# HIPAA Confidentiality Agreement for NEMT Employees: The Signed Statement Brokers Collect

Canonical URL: https://nemtguide.com/templates/hipaa-confidentiality-agreement/ · Updated 2026-10-02

A HIPAA confidentiality agreement for employees is a one-page statement each driver, dispatcher, biller, volunteer, and trainee signs before seeing rider information. It commits them to use only what the job needs, keep manifests and phones secure, report problems the same day, and hand everything back when they leave. Kentucky's transportation rule and Paratransit Services, a Washington broker, require a signed statement from each person.

- Everyone who sees rider information signs, paid or not: drivers, attendants, dispatchers, billers, volunteers, trainees, and the relative who answers the phone.
- If a broker hands you its own confidentiality form, use the broker's form. Paratransit Services requires agreements in the form it sets.
- Write in what the statement does not stop: reports to a government agency or a lawyer, complaints to HHS, 911 calls, and talk about pay and working conditions.
- Close the statement out on the person's last day: papers and devices back, logins off, and a reminder that the promise continues.
- Keep each signed statement at least 6 years after the person leaves, or longer when a broker asks: MTM Health's agreement asks for 10 years of records.

A driver with a manifest knows where your riders live and where they go for care, and a dispatcher can see far more. This form puts in writing what each person promises to do with that information, and gives you the signed copy a broker or state asks to see. It is the standalone statement. Your [NEMT HIPAA policy](https://nemtguide.com/templates/nemt-hipaa-policy/) has its own acknowledgment in Part 16, which records that staff read the policy. Kentucky's rule asks for signed HIPAA confidentiality statements, and Paratransit Services in Washington asks for a separate confidentiality agreement from each person.

## How to use this template

1. **Check your broker's forms first.** Paratransit Services requires the employee agreements to take the form it sets. If a broker gives you its own statement, have staff sign that one, and use this template for everyone and everything the broker's form does not cover.
2. **Fill in Part 1 once.** Name the person who takes privacy reports, a backup, and every system that holds rider information, from broker portals to the paper manifest.
3. **Train, then sign.** Read the statement aloud during the person's HIPAA training and answer questions before they sign. See [HIPAA training for NEMT staff](https://nemtguide.com/guides/hipaa-training-for-nemt-staff/) for what the session covers.
4. **Sign before the first shift.** Every person signs Part 2 before their first ride, first login, or first ride-along: drivers, attendants, dispatchers, schedulers, billers, office help, volunteers, trainees, and family members who answer the phone. The owner signs too.
5. **File it.** Put the original in the person's file (the [driver file checklist](https://nemtguide.com/templates/nemt-driver-file-checklist/) shows where), give them a copy, send a copy to any broker that asks, and add the name to the roster in Part 4.
6. **Sign again each year.** Have everyone sign a fresh statement with their yearly training, and whenever you change the wording.
7. **Close it out on the last day.** Complete Part 3 when the person leaves, alongside the [termination checklist](https://nemtguide.com/templates/nemt-employee-termination-checklist/).

## The template

### Part 1: Company details (filled in once)

| Field | Entry |
|---|---|
| Company name | |
| Address and phone | |
| Person who takes privacy reports (name, phone, email) | |
| Backup when that person is away | |
| Brokers, health plans, and facilities we drive for | |
| Systems that hold rider information (broker portals, dispatch app, email, phones, paper manifests) | |
| Version date of this statement | |

### Part 2: Confidentiality statement (one per person)

| Field | Entry |
|---|---|
| Printed full name | |
| Role (driver, attendant, dispatcher, biller, office, volunteer, trainee, other) | |
| Paid employee, contract driver, volunteer, or trainee | |
| First day with access to rider information | |

While I work for ______________________ (the company), I will see and hear private information about riders. Rider information means anything that identifies a rider together with their rides, health, or coverage, on paper, on a screen, or spoken aloud. It includes names, addresses, phone numbers, dates of birth, Medicaid or health plan ID numbers, trip numbers, pickup and drop-off places and times, the clinic or program a rider visits, wheelchair, stretcher, oxygen, or escort needs, notes about a condition, signatures, and photos.

I agree that:

1. **I use only what my job needs.** I look up, read, and share only the rider information I need for the rides and tasks I am given. I never look up a rider out of curiosity, including family, friends, neighbors, and people in the news.
2. **I talk about riders only for the ride.** I share trip details only with dispatch, the rider, and people the rider or dispatch has approved, such as a caregiver or the facility we are driving to. I do not discuss riders where other passengers or the public can hear.
3. **I keep papers and screens out of sight.** Manifests stay with me or locked in the vehicle or office, out of other riders' view. At the end of each shift I return them or put them in the shred bin.
4. **I protect phones and logins.** I keep a screen lock on any phone or tablet that shows rider information. I never photograph a manifest or a rider's papers. I send rider messages only through the apps and accounts the company approves. I use my own login and never share it.
5. **I never post about riders.** No photos, videos, names, or stories about riders on social media or in group chats, even without a name.
6. **I report problems the same day.** If I lose a phone or a manifest, send rider information to the wrong person, see someone looking at information they should not, or think a rider's information got out, I tell the person named in Part 1 that same day, even when the mistake was mine.
7. **I give everything back when I leave.** On my last day I return manifests, papers, keys, badges, and company devices, and I delete rider information from any personal phone I used for work. My logins will be turned off.
8. **This promise continues.** I keep rider information private after I leave the company.
9. **I understand the consequences.** Breaking this statement can lead to retraining, discipline, or losing my job, and the company may have to report it to the brokers and plans it works for. Knowingly obtaining or sharing health information without permission can also be a federal crime.

**What this statement does not stop.** Nothing in it stops me from:

- calling 911 in an emergency and telling responders what they need to help a rider
- reporting, in good faith, conduct I believe is unlawful or unsafe to a government agency that oversees it, or discussing it with my own lawyer
- filing a complaint with the U.S. Department of Health and Human Services, or taking part in its investigation
- giving police limited information, such as a name, address, and description, about a person who committed a crime against me
- talking with coworkers or anyone else about my pay, hours, or working conditions

The company will not retaliate against me for doing any of these.

| Signatures | Entry |
|---|---|
| Signature of the person signing | |
| Date signed | |
| Date of the HIPAA training this follows | |
| Company representative's printed name | |
| Company representative's signature and date | |

### Part 3: Last day (completed when the person leaves)

| Item | Done (date and initials) |
|---|---|
| Manifests, trip papers, and keys returned | |
| Badge and company phone or tablet returned | |
| Rider information deleted from any personal phone used for work | |
| Broker portal logins turned off | |
| Dispatch app, email, and shared drive accounts turned off | |
| Shared passwords and door or lockbox codes changed | |
| Broker told, if the person was on its driver list | |
| Person reminded that item 8 continues after today | |
| Departing person's signature (if available) | |
| Company representative's signature | |

### Part 4: Signed statements roster (for brokers that ask for a list)

| Name | Role | Date signed | Date signed again | Last day |
|---|---|---|---|---|
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |

## Who has to sign

HIPAA calls the people who work for you your workforce: employees, volunteers, trainees, and anyone else whose work for you is under your direct control, whether or not you pay them ([45 CFR 160.103](https://www.ecfr.gov/current/title-45/section-160.103)). So a volunteer driver, an unpaid trainee on a ride-along, and a relative who answers the dispatch line all sign. Kentucky's rule names volunteers outright.

A driver you dispatch and direct can count as workforce even when you pay them on a 1099. A driver who runs a separate company with its own van and staff is different. That company is outside your workforce: it signs a business associate agreement with you (see the [business associate agreement checklist](https://nemtguide.com/templates/business-associate-agreement-checklist/)), and its own people sign statements. Paratransit Services' agreement makes you responsible for the actions of your independent contract providers and their employees, and asks for a separate agreement from each of them.

## Where brokers and states ask for a signed statement

These are the requirements in force as of October 2026. Check your own agreements for others.

- **Kentucky.** Under 603 KAR 7:080, certified effective April 25, 2025, every subcontract between a regional broker and a transportation provider must include signed HIPAA confidentiality agreement statements for subcontractor and volunteer employees (section 12(6)(g)). Section 25(2) also has employees of brokers and subcontractors sign confidentiality statements on access to or disclosure of confidential records, and section 25(1) keeps records for 5 years. See the [Kentucky guide](https://nemtguide.com/states/kentucky/).
- **Washington, Paratransit Services.** The Health Care Authority's broker for nine western Washington counties lists a Corporate Confidentiality Agreement as mandatory on its provider document checklist. In it, you agree to tell your employees, agents, and independent contract providers, and their employees, about the confidentiality rules and to get a separate confidentiality agreement from each in the form Paratransit Services requires. A breach lets it end your contract or seek a court order. See [Paratransit Services](https://nemtguide.com/brokers/paratransit-services/) and the [Washington guide](https://nemtguide.com/states/washington/).
- **MTM Health.** Its standard provider agreement, in the January 1, 2023 version Pennsylvania posts, limits member information to employees who need it for their duties, and only the parts their jobs require. You agree to instruct those employees not to disclose it, and the duty survives the end of the agreement (section 21). A signed statement is one way to show you gave that instruction. See [MTM Health](https://nemtguide.com/brokers/mtm-health/).
- **Texas.** State law defines a covered entity broadly enough to include business associates and anyone who comes into possession of health information (Health and Safety Code 181.001). Each employee who completes privacy training signs a statement verifying it, kept 6 years from signing (181.101). That is a training statement, separate from this one, so have both signed on the same day. See the [Texas guide](https://nemtguide.com/states/texas/).

## What a confidentiality statement cannot forbid

A statement that bans every disclosure is broader than the law allows. The "does not stop" list in Part 2 keeps it inside these rules.

- **Reports of wrongdoing.** A covered entity's workforce member who believes in good faith that the company acted unlawfully or endangered riders, workers, or the public may disclose information to a health oversight agency or public health authority, or to a lawyer they hire to learn their options ([45 CFR 164.502(j)(1)](https://www.ecfr.gov/current/title-45/section-164.502)). HIPAA's sanction rule does not apply to those disclosures (164.530(e)(1)). Both rules are written for a covered entity's own staff. If your company is a business associate, the Part 2 list makes the same promise to your staff in your own words.
- **Complaints to HHS.** A covered entity or business associate may not threaten or retaliate against anyone for filing a HIPAA complaint, testifying, or taking part in an investigation ([45 CFR 160.316](https://www.ecfr.gov/current/title-45/section-160.316)).
- **Crimes against staff.** A workforce member who is the victim of a crime may tell police about the suspect, limited to items such as name and address, date and place of birth, type of injury, and a physical description (164.502(j)(2) and 164.512(f)(2)(i)). A driver assaulted by a passenger can report it.
- **Emergencies.** HIPAA allows disclosures to a health care provider for treatment (164.506(c)(2)), and the minimum necessary rule does not apply to them (164.502(b)(2)(i)), so a driver can tell paramedics what they need.
- **Pay and working conditions.** For employees covered by the National Labor Relations Act, the NLRB says policies that bar or chill talk about wages are unlawful. Under its Stericycle decision of August 2, 2023, a work rule with a reasonable tendency to chill employees from using their rights is presumed unlawful, unless the employer shows a legitimate and substantial business interest that a narrower rule could not serve. On August 26, 2026, the General Counsel told regional offices (GC 26-04) that she is asking the Board to overturn Stericycle, while regions keep applying current law. A statement limited to rider information, with the pay line in it, meets the rule either way.

Keep company secrets, prices, and customer lists out of this form. They raise different legal questions and belong in a separate agreement.

## The HIPAA rule behind each line

The Security Rule applies to covered entities and business associates alike for electronic rider information (45 CFR 164.302), so it reaches most companies running broker trips. Some parts of the Privacy Rule bind covered entities directly and reach business associates through their agreements; see [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/) to work out your status.

| Line in Part 2 | Rule, in 45 CFR | What it asks of you |
|---|---|---|
| Who signs | 160.103 | Workforce includes employees, volunteers, and trainees under your direct control, paid or not |
| Item 1 | 164.502(b), 164.514(d) | Limit information to the minimum needed, and decide which staff need which information |
| Items 2, 3, and 5 | 164.530(c) | Reasonable safeguards for information in any form (covered entities) |
| Item 4 | 164.312(a)(2)(i) | A unique name or number for each user (required) |
| Item 6 | 164.404(a)(2), 164.410(a)(2) | A breach counts as discovered when any employee, other than the one who caused it, knew or should have known |
| Item 7 | 164.308(a)(3)(ii)(C) | Procedures to end access when someone's work ends (addressable) |
| Item 9 | 164.308(a)(1)(ii)(C), 164.530(e) | Apply sanctions to staff who break your policies, and covered entities document them |
| What it does not stop | 164.502(j), 160.316 | Whistleblower and crime victim disclosures are allowed, and retaliation is barred |

Item 6 matters more than it looks. A breach counts as discovered on the first day anyone on your staff, other than the person who caused it, knew of it or should have. So a dispatcher who hears on Friday that a driver lost a phone, and waits until Monday to tell you, has already started your reporting clock. Your broker agreement may give you far less time than HIPAA's outer limit of 60 days after discovery (164.404(b) and 164.410(b)). The response steps are in [NEMT data breach](https://nemtguide.com/guides/nemt-data-breach/).

## How long to keep signed statements

HIPAA keeps the documentation it requires for 6 years from the date it was created or the date it was last in effect, whichever is later ([45 CFR 164.316(b)(2)](https://www.ecfr.gov/current/title-45/section-164.316) and 164.530(j)(2)). Put signed statements on the same clock. A statement is in effect for as long as the person works for you, so keep it at least 6 years after their last day, with Part 3 stapled to it.

Some contracts run longer. MTM Health's standard agreement asks you to keep full records of your work under it for 10 years (section 2.S), and Kentucky's rule asks for 5. Keep the longest period that applies, and see [NEMT record retention](https://nemtguide.com/guides/nemt-record-retention/) for the rest of your files.

## Frequently asked questions

### Does HIPAA require employees to sign a confidentiality agreement?

No HIPAA rule names a signed staff agreement. Its rules for staff call for training, safeguards, access limited to what each job needs, and sanctions for people who break your policies (45 CFR 164.308 and 164.530). A signed statement is a simple record that each person heard those rules. Some states and brokers require the signature outright: Kentucky's rule 603 KAR 7:080 (certified effective April 25, 2025) puts signed HIPAA confidentiality statements in every broker subcontract.

### Who has to sign a HIPAA confidentiality agreement?

Everyone in your HIPAA workforce: employees, volunteers, trainees, and anyone else whose work for you is under your direct control, whether or not you pay them (45 CFR 160.103). That covers a ride-along trainee and a spouse who takes calls. A driver who runs a separate company is outside your workforce: that company signs a business associate agreement with you, and its own staff sign statements.

### Can a confidentiality agreement stop drivers from talking about their pay?

No. The NLRB says rules that bar employees covered by federal labor law from discussing wages, or that chill those talks, are unlawful. Its Stericycle decision of August 2, 2023 is still the standard for work rules as of October 2026, though the agency's General Counsel told regions on August 26, 2026 (GC 26-04) that she is asking the Board to overturn it. Keep the statement about rider information, and keep the pay line in it.

### Can an employee who signed still report the company to the government?

Yes. HIPAA lets a covered entity's workforce member who believes in good faith that the company broke the law or put people at risk disclose information to a health oversight agency or to their own lawyer (45 CFR 164.502(j)). The sanction rule does not reach those disclosures (164.530(e)), and you may not retaliate against anyone for filing a complaint with HHS or taking part in an investigation (160.316).

### What happens if an employee breaks the agreement?

You apply your sanction policy, which the Security Rule requires (45 CFR 164.308(a)(1)(ii)(C)), and a covered entity documents the sanction (164.530(e)). The incident may also start a broker or HIPAA breach report. Separately, federal law makes it a crime to knowingly obtain or disclose health information held by a covered entity without authorization: up to $50,000 and 1 year in prison, and up to $250,000 and 10 years when it is done for gain or to cause harm (42 U.S.C. 1320d-6).

### How long do I keep signed confidentiality statements?

At least 6 years after the person leaves. HIPAA keeps the documentation it requires for 6 years from the date it was created or last in effect, whichever is later (45 CFR 164.316(b)(2) and 164.530(j)(2)). Put signed statements on the same clock: a statement stays in effect while the person works for you. Kentucky's rule keeps records 5 years, and MTM Health's standard agreement asks for records of your work under it for 10 years.

## Official resources

- [CMS: HIPAA Basics for Providers (free fact sheet, May 2025)](https://www.cms.gov/files/document/mln909001-hipaa-basics-providers-privacy-security-breach-notification-rules.pdf)
- [Kentucky: 603 KAR 7:080, the human service transportation rule](https://apps.legislature.ky.gov/law/kar/titles/603/007/080/)
- [Paratransit Services: provider forms, including its confidentiality agreement](https://www.wanemt.com/transportation-provider-resources)
- [NLRB: Your Right to Discuss Wages](https://www.nlrb.gov/about-nlrb/rights-we-protect/your-rights/your-rights-to-discuss-wages)
- [eCFR: 45 CFR part 164, the HIPAA Privacy, Security, and Breach Notification Rules](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164)
