# HIPAA for NEMT Providers in 2027: What Applies and What to Put in Place

Canonical URL: https://nemtguide.com/guides/hipaa-for-nemt/ · Updated 2026-09-28

HIPAA reaches most NEMT providers in one of two ways. If your rides count as health care and you bill health plans electronically, you may be a covered entity. If a broker or plan hands you member information to run its rides, you are usually its business associate. Either way, plan on a signed agreement, a risk analysis, safeguards for phones and manifests, training, and a breach plan.

- MTM Health and WellTrans have the companies that run their rides sign a business associate agreement, and Modivcare treats them as HIPAA subcontractors.
- Whether a van company is a covered entity turns on whether its rides count as health care, and state Medicaid programs classify NEMT differently.
- Every business associate must follow the HIPAA Security Rule, starting with a written risk analysis.
- Broker agreements can be much stricter than HIPAA. WellTrans wants a breach reported within one business day.
- HHS plans a stricter Security Rule and lists July 2027 as its target for the final rule.

A trip manifest holds exactly what HIPAA protects. MTM Health's Virginia manifests, for example, list the member's full name and phone number, the pickup and appointment addresses and times, the doctor's name and phone number, the level of assistance, any escort, and the member's weight with mobility equipment. Your drivers carry that on a phone or a clipboard all day. How much of HIPAA applies to your company depends on what you are under the rule and what your contracts say.

## Does HIPAA apply to a NEMT company?

HIPAA can reach you in three ways. You may be a covered entity, a business associate, or bound by a contract that requires HIPAA compliance. Many NEMT companies are at least one of these.

### Test 1: are you a covered entity?

A covered entity is a health plan, a health care clearinghouse, or a health care provider that sends health information electronically in a standard transaction ([45 CFR 160.103](https://www.ecfr.gov/current/title-45/section-160.103)). CMS's Covered Entity Decision Tool asks a provider two questions:

1. **Do you furnish, bill, or get paid for health care in the normal course of business?**
2. **Do you send any covered transactions electronically?** A claim counts when it asks a health plan to pay a health care provider for health care ([45 CFR 162.1101](https://www.ecfr.gov/current/title-45/section-162.1101)). The Medicaid program is a health plan under HIPAA. Using a billing service or clearinghouse to send your claims still counts as sending them yourself.

Answer yes to both and you are a covered entity. The first question is the hard one for NEMT:

- **Ambulance companies** are health care providers. Ambulance service is one of the medical services listed in the Medicare law HIPAA points to ([42 U.S.C. 1395x(s)(7)](https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title42-section1395x&num=0&edition=prelim)).
- **Van and sedan companies** are less settled. CMS told state Medicaid directors on September 19, 2006 that taxi services are atypical providers, meaning they do not provide health care as HIPAA defines it, even when they submit HIPAA transactions (SMDL 06-020).
- **States differ.** As of September 2026, North Carolina Medicaid lists non-emergency transportation providers as atypical providers that do not meet HIPAA's definition of a health care provider, and Pennsylvania lists taxi services. Illinois lets atypical transportation providers bill with a state provider number instead of an NPI (handbook, March 11, 2024).

Ask your state Medicaid agency how it classifies your provider type. If you bill Medicaid or a health plan directly, have a health care attorney confirm your status. For more on the covered entity test, see HIPAA covered entity.

### Test 2: are you a business associate?

A business associate creates, receives, maintains, or transmits protected health information on behalf of a covered entity. The definition also covers a subcontractor that does the same for another business associate (45 CFR 160.103). That is how most broker work fits:

- **The state hires the broker as its business associate.** Washington's Health Care Authority says its contracts designate its NEMT brokers as HIPAA business associates (May 2025).
- **The broker treats you as its subcontractor.** Modivcare's 2023 provider compliance training says transportation providers are subcontractors of Modivcare, a business associate of health plans and state Medicaid agencies.
- **The broker has you sign.** MTM Health's standard agreement, in the January 1, 2023 version Pennsylvania posts, requires you to sign its business associate agreement. WellTrans attaches a Subcontractor Business Associate Agreement to its provider agreement, revised October 16, 2025.

HHS says a business associate is directly liable under HIPAA for uses and disclosures its contract does not allow, and for failing to protect electronic health information under the Security Rule.

### Test 3: what do your contracts require?

Broker agreements write HIPAA into your duties whatever your status. MTM's standard agreement requires you to keep member health and personal information confidential, report any breach to MTM, and include HIPAA in driver training. MTM's Virginia handbook requires HIPAA training before a driver transports members.

| Your situation | Where HIPAA usually lands | What to plan for |
|---|---|---|
| Ambulance company billing Medicaid or plans electronically | Covered entity | The full Privacy, Security, and Breach Notification Rules |
| Van or sedan company billing Medicaid or plans electronically | Depends on how your state and your lawyer treat your service | Covered entity duties until your status is confirmed |
| Company running rides for a broker or plan that sends you manifests | Business associate under the broker's agreement | The Security Rule, the agreement's terms, and breach reports to the broker |
| Company carrying only private pay riders, billing no plan or broker | Outside HIPAA's covered entity test | Protect rider information anyway, and read any facility contract's privacy terms |

## What counts as protected health information on a NEMT trip

Protected health information is health information that identifies a person, in any form: electronic, paper, or spoken (45 CFR 160.103). It includes information about a person's health condition, the care they receive, or payment for that care. Modivcare's training puts it simply: treat any identifiable information about its members as protected.

On a NEMT trip, that covers:

- **Who and where together.** A name with a pickup address and a dialysis center, cancer clinic, or treatment program as the destination.
- **Member numbers.** Medicaid IDs, health plan numbers, trip numbers, and dates of birth.
- **Health details.** Wheelchair or stretcher needs, weight with equipment, escort requirements, and notes about a condition.
- **Trip records.** Signed trip logs, GPS records tied to a rider, claims, and payment statements.

HIPAA lists 18 identifiers that must come out before information counts as de-identified under its safe harbor method. They include names, street addresses, cities, and zip codes, every date but the year, phone numbers, health plan numbers, license plates, and full-face photos ([45 CFR 164.514(b)](https://www.ecfr.gov/current/title-45/section-164.514)). A daily count of rides by vehicle type, with nothing else, identifies no one. A photo of a manifest identifies everyone on it. See protected health information.

## What a business associate agreement requires

The broker writes the agreement, and you sign it. Under [45 CFR 164.504(e)](https://www.ecfr.gov/current/title-45/section-164.504), every business associate agreement must:

1. Say how you may use and disclose the information, and bar any other use.
2. Require safeguards, including the Security Rule for electronic information.
3. Require you to report any use or disclosure the agreement does not allow, including breaches.
4. Pass the same terms down to any subcontractor you use.
5. Make information available for members' access, amendment, and accounting requests.
6. Open your records to HHS.
7. Require you to return or destroy the information when the agreement ends, where feasible.
8. Let the other party end the agreement if you violate a material term.

A broker's agreement can go further than the rule. WellTrans's Subcontractor Business Associate Agreement, revised October 16, 2025, requires you to:

- **Report fast.** Any disallowed use or disclosure, any security incident, and any breach within one business day of discovery.
- **Sign your own vendors.** Put a business associate agreement in place with billing companies, factoring companies, and anyone else who gets your trip logs, manifests, or billing documents.
- **Answer requests quickly.** Give WellTrans access to member records within five business days of a request.
- **Clean up at the end.** Return or destroy all health information when the agreement ends, and certify that you destroyed it.
- **Train and prove it.** Train your employees and agents on HIPAA and show proof on request.

Your own vendors need agreements too. A business associate may give health information to a subcontractor only after getting written assurances in a business associate agreement ([45 CFR 164.502(e)](https://www.ecfr.gov/current/title-45/section-164.502) and 164.308(b)). That can include your billing service, dispatch and GPS software vendors, cloud storage, answering service, IT support, and factoring company, whenever they create, receive, keep, or send rider information for you. See business associate agreement and the business associate agreement checklist.

## The safeguards a small NEMT company needs

The Security Rule applies to covered entities and business associates alike (45 CFR 164.302). It lets you fit safeguards to your size, your systems, your costs, and your risks (164.306(b)). Some parts are required. Others are addressable, which means you put them in place if reasonable, or write down why not and use an equal alternative (164.306(d)).

| Safeguard | Rule | What it looks like in a five-van company |
|---|---|---|
| Risk analysis (required) | 164.308(a)(1) | List every place rider information lives: driver phones, tablets, the dispatch computer, email, broker portals, paper manifests, and the file cabinet. Rate what could go wrong with each. |
| Risk management (required) | 164.308(a)(1) | Fix the biggest risks first and write down the plan. |
| Security official | 164.308(a)(2) | Name one person, often the owner, in writing. |
| Sanction policy (required) | 164.308(a)(1) | Written consequences for staff who break the rules. |
| Security awareness training | 164.308(a)(5) | Train everyone, managers included, before they touch rider information. |
| Unique logins (required) | 164.312(a)(2)(i) | One login per person for every portal and dispatch account. No shared passwords. |
| Automatic logoff and encryption (addressable) | 164.312(a)(2) | Passcodes, auto-lock, and device encryption on every phone and tablet. |
| Backups and a recovery plan (required) | 164.308(a)(7) | Back up trip records and test that you can restore them. |
| Disposal and reuse (required) | 164.310(d)(2) | Wipe old phones and drives before you sell, recycle, or reassign them. |
| Ending access (addressable) | 164.308(a)(3) | Remove a driver's logins the day they leave. |
| Documentation (required) | 164.316(b) | Keep policies and records in writing for 6 years and review them periodically. |

Rule citations are to 45 CFR.

"Workforce" in HIPAA means employees and anyone else whose work you directly control, paid or not (45 CFR 160.103). Contract drivers you dispatch and direct can count, so train them too.

For the risk analysis, the free Security Risk Assessment Tool from HHS and its health IT office walks you through it. Version 3.7 comes as a Windows app or an Excel workbook, and it is built for small and medium providers (page updated September 18, 2026). The HIPAA risk assessment template covers the same ground on paper.

Encryption does double duty. HHS guidance says electronic information encrypted to the standard in NIST Special Publication 800-111, with the key kept safe, is not "unsecured," so the breach notice rules do not apply if the device is lost. Your broker agreement may still require you to report the loss: WellTrans wants any security incident reported within one business day. Paper that has been shredded so it cannot be read or put back together counts as destroyed. Blacking out names does not.

## Everyday privacy rules for drivers and dispatchers

Drivers and dispatchers handle rider information all day, so these rules matter most in the van and at the dispatch desk.

- **Share the minimum.** Use and share only the information needed for the job ([45 CFR 164.502(b)](https://www.ecfr.gov/current/title-45/section-164.502)). A driver needs the pickup, the destination, the time, and the assistance level, not the diagnosis. See minimum necessary.
- **Keep rides private from each other.** MTM's Virginia handbook bars drivers from showing or discussing health information with unauthorized people, including other members on the same ride. Modivcare lists discussing one member's trip with another rider as an improper disclosure.
- **Keep paper out of sight.** Modivcare's training tells providers to keep trip records out of view, never leave health information in an unlocked vehicle, and dispose of paperwork properly.
- **Speak with care.** HIPAA accepts incidental disclosures, such as being overheard, when you use reasonable safeguards and share only what is needed. HHS gives speaking quietly in public areas as an example.
- **Text and email with limits.** HHS says covered providers may email patients with reasonable safeguards, such as checking the address and limiting what is sent. Patients may ask to be contacted another way. Keep reminders to the pickup time and place. See HIPAA texting for NEMT.
- **Family and caregivers.** A covered entity may share information with a family member or friend involved in the rider's care when the rider agrees or does not object ([45 CFR 164.510(b)](https://www.ecfr.gov/current/title-45/section-164.510)). Under a broker, follow the broker's rule on who you may talk to.
- **Never post or browse.** Modivcare lists posting members' trip records on social media and looking up trip records out of curiosity as improper disclosures.

## When something goes wrong: breach rules and deadlines

A breach is any use or disclosure of protected health information the rules do not allow that compromises it. HIPAA presumes a breach unless a written risk assessment shows a low probability the information was compromised ([45 CFR 164.402](https://www.ecfr.gov/current/title-45/section-164.402)). The assessment weighs four factors:

1. What information was involved and how easily it identifies people.
2. Who got it.
3. Whether it was actually viewed or taken.
4. How far the risk has been reduced, for example by getting a written promise to delete it.

Three narrow exceptions apply: an honest mistake by staff acting within their job, a mix-up between two people allowed to see the information at the same company, and a disclosure where the person could not reasonably have kept the information. You carry the burden of proving a notice was not needed (164.414), so write the assessment down.

| Who | Must tell | Deadline | Rule |
|---|---|---|---|
| A business associate, such as a company running broker trips | The broker or covered entity in its agreement | Without unreasonable delay and within 60 days of discovery. WellTrans's agreement: one business day. | 164.410 |
| A covered entity | Each person affected, by first-class mail or agreed email | Without unreasonable delay and within 60 days of discovery | 164.404 |
| A covered entity | HHS, through the OCR breach portal | 500 or more people: with the notices to individuals. Fewer than 500: within 60 days after the end of the calendar year. | 164.408 |
| A covered entity | Prominent media in the state | More than 500 residents of one state: within 60 days | 164.406 |

A breach counts as discovered on the first day anyone on your staff, other than the person who caused it, knows about it or should have. The clock starts then, not when the owner hears. See NEMT data breach for a step-by-step response.

## Penalties and enforcement

HHS's Office for Civil Rights enforces HIPAA with civil money penalties. The amounts below were adjusted for inflation on January 28, 2026 ([45 CFR 102.3](https://www.ecfr.gov/current/title-45/section-102.3)):

| What OCR finds | Per violation | Yearly cap for identical violations |
|---|---|---|
| You did not know, and reasonable care would not have told you | $145 to $73,011 | $2,190,294 |
| Reasonable cause, not willful neglect | $1,461 to $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 to $73,011 | $2,190,294 |
| Willful neglect, not corrected within 30 days | $73,011 to $2,190,294 | $2,190,294 |

HHS said on April 30, 2019 that, until further notice, it would apply lower yearly caps to the first three tiers: $25,000, $100,000, and $250,000, each adjusted for inflation (84 FR 18151). The cap for uncorrected willful neglect stays at the top amount.

Business associates face enforcement too. On August 18, 2025, OCR announced that BST & Co. CPAs, an accounting firm acting as a business associate, paid $175,000 and agreed to two years of monitoring after a ransomware attack. OCR found it had failed to conduct an accurate and thorough risk analysis.

Other exposure:

- **Complaints.** Anyone can complain to OCR within 180 days of learning of a problem (45 CFR 160.306).
- **State attorneys general** can sue in federal court on behalf of their residents ([42 U.S.C. 1320d-5(d)](https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title42-section1320d-5&num=0&edition=prelim)).
- **Criminal penalties.** Knowingly obtaining or disclosing health information in violation of HIPAA can bring up to $50,000 and 1 year in prison, up to $100,000 and 5 years under false pretenses, and up to $250,000 and 10 years with intent to sell it or cause harm (42 U.S.C. 1320d-6).
- **Your contracts.** A broker can end your agreement for a HIPAA violation, and a business associate agreement must allow that.

## What is changing in 2027

HHS proposed a major update to the Security Rule on January 6, 2025 (90 FR 898). As proposed, it would:

- Remove the difference between required and addressable safeguards, so every one becomes required.
- Require encryption of all electronic health information at rest and in transit, with limited exceptions.
- Require multi-factor authentication.
- Require written plans to restore critical systems and data within 72 hours.
- Require an inventory of your technology and a map of how health information moves through it.
- Require covered entities and business associates to get written verification from their business associates, at least every 12 months, that required technical safeguards are in place.

HHS's 2026 regulatory agenda lists the final rule as a long-term action with a target of July 2027. Under 45 CFR 160.105, compliance with a new or changed standard is generally due 180 days after the rule's effective date. The same agenda lists final changes to the Privacy Rule first proposed on January 21, 2021. As of September 28, 2026, neither change is final, and the current rules apply.

Encryption is already an addressable safeguard under today's rule. Turning it on, along with multi-factor login, puts you ahead of the proposal.

## A one-page HIPAA action list

1. **Decide your status.** Work through the three tests above and write down whether you are a covered entity, a business associate, or both.
2. **Read every business associate agreement** you have signed and list each reporting deadline.
3. **Name your privacy and security official** in writing.
4. **Do a risk analysis** with the free HHS tool, then fix the top risks. Review it on a set schedule, such as once a year, and after any change.
5. **Lock down phones and tablets:** passcode, auto-lock, encryption, and remote wipe. Keep manifests out of personal photo rolls and chat apps.
6. **Give everyone their own login** to every portal and dispatch account, and remove access the day someone leaves.
7. **Handle paper with care:** carry manifests in a folder, keep them out of sight, never leave them in an unlocked van, and shred them when you no longer need them.
8. **Train everyone** before their first trip and again each year, as WellTrans requires. Keep the sign-in sheets. The HIPAA training guide covers what to teach.
9. **Get business associate agreements** from your billing service, software vendors, cloud storage, answering service, and factoring company when they handle rider information for you.
10. **Write short policies** on minimum necessary use, texting, social media, sanctions, and incident reporting. Start from the [NEMT HIPAA policy template](https://nemtguide.com/templates/nemt-hipaa-policy/).
11. **Back up your records** and test a restore.
12. **Write a breach plan** that names who calls the broker, who does the risk assessment, and the deadline in each agreement.
13. **Keep every HIPAA record for 6 years,** and keep trip records for as long as each contract requires, such as 10 years under MTM's standard agreement.

HIPAA work sits alongside your other trip records. See [NEMT trip documentation](https://nemtguide.com/guides/nemt-trip-documentation/) for what brokers and states expect you to keep.

## Frequently asked questions

### Is a NEMT company a HIPAA covered entity?

It depends. A covered entity is a health care provider that sends standard electronic transactions, such as claims to Medicaid or a health plan, itself or through a billing service. Ambulance services are health care providers. For van and sedan rides it is less settled: CMS called taxi services atypical providers in 2006, and North Carolina Medicaid lists non-emergency transportation as atypical as of September 2026.

### Do I need a business associate agreement with my NEMT broker?

Usually yes, and the broker writes it. MTM Health's standard agreement, in the January 1, 2023 version Pennsylvania posts, requires you to sign its business associate agreement. WellTrans attaches a subcontractor business associate agreement to its provider agreement, and Modivcare's compliance training calls its transportation providers subcontractors of a business associate. Read the reporting deadlines before you sign.

### Do NEMT drivers need HIPAA training?

Yes. The Security Rule requires security awareness training for your whole workforce, managers included (45 CFR 164.308(a)(5)). Brokers add their own rules: MTM Health's Virginia handbook requires HIPAA training before a driver transports members, and WellTrans's agreement requires HIPAA training at hire and every year after, with proof on request.

### Can drivers text riders about their pickup?

Yes, with care. HHS says covered providers may email patients if they apply reasonable safeguards, such as checking the address and limiting the information sent, and patients may ask for another way to be contacted. Keep texts to the pickup time and place, leave out the clinic and the reason for the trip, and follow any texting rule in your broker agreement.

### What if a driver loses a phone with trip information on it?

Treat it as a possible breach the same day. If the phone was encrypted and the passcode was not exposed, the data is not unsecured under HHS guidance. If not, the loss is presumed a breach unless a written risk assessment shows a low probability the information was compromised. A business associate must tell the broker within 60 days at most, and many broker agreements require far less time.

### How long do I keep HIPAA records?

Keep your HIPAA policies, risk analyses, training records, and other required documentation for 6 years from the date they were created or last in effect, whichever is later (45 CFR 164.316 and 164.530). Trip records follow your contracts. MTM Health's standard agreement requires records of its trips for 10 years.

### What are the penalties for a HIPAA violation?

Under the amounts HHS adjusted on January 28, 2026 (45 CFR 102.3), a civil money penalty runs from $145 per violation when a company did not know, to $73,011 or more per violation for willful neglect that is not corrected, with a yearly cap of $2,190,294 for identical violations. Since 2019, HHS has said it will use lower yearly caps for the three less serious tiers. Knowingly misusing health information is also a federal crime.

### Is the HIPAA Security Rule changing in 2027?

It may. HHS proposed a stricter Security Rule on January 6, 2025, with required encryption, multi-factor authentication, and 72-hour restoration of critical systems. HHS's 2026 regulatory agenda lists July 2027 as its target for a final rule. As of September 28, 2026 the proposal is not final, and the current rule applies.

## Official resources

- [HHS: HIPAA for professionals](https://www.hhs.gov/hipaa/for-professionals/index.html)
- [CMS: Covered Entity Decision Tool](https://www.cms.gov/regulations-and-guidance/administrative-simplification/hipaa-aca/downloads/coveredentitieschart20160617.pdf)
- [HHS: Sample business associate agreement provisions](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html)
- [ASTP/ONC: Free Security Risk Assessment Tool for small providers](https://healthit.gov/privacy-security/security-risk-assessment-tool/)
- [HHS: Guidance on encrypting and destroying health information](https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html)
- [HHS OCR: Breach portal, report a breach to HHS](https://ocrportal.hhs.gov/ocr/breach/)
- [eCFR: 45 CFR part 164, the Privacy, Security, and Breach Notification Rules](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164)
