# HIPAA Training for NEMT Drivers and Dispatchers in 2027: What to Cover, How Often, and How to Prove It

Canonical URL: https://nemtguide.com/guides/hipaa-training-for-nemt-staff/ · Updated 2026-10-02

A NEMT company that is a HIPAA covered entity or a broker's business associate must train its whole workforce on protecting rider information: drivers, dispatchers, office staff, managers, and volunteers. HIPAA sets no yearly schedule, but brokers do. Modivcare wants training within 30 days of hire and every calendar year, and WellTrans at hire and yearly. Keep signed, dated records for at least 6 years.

- Everyone whose work you direct counts as workforce under HIPAA, paid or not, so volunteer drivers and office help need training too.
- HIPAA says train new staff within a reasonable time. Brokers set the real clock: Modivcare wants 30 days from hire and every calendar year.
- Training must cover your own rules for manifests, phones, and reporting, so a generic online course alone leaves gaps.
- Keep a dated record with the topics, the trainer, and each person's signature. Modivcare wants it kept 10 years, HIPAA at least 6.
- HHS has proposed yearly security training, due within 30 days of a new hire's first login. As of October 2, 2026, it is not final.

One trip manifest can hold a whole day of riders' names, home addresses, clinics, and mobility needs. A driver can expose all of it with one photo in a group chat, or one phone call taken in front of another rider. Training is how you prevent that, and brokers ask for proof of it before they send trips. This guide covers what the rules require, what to teach each role, how often, and how to keep records that hold up in an audit.

## Does HIPAA require training for NEMT staff?

Yes, if HIPAA reaches your company at all. Two HIPAA rules require training, and your status decides which ones apply to you. To work out whether you are a covered entity, a business associate, or neither, see [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/).

- **The Privacy Rule** applies to covered entities, such as an ambulance company that bills Medicaid electronically. You train every workforce member on your privacy policies, as far as each person's job needs ([45 CFR 164.530(b)](https://www.ecfr.gov/current/title-45/section-164.530)). New people are trained within a reasonable time after they join. Anyone whose job is affected by a material change in your policies is retrained. You document all of it.
- **The Security Rule** applies to covered entities and business associates alike ([45 CFR 164.302](https://www.ecfr.gov/current/title-45/section-164.302)), so it reaches a company running trips for a broker. It requires a security awareness and training program for all workforce members, management included ([45 CFR 164.308(a)(5)](https://www.ecfr.gov/current/title-45/section-164.308)). The program has four addressable parts: periodic security reminders, guarding against malicious software, watching log-in attempts, and password rules.
- **Private pay only.** If you bill no health plan, run no broker or plan trips, and have signed no business associate agreement, HIPAA's training rules do not reach you. State law still can, as Texas shows below.

"Workforce" is broad. It means employees, volunteers, trainees, and anyone else whose work for you is under your direct control, whether or not you pay them ([45 CFR 160.103](https://www.ecfr.gov/current/title-45/section-160.103)). A volunteer driver you dispatch, a relative who answers the phone, and a part-time billing clerk all count.

Broker agreements fill in the details. WellTrans's Subcontractor Business Associate Agreement, revised October 16, 2025, requires you to train your employees, agents, and subcontractors on the agreement, HIPAA, and the HITECH Act, and to show proof on request. It also requires you to train your workforce to recognize a breach and report it promptly, and to keep a system of sanctions for staff who break the rules.

### Texas adds its own training law

Texas defines a covered entity far more widely than HIPAA does. It includes business associates, anyone who comes into possession of protected health information, and their employees and contractors (Health and Safety Code 181.001). Under section 181.101, each employee must finish training on state and federal health privacy law no later than 90 days after hire. After a material change in that law, affected employees are retrained within a reasonable time, and no later than one year after the change takes effect. Each employee signs a statement, on paper or electronically, confirming the training, and you keep it 6 years. Modivcare's 2025 provider training teaches HIPAA and Texas medical privacy law together. See the [Texas guide](https://nemtguide.com/states/texas/).

## How often HIPAA training is required

HIPAA itself sets no yearly schedule. Brokers and some states do, and the strictest one you work under becomes your schedule. As of October 2026:

| Rule or broker | New staff | After that |
|---|---|---|
| HIPAA Privacy Rule | Within a reasonable time after joining | After a material change in your policies |
| HIPAA Security Rule | No set time | Periodic security reminders |
| Texas law (HSC 181.101) | Within 90 days of hire | Within a year of a material change in the law |
| Modivcare (2025 attestation) | Within 30 days of hire | Each calendar year |
| WellTrans (agreement revised October 16, 2025) | At hire | Every year |
| MTM Health, Virginia (handbook approved August 10, 2026) | Before carrying members | Refreshers as MTM Health directs |
| GOBHI, Oregon (manual revised July 2025) | At credentialing, before billable trips | Every year |
| Louisiana Medicaid (section 10.3, July 14, 2025) | Before carrying anyone | Not set in the manual |

One schedule meets every row: train each person before the first trip or first login, again every year, and again whenever you change a policy. The HHS Office of Inspector General's voluntary compliance guidance (November 2023) points the same way. It says everyone in a health care organization, contractors included, should get compliance training at least once a year.

The Security Rule's reminders can be short. HHS's audit protocol, last reviewed February 3, 2025, asks auditors to check how often you send security updates and how, and names emails, newsletters, and posters as examples. A two-line text to drivers about a new scam, or a posted note about locking screens, counts as a reminder too. Keep a dated copy of each one.

## What HIPAA training should cover

HIPAA requires training on your own policies, not just on HIPAA in general. So the core of every session is how your company handles rider information. Start from your [NEMT HIPAA policy](https://nemtguide.com/templates/nemt-hipaa-policy/), then teach these topics to everyone.

- **What counts as rider information.** Names with addresses, destinations, member ID numbers, dates of birth, and mobility needs, on paper, on a screen, or spoken aloud. See [protected health information](https://nemtguide.com/glossary/protected-health-information/).
- **Only what the job needs.** Use and share only the minimum the task requires, such as the pickup, drop-off, time, and assistance level ([45 CFR 164.502(b)](https://www.ecfr.gov/current/title-45/section-164.502)). See minimum necessary.
- **The whole ride is private.** Two Oregon provider manuals, CareOregon's (version 1.3, February 2024) and GOBHI's (revised July 2025), tell drivers to keep every part of a trip confidential, even the fact that a person is a program member.
- **Logins and passwords.** Every person gets their own login for every portal and app, and never shares it. A unique user ID for each person is a required Security Rule safeguard ([45 CFR 164.312(a)](https://www.ecfr.gov/current/title-45/section-164.312)).
- **Scam emails, texts, and calls.** How to spot a fake login page, a bad attachment, or a caller fishing for rider details.
- **Report problems at once.** A lost phone, a text to the wrong number, or a manifest left behind goes to the owner the same day.
- **Consequences.** What happens to staff who break the rules. Both rules require sanctions, and a covered entity documents the ones it applies (45 CFR 164.530(e) and 164.308(a)(1)).

The reporting topic matters more than it looks. HIPAA treats a breach as discovered on the first day any employee or agent, other than the person who caused it, knew about it or would have known with reasonable care ([45 CFR 164.410](https://www.ecfr.gov/current/title-45/section-164.410)). WellTrans then gives you one business day to tell it in writing. A driver who waits until Monday to mention a lost phone can put you past that deadline. The response steps are in [NEMT data breach](https://nemtguide.com/guides/nemt-data-breach/).

### Extra topics by role

**Drivers and attendants**

- Keep papers and screens with rider information where no one else can see them, and do not read a rider's details when another passenger could see them too. Both are on the Oregon manuals' list of minimum safeguards.
- Never talk about a rider's trip over the phone or radio where others can hear, and never tell anyone outside the rider's care team about the appointment or diagnosis. Both are on the same list.
- Use a privacy screen on phones and tablets, and never leave rider information in an unlocked vehicle. Both are on the safeguard list in Modivcare's 2025 training.
- Lock the phone with a passcode, and never photograph a manifest. The [driver phone policy guide](https://nemtguide.com/guides/nemt-driver-phone-policy/) has the rest of the phone rules.

**Dispatchers and schedulers**

- Email health information only through a secure or encrypted service. The GOBHI and CareOregon manuals require a secure email portal, and a provider without one can ask the broker to send encrypted email instead.
- Confirm who is calling before giving out trip details. The Oregon manuals limit what staff may share to the member, the member's caregiver or representative, and the member's health care provider.
- Lock the screen whenever you step away from the desk.

**Billing and office staff**

- Treat claims, remittances, and trip logs as health information.
- Keep the work in the United States. Modivcare's 2025 attestation has you certify that your company does no offshore work, including receiving, viewing, storing, or handling health information outside the country.
- Shred paper you no longer need. HHS guidance counts paper as destroyed only when it cannot be read or put back together, and says blacking out names does not count (74 FR 42740, August 24, 2009).

**Owners and managers**

- Name a security official in writing ([45 CFR 164.308(a)(2)](https://www.ecfr.gov/current/title-45/section-164.308)). A covered entity also names a privacy official (164.530(a)).
- Remove a departing worker's logins the day they leave. The Security Rule lists procedures for ending access when employment ends.
- Run the risk analysis, then teach staff what it found. The [HIPAA risk assessment template](https://nemtguide.com/templates/hipaa-risk-assessment/) walks through it.

## What brokers and states add to HIPAA training

Most NEMT contracts write HIPAA training in. The full course list for each broker is in [NEMT broker training requirements](https://nemtguide.com/guides/nemt-broker-training-requirements/). These are the HIPAA parts, as of October 2026:

- **[MTM Health](https://nemtguide.com/brokers/mtm-health/).** Its standard agreement, in the January 1, 2023 version Pennsylvania posts, makes fraud, waste, and abuse and HIPAA part of every driver training program, with training records kept in each driver's file. In Virginia, HIPAA training comes before a driver carries members. MTM Health's driver roster records each driver's HIPAA training date, and it keeps proof of training in MTM Link.
- **[Modivcare](https://nemtguide.com/brokers/modivcare/).** Its yearly compliance training for all owners and drivers includes HIPAA privacy and security. You sign its 2025 attestation and keep a training roster.
- **[WellTrans](https://nemtguide.com/brokers/welltrans/).** HIPAA and fraud, waste, and abuse training for all employees, drivers, and attendants at hire and every year. Its Acknowledgment of Required Training Attestation (2022) has each employee sign for its materials on fraud, waste, and abuse, HIPAA privacy, general compliance, and its code of conduct, and confirm the training is yearly.
- **Verida.** Its provider training page lists HIPAA privacy requirements and business associate agreements as part of required customer service training.
- **GOBHI, Oregon.** HIPAA training every year for each credentialed driver, with certificates sent to its credentialing team. See the [Oregon guide](https://nemtguide.com/states/oregon/).
- **Louisiana Medicaid.** HIPAA privacy and security training before a driver carries any member, with the broker collecting the proof (manual section 10.3, issued July 14, 2025). See the [Louisiana guide](https://nemtguide.com/states/louisiana/).
- **Kentucky.** A broker's subcontract must include signed HIPAA confidentiality statements for subcontractor and volunteer employees (603 KAR 7:080, certified effective April 25, 2025). See the [Kentucky guide](https://nemtguide.com/states/kentucky/).

## How to document HIPAA training

A session that is not written down did not happen, as far as an auditor or broker is concerned. The Privacy Rule requires a covered entity to document training and keep the record 6 years from when it was made or last in effect, whichever is later ([45 CFR 164.530(j)](https://www.ecfr.gov/current/title-45/section-164.530)).

### What each record should show

- The date, and the time if your broker asks for it (Modivcare does)
- The course name, with the slides or a summary of what was covered
- The trainer's name
- Each attendee's full name and job title
- Each attendee's signature, confirming completion

### What auditors look for

HHS's HIPAA Audit Protocol tells auditors to read your training policies, including who gets trained and how often. They pull a sample of people hired during the audit period and ask for each one's Privacy Rule training record. They check that training reached the whole organization, and independent contractors where appropriate. They also check that staff were trained on material policy changes, such as those the HITECH Act required. Every new hire needs a record of their own.

### A filing routine that works for every broker

1. **Train before the first trip** or the first login to any broker portal.
2. **Have each person sign** a dated acknowledgment on the [driver training log](https://nemtguide.com/templates/nemt-driver-training-log/), listing the topics.
3. **Put a copy in the driver's file.** The [driver file checklist](https://nemtguide.com/templates/nemt-driver-file-checklist/) shows where it fits.
4. **Send proof to each broker** the way it asks: MTM Link in Virginia, the Modivcare roster to TPCompliance@modivcare.com, certificates to GOBHI's credentialing team, or copies on request for WellTrans.
5. **Keep records 10 years** if any broker requires it. Modivcare's attestation asks for training records kept at least 10 years, and MTM Health's standard agreement requires full records of your work under it for 10 years. See [NEMT record retention](https://nemtguide.com/guides/nemt-record-retention/).
6. **Put each person's yearly date on your calendar,** using the [compliance calendar](https://nemtguide.com/templates/nemt-compliance-calendar/).

## Where to get HIPAA training and what it costs

HHS says the rules scale to each business, so there is no single standardized program that could train the staff of every entity. Its training page, last reviewed May 30, 2025, points to two free starting points: HealthIT.gov's Guide to Privacy and Security of Electronic Health Information, and CMS's HIPAA Basics for Providers fact sheet (MLN909001, May 2025).

- **Broker modules.** MTM Health's Virginia handbook says its mandated training, including a compliance module on HIPAA privacy and security, costs providers nothing. WellTrans's provider training page has a HIPAA video and quiz, and a passing score earns a certificate of completion. Modivcare posts its yearly provider training deck (version 2025).
- **Your own session.** Use it for your own rules on manifests, phones, texting, and reporting. No outside course can teach those.
- **Paid online courses.** These are fine for the basics, as long as you add your own policies.

HIPAA does not require a certificate from any particular course. It requires training on your policies and, for a covered entity, a record that it happened.

Pay employees for the time. Under federal wage rules, a training session is work time unless it is outside regular hours, truly voluntary, not directly related to the job, and involves no productive work ([29 CFR 785.27](https://www.ecfr.gov/current/title-29/section-785.27)). Training you require is not voluntary (29 CFR 785.28). WellTrans may run driver training for free, but it can deduct the cost of the materials it hands out from your invoice.

## A 45-minute HIPAA session for new drivers

1. **What counts (5 minutes).** Show a sample manifest filled with made-up riders, and point to each piece of health information.
2. **The van rules (10 minutes).** Where the manifest goes, locking the vehicle, and what never to say in front of other riders.
3. **Phones and texts (10 minutes).** Passcodes, no photos of manifests, what a pickup text may say, and how to spot a scam message.
4. **Families, facilities, and callers (5 minutes).** What to tell a caregiver, a clinic, or a stranger on the phone under your broker's rules.
5. **When something goes wrong (10 minutes).** Who to call, how fast, and why the deadline starts when the driver knows.
6. **Consequences and questions (5 minutes).** Walk through your sanction policy, then take questions.

End with signatures, and log the session the same day.

## What happens when training is missing

**Federal enforcement.** On December 30, 2019, HHS announced that West Georgia Ambulance, which provides emergency and non-emergency ambulance service in Carroll County, Georgia, agreed to pay $65,000 and follow a corrective action plan with two years of monitoring. The investigation began with a 2013 breach report about a lost unencrypted laptop holding 500 people's information. It found long-standing failures, including no security awareness and training program, and HHS said the company took no meaningful steps to fix them even after technical assistance. For penalty amounts, see [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/).

**Broker action.** Brokers do not wait for HHS. Their own contracts and manuals set the penalties:

- MTM Health's Virginia handbook says failing to complete training means lost trip assignments or removal from the network. Other training failures can bring infraction points, suspension, liquidated damages, or the end of your contract.
- GOBHI's manual lists a violation of confidentiality policies, including protecting member health information, as grounds for immediately disqualifying a driver. GOBHI can also suspend a driver who cannot show they understand or follow required training. CareOregon's manual sets the same rules for the brokerages that use it.
- Modivcare's attestation lets it hand your signed statement to its state agency and health plan clients to show compliance.

## What may change in 2027

HHS proposed a stricter Security Rule on January 6, 2025 (90 FR 898). As proposed, it would require:

- Security training for every workforce member at least once every 12 months
- Training for new staff no later than 30 days after they first get access to your systems
- Retraining within 30 days after a material policy change
- Ongoing reminders about current threats, such as malicious software and scam messages
- Written proof of both the training and the reminders

HHS's latest regulatory agenda lists July 2027 as the target for a final rule. As of October 2, 2026, it is still a proposal, and the current rules apply. A company that already trains before the first login, repeats it yearly, and sends short, dated reminders is close to what the proposal asks.

## Frequently asked questions

### Do NEMT drivers need HIPAA training?

Yes, whenever HIPAA or a broker contract applies. The HIPAA Security Rule requires covered entities and business associates to run security awareness training for all workforce members, management included (45 CFR 164.308(a)(5)). MTM Health's standard agreement makes HIPAA part of every driver training program, and Louisiana Medicaid requires drivers to finish HIPAA privacy and security training before they carry anyone (manual section 10.3, July 14, 2025).

### How often do NEMT employees need HIPAA training?

HIPAA requires training for each new workforce member within a reasonable time after joining and after a material change in your policies, with no fixed yearly cycle. Brokers add one. Modivcare wants training within 30 days of hire and every calendar year, WellTrans at hire and every year after, and GOBHI in Oregon every year. Training every driver before the first trip, then yearly, and again after any policy change meets all of them.

### Is an online HIPAA course enough for NEMT staff?

Not on its own. The Privacy Rule requires training on your company's own policies and procedures, as needed for each person's job (45 CFR 164.530(b)). HHS says no single standardized program could train the staff of every entity. Use an online course or your broker's module for the basics, then add a short session on your rules for manifests, phones, texting, and reporting problems.

### Do volunteer and part-time drivers need HIPAA training?

Yes, if you direct their work. HIPAA's workforce includes employees, volunteers, trainees, and anyone else whose work for you is under your direct control, whether or not you pay them (45 CFR 160.103). Kentucky's human service transportation rule requires a broker's subcontracts to include signed HIPAA confidentiality statements for subcontractor and volunteer employees (603 KAR 7:080).

### What records prove HIPAA training to a broker or auditor?

Keep the date, the topics or slides, the trainer's name, and each attendee's name, job title, and signature. Modivcare's 2025 roster asks for each employee's full name, courses, completion date and time, and signature, kept at least 10 years. HHS auditors review a sample of new hires' training records and how often you train. Texas requires a signed statement from each employee, kept 6 years.

### Who pays for HIPAA training time?

You do, for employees. Under federal wage rules, training is work time unless it is outside regular hours, voluntary, not directly related to the job, and involves no productive work (29 CFR 785.27). Training you require is not voluntary. MTM Health says its mandated Virginia training costs providers nothing, and WellTrans may provide training free but can deduct the cost of its materials from your invoice.

### Do owners and dispatchers who never drive need HIPAA training?

Yes. The Security Rule names management in the training duty, and anyone who books trips, reads manifests, or sends claims handles rider information. Modivcare's attestation covers all owners and drivers who serve its members, and LCP Transportation in Indiana wants HIPAA training for every employee and driver (checklist dated July 2026). Dispatchers and billing staff need extra time on email, portals, and phone calls.

## Official resources

- [HHS OCR: HIPAA Training and Resources](https://www.hhs.gov/hipaa/for-professionals/training/index.html)
- [CMS: HIPAA Basics for Providers (MLN909001)](https://www.cms.gov/files/document/mln909001-hipaa-basics-providers-privacy-security-breach-notification-rules.pdf)
- [HHS OCR: HIPAA Audit Protocol, what auditors review](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/protocol/index.html)
- [Modivcare: Transportation Provider Compliance Attestation and Training Roster](https://www.modivcare.com/wp-content/uploads/2025/10/TP-Compliance-Attestation-2025-1.pdf)
- [Modivcare: Annual transportation provider compliance training deck (2025)](https://www.modivcare.com/wp-content/uploads/2025/08/2025-Modivcare-Annual-TP-Compliance-Training.pptx)
- [WellTrans: Provider training videos and HIPAA quiz](https://www.welltransnemt.com/provider-training/)
- [eCFR: 45 CFR 164.530, Privacy Rule administrative requirements](https://www.ecfr.gov/current/title-45/section-164.530)
- [Texas Health and Safety Code chapter 181](https://statutes.capitol.texas.gov/Docs/HS/htm/HS.181.htm)
