Compliance

Business Associate Agreement Checklist for NEMT: Review Any BAA Before You Sign

A business associate agreement checklist lets you check any HIPAA agreement term by term before you sign it or hand it to a vendor. It covers the terms 45 CFR 164.504(e) and 164.314(a) require in every agreement, the short deadlines brokers add, and what to ask billing services and software vendors for, such as a fast breach report and the return of your trip data.

  • Every agreement needs the same core terms, whether a broker hands it to you or you hand it to a vendor.
  • A broker's agreement sets your deadlines. WellTrans wants a breach reported in writing within one business day, well inside HIPAA's 60-day outer limit.
  • Give your vendors a reporting deadline shorter than your broker gives you, so you can still meet yours.
  • Write down how your trip data comes back, in what format, and by when, before any vendor stores it.
  • Keep each signed agreement for 6 years after it was last in effect.

Only the title and the template print.

A business associate agreement is the paper HIPAA requires before rider information changes hands with an outside company. A NEMT company deals with it in two directions. You sign the agreement your broker or health plan writes, and you get one signed by every billing service, software company, and IT helper that touches your trip data. This checklist works both ways: one set of required terms, then the extra points for each side.

How to use this template

  1. List every outside company first. Part 1 names the kinds of companies that usually see rider details. Fill in who you use, and mark which side writes the agreement.
  2. Take one agreement at a time. Fill in Part 2, then go down Parts 3 and 4 and write the section number where each term appears. A blank section number means the term is missing.
  3. Signing a broker’s or plan’s agreement? Work through Part 5. It lists the deadlines and duties you take on, so you can name who handles each one before you sign.
  4. Handing your agreement to a vendor? Work through Part 6. It lists what to ask for beyond the legal minimum.
  5. Fix gaps in writing. Send a vendor the list of missing terms. For a broker, send your questions to its provider relations team and keep the answer.
  6. File and review. Complete Part 7, keep the signed copy for 6 years after it was last in effect, and check every agreement once a year and whenever a vendor’s service changes.

This is a checklist, not legal advice. A health care attorney should review any agreement you are unsure about.

The template

Part 1: Outside companies that see rider information

Kind of company Company name Rider information it sees or stores Who writes the agreement (theirs or yours) Date signed Next review
Broker or health plan that sends you trips
Second broker or plan
Billing service or clearinghouse
Dispatch, scheduling, or GPS software
Email, file storage, or backup service
IT support for your computers and phones
Accountant or bookkeeper who sees trip records
Attorney who sees trip records
Factoring company that buys broker invoices
Shredding or records storage company
Another NEMT company that runs your trips
Other

HHS’s business associate guidance, last reviewed July 30, 2026, lists cases that need no agreement: your own employees, a company that only carries information like the Postal Service, and a worker such as a janitor whose access is incidental while reasonable safeguards are in place.

Part 2: The agreement in front of you

Item Answer
Company, agreement title, and version date
Whose form it is (theirs or yours)
Your role in it: covered entity, business associate, or subcontractor
The service contract it attaches to, and that contract’s date
Rider information involved: names, addresses, phone numbers, Medicaid IDs, appointment places, mobility needs, trip logs, signatures
Where the information is stored, and from which countries it is reached
Privacy contact at each company: name, phone, email
Where reports of problems must be sent, and how (phone, fax, email, mail)
Reviewed by, and date

Part 3: Terms HIPAA requires in every agreement

Required term Rule Section in this agreement OK or missing
Says what the other company is allowed and required to do with rider information 164.504(e)(2)(i)
No use or disclosure beyond the agreement or what the law requires 164.504(e)(2)(ii)(A)
Appropriate safeguards, and the Security Rule for electronic information 164.504(e)(2)(ii)(B), 164.314(a)(2)(i)(A)
Reports any use or disclosure the agreement does not allow, including breaches under 164.410 164.504(e)(2)(ii)(C)
Reports any security incident it becomes aware of 164.314(a)(2)(i)(C)
Its own subcontractors agree in writing to the same restrictions 164.504(e)(2)(ii)(D), 164.314(a)(2)(i)(B)
Makes information available when a rider asks for a copy 164.504(e)(2)(ii)(E)
Makes information available for amendment and adds the changes 164.504(e)(2)(ii)(F)
Keeps what is needed for an accounting of disclosures 164.504(e)(2)(ii)(G)
Follows the Privacy Rule when it does a task the covered entity owes 164.504(e)(2)(ii)(H)
Opens its practices, books, and records to HHS 164.504(e)(2)(ii)(I)
Returns or destroys the information at the end and keeps no copies, or extends the protections where that is not feasible 164.504(e)(2)(ii)(J)
Lets the party that shared the information end the contract for a material violation 164.504(e)(2)(iii)

Part 4: Permissions that must be spelled out

Permission Allowed in this agreement? (section, or no) Your decision
Use of rider information for the vendor’s own management, administration, and legal duties
Disclosure for those purposes, only if the law requires it or the recipient gives reasonable assurance that it will keep the information confidential and report any breach of that confidentiality
Data aggregation: combining your data with other clients’ data for your operations
De-identifying rider information, how it is done, and what the vendor may do with the result
Limits to the minimum information needed for each task
No sale of rider information and no payment received in exchange for it
Who owns the data and anything made from it

Part 5: When you sign a broker’s or health plan’s agreement

Duty you take on Deadline or term in this agreement Who at your company handles it
Report an improper use or disclosure within
Report a security incident within
Report a breach in writing within
What the breach report must contain
Where and how reports are sent
Give the broker a rider’s records for access or amendment within
Keep a record of disclosures, and hand it over on request
Written consent needed before sharing member information or subcontracting
Same terms signed by your billing, factoring, and software companies
HIPAA training for staff and drivers, and proof on request
Privacy and security surveys, audits, or attestations on request
Harm caused by a breach reduced at your expense
Sanctions for staff who break the rules
Indemnity: what you pay for if a breach or violation is yours
Return or destroy at the end, and certify destruction
How the agreement is amended, and what happens if you do not agree
State privacy law terms

Part 6: When a vendor signs yours

Term to ask for In this agreement (section) Agreed, refused, or changed
Improper uses and security incidents reported to you within ___ hours
Breaches reported in writing within ___ hours, well inside your broker’s deadline
Who sends notices to riders, HHS, and the media, and who pays for them
What happens when a rider or broker contacts the vendor directly
Records for access or amendment handed to you within ___ business days
Countries where data is stored or reached from
Backups, and how fast service and data come back after an outage or ransomware
Your data returned at the end within ___ days, in a format you can open and use
No lockout of your data during a billing dispute
Proof of safeguards, such as audit reports or a security questionnaire, on request
List of the vendor’s own subcontractors that touch your data
Cure period before you end the agreement for a violation: ___ days
Binds any company that buys or takes over the vendor

Part 7: Sign-off and filing

Item Answer
Missing terms sent back, and date
Final version signed by both sides, and date
Where the signed copy is kept
Keep until (6 years after it was last in effect)
Next review date
Reviewed by (name and title)

What HIPAA requires in every agreement

HIPAA lets a covered entity share rider information with a business associate only after getting satisfactory assurances, written down in a contract that meets 45 CFR 164.504(e) (45 CFR 164.502(e)). A business associate needs the same written assurances before it lets a subcontractor handle the information. The Security Rule adds its own contract terms for electronic information in 45 CFR 164.314(a): comply with the Security Rule, bind subcontractors, and report security incidents. Both sets of terms apply to an agreement between a business associate and its subcontractor in the same way. Part 3 lists all of them.

That matters because most NEMT companies sit in the middle. Modivcare’s 2025 annual compliance training for transportation providers (August 2025) says Modivcare is a business associate of the health plans and state Medicaid agencies it works for, and that its transportation providers are its subcontractors. HHS’s business associate guidance, last reviewed July 30, 2026, says a business associate must have an agreement with a subcontractor before disclosing information to it. So the agreement you sign with a broker makes you answerable for the vendors below you.

Three more rules shape a review:

  • You are directly liable. HHS’s fact sheet on business associates, last reviewed July 16, 2021, lists what OCR can enforce against a business associate itself. The list includes failing to sign agreements with subcontractors, failing to report a breach, and failing to act on a subcontractor’s known material breach.
  • You must act on a vendor’s pattern of violations. If you know of a pattern of activity that breaks a subcontractor’s agreement, you must take reasonable steps to fix it, and end the contract if that fails and ending it is feasible (164.504(e)(1)(iii)).
  • Stricter state laws still apply. A state law on the privacy of health information that is more stringent than the HIPAA Privacy Rule is not preempted (45 CFR 160.203). WellTrans’s agreement has providers follow such state laws (section 7.c).

HHS publishes sample provisions, published January 25, 2013 and last reviewed June 16, 2017. HHS says they are sample language only, may be adapted for an agreement with a subcontractor, and may not be enough on their own for a binding contract under state law. The brackets in the sample show where the two sides are expected to decide something, such as a stricter reporting timeframe, who notifies riders after a breach, and whether the vendor may de-identify data. Parts 4 and 6 turn those brackets into questions.

What broker agreements add

Brokers write their own agreements, and their deadlines are much shorter than HIPAA’s. HIPAA requires a business associate to give notice of a breach without unreasonable delay and no later than 60 calendar days after discovering it (45 CFR 164.410). Here is how two published broker agreements compare with that floor:

Term HIPAA floor WellTrans, Exhibit C (revised October 16, 2025) MTM Health standard agreement (January 1, 2023 version posted by Pennsylvania)
Breach of unsecured information Without unreasonable delay, within 60 calendar days Written notice within one business day of discovery Report any breach of member health or personal information to MTM (2.I)
Improper use or security incident Report it Within one business day The main agreement names only breaches (2.I). Member information may be used only as needed to perform the agreement (21.F).
Rider access or amendment Make the information available Within five business days of WellTrans’s request Not in the main agreement. See Appendix A, the business associate agreement you must sign (2.I).
Your own vendors Same restrictions in writing An agreement with billing companies, factoring companies, and anyone who gets trip logs, manifests, or billing documents No sharing of member information with anyone without MTM’s written consent (21.B), and no subcontracting without it (12.A)
Training Security training for your workforce Staff, agents, and subcontractors trained, with proof on request Driver training must cover HIPAA (5.B)
Checks on you HHS may review your records Privacy and security surveys, audits, or attestations on request Inspections and audits of your premises and records, which may be unannounced (2.T)
At the end Return or destroy if feasible Return or destroy, and certify destruction Confidentiality survives termination (21.F)

WellTrans’s agreement also has you mitigate harm at your own expense, keep a sanctions system for staff, and indemnify WellTrans and its clients for claims, fines, and penalties from your breach. If the two sides cannot agree on an amendment needed for a HIPAA change within ten business days, WellTrans may end the agreement. See WellTrans and MTM Health.

MTM’s agreement makes Appendix A part of the contract by reference. Read Appendix A itself before you sign, and ask provider relations for it in writing if it is not attached.

Plan for the clock before you sign. Under 164.410, a breach counts as discovered on the first day it was known, or would have been known with reasonable diligence, to any employee or agent other than the person who caused it. If a driver tells a dispatcher on Monday that a printed manifest is missing, your deadline started on Monday. The report has to identify each affected rider, to the extent possible. It also has to carry, then or as soon as you learn them, the details the covered entity needs for its own notices under 45 CFR 164.404: what happened and when, what information was involved, what riders should do, and what you are doing about it. See NEMT data breaches for the full response.

What to ask of billing services and software vendors

When you hand your own agreement to a vendor, the legal minimum is the floor, not the goal. These points come from HHS guidance:

  • Encrypted storage still counts. HHS’s cloud computing guidance, last reviewed December 23, 2022, says a cloud service that stores your electronic health information is a business associate even if it cannot read the encrypted data. It lists terms a service level agreement can cover: system availability, backup and data recovery, how data is returned when the service ends, security responsibility, and limits on use and retention.
  • Audits are yours to ask for. The same guidance says HIPAA does not require a cloud vendor to show you its security practices, but you may require documentation or audits through the agreement.
  • Offshore storage is allowed, with more risk. HIPAA allows storing information outside the United States with an agreement in place. HHS notes the risks vary by country and belong in your risk analysis. Record the countries in Part 2 and in your HIPAA risk assessment.
  • No lockouts. HHS FAQ 2074 says a vendor that blocks your access to health information it keeps for you, such as with a kill switch during a payment dispute, is making an impermissible use. When the agreement calls for the information to come back at the end, the vendor must return it in a format that keeps it usable.
  • Shredding counts too. HHS FAQ 575 names a disposal vendor that picks up and destroys records as a business associate. Paper manifests belong on that list.

The cost of skipping the agreement is real. On March 16, 2016, HHS announced that North Memorial Health Care of Minnesota agreed to pay $1,550,000 to settle potential violations. It had given a contractor doing payment and operations work access to a hospital database holding electronic information on 289,904 patients without a business associate agreement. It also had no organization-wide risk analysis. Your billing service is the vendor to sign first, because it sees every claim.

Set each vendor’s reporting deadline inside your broker’s. If your broker wants written notice within one business day, a vendor that takes three days leaves you in breach of your broker’s agreement before you hear about the problem.

Keeping and reviewing agreements

Keep each signed agreement for 6 years from the date it was created or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)). Review an agreement when the vendor’s service changes, when a broker sends a new version, and when your own role changes, for example if you start billing a health plan directly. HHS’s guidance says a provider that submits its own claims to a health plan is not the plan’s business associate. A broker contract can still require one, so read each contract.

Rider requests run on legal clocks too. A covered entity must act on a rider’s request for access within 30 days (45 CFR 164.524), and on requests for an amendment or an accounting of disclosures within 60 days (164.526 and 164.528). Whoever holds the records, you or your vendor, needs a deadline well inside those.

A change is proposed but not final. On January 6, 2025, HHS proposed Security Rule changes that would require written verification from each business associate, at least once every 12 months, that it has the required technical safeguards in place. The same proposal would have a business associate report the activation of its contingency plan within 24 hours. As of September 2026 it is still a proposal. Nothing stops you from asking vendors for a yearly written confirmation now. Put the rule for staff in your NEMT HIPAA policy: no outside company gets rider information until its agreement is signed and filed. For what the agreement is and when you need one, see business associate agreement and HIPAA for NEMT providers.

Frequently asked questions

What must a business associate agreement include?

Under 45 CFR 164.504(e) and 164.314(a), it must say what the business associate may do with the information, bar other uses, require safeguards and Security Rule compliance, require reports of improper uses, security incidents, and breaches, bind its subcontractors to the same terms, support a rider's rights to access, amendment, and an accounting, open its records to HHS, return or destroy the information at the end, and allow termination for a material violation.

Does my billing service need to sign a business associate agreement?

Yes, if it sees rider information for you. HIPAA's definition of a business associate names billing and claims processing (45 CFR 160.103). HHS announced on March 16, 2016 that North Memorial Health Care agreed to pay $1,550,000 to settle potential violations after giving a contractor doing payment and operations work access to data on 289,904 patients with no agreement in place. WellTrans also requires one with any billing or factoring company that gets your trip logs.

What if I cannot meet a broker's one-business-day reporting deadline?

Build the process before you sign. Under 45 CFR 164.410, a breach counts as discovered on the first day any employee or agent other than the person who caused it knew or should have known. WellTrans's agreement uses the same rule. Name one privacy contact, train drivers and dispatchers to tell that person the same day, and give your vendors a shorter deadline than your broker gives you.

Does a software company that only stores encrypted trip data need to sign one?

Yes. HHS guidance on cloud computing, last reviewed December 23, 2022, says a cloud service provider that stores electronic health information for you is a business associate even if the data is encrypted and it holds no key to read it. The conduit exception, for a service that only carries data from place to place like the Postal Service, does not cover a service that stores it.

Can a vendor lock me out of my trip records during a billing dispute?

No. HHS says a business associate that blocks a covered entity's access to the health information it keeps, for example with a kill switch to settle a payment dispute, makes an impermissible use and violates the Security Rule. At the end of the contract it must return the information as the agreement provides, in a format that keeps it usable (HHS FAQ 2074, last reviewed January 9, 2023).

How long do I keep a signed business associate agreement?

At least 6 years from the date it was created or the date it was last in effect, whichever is later. That is the HIPAA Security Rule's retention period for required documentation (45 CFR 164.316(b)(2)). Keep the agreement with the service contract it belongs to, and keep any amendments with both.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter