# Business Associate Agreement Checklist for NEMT: Review Any BAA Before You Sign

Canonical URL: https://nemtguide.com/templates/business-associate-agreement-checklist/ · Updated 2026-09-30

A business associate agreement checklist lets you check any HIPAA agreement term by term before you sign it or hand it to a vendor. It covers the terms 45 CFR 164.504(e) and 164.314(a) require in every agreement, the short deadlines brokers add, and what to ask billing services and software vendors for, such as a fast breach report and the return of your trip data.

- Every agreement needs the same core terms, whether a broker hands it to you or you hand it to a vendor.
- A broker's agreement sets your deadlines. WellTrans wants a breach reported in writing within one business day, well inside HIPAA's 60-day outer limit.
- Give your vendors a reporting deadline shorter than your broker gives you, so you can still meet yours.
- Write down how your trip data comes back, in what format, and by when, before any vendor stores it.
- Keep each signed agreement for 6 years after it was last in effect.

A business associate agreement is the paper HIPAA requires before rider information changes hands with an outside company. A NEMT company deals with it in two directions. You sign the agreement your broker or health plan writes, and you get one signed by every billing service, software company, and IT helper that touches your trip data. This checklist works both ways: one set of required terms, then the extra points for each side.

## How to use this template

1. **List every outside company first.** Part 1 names the kinds of companies that usually see rider details. Fill in who you use, and mark which side writes the agreement.
2. **Take one agreement at a time.** Fill in Part 2, then go down Parts 3 and 4 and write the section number where each term appears. A blank section number means the term is missing.
3. **Signing a broker's or plan's agreement?** Work through Part 5. It lists the deadlines and duties you take on, so you can name who handles each one before you sign.
4. **Handing your agreement to a vendor?** Work through Part 6. It lists what to ask for beyond the legal minimum.
5. **Fix gaps in writing.** Send a vendor the list of missing terms. For a broker, send your questions to its provider relations team and keep the answer.
6. **File and review.** Complete Part 7, keep the signed copy for 6 years after it was last in effect, and check every agreement once a year and whenever a vendor's service changes.

This is a checklist, not legal advice. A health care attorney should review any agreement you are unsure about.

## The template

### Part 1: Outside companies that see rider information

| Kind of company | Company name | Rider information it sees or stores | Who writes the agreement (theirs or yours) | Date signed | Next review |
|---|---|---|---|---|---|
| Broker or health plan that sends you trips | | | | | |
| Second broker or plan | | | | | |
| Billing service or clearinghouse | | | | | |
| Dispatch, scheduling, or GPS software | | | | | |
| Email, file storage, or backup service | | | | | |
| IT support for your computers and phones | | | | | |
| Accountant or bookkeeper who sees trip records | | | | | |
| Attorney who sees trip records | | | | | |
| Factoring company that buys broker invoices | | | | | |
| Shredding or records storage company | | | | | |
| Another NEMT company that runs your trips | | | | | |
| Other | | | | | |

HHS's business associate guidance, last reviewed July 30, 2026, lists cases that need no agreement: your own employees, a company that only carries information like the Postal Service, and a worker such as a janitor whose access is incidental while reasonable safeguards are in place.

### Part 2: The agreement in front of you

| Item | Answer |
|---|---|
| Company, agreement title, and version date | |
| Whose form it is (theirs or yours) | |
| Your role in it: covered entity, business associate, or subcontractor | |
| The service contract it attaches to, and that contract's date | |
| Rider information involved: names, addresses, phone numbers, Medicaid IDs, appointment places, mobility needs, trip logs, signatures | |
| Where the information is stored, and from which countries it is reached | |
| Privacy contact at each company: name, phone, email | |
| Where reports of problems must be sent, and how (phone, fax, email, mail) | |
| Reviewed by, and date | |

### Part 3: Terms HIPAA requires in every agreement

| Required term | Rule | Section in this agreement | OK or missing |
|---|---|---|---|
| Says what the other company is allowed and required to do with rider information | 164.504(e)(2)(i) | | |
| No use or disclosure beyond the agreement or what the law requires | 164.504(e)(2)(ii)(A) | | |
| Appropriate safeguards, and the Security Rule for electronic information | 164.504(e)(2)(ii)(B), 164.314(a)(2)(i)(A) | | |
| Reports any use or disclosure the agreement does not allow, including breaches under 164.410 | 164.504(e)(2)(ii)(C) | | |
| Reports any security incident it becomes aware of | 164.314(a)(2)(i)(C) | | |
| Its own subcontractors agree in writing to the same restrictions | 164.504(e)(2)(ii)(D), 164.314(a)(2)(i)(B) | | |
| Makes information available when a rider asks for a copy | 164.504(e)(2)(ii)(E) | | |
| Makes information available for amendment and adds the changes | 164.504(e)(2)(ii)(F) | | |
| Keeps what is needed for an accounting of disclosures | 164.504(e)(2)(ii)(G) | | |
| Follows the Privacy Rule when it does a task the covered entity owes | 164.504(e)(2)(ii)(H) | | |
| Opens its practices, books, and records to HHS | 164.504(e)(2)(ii)(I) | | |
| Returns or destroys the information at the end and keeps no copies, or extends the protections where that is not feasible | 164.504(e)(2)(ii)(J) | | |
| Lets the party that shared the information end the contract for a material violation | 164.504(e)(2)(iii) | | |

### Part 4: Permissions that must be spelled out

| Permission | Allowed in this agreement? (section, or no) | Your decision |
|---|---|---|
| Use of rider information for the vendor's own management, administration, and legal duties | | |
| Disclosure for those purposes, only if the law requires it or the recipient gives reasonable assurance that it will keep the information confidential and report any breach of that confidentiality | | |
| Data aggregation: combining your data with other clients' data for your operations | | |
| De-identifying rider information, how it is done, and what the vendor may do with the result | | |
| Limits to the minimum information needed for each task | | |
| No sale of rider information and no payment received in exchange for it | | |
| Who owns the data and anything made from it | | |

### Part 5: When you sign a broker's or health plan's agreement

| Duty you take on | Deadline or term in this agreement | Who at your company handles it |
|---|---|---|
| Report an improper use or disclosure within | | |
| Report a security incident within | | |
| Report a breach in writing within | | |
| What the breach report must contain | | |
| Where and how reports are sent | | |
| Give the broker a rider's records for access or amendment within | | |
| Keep a record of disclosures, and hand it over on request | | |
| Written consent needed before sharing member information or subcontracting | | |
| Same terms signed by your billing, factoring, and software companies | | |
| HIPAA training for staff and drivers, and proof on request | | |
| Privacy and security surveys, audits, or attestations on request | | |
| Harm caused by a breach reduced at your expense | | |
| Sanctions for staff who break the rules | | |
| Indemnity: what you pay for if a breach or violation is yours | | |
| Return or destroy at the end, and certify destruction | | |
| How the agreement is amended, and what happens if you do not agree | | |
| State privacy law terms | | |

### Part 6: When a vendor signs yours

| Term to ask for | In this agreement (section) | Agreed, refused, or changed |
|---|---|---|
| Improper uses and security incidents reported to you within ___ hours | | |
| Breaches reported in writing within ___ hours, well inside your broker's deadline | | |
| Who sends notices to riders, HHS, and the media, and who pays for them | | |
| What happens when a rider or broker contacts the vendor directly | | |
| Records for access or amendment handed to you within ___ business days | | |
| Countries where data is stored or reached from | | |
| Backups, and how fast service and data come back after an outage or ransomware | | |
| Your data returned at the end within ___ days, in a format you can open and use | | |
| No lockout of your data during a billing dispute | | |
| Proof of safeguards, such as audit reports or a security questionnaire, on request | | |
| List of the vendor's own subcontractors that touch your data | | |
| Cure period before you end the agreement for a violation: ___ days | | |
| Binds any company that buys or takes over the vendor | | |

### Part 7: Sign-off and filing

| Item | Answer |
|---|---|
| Missing terms sent back, and date | |
| Final version signed by both sides, and date | |
| Where the signed copy is kept | |
| Keep until (6 years after it was last in effect) | |
| Next review date | |
| Reviewed by (name and title) | |

## What HIPAA requires in every agreement

HIPAA lets a covered entity share rider information with a business associate only after getting satisfactory assurances, written down in a contract that meets [45 CFR 164.504(e)](https://www.ecfr.gov/current/title-45/section-164.504) ([45 CFR 164.502(e)](https://www.ecfr.gov/current/title-45/section-164.502)). A business associate needs the same written assurances before it lets a subcontractor handle the information. The Security Rule adds its own contract terms for electronic information in [45 CFR 164.314(a)](https://www.ecfr.gov/current/title-45/section-164.314): comply with the Security Rule, bind subcontractors, and report security incidents. Both sets of terms apply to an agreement between a business associate and its subcontractor in the same way. Part 3 lists all of them.

That matters because most NEMT companies sit in the middle. Modivcare's 2025 annual compliance training for transportation providers (August 2025) says Modivcare is a business associate of the health plans and state Medicaid agencies it works for, and that its transportation providers are its subcontractors. HHS's business associate guidance, last reviewed July 30, 2026, says a business associate must have an agreement with a subcontractor before disclosing information to it. So the agreement you sign with a broker makes you answerable for the vendors below you.

Three more rules shape a review:

- **You are directly liable.** HHS's fact sheet on business associates, last reviewed July 16, 2021, lists what OCR can enforce against a business associate itself. The list includes failing to sign agreements with subcontractors, failing to report a breach, and failing to act on a subcontractor's known material breach.
- **You must act on a vendor's pattern of violations.** If you know of a pattern of activity that breaks a subcontractor's agreement, you must take reasonable steps to fix it, and end the contract if that fails and ending it is feasible (164.504(e)(1)(iii)).
- **Stricter state laws still apply.** A state law on the privacy of health information that is more stringent than the HIPAA Privacy Rule is not preempted ([45 CFR 160.203](https://www.ecfr.gov/current/title-45/section-160.203)). WellTrans's agreement has providers follow such state laws (section 7.c).

HHS publishes sample provisions, published January 25, 2013 and last reviewed June 16, 2017. HHS says they are sample language only, may be adapted for an agreement with a subcontractor, and may not be enough on their own for a binding contract under state law. The brackets in the sample show where the two sides are expected to decide something, such as a stricter reporting timeframe, who notifies riders after a breach, and whether the vendor may de-identify data. Parts 4 and 6 turn those brackets into questions.

## What broker agreements add

Brokers write their own agreements, and their deadlines are much shorter than HIPAA's. HIPAA requires a business associate to give notice of a breach without unreasonable delay and no later than 60 calendar days after discovering it ([45 CFR 164.410](https://www.ecfr.gov/current/title-45/section-164.410)). Here is how two published broker agreements compare with that floor:

| Term | HIPAA floor | WellTrans, Exhibit C (revised October 16, 2025) | MTM Health standard agreement (January 1, 2023 version posted by Pennsylvania) |
|---|---|---|---|
| Breach of unsecured information | Without unreasonable delay, within 60 calendar days | Written notice within one business day of discovery | Report any breach of member health or personal information to MTM (2.I) |
| Improper use or security incident | Report it | Within one business day | The main agreement names only breaches (2.I). Member information may be used only as needed to perform the agreement (21.F). |
| Rider access or amendment | Make the information available | Within five business days of WellTrans's request | Not in the main agreement. See Appendix A, the business associate agreement you must sign (2.I). |
| Your own vendors | Same restrictions in writing | An agreement with billing companies, factoring companies, and anyone who gets trip logs, manifests, or billing documents | No sharing of member information with anyone without MTM's written consent (21.B), and no subcontracting without it (12.A) |
| Training | Security training for your workforce | Staff, agents, and subcontractors trained, with proof on request | Driver training must cover HIPAA (5.B) |
| Checks on you | HHS may review your records | Privacy and security surveys, audits, or attestations on request | Inspections and audits of your premises and records, which may be unannounced (2.T) |
| At the end | Return or destroy if feasible | Return or destroy, and certify destruction | Confidentiality survives termination (21.F) |

WellTrans's agreement also has you mitigate harm at your own expense, keep a sanctions system for staff, and indemnify WellTrans and its clients for claims, fines, and penalties from your breach. If the two sides cannot agree on an amendment needed for a HIPAA change within ten business days, WellTrans may end the agreement. See [WellTrans](https://nemtguide.com/brokers/welltrans/) and [MTM Health](https://nemtguide.com/brokers/mtm-health/).

MTM's agreement makes Appendix A part of the contract by reference. Read Appendix A itself before you sign, and ask provider relations for it in writing if it is not attached.

Plan for the clock before you sign. Under 164.410, a breach counts as discovered on the first day it was known, or would have been known with reasonable diligence, to any employee or agent other than the person who caused it. If a driver tells a dispatcher on Monday that a printed manifest is missing, your deadline started on Monday. The report has to identify each affected rider, to the extent possible. It also has to carry, then or as soon as you learn them, the details the covered entity needs for its own notices under [45 CFR 164.404](https://www.ecfr.gov/current/title-45/section-164.404): what happened and when, what information was involved, what riders should do, and what you are doing about it. See [NEMT data breaches](https://nemtguide.com/guides/nemt-data-breach/) for the full response.

## What to ask of billing services and software vendors

When you hand your own agreement to a vendor, the legal minimum is the floor, not the goal. These points come from HHS guidance:

- **Encrypted storage still counts.** HHS's cloud computing guidance, last reviewed December 23, 2022, says a cloud service that stores your electronic health information is a business associate even if it cannot read the encrypted data. It lists terms a service level agreement can cover: system availability, backup and data recovery, how data is returned when the service ends, security responsibility, and limits on use and retention.
- **Audits are yours to ask for.** The same guidance says HIPAA does not require a cloud vendor to show you its security practices, but you may require documentation or audits through the agreement.
- **Offshore storage is allowed, with more risk.** HIPAA allows storing information outside the United States with an agreement in place. HHS notes the risks vary by country and belong in your risk analysis. Record the countries in Part 2 and in your [HIPAA risk assessment](https://nemtguide.com/templates/hipaa-risk-assessment/).
- **No lockouts.** HHS FAQ 2074 says a vendor that blocks your access to health information it keeps for you, such as with a kill switch during a payment dispute, is making an impermissible use. When the agreement calls for the information to come back at the end, the vendor must return it in a format that keeps it usable.
- **Shredding counts too.** HHS FAQ 575 names a disposal vendor that picks up and destroys records as a business associate. Paper manifests belong on that list.

The cost of skipping the agreement is real. On March 16, 2016, HHS announced that North Memorial Health Care of Minnesota agreed to pay $1,550,000 to settle potential violations. It had given a contractor doing payment and operations work access to a hospital database holding electronic information on 289,904 patients without a business associate agreement. It also had no organization-wide risk analysis. Your [billing service](https://nemtguide.com/guides/nemt-billing-service/) is the vendor to sign first, because it sees every claim.

Set each vendor's reporting deadline inside your broker's. If your broker wants written notice within one business day, a vendor that takes three days leaves you in breach of your broker's agreement before you hear about the problem.

## Keeping and reviewing agreements

Keep each signed agreement for 6 years from the date it was created or the date it was last in effect, whichever is later ([45 CFR 164.316(b)(2)](https://www.ecfr.gov/current/title-45/section-164.316)). Review an agreement when the vendor's service changes, when a broker sends a new version, and when your own role changes, for example if you start billing a health plan directly. HHS's guidance says a provider that submits its own claims to a health plan is not the plan's business associate. A broker contract can still require one, so read each contract.

Rider requests run on legal clocks too. A covered entity must act on a rider's request for access within 30 days (45 CFR 164.524), and on requests for an amendment or an accounting of disclosures within 60 days (164.526 and 164.528). Whoever holds the records, you or your vendor, needs a deadline well inside those.

A change is proposed but not final. On January 6, 2025, HHS proposed Security Rule changes that would require written verification from each business associate, at least once every 12 months, that it has the required technical safeguards in place. The same proposal would have a business associate report the activation of its contingency plan within 24 hours. As of September 2026 it is still a proposal. Nothing stops you from asking vendors for a yearly written confirmation now. Put the rule for staff in your [NEMT HIPAA policy](https://nemtguide.com/templates/nemt-hipaa-policy/): no outside company gets rider information until its agreement is signed and filed. For what the agreement is and when you need one, see [business associate agreement](https://nemtguide.com/glossary/business-associate-agreement/) and [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/).

## Frequently asked questions

### What must a business associate agreement include?

Under 45 CFR 164.504(e) and 164.314(a), it must say what the business associate may do with the information, bar other uses, require safeguards and Security Rule compliance, require reports of improper uses, security incidents, and breaches, bind its subcontractors to the same terms, support a rider's rights to access, amendment, and an accounting, open its records to HHS, return or destroy the information at the end, and allow termination for a material violation.

### Does my billing service need to sign a business associate agreement?

Yes, if it sees rider information for you. HIPAA's definition of a business associate names billing and claims processing (45 CFR 160.103). HHS announced on March 16, 2016 that North Memorial Health Care agreed to pay $1,550,000 to settle potential violations after giving a contractor doing payment and operations work access to data on 289,904 patients with no agreement in place. WellTrans also requires one with any billing or factoring company that gets your trip logs.

### What if I cannot meet a broker's one-business-day reporting deadline?

Build the process before you sign. Under 45 CFR 164.410, a breach counts as discovered on the first day any employee or agent other than the person who caused it knew or should have known. WellTrans's agreement uses the same rule. Name one privacy contact, train drivers and dispatchers to tell that person the same day, and give your vendors a shorter deadline than your broker gives you.

### Does a software company that only stores encrypted trip data need to sign one?

Yes. HHS guidance on cloud computing, last reviewed December 23, 2022, says a cloud service provider that stores electronic health information for you is a business associate even if the data is encrypted and it holds no key to read it. The conduit exception, for a service that only carries data from place to place like the Postal Service, does not cover a service that stores it.

### Can a vendor lock me out of my trip records during a billing dispute?

No. HHS says a business associate that blocks a covered entity's access to the health information it keeps, for example with a kill switch to settle a payment dispute, makes an impermissible use and violates the Security Rule. At the end of the contract it must return the information as the agreement provides, in a format that keeps it usable (HHS FAQ 2074, last reviewed January 9, 2023).

### How long do I keep a signed business associate agreement?

At least 6 years from the date it was created or the date it was last in effect, whichever is later. That is the HIPAA Security Rule's retention period for required documentation (45 CFR 164.316(b)(2)). Keep the agreement with the service contract it belongs to, and keep any amendments with both.

## Official resources

- [HHS: Sample Business Associate Agreement Provisions](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html)
- [eCFR: 45 CFR 164.504(e), what a business associate contract must contain](https://www.ecfr.gov/current/title-45/section-164.504)
- [eCFR: 45 CFR 164.314(a), Security Rule contract terms](https://www.ecfr.gov/current/title-45/section-164.314)
- [HHS: Business Associates guidance](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html)
- [HHS: Guidance on HIPAA and Cloud Computing](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html)
- [WellTrans provider agreement with its subcontractor business associate agreement (October 16, 2025)](https://www.welltransnemt.com/wp-content/uploads/2025/10/WellTrans-Provider-In-Network-Agreement_FINAL_10_16_2025.pdf)
