Compliance
HIPAA Breach Log Template for NEMT: Every Incident, the Risk Assessment, and the Yearly HHS Report
Overview
A HIPAA breach log template is a running record of every privacy or security incident: what happened, when you found it, the four-factor risk assessment, and who you told and when. A NEMT company that is a broker's business associate uses it to prove timely reports. A covered entity also uses it to report breaches of fewer than 500 people to HHS, due March 1, 2027 for 2026.
- Log every incident the day it is found, including the ones that turn out not to be breaches, because you carry the burden of proof.
- A misdialed text, a lost unencrypted phone, or a manifest left at a clinic is presumed a breach until a written four-factor assessment shows a low probability of compromise.
- Write each broker's reporting deadline at the top of the log. WellTrans's is one business day in writing, far inside HIPAA's 60 days.
- Covered entities report each breach of fewer than 500 people to HHS within 60 days after the year ends: by March 1, 2027 for 2026.
- Keep the log, every assessment, and proof of every notice for at least 6 years, longer if a broker contract says so.
Only the title and the template print.
Most privacy incidents at a NEMT company are small: a manifest left on a clinic counter, a text about a rider’s appointment sent to the wrong number, a driver’s phone forgotten at a gas station. Each one still needs a written record, a decision on whether it is a breach, and proof of who you told and when. This log keeps all of it in one place for the whole year.
How to use this template
- Fill in Part 1 at the start of each year. Write whether you are a covered entity, a business associate, or both. If you are not sure, the tests are in HIPAA for NEMT providers. Copy each broker’s reporting deadline and contact from its business associate agreement.
- Open a line in Part 2 the day anyone reports a problem. A breach counts as discovered on the first day anyone on your staff or acting for you, other than the person who caused it, knew or with reasonable diligence would have known (45 CFR 164.410; 164.404(a)(2) for covered entities). Your HIPAA policy should tell drivers and dispatchers to report the same day.
- Start a Part 3 incident record for each line. Its choices for the type of incident, where the information was, and what it included follow the HHS breach portal, so a covered entity can copy them into its report.
- Tell the broker on its clock. Write the deadline in Part 5 before you finish the assessment, because a broker’s deadline is usually much shorter than the time an assessment can take. The response steps, from stopping the loss to reporting a crime, are in what to do after a NEMT data breach. This log is where you record them.
- Do the assessment in Part 4. Check the three exceptions first. If none applies, write one or two sentences for each of the four factors, then sign and date the conclusion.
- Record every notice in Part 5 and every fix in Part 6. Keep a copy of each notice and proof of the date it went out.
- Covered entities: complete Part 7 in January. Report each breach of fewer than 500 people discovered during the year on the HHS portal, by March 1, 2027 for 2026, and write down the tracking number. Put that date on your compliance calendar.
- Sign Part 8 and file the year. Keep the log with every incident record, assessment, and notice for at least 6 years.
This incident assessment is separate from your Security Rule risk analysis of the whole company. That one goes in the HIPAA risk assessment template, and a pattern in this log is a good reason to update it.
The template
Part 1: Log details (once a year)
| Field | Entry |
|---|---|
| Company legal name | |
| Year this log covers | |
| Our HIPAA role (covered entity, business associate, or both) | |
| Privacy or security officer (name and phone) | |
| Backup contact | |
| Broker or plan 1: name, reporting deadline, and where notice goes | |
| Broker or plan 2: name, reporting deadline, and where notice goes | |
| Broker or plan 3: name, reporting deadline, and where notice goes | |
| Where incident records and copies of notices are kept | |
| Yearly HHS report due (covered entities only) |
Part 2: Running log (one line per incident)
| No. | Date found | Reported by | What happened (a few words) | Riders affected | Breach? (yes, no, or exception) | Broker told (date) | Closed (date) |
|---|---|---|---|---|---|---|---|
| 1 | |||||||
| 2 | |||||||
| 3 | |||||||
| 4 | |||||||
| 5 | |||||||
| 6 | |||||||
| 7 | |||||||
| 8 | |||||||
| 9 | |||||||
| 10 | |||||||
| 11 | |||||||
| 12 |
Part 3: Incident record (one for each line in Part 2)
| Field | Entry |
|---|---|
| Incident number | |
| Date and time found, and who found it | |
| When it happened (start and end dates, if known) | |
| Type: hacking or IT incident, improper disposal, loss, theft, or unauthorized access or disclosure | |
| Where the information was: desktop computer, email, laptop, network server, phone, tablet, or other portable device, paper, or other | |
| Rider information involved: names, addresses, dates of birth, member or Medicaid ID, Social Security numbers, driver’s license numbers, diagnoses or conditions, medications, clinic or trip destinations, claims, bank or card numbers, other | |
| Number of riders affected (exact or approximate) | |
| Was electronic information encrypted, with the key kept apart and not compromised? (yes, no, or not electronic) | |
| Who received, saw, or took the information | |
| Recovered, returned, or deleted? (how, and the proof) | |
| Steps taken to stop the loss (what, when, and by whom) | |
| Crime involved? Police agency and report number | |
| Safeguards in place before: training and policies, risk analysis, physical safeguards, technical safeguards, or none | |
| What happened, in plain words |
Part 4: Is it a reportable breach?
A. The three exceptions. If one applies, record why and stop here.
| Exception | Applies? (yes or no) | Why |
|---|---|---|
| A staff member, or someone acting for us, used or viewed it by mistake, in good faith, within their job, with no further use or disclosure | ||
| A person allowed to see rider information here sent it by mistake to another person here who is also allowed, with no further use or disclosure | ||
| We believe in good faith that the person who got it could not have kept it |
B. The four factors. Complete all four if no exception applies.
| Factor | What we found |
|---|---|
| 1. What information was involved, which identifiers, and how easily it could identify a rider | |
| 2. Who used or received it (a clinic or other HIPAA-covered organization, a family member, a stranger, or unknown) | |
| 3. Whether it was actually viewed or taken | |
| 4. How far the risk was reduced (remote wipe finished, paper returned, written promise to delete) |
C. Conclusion
| Field | Entry |
|---|---|
| Result: low probability of compromise (not a breach), or a breach | |
| Reasons, in one or two sentences | |
| Decided by (name and title) and date |
Part 5: Notices
| Notice | Deadline | Date sent | How, and to whom |
|---|---|---|---|
| Broker or plan, as its agreement requires | |||
| Law enforcement delay requested (official’s name, agency, written or spoken, end date) | |||
| Riders (covered entity, or when your agreement assigns it to you) | 60 days from discovery at most | ||
| Media (covered entity, more than 500 residents of one state) | 60 days from discovery at most | ||
| HHS (covered entity) | 500 or more: with the rider notices. Fewer than 500: within 60 days after the year ends | ||
| State agency or attorney general, if state law or a contract requires | |||
| Other (insurer, facility, police) |
Part 6: Fixes and follow-up
| Action | Date done | Notes |
|---|---|---|
| Trained or retrained the staff involved | ||
| Applied our sanctions policy to staff who broke the rules | ||
| Changed passwords or locked accounts | ||
| Turned on encryption, screen locks, or remote wipe | ||
| Improved physical security (locked bins, covered clipboards) | ||
| Revised a policy or procedure | ||
| Updated the Security Rule risk analysis | ||
| Revised a vendor or subcontractor agreement | ||
| Offered riders free credit monitoring | ||
| Other | ||
| Record closed by (name) and date |
Part 7: Yearly HHS report worksheet (covered entities only)
One line for each breach of fewer than 500 people discovered during the year.
| No. | Breach dates | Discovery dates | Riders affected | Type and location | Rider notices sent | Filed with HHS (date) | HHS tracking number |
|---|---|---|---|---|---|---|---|
Part 8: Year-end review
| Field | Entry |
|---|---|
| Incidents logged this year | |
| Breaches found this year | |
| Patterns (same driver, same clinic, same kind of device) | |
| Changes made to policies or training | |
| Reviewed by (name, title, and signature) and date | |
| Keep this log until (at least 6 years from today) |
What HIPAA requires you to write down
The log answers five rules in the breach and security regulations.
- Every slip starts as a presumed breach. A use or disclosure HIPAA does not allow is presumed a breach unless you show a low probability that the information was compromised, using at least the four factors in Part 4 (45 CFR 164.402). The same section sets the three exceptions. “Unsecured” information is what the rule covers, which is why Part 3 asks about encryption.
- You carry the burden of proof. A covered entity or business associate must be able to show either that an incident was not a breach or that every notice went out as required (45 CFR 164.414). A covered entity must also keep documentation that meets that burden (164.530(j)(1)(iv)). Without a dated assessment, you cannot show either.
- Security incidents get documented too. The Security Rule requires covered entities and business associates to identify and respond to security incidents, limit the harm, and document each incident and its outcome (164.308(a)(6)(ii)). A security incident includes an attempted break-in, not only a successful one (164.304). A business associate agreement must require you to report security incidents to the covered entity (164.314(a)(2)(i)(C)).
- A spoken police request must be written down. If an officer says a notice would hurt an investigation, record the officer’s name and the statement. A spoken request delays notice no more than 30 days unless a written one follows (45 CFR 164.412).
- Sanctions and fixes are part of the record. A covered entity must document any sanctions it applies and limit known harm from a wrongful use or disclosure (164.530(e) and (f)). Parts 6 and 8 hold that proof.
Broker deadlines come before HIPAA’s
HIPAA gives a business associate up to 60 calendar days from discovery to tell the covered entity, and asks it not to delay without reason. The notice must name each affected person if possible, plus what the covered entity needs for its own notices (164.410). Broker agreements are much shorter, so copy each clock into Part 1 from the agreement you signed. As of October 2026:
- WellTrans. Its provider packet (revised October 16, 2025) sets two clocks. The business associate agreement requires written notice to its HIPAA Compliance Officer no more than one business day after discovery, plus a call or email at once if misuse seems imminent. The account setup agreement in the same packet requires a report to its HIPAA privacy and security officer within 48 hours. Write both in Part 1 and meet whichever comes first. The agreement also puts the burden of proving that no notice was needed on you, and tells you to document each risk assessment and how any exception was met. Part 4 is that record.
- Modivcare. Its 2025 annual compliance training for transportation providers says to report any security breach involving rider health information, big or small, immediately to your provider relations partner or to its privacy officer.
- MTM Health. Its standard agreement (January 1, 2023 version, posted by Pennsylvania) requires providers to report any breach of rider health or personal information to MTM and to follow the business associate agreement attached as Appendix A. Copy the deadline from your signed Appendix A.
What each notice must say, and the clocks for security incidents, are in what to do after a NEMT data breach and the HIPAA policy template.
The yearly HHS report for breaches under 500
A covered entity keeps a log or other documentation of breaches affecting fewer than 500 people, and reports the breaches discovered during each calendar year to HHS no later than 60 days after the year ends (45 CFR 164.408). For breaches found in 2026, that is March 1, 2027. Breaches affecting 500 or more people go to HHS at the same time as the rider notices instead. HHS explained in its August 24, 2009 rule that the yearly report does not delay anything else: each rider is still owed notice within 60 days of discovery, and the log must be kept for six years and shown to HHS on request.
HHS’s filing instructions (last reviewed February 13, 2026) let you file several reports on the same day, but each breach needs its own notice. As of October 2026, the portal’s form (OMB No. 0945-0003) asks for the details below. Part 3 and Part 7 collect each of them.
- General. An initial report or an addendum to an earlier one, with its tracking number.
- Contact. The covered entity, or a business associate filing for one, and a contact person.
- Breach. Start and end dates of the breach and of its discovery, the approximate number of people affected (HHS asks for an estimate when you are unsure), the type of breach, where the information was, the kinds of information, a description of up to 4,000 characters, and the safeguards in place before.
- Notice and actions. When rider notices started and are expected to finish, whether substitute or media notice was needed, and the actions taken in response.
- Attestation. The name of the person confirming the report is accurate.
HHS says on the portal that it investigates every breach affecting 500 or more people, while smaller ones may be investigated depending on its resources and priorities. A clean log is what you hand over if yours is one of them.
How long to keep the log
Keep the log, every incident record, and copies of every notice for at least 6 years from the date each was made or last in effect, whichever is later (45 CFR 164.530(j) for covered entities; 164.316(b)(2) for Security Rule records, which covers business associates too). Broker contracts can ask for more. MTM Health’s standard agreement requires full records of your operations for 10 years, and WellTrans’s requires all records related to the agreement for its term plus 10 years. Use the longest rule that applies to you, and see NEMT record retention for one schedule that covers everything.
Frequently asked questions
Does a NEMT company need a HIPAA breach log?
If you are a covered entity, yes. HIPAA requires a log or other record of breaches affecting fewer than 500 people for the yearly HHS report. If you are a business associate, the Security Rule still requires you to document security incidents and their outcomes, and you carry the burden of proving that an incident was not a breach or that every notice went out on time. One log does both jobs.
When is the HHS report for small breaches due?
Within 60 days after the end of the calendar year in which you discovered the breaches, so breaches found in 2026 are due by March 1, 2027. The rule counts by the year you found the breach, not the year it happened. Only covered entities file it, and they may file sooner. Each rider is still owed notice within 60 days of discovery.
Should I log incidents that turn out not to be breaches?
Yes. A text with a rider's name and appointment sent to the wrong number is presumed a breach until your written risk assessment shows a low probability that the information was compromised, or one of the three exceptions applies. The log, with the assessment attached, is your proof. WellTrans's agreement also tells providers to document each risk assessment and how any exception was met.
Is a lost phone with rider information a breach?
It depends on whether the information was secured. HHS guidance from August 24, 2009 says electronic information encrypted to the Security Rule standard, with the key kept apart from the data and not compromised, is secured, so losing it is not a reportable breach. An unencrypted phone is presumed a breach until your assessment shows otherwise. Either way, log it and tell your broker on its clock.
Who files the HHS report, my company or the broker?
The covered entity. HIPAA counts the Medicaid program and other health plans as covered entities, so for broker trips the filer is usually the state or health plan above your broker, and your job is to tell the broker fast and completely. The HHS portal also lets a business associate file for a covered entity, but do that only when your agreement gives you that job.
How long do I keep the breach log?
At least 6 years from the date each record was made or last in effect, under HIPAA's documentation rules. Broker contracts can run longer. MTM Health's standard agreement asks for 10 years of records of your operations, and WellTrans's asks for records for the agreement term plus 10 years.