Compliance
HIPAA Website Requirements for NEMT in 2027: Ride Request Forms, Tracking Code, and State Health Data Laws

Overview
HIPAA has no separate website rule. It reaches your site through the rider information the site collects or stores, if you are a covered entity or business associate. That means a signed agreement with any vendor that stores form submissions, tracking code kept off request and login pages, and a posted privacy notice for a covered entity. Where HIPAA does not apply, Washington and Nevada laws and the FTC may.
- HIPAA has no website rule of its own. It reaches your site through the rider information the site collects or stores.
- A form host, chat tool, or tracking vendor that receives rider information for you is a business associate and needs a signed agreement.
- A court vacated one part of HHS's tracking bulletin on June 20, 2024. HHS still posts the rest, including its warnings about login pages and pages where people book appointments.
- A covered entity must post its Notice of Privacy Practices prominently on its website (45 CFR 164.520(c)(3)).
- Private-pay riders may fall under Washington's and Nevada's health data laws instead of HIPAA.
A ride request form on your website asks for a name, a pickup address, and an appointment at a clinic. If HIPAA covers you, that is exactly the information it protects. This page covers the rules that decide what your site may collect, what code it may run, which vendors need an agreement, and what else applies when HIPAA does not. Layout and accessibility are covered in Section 504 website accessibility.
Does HIPAA apply to your website?
HIPAA has no separate website rule. It applies to the rider information your site collects or stores, when your company is a covered entity or a business associate, and it adds a notice that covered entities must post. HIPAA for NEMT providers walks through the three tests, and which one fits you changes what your site must do.
| Your company is | Rider information on your site falls under | Read next |
|---|---|---|
| A covered entity | HIPAA | Forms, tracking code, vendors, and the privacy notice |
| A business associate running broker trips | HIPAA as a business associate, plus the broker’s own rules | Vendors, and your broker agreement |
| Neither, with private-pay riders | The FTC Act and state health data laws | Washington, Nevada, and the FTC |
Whether a van company is a covered entity is not settled, as the HIPAA guide explains. A company in that gray area should ask a health care lawyer whether the state laws below apply to its riders too.
What a ride request form can ask
The Privacy Rule tells a covered entity or business associate to make reasonable efforts to limit protected health information to the minimum necessary for the purpose (45 CFR 164.502(b)). A ride needs few things: the rider’s name and phone number, the pickup and destination addresses, the appointment time, a ride home, how the rider moves, and whether someone rides along. It does not need a diagnosis, a medication, or a medical record number. Ask for an insurance or Medicaid ID only if you need it to book the trip. The trip intake guide lists the questions in order.
Four habits make a form safer:
- Ask how the rider moves, not why. A field labeled “Mobility needs, such as wheelchair or walker” works. Add the line “Please do not enter medical details” under any free-text box, because people type diagnoses into any open space.
- Put the form on a secure page. The Security Rule requires technical measures against unauthorized access to health information sent over a network, and encryption in transit is addressable (45 CFR 164.312(e)). HHS says to implement it if reasonable and appropriate, or to write down why not and, where one is reasonable, use an equivalent alternative. For a public form, an https page is the usual answer.
- Control where submissions go. Store requests in a system you have an agreement with (see below), and have it send staff an alert that only says a request is waiting. A full copy of every request in ordinary email spreads rider information across every inbox and phone that receives it.
- Handle reminder texts with a consent box. If the form offers ride reminders by text, add a box the rider ticks, name the number, and keep the record. The HIPAA texting guide has the wording and the consent rules.
Tracking code, chat tools, and what the court changed
A tracking technology is a script or code on a website or app that gathers information about how users interact with it. HHS’s Office for Civil Rights issued a bulletin on how HIPAA applies in December 2022 and revised it on March 18, 2024. On June 20, 2024, a federal court in Texas vacated one part of it in American Hospital Association v. Becerra (No. 4:23-cv-1110). The court struck HHS’s position that HIPAA is triggered when a technology connects a visitor’s IP address with a visit to a public page about specific health conditions or providers. The court added that its ruling is not meant to limit the legal operability of the bulletin’s other guidance. HHS’s page, last reviewed June 26, 2024, says HHS is evaluating its next steps, and it notes that the bulletin does not have the force and effect of law.
HHS still posts the rest of the bulletin. These are the parts that matter for a ride company:
- Pages behind a login. HHS says tracking technologies on a login-protected page, such as a rider portal, generally have access to protected health information. The company must let those tools use and disclose it only as the Privacy Rule allows, and protect it under the Security Rule.
- Public pages that take requests. Many public pages, such as hours or job postings, do not give a tracking tool any health information. HHS says a public page where a person can schedule an appointment without logging in may give a tracking tool health information, because the tool can read an email address or the reason the person typed or selected. A public ride request form is the same kind of page, so treat it that way.
- Login and sign-up pages. If a tracking tool collects the login or registration details a person types, HHS counts that as a disclosure of protected health information.
- Your own app. Information typed into a regulated company’s own app, or sent from the device, such as a device ID or location, is generally protected health information.
If rider information reaches a tracking vendor, the bulletin says:
- The disclosure must be allowed by the Privacy Rule. A vendor that receives rider information on your behalf is a business associate that needs a signed agreement. It is a business associate if it meets the definition, whether or not anyone signed.
- A notice is not permission. A line in your privacy policy is not permission, a cookie banner is not a HIPAA authorization, and a vendor’s promise to strip names afterward is not enough.
- Marketing needs authorization. Using protected health information for marketing requires the person’s written authorization (45 CFR 164.508(a)(3)).
- A disclosure with no permission and no agreement is presumed a breach, unless you can show a low probability the information was compromised. See what to do after a NEMT data breach.
HHS lists tracking technologies among the things a company’s risk analysis should address, and says it is prioritizing Security Rule compliance in its tracking investigations. The HIPAA risk assessment template is the place to list them.
The practical rule: keep advertising and analytics code off every page where a rider types anything, off the page that confirms a request, and off every login page. Pages that only describe your service are a different matter.
Form hosts, chat tools, and email: who needs an agreement
A business associate is a person who, on behalf of a covered entity, creates, receives, maintains, or transmits protected health information (45 CFR 160.103). HHS applies that to cloud services in its cloud computing guidance, last reviewed December 23, 2022. A cloud provider that stores or transmits your protected health information is a business associate, even if it holds only encrypted data and lacks the key. Then you and the provider must sign a business associate agreement.
For a ride company’s website, that reaches any service that keeps or passes along what a rider typed:
- the host or service that stores form submissions
- an online chat or call-back tool that keeps transcripts
- a scheduling or booking widget
- an email or text platform that keeps copies of messages with ride details
- a tracking vendor, as above
The test is whether the service receives or keeps rider information for you. A host that only serves public pages and never receives a rider’s details has nothing to sign. If a vendor that does receive them will not sign, do not send it rider information. The business associate agreement checklist lists what the agreement must say.
The privacy notice and what not to claim
A covered entity that has a website providing information about its services must post its Notice of Privacy Practices on it prominently and make it available through the site (45 CFR 164.520(c)(3)(i)). Put a plain link in the footer of every page, and see the notice of privacy practices template for what the notice says. The posting duty belongs to the covered entity.
Do not put a “HIPAA compliant” badge on the site unless you can back every word. The FTC’s business guidance tells companies not to make false or misleading claims that they are “HIPAA Compliant,” “HIPAA Secure,” or “HIPAA Certified,” and to be upfront rather than bury key facts in a privacy policy or terms of use (August 2024).
When HIPAA does not cover the data: Washington, Nevada, and the FTC
Two states have laws written for health data that HIPAA does not reach. They matter most to a ride company with private-pay riders that is not a covered entity or business associate for them. If HIPAA covers your riders’ information, most of this section does not reach you, although Washington’s law can still apply to information that is not protected health information, as explained below.
Washington’s My Health My Data Act
The Act (RCW chapter 19.373) covers a legal entity that conducts business in Washington or targets Washington consumers and decides how consumer health data is collected, used, or shared. Consumer health data includes data that identifies a person seeking health care services (19.373.010). A ride request that names a clinic could fit that, so plan as if it counts. The definition of personal information also includes identifiers such as a cookie ID or an IP address.
Washington’s exemption is for information, not for companies. The chapter does not apply to information that is HIPAA protected health information, or that is mixed in with it and kept by a covered entity or business associate (19.373.100). Information that is not protected health information is not exempt by that clause.
The privacy policy, consent, rights, security, processor, and sale rules (RCW 19.373.020 through 19.373.070) took effect for most businesses on March 31, 2024. A small business, meaning one that collects, processes, sells, or shares the data of fewer than 100,000 consumers in a calendar year, had until June 30, 2024. A ride company with fewer riders than that is a small business. If the Act covers you, you must:
- Post a separate privacy policy. A consumer health data privacy policy, linked prominently from your homepage. The Attorney General says it must be a separate link and may not carry other information (19.373.020). It lists the categories of data you collect and why, the sources, what you share, the categories of third parties, and how people use their rights.
- Collect only with consent or for the service. You may collect consumer health data with consent for a stated purpose, or as necessary to provide a product or service the person requested (19.373.030). A ride request is the second case.
- Get separate consent to share. Sharing needs consent that is separate from the consent to collect, unless it is necessary to provide the requested service. Sending ride details to an advertising company is neither. Accepting a general terms of use is not consent, and neither is a design that tricks the person (19.373.010). A vendor that handles data for you under a binding contract with your instructions is a processor, and giving it data for that purpose is not “sharing” (19.373.010 and 19.373.060).
- Honor deletion and other rights. People can confirm what you collect, see it, withdraw consent, and ask for deletion. You must answer within 45 days, extendable once by 45 more (19.373.040).
- Limit access and secure the data to the people who need it, to a reasonable standard of care in your industry (19.373.050).
- Do not sell it without a valid authorization from the person (19.373.070).
A violation is an unfair or deceptive act under Washington’s Consumer Protection Act, which the Attorney General enforces and people can also enforce through private lawsuits (19.373.090; Attorney General FAQ).
Nevada’s Senate Bill 370
Nevada’s law (NRS 603A.400 to 603A.550) took effect March 31, 2024. It covers a person who conducts business in Nevada or targets Nevada consumers and decides how consumer health data is processed, shared, or sold. Unlike Washington, Nevada exempts any person or entity that is subject to HIPAA, as a whole (603A.490). It reaches only companies that HIPAA does not cover at all.
A company the law covers must post a privacy policy with a conspicuous link on its main website (603A.495), get consent to collect consumer health data unless it is necessary to provide the product or service the person requested, get separate consent to share (603A.500), and answer requests to confirm, list third parties, stop, or delete (603A.505). A violation is a deceptive trade practice, and the law creates no private right of action (603A.550).
The geofence bans
Washington says it is “unlawful for any person to implement a geofence around an entity that provides in-person health care services” when the geofence is used to identify or track people seeking health care, collect their health data, or send them messages or ads about it (RCW 19.373.080). It defines a geofence as a virtual boundary 2,000 feet or less from the perimeter of the place (19.373.010). The Attorney General says every person, not only regulated entities, has had to follow this section since July 23, 2023. Nevada bans a geofence within 1,750 feet of a medical facility or other in-person health care provider for the same three purposes (NRS 603A.540). Nevada’s ban sits in a chapter that exempts HIPAA-covered persons.
Many driver apps use a geofence to mark a pickup or a clinic arrival (see geofence). Neither statute mentions vehicles or ride arrivals, and the Washington Attorney General’s FAQ does not address them. Do not assume either answer. If your app does this for private-pay riders in Washington or Nevada, ask a lawyer licensed in that state.
The FTC Act
The FTC Act reaches companies HIPAA does not. The FTC’s business guidance, dated August 2024, says health information is anything that conveys information or lets someone infer something about a person’s health, and gives as an example location data showing a visit to a cancer center. It says disclosing health information for advertising without affirmative express consent may be an unfair practice, and that using hidden tracking tools to share sensitive health data against your privacy promises violates the Act.
A website checklist
- Write down your status: covered entity, business associate, or neither.
- List every page where a rider types anything, and remove any field that asks for a diagnosis or other medical detail.
- Take advertising and analytics code off those pages, the confirmation page, and every login page.
- Sign an agreement with every vendor that stores or keeps copies of what riders type, or stop sending them rider information.
- Put every form page on https, and send staff an alert instead of the full request.
- Link your Notice of Privacy Practices in the footer if you are a covered entity.
- Add the Washington or Nevada policy if you carry private-pay riders there and are not covered by HIPAA.
- Ask counsel about geofences if your driver app marks clinic arrivals in those states.
- Review the site whenever you add a plug-in, chat tool, or tag. Each one can change what leaves your site.
Frequently asked questions
Is there a HIPAA compliant website?
HIPAA sets duties for covered entities and business associates, not for websites or software products, so no page or tool is compliant on its own. The FTC tells businesses not to make false or misleading claims that they are "HIPAA Compliant," "HIPAA Secure," or "HIPAA Certified" (guidance dated August 2024). Describe what you actually do with rider information instead.
Does a ride request form have to be encrypted?
HIPAA does not use the word SSL. The Security Rule requires technical measures against unauthorized access to health information sent over a network, and encryption of transmitted information is addressable (45 CFR 164.312(e)). HHS says to encrypt in transit if it is reasonable and appropriate, or to document why not and use an equivalent alternative where one is reasonable. For a form on the public internet, a secure https page is the usual way to do it.
Can I use ad or analytics tracking code on my NEMT website?
On pages that collect nothing about a rider, such as your hours and service area, HHS says tracking is often not regulated by HIPAA. On a ride request form or a login page it may receive rider information, and then the vendor needs a business associate agreement. HHS also says a cookie banner is not a HIPAA authorization. A June 20, 2024 court order vacated only HHS's view that an IP address plus a visit to a public page about a health condition or provider triggers HIPAA.
Do I need a business associate agreement with my website host or form service?
If the service creates, receives, maintains, or transmits rider information for you, yes. HHS says a cloud provider that stores your information is a business associate even if it holds only encrypted data and has no key (guidance last reviewed December 23, 2022). A host that only serves public pages and never receives rider information does not meet that test.
Do I need a privacy policy on my website?
HIPAA requires a covered entity with a website about its services to post its Notice of Privacy Practices prominently there (45 CFR 164.520(c)(3)(i)). Washington requires a separate consumer health data privacy policy, linked from the homepage, from businesses its law covers (RCW 19.373.020), and Nevada requires one for its regulated entities (NRS 603A.495). Whatever you post must match what you do.
Does Washington''s My Health My Data Act apply to a ride company outside Washington?
It can. The Act covers a legal entity that conducts business in Washington or targets Washington consumers, and a consumer is a Washington resident or a person whose health data is collected in Washington (RCW 19.373.010). Information that is HIPAA protected health information is exempt, so the Act matters most for private-pay riders of a company that is not a covered entity or business associate.
Does the geofence ban reach my driver app?
The statutes do not say. Washington bars a geofence around an in-person health care provider used to identify or track people seeking care, collect their health data, or send them messages (RCW 19.373.080), and Nevada has a similar ban within 1,750 feet (NRS 603A.540). Neither mentions vehicles or ride arrivals, and Washington's Attorney General FAQ does not address them. If your app marks clinic arrivals for private-pay riders there, ask a lawyer licensed in the state.