually identifiable |
| Your drivers’ files, drug tests, and background checks | Not under HIPAA | Employment records held as an employer are excluded |
| Your own vans’ plates and VINs | Not by themselves | The identifier list covers the rider’s vehicle, not your fleet |
The last rows matter for your office. A driver’s drug test result is private, but it is an employment record, not PHI. Keep driver files locked anyway, because other laws and broker contracts protect them.
The 18 identifiers that make trip data identifiable
HIPAA’s safe harbor method says health information is de-identified only when all 18 kinds of identifiers are removed, for the person and for their relatives, employers, and household members, and the company has no actual knowledge that what is left could identify anyone (45 CFR 164.514(b)). The list shows what to strip before you share any trip data outside the job:
| Identifier | Where it shows up in NEMT |
|---|---|
| Names | Manifests, trip logs, dispatch notes |
| Geographic units smaller than a state, including street address, city, county, and zip code | Pickup and drop-off addresses. Only the first 3 digits of a zip code may stay, and only for areas of more than 20,000 people. |
| Every part of a date except the year, such as birth, admission, discharge, and death dates, and ages over 89 | Trip dates, appointment times, dates of birth |
| Phone numbers and fax numbers | Rider and caregiver contacts, facility fax requests |
| Email addresses | Trip confirmations |
| Social Security numbers | Old intake forms |
| Medical record numbers | Facility trip requests |
| Health plan beneficiary numbers | Medicaid and plan member IDs |
| Account numbers | Private pay invoices |
| Certificate and license numbers | A rider’s ID shown at pickup |
| Vehicle identifiers and license plates | A rider’s or family member’s own car |
| Device identifiers and serial numbers | A power chair’s serial number |
| Web addresses and IP addresses | Online booking forms |
| Biometric identifiers, such as fingerprints and voice prints | Voice recordings of calls |
| Full-face photos and similar images | Dash camera and door camera footage |
| Any other unique number, characteristic, or code | Broker trip numbers, rider numbers in your own system |
Everyday habits that protect PHI
Most of the rules come down to a few habits in the van and at the desk.
- Share the minimum. HIPAA requires reasonable efforts to limit each use or disclosure of PHI to the minimum needed (45 CFR 164.502(b)). A driver needs the pickup, the drop-off, the time, and the assistance level, not the diagnosis. Disclosures to a health care provider for treatment are an exception. See minimum necessary.
- Keep rides private from each other. MTM Health’s Virginia handbook (approved August 10, 2026) bars drivers from showing or discussing PHI with unauthorized people, including other members on the same ride.
- Keep paper out of sight. Keep manifests in a folder or face down, never on the dashboard, and lock the van when you walk a rider to the door.
- Lock every phone and tablet. Use a passcode and auto-lock, and remove a driver’s logins the day they leave.
- Say less at the door. “I’m here for your 9:30 ride” tells a neighbor nothing. HIPAA accepts incidental disclosures, such as being overheard, only when you use reasonable safeguards and share the minimum (45 CFR 164.502(a)(1)(iii) and 164.530(c)).
- Talk to family with care. A covered entity may share information directly relevant to a family member’s or friend’s involvement in the rider’s care when the rider agrees or does not object (45 CFR 164.510(b)). Under a broker, follow its rule on who you may speak with.
- Never post, share, or keep photos. No pictures of manifests, riders, or addresses on personal phones or social media.
- Destroy it properly. Shred old manifests and trip logs once your retention period ends, and wipe phones before you sell or reassign them.
Training is required, not optional. A covered entity must train its whole workforce on its privacy policies and train new members within a reasonable time after they join (45 CFR 164.530(b)). Covered entities and business associates alike must run a security awareness program for everyone, managers included (45 CFR 164.308(a)(5)). Brokers go further: MTM Health’s Virginia handbook requires HIPAA training before a driver transports members, and its standard agreement, in the version Pennsylvania posts dated January 1, 2023, requires fraud, waste, and abuse and HIPAA in driver training. The NEMT HIPAA policy template puts these habits in writing.
When PHI gets out
A breach is an access, use, or disclosure of PHI the rules do not allow that compromises it. It is presumed unless a risk assessment of the factors the rule lists shows a low probability the information was compromised (45 CFR 164.402). Three situations are not breaches:
- A workforce member opens PHI by mistake, in good faith and within their job, and does nothing more with it.
- One authorized person at your company sends PHI to another authorized person there by mistake, such as a manifest emailed to the wrong dispatcher.
- You believe in good faith that the person who received it could not have kept it, such as a manifest handed to the wrong clinic desk and returned unread.
Anything else is presumed a breach and starts the clock. MTM’s standard agreement requires you to report any breach of PHI or personal information to MTM. WellTrans’s subcontractor business associate agreement, revised October 16, 2025, allows one business day from discovery. For the notice steps and deadlines, see NEMT data breach.
Frequently asked questions
Is a rider's name and address protected health information?
On its own, a name and address in a phone book is not. Once your company holds it as a covered entity or business associate, in connection with a ride to care, it is. HIPAA's definition covers demographic information collected from a person when it relates to their health, their care, or payment for it and identifies them (45 CFR 160.103). A name and address on a Medicaid trip manifest tells anyone who reads it that the person gets care there.
Is a NEMT trip manifest PHI?
Yes. A manifest links each rider's name, address, and phone number to an appointment, a destination such as a clinic, a member number, and often a level of service such as wheelchair or stretcher. Each of those is either a HIPAA identifier or health information. Treat every copy, printed or on a phone, as PHI.
Are my drivers' background checks and drug test results PHI?
Not under HIPAA. The definition of PHI leaves out employment records a covered entity holds in its role as employer (45 CFR 160.103). Other laws and your broker's rules can still require you to keep driver files confidential, so store them locked and limit who sees them.
Does HIPAA apply to PHI if I only carry private pay riders?
The HIPAA rules apply to covered entities and their business associates. A company that bills no health plan electronically and handles no rider information for a broker, plan, or provider may fall outside them. State privacy laws, facility contracts, and your riders' trust still apply, and one broker contract changes the answer. See HIPAA for NEMT providers for the full test.
How long does PHI stay protected after a rider dies?
For 50 years. A covered entity must keep following the privacy rules for a deceased person's information for 50 years after death (45 CFR 164.502(f)), and information about someone who died more than 50 years ago is no longer PHI.