Compliance

What to Do After a NEMT Data Breach: Steps, Deadlines, and Who to Tell

Shattered window glass on the front seat of a car after a break-in
Photo: Zoshua Colah, Unsplash, Unsplash License

After a NEMT data breach, such as a lost driver phone, stolen manifests, or a hacked email account, stop the loss the same day and tell whoever your agreement names, usually your broker. Broker deadlines can be one business day, far inside HIPAA's 60-day limit. Then write a four-factor risk assessment. If you bill Medicaid directly, you may also owe notices to riders, HHS, and your state.

  • Any rider information that leaks is presumed a breach unless a written risk assessment shows a low probability it was compromised.
  • The clock starts the day any employee other than the person at fault knows, not the day the owner hears.
  • Most NEMT companies report to their broker first. WellTrans wants a written report within one business day.
  • An encrypted, passcode-locked phone that goes missing is usually not a reportable breach. Paper manifests are never encrypted.
  • State laws in California, Florida, and New York set 30-day deadlines, tighter than HIPAA's 60 days.

A driver leaves a phone on a clinic bench. A clipboard of manifests disappears when a van window is smashed. Your office email starts sending messages you never wrote. Each of these can be a data breach, because a trip manifest holds names, home addresses, phone numbers, Medicaid IDs, and the clinics riders visit. What you do in the first day decides how much harm it does and whether you meet the deadlines that follow.

This page covers the response. For which HIPAA rules apply to your company in the first place, start with HIPAA for NEMT providers.

What counts as a data breach for a NEMT company

Under HIPAA, a breach is any acquisition, access, use, or disclosure of protected health information that the Privacy Rule does not allow and that compromises it (45 CFR 164.402). The rule works backward from what most owners expect. Every improper use or disclosure is presumed a breach unless you can show, in a written risk assessment, a low probability that the information was compromised.

Three narrow exceptions apply:

  1. An honest mistake inside the job. A staff member acting in good faith and within their authority views or uses information they should not have, and it goes no further.
  2. A mix-up between two authorized people. Someone allowed to see rider information at your company sends it to another person allowed to see it at your company, and it goes no further.
  3. Information the recipient could not keep. You have a good faith belief the person who got it could not reasonably have retained it.

The notice rules apply only to “unsecured” information. HHS guidance names two ways to secure it. Stored electronic information encrypted in line with NIST Special Publication 800-111, with the decryption key kept separate and not compromised, is secured. Paper shredded or destroyed so it cannot be read or put back together is secured. Blacking out names does not count. A paper manifest in a clipboard is always unsecured.

Rider information on a manifest is protected health information even when it shows no diagnosis. A name with a pickup address and a dialysis center as the destination identifies a person and their care.

Common NEMT incidents and how they usually come out

What happened Secured? Where it usually lands
Driver phone lost, encrypted, passcode not exposed Yes Not a reportable breach under HIPAA. Your broker agreement may still require you to report it as a security incident.
Driver phone lost or stolen with no passcode No Presumed breach unless your risk assessment shows a low probability of compromise
Paper manifests stolen from a van No Presumed breach
Manifest texted to another of your own drivers by mistake No May fit the second exception if it goes no further
Manifest texted or emailed to someone outside your company No Presumed breach. Written promise to delete helps your risk assessment.
Office email account taken over No Presumed breach for rider information in the mailbox
Ransomware locks your dispatch or billing computer No Presumed breach, per HHS’s ransomware guidance
Driver posts a photo that shows a manifest No Presumed breach

The first 24 hours: step by step

Work through these steps the day you learn of the problem. Write down the time of each one as you go.

1. Stop the loss

  • Lost or stolen phone or tablet. Lock it and erase it remotely with the device’s find-and-erase feature. Change the passwords for every account the device could open: dispatch, broker portals, email, and messaging apps. Sign the device out of all sessions.
  • Paper manifests. Retrace the route and call the places the driver stopped. If they were stolen, file a police report.
  • Email or portal account. Change the password from a clean device, turn on multi-factor login, and check the account’s forwarding rules and filters. The FBI reported on April 6, 2020 that attackers who take over business email often set rules that delete key messages, and may turn on forwarding to an outside account.
  • Ransomware. Disconnect the affected computers from the network and do not wipe them before you know what was taken.

2. Write down what happened

Record the date and time the incident happened, the date and time anyone at your company first knew, who reported it, which riders and trips are involved, and what information was on the device or paper. HIPAA’s Security Rule requires you to identify and respond to suspected or known security incidents, reduce harm where you can, and document each incident and its outcome (45 CFR 164.308(a)(6)). An incident report form works for this.

3. Tell the broker or plan your agreement names

If you run trips for a broker, the broker is usually your first call. Read your business associate agreement for the deadline and the contact. Do not wait until you finish the risk assessment if your agreement sets a short clock.

4. Report crimes, without rider health details

Report thefts to the police. HHS’s 2016 ransomware fact sheet recommends contacting your local FBI or Secret Service field office after a ransomware attack, and the FBI takes reports of email fraud at ic3.gov. HHS’s June 2017 checklist says reports to law enforcement should not include protected health information unless HIPAA allows it. A police report can describe “a phone containing trip schedules” without listing riders.

5. Limit the harm

Get the information back or deleted where you can. If a manifest went to the wrong person, ask them to delete it and confirm in writing. HHS said in its 2013 rule that a recipient’s assurance, such as a confidentiality agreement, that the information will not be used further or will be destroyed can lower the risk. If money moved because of a hacked email, the FBI’s advice is to call your bank immediately and ask it to recall the funds.

6. Start the risk assessment

Begin the written four-factor assessment described below, and keep every note, email, and photo from the response.

When the clock starts and the deadlines that follow

A breach counts as discovered on the first day it is known, or would have been known with reasonable diligence, to anyone on your staff or acting as your agent other than the person who caused it (45 CFR 164.410). If a driver loses a phone on Monday and tells dispatch that evening, Monday is the discovery date. Train drivers and dispatchers to report the same day.

HIPAA sets the outer limits. Your contracts set tighter ones.

Who Must tell Deadline Rule
A business associate or subcontractor, such as a company running broker trips The broker or covered entity above it Without unreasonable delay and within 60 calendar days of discovery 45 CFR 164.410
WellTrans providers (Indiana) WellTrans’s HIPAA Compliance Officer, in writing One business day for a breach, a security incident, or any use the agreement does not allow. Imminent misuse also needs immediate phone or email notice. Agreement revised October 16, 2025
MTM Health providers MTM Every breach of rider health or personal information must be reported. The timing is in the business associate agreement attached as Appendix A. Standard agreement, January 1, 2023 version, section 2.I
Modivcare providers Your provider relations partner or Modivcare’s privacy officer Immediately, for any breach “big or small” 2023 provider compliance training
A covered entity Each affected rider Without unreasonable delay and within 60 calendar days of discovery 45 CFR 164.404
A covered entity Prominent media in the state Within 60 days, when more than 500 residents of one state are affected 45 CFR 164.406
A covered entity HHS, through the OCR breach portal 500 or more people: at the same time as the rider notices. Fewer than 500: within 60 days after the end of the calendar year. 45 CFR 164.408

The notices move up a chain. HHS explained in its 2013 rule that a subcontractor notifies the business associate it works for, which notifies the covered entity, which then notifies riders, HHS, and the media, unless it has handed that job to a business associate. For most NEMT companies, that means you report to the broker, the broker reports to the state or health plan, and the state or plan decides on notices.

Your report to the broker should include, as far as you know them, the name of each affected rider and the facts the covered entity needs for its notice (164.410(c)). WellTrans’s agreement spells it out: what happened with the dates, the types of information, steps riders should take, what you are doing about it, and a contact for questions.

A law enforcement agency can pause the clock. If an official says in writing that a notice would impede a criminal investigation, you delay for the time stated. If the request is spoken, you write down who made it and delay no more than 30 days unless a written request follows (45 CFR 164.412).

How to do the four-factor risk assessment

The assessment decides whether a presumed breach is reportable. HIPAA requires at least these four factors (164.402), and HHS explained each one in its January 25, 2013 rule. Write one short paragraph per factor.

  1. What information was involved. Names with Medicaid IDs, dates of birth, addresses, and clinic destinations weigh more than a first name and a pickup time. A manifest for a behavioral health or cancer clinic may weigh more than a ride to a pharmacy.
  2. Who got it. Information sent by mistake to another company that must follow HIPAA, such as a different broker or a clinic, may carry less risk than information in a thief’s hands.
  3. Whether it was actually viewed or taken. HHS’s example: a laptop stolen and later recovered, where a forensic check shows the files were never opened, was not actually acquired. A letter mailed to the wrong person who opened it and called to say so was viewed.
  4. How far the risk has been reduced. A remote erase that finished, a written promise from the recipient to delete, or a recovered clipboard all count. HHS says to weigh how complete and effective each step was. A promise to delete from a clinic or another company that follows HIPAA counts for more than one from a stranger.

If the four factors together show a low probability of compromise, record that conclusion and keep it. If they do not, treat it as a reportable breach. You carry the burden of proving either that no notice was needed or that every notice went out on time (45 CFR 164.414). HHS also lets you skip the assessment and simply give the notices. The HIPAA risk assessment template covers your year-round risk analysis, which is a separate document from this incident assessment.

State breach laws add their own deadlines

State breach laws apply alongside HIPAA. The four below cover electronic data, count health or health insurance information as protected, and make a company that holds data for someone else notify that owner.

State Notice to people State agency notice If you hold data for a broker or plan Rule
California Within 30 calendar days of discovery, since January 1, 2026 Sample copy to the Attorney General within 15 days of notifying people, when more than 500 residents are affected Notify the owner immediately Civil Code 1798.82
Texas Within 60 days of determining the breach occurred Attorney General within 30 days, on its online form, when at least 250 Texans are affected Notify the owner immediately Business and Commerce Code 521.053
Florida Within 30 days Department of Legal Affairs within 30 days, when 500 or more Floridians are affected Notify the covered entity within 10 days Statutes 501.171
New York Within 30 days after discovery Attorney General, Department of State, and State Police whenever New Yorkers are notified Notify the owner immediately General Business Law 899-aa

A few details matter for NEMT:

  • California treats a HIPAA covered entity as meeting its notice content rules if it follows HIPAA’s content rules. The 30-day deadline still applies.
  • Florida has also counted a name combined with any geolocation information as personal information since July 1, 2024, which matters for GPS trip records. Notice given under the rules of a company’s primary or functional federal regulator is deemed to meet Florida’s rule for notice to people, and sending the Department a copy on time meets the Department notice. A covered entity that misses the Department or individual notice can owe up to $500,000 per breach.
  • New York requires a HIPAA covered entity that reports a breach to HHS to notify the Attorney General within 5 business days of that report. If riders were already notified under HIPAA, New York requires no second letter, but the state notices still go out.
  • Texas requires notice to the national consumer reporting agencies when more than 10,000 people are notified at one time. Florida’s threshold is more than 1,000 and New York’s more than 5,000.

These laws cover computerized data. A stolen stack of paper manifests falls under HIPAA and your contract, not these four statutes. Other states have their own laws, so check the one where your riders live.

Playbooks for the incidents NEMT companies see most

A driver’s phone is lost or stolen

  1. Remote lock and erase, then change every password the phone could reach.
  2. Confirm whether the phone had a passcode and device encryption turned on. Write down how you know.
  3. Report it to your broker under your agreement’s security incident terms, even if you believe the data was secured.
  4. If it was not secured, run the four-factor assessment and send your broker the list of riders on that phone’s manifests.
  5. File a police report if it was stolen.

Paper manifests are stolen or left behind

  1. Check with every stop on the route and your drivers.
  2. Report a theft to the police, describing the papers without listing riders.
  3. Report to your broker within your agreement’s deadline, with the riders’ names from the manifest copy.
  4. Switch drivers to a folder kept out of sight, and shred each day’s paper once trips are logged. See HIPAA texting for NEMT for sending trip details by phone with fewer risks.

Your office email is taken over

  1. Change the password, turn on multi-factor login, and remove any forwarding rules or filters you did not create.
  2. Review sent mail and the mailbox for rider information: manifests, trip requests, claims, and signed logs.
  3. Warn brokers, facilities, and your bank that messages from your account may be fake. Confirm any payment change by calling a number you already have, as the FBI advises.
  4. Report to IC3 and to your broker.

Ransomware locks your computers

  1. Isolate the machines and call your IT support and, if you carry one, your cyber insurance carrier.
  2. Contact the FBI or Secret Service field office, as HHS recommends.
  3. Treat it as a presumed breach. HHS’s July 11, 2016 fact sheet says rider information encrypted by ransomware has been acquired, and full-disk encryption alone may not protect files if the computer was on and in use when it was infected.
  4. Restore from backups and report to your broker.

What goes in a breach notice to riders

If your company is the covered entity, or your broker hands you the job, the letter must be in plain language and cover, as far as possible (45 CFR 164.404(c)):

  1. What happened, with the date of the breach and the date you found it.
  2. What types of information were involved, such as name, address, date of birth, Medicaid ID, or trip destinations.
  3. Steps riders should take to protect themselves.
  4. What you are doing to investigate, reduce harm, and prevent a repeat.
  5. How to reach you, including a toll-free number, an email address, a website, or a postal address.

Send it by first-class mail, or by email if the rider agreed to email notices. If you have bad addresses for 10 or more riders, you must post the notice on your website home page for 90 days or run it in major print or broadcast media where they live, with a toll-free number active for 90 days. For fewer than 10, a phone call or another written notice works. California requires the title “Notice of Data Breach” and set headings for notices to its residents.

Records, penalties, and what reduces them

Keep the incident report, the risk assessment, copies of every notice, and proof of when each went out for at least 6 years. HIPAA sets that retention for required documentation (45 CFR 164.530(j) and 164.316). A covered entity also keeps a log of breaches under 500 people for its yearly HHS report. For all your other records, see NEMT record retention.

Transport companies do pay for these failures. On December 30, 2019, HHS announced that West Georgia Ambulance agreed to pay $65,000 and accept two years of monitoring. Its case began with a 2013 breach report about a lost unencrypted laptop holding information on 500 people. HHS said its investigation uncovered failures to do a risk analysis, train staff on security, and adopt Security Rule policies.

Contracts carry their own costs. WellTrans’s agreement makes you cover WellTrans and its covered entity clients for fines, penalties, and investigation costs caused by your HIPAA violations. Apply your written sanction policy to staff who broke the rules, as the Security Rule requires (164.308(a)(1)).

Preparation helps if HHS ever reviews you. Under Public Law 116-321, signed January 5, 2021, HHS must consider whether you had recognized security practices in place for at least the previous 12 months when it sets fines or settles a case.

How to make the next incident smaller

  • Encrypt and lock every device. Turn on passcodes, auto-lock, and encryption on every phone and tablet that shows trips. A locked, encrypted phone that goes missing is usually not a reportable breach.
  • Use multi-factor login on email, dispatch, and broker portals, and block automatic forwarding to outside addresses.
  • Carry less paper. Keep manifests in a closed folder, never on the dashboard, and shred them when trips are logged.
  • Give each person their own login and remove access the day someone leaves.
  • Train for the report, not just the rule. Every driver should know to call dispatch the moment a phone or clipboard is missing. See HIPAA training for NEMT staff.
  • Write the plan now. Your NEMT HIPAA policy should name who calls the broker, who writes the risk assessment, and each agreement’s deadline.

Frequently asked questions

Is a lost driver phone a HIPAA breach?

It depends on how the phone was protected. If it was encrypted to the HHS standard and the passcode was not exposed, the information is not unsecured, so the breach notice rules do not apply. If it had no passcode or encryption, the loss is presumed a breach unless a written four-factor risk assessment shows a low probability the information was compromised. Report it to your broker either way if your agreement covers security incidents.

Who tells the riders, my company or the broker?

Usually the covered entity, meaning the state Medicaid agency or the health plan, decides and sends the notices. Your job as a broker subcontractor is to report to the broker with each affected rider's name and the facts. HHS lets a covered entity hand the notice job to a business associate, so read your agreement to see whether the broker can ask you to send letters or pay for them.

How long do I have to report a NEMT data breach?

HIPAA's outer limit is 60 calendar days from discovery for a business associate reporting to its covered entity, and for a covered entity notifying riders. Contracts are much shorter. WellTrans's agreement, revised October 16, 2025, requires written notice within one business day, and Modivcare's 2023 provider training says to report any breach immediately. State laws in California, Florida, and New York set 30 days.

Do I have to report a small breach to HHS?

Only if your company is a covered entity. A covered entity logs every breach affecting fewer than 500 people and reports them to HHS within 60 days after the end of the calendar year it found them, so breaches found in 2026 are due by March 1, 2027. It can report sooner. Each breach needs its own report on the HHS portal.

Is a manifest texted to the wrong driver a breach?

Maybe not. HIPAA excludes an inadvertent disclosure between two people who are both allowed to see rider information at the same company, if it goes no further. If the text went to someone outside your company, it is presumed a breach. Ask the recipient to delete it and confirm in writing, then record that promise in your risk assessment.

Should I call the police after a breach?

Call the police for a theft, such as a stolen phone, laptop, or van with manifests inside. For ransomware, HHS recommends contacting your local FBI or Secret Service field office, and the FBI takes reports of email fraud at ic3.gov. HHS advises leaving rider health information out of those reports unless HIPAA allows it. Keep the report number for your file.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter