# HIPAA Risk Assessment Template for NEMT: Phones, Manifests, Email, and Vans

Canonical URL: https://nemtguide.com/templates/hipaa-risk-assessment/ · Updated 2026-09-30

A HIPAA risk assessment template is a worksheet for the risk analysis the Security Rule requires of every covered entity and business associate, including a NEMT company that signs a broker's business associate agreement. You list every place rider information lives, from driver phones and paper manifests to email and broker portals, rate how likely and harmful each threat is, and write a dated plan to fix the worst.

- The Security Rule requires a risk analysis and a plan that lowers the risks it finds, for covered entities and business associates alike.
- Start with an inventory of every phone, computer, account, vendor, and paper file that holds rider information, including drivers' own phones.
- A list of safeguards you have is only a gap check. Rate each threat's likelihood and impact so you know what to fix first.
- HHS sets no fixed schedule, so pick a yearly review date and redo it after new software, a new broker, a breach, or a key staff change.
- Keep every version, with its plan, for 6 years. OCR's recent corrective action plans start by ordering an accurate and thorough risk analysis.

At a NEMT company, rider information does not stay in the office. It sits on the dispatch computer, rides along on every driver's phone, prints out on the day's manifests, and moves through email and broker portals. The HIPAA Security Rule asks you to find each of those places, decide what could go wrong at each one, and fix the biggest risks first. This worksheet walks through it in eight parts, in plain terms, and leaves you with the written record the rule requires.

## How to use this template

1. **Name who is responsible.** Write your security official's name in Part 1. The Security Rule requires one ([45 CFR 164.308(a)(2)](https://www.ecfr.gov/current/title-45/section-164.308)), and in a small company it is often the owner. Do the work with your dispatcher and at least one driver, because they know where rider information really goes.
2. **Set the scope before you start.** Include every location and device: the office, any home office, the garage, every van, and every phone that opens a trip app, a portal, or work email. That includes drivers' personal phones. HHS says the scope covers all electronic rider information you create, receive, keep, or send, in every kind of device or media.
3. **Walk the company to fill in Part 2.** Sit at the dispatch desk, open each van, look at the apps on each work phone, and list every account and vendor. HHS suggests interviews and reviewing documents to find where the information is, and says to write down what you find.
4. **List what could go wrong in Part 3,** one line for each threat to a Part 2 item. The NEMT examples above the table are a starting point.
5. **Mark the safeguards you have now in Part 4:** yes, no, or partly. Add a note when the answer is "partly."
6. **Rate each threat** low, medium, or high for likelihood and for impact, and read the risk level from the grid in Part 5.
7. **Write the fixes in Part 6.** Every medium and high risk gets a fix, a person, and a due date. The rule requires this risk management step, not only the analysis.
8. **Explain any addressable safeguard you skip in Part 7.** Write why it is not reasonable for your company and what you do instead.
9. **Sign Part 8 and file it with your HIPAA records.** Put the next review date on your [compliance calendar](https://nemtguide.com/templates/nemt-compliance-calendar/), and redo the worksheet after any change listed in Part 8.

Before you start, read [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/) if you are not sure whether you are a covered entity, a business associate, or both.

## The template

### Part 1: About this assessment

| Field | Write the entry here in pen |
|---|---|
| Company legal name | |
| Date started and date finished | |
| Security official (name and title) | |
| People who helped (dispatcher, drivers, billing, IT help) | |
| Your HIPAA role: covered entity, business associate, or both | |
| Brokers and health plans whose business associate agreements you signed | |
| Breach and incident reporting deadline in each agreement | |
| Locations covered (office, home office, garage, vans) | |
| Number of vans, phones, tablets, and computers covered | |
| Date of the last assessment | |
| Date of the next review | |

### Part 2: Where rider information lives

One line for each device, account, vendor, or paper file that holds rider names, addresses, trip times, member numbers, or health details. Mark "company" or "personal" for who owns each device, and note whether a business associate agreement covers each vendor.

| No. | Item | Rider information on it | Who uses it | Company or personal | Where it is kept | Vendor and agreement on file |
|---|---|---|---|---|---|---|
| 1 | Driver phones | | | | | |
| 2 | Tablets or mounted devices in vans | | | | | |
| 3 | Dispatch computer | | | | | |
| 4 | Owner's laptop or home computer | | | | | |
| 5 | Business email accounts | | | | | |
| 6 | Text messages and chat apps | | | | | |
| 7 | Broker and health plan portals | | | | | |
| 8 | Dispatch or scheduling software | | | | | |
| 9 | Billing software, clearinghouse, or billing service | | | | | |
| 10 | Cloud storage and backups | | | | | |
| 11 | Office phone, voicemail, and fax | | | | | |
| 12 | Printer, scanner, or copier that stores copies | | | | | |
| 13 | Paper manifests and trip logs | | | | | |
| 14 | Signature sheets and forms from facilities | | | | | |
| 15 | File cabinet and stored records | | | | | |
| 16 | Dash cameras and saved video | | | | | |
| 17 | GPS and vehicle tracking records | | | | | |
| 18 | USB drives and external hard drives | | | | | |
| 19 | Old phones and computers not yet wiped | | | | | |
| 20 | | | | | | |
| 21 | | | | | | |
| 22 | | | | | | |

### Part 3: Threats and risk ratings

HHS groups threats as natural (floods, tornadoes), human (on purpose or by mistake), and environmental (power failures, water leaks). Start with these NEMT examples:

- A phone is lost, stolen, or left open on a seat.
- A phone or laptop has no passcode, no auto-lock, or no encryption.
- A manifest is left on a dashboard, a clinic counter, or an unlocked van.
- A driver photographs a manifest or sends rider details in a personal chat.
- Two people share one login to a broker portal or dispatch account.
- A driver or dispatcher who left still has a working login.
- A fake email installs ransomware or steals a password.
- A text, email, or fax goes to the wrong person.
- Dispatch runs on one computer with no backup.
- A fire, flood, storm, or power or internet outage stops dispatch.
- A rider's details are discussed where other riders or family can hear.
- An old phone or computer is sold or recycled without being wiped.
- A vendor that keeps your trip data has its own breach.

| Part 2 No. | What could go wrong | Weakness that allows it | Likelihood (L, M, H) | Impact (L, M, H) | Risk level (Part 5) |
|---|---|---|---|---|---|
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |

### Part 4: Safeguards in place now

Rule numbers are sections of 45 CFR. "Required" and "addressable" follow the rule's own labels. A section with no label is a standard, which you must meet in a way that fits your company. Mark each line Y (yes), N (no), or P (partly).

**People and paperwork**

| Safeguard | Rule | Y, N, or P | Notes |
|---|---|---|---|
| A security official is named in writing | 164.308(a)(2) | | |
| Written security policies, reviewed periodically | 164.316(a) and (b)(2)(iii), required | | |
| A written sanction policy for staff who break the rules | 164.308(a)(1)(ii)(C), required | | |
| Someone regularly reviews login and activity records for portals and software | 164.308(a)(1)(ii)(D), required | | |
| Each person can reach only the rider information the job needs | 164.308(a)(4) | | |
| Logins are removed the day someone leaves | 164.308(a)(3)(ii)(C), addressable | | |
| Everyone, managers included, gets security training | 164.308(a)(5) | | |
| Staff know how to report a lost phone or odd email the same day | 164.308(a)(6)(ii), required | | |
| Exact backup copies of trip and billing records | 164.308(a)(7)(ii)(A), required | | |
| A written plan to restore lost data and keep rider information protected while systems are down | 164.308(a)(7)(ii)(B) and (C), required | | |
| Backups and the plan are tested | 164.308(a)(7)(ii)(D), addressable | | |
| A business associate agreement with each vendor that handles rider information | 164.308(b) | | |

**Office, vans, and devices**

| Safeguard | Rule | Y, N, or P | Notes |
|---|---|---|---|
| The office is locked and visitors are supervised | 164.310(a) | | |
| Screens face away from visitors and riders | 164.310(b) and (c) | | |
| A list of every phone, tablet, laptop, and drive, and who has it | 164.310(d)(2)(iii), addressable | | |
| Devices are wiped before reuse, sale, or recycling | 164.310(d)(2)(i) and (ii), required | | |

**Logins and data**

| Safeguard | Rule | Y, N, or P | Notes |
|---|---|---|---|
| One login per person on every account, never shared | 164.312(a)(2)(i), required | | |
| A way to reach trip records in an emergency | 164.312(a)(2)(ii), required | | |
| Phones and computers lock after a short idle time | 164.312(a)(2)(iii), addressable | | |
| Phones, laptops, and backups are encrypted | 164.312(a)(2)(iv), addressable | | |
| Software keeps activity logs | 164.312(b) | | |
| Strong passwords, plus multi-factor login wherever it is offered | 164.312(d) | | |
| Rider information is sent through secure portals or encrypted email | 164.312(e) | | |

**Paper and conversations**

| Safeguard | Rule | Y, N, or P | Notes |
|---|---|---|---|
| Manifests travel in a closed folder, out of sight | 164.530(c) and your agreements | | |
| Trip records are stored in a locked cabinet | 164.530(c) and your agreements | | |
| Paper is shredded once it is no longer needed | 164.530(c) and your agreements | | |
| Drivers and dispatchers keep rider talk to the minimum, away from other riders | 164.530(c) and your agreements | | |

### Part 5: Risk level grid

Rate likelihood and impact with the same scale every time. This is one simple scale. HHS lets you choose your own method.

- **Likelihood.** Low: not expected in the next year. Medium: could happen in the next year. High: has happened here before, or is expected.
- **Impact.** Low: little information about a few riders, fixed within a day. Medium: one rider's health details exposed, or dispatch down for part of a day. High: many riders' information exposed, notices to the broker or riders needed, or dispatch down for a day or more.

| Likelihood | Impact low | Impact medium | Impact high |
|---|---|---|---|
| Low | Low | Low | Medium |
| Medium | Low | Medium | High |
| High | Medium | High | High |

### Part 6: Risk management plan

| Risk (Part 3 line) | Risk level | Fix | Who | Cost | Due date | Done (date, initials) |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |

### Part 7: Addressable safeguards you did not adopt

| Safeguard | Why it is not reasonable and appropriate here | What you do instead | Date decided |
|---|---|---|---|
| | | | |
| | | | |
| | | | |

### Part 8: Review and sign-off

Update this assessment when any of these happen, and write the date here.

| Change | Date it happened | Assessment updated (date, initials) |
|---|---|---|
| New software, app, or vendor that handles rider information | | |
| New broker or health plan | | |
| New office, home office, or garage | | |
| New kind of device, such as tablets in the vans | | |
| Security incident or breach | | |
| New owner, manager, or dispatcher | | |
| Sale or merger of the company | | |
| New HIPAA rule or state law | | |

Every item in Part 2 was reviewed. Each threat in Part 3 has a risk level, and each medium or high risk has a fix in Part 6.

| Completed by (signature and date) | Security official (signature and date) | Owner (signature and date) |
|---|---|---|
| | | |

## What HIPAA requires of a risk analysis

The Security Rule has two required steps at its center. First, a risk analysis: "an accurate and thorough assessment of the potential risks and vulnerabilities" to the confidentiality, integrity, and availability of the electronic health information you hold. Second, risk management: security measures that bring those risks down to a reasonable and appropriate level ([45 CFR 164.308(a)(1)](https://www.ecfr.gov/current/title-45/section-164.308)). Parts 2 to 5 of this worksheet are the analysis. Part 6 is the management.

The rule applies to covered entities and business associates alike ([45 CFR 164.302](https://www.ecfr.gov/current/title-45/section-164.302)). Broker agreements make the point directly. MTM Health's standard agreement, in the January 1, 2023 version Pennsylvania posts, requires you to sign its business associate agreement. WellTrans's subcontractor business associate agreement, revised October 16, 2025, requires you to comply with sections 164.308, 164.310, 164.312, and 164.316, and to complete a privacy and security survey, audit, or attestation if WellTrans asks. A finished worksheet is the answer to that request. See the [business associate agreement](https://nemtguide.com/glossary/business-associate-agreement/) entry for what those contracts contain.

The rule scales to your size. You choose safeguards based on your size and capabilities, your technology, the cost, and how likely and serious each risk is ([45 CFR 164.306(b)](https://www.ecfr.gov/current/title-45/section-164.306)). "Addressable" does not mean optional. For each addressable item, you either put it in place, or you write down why it is not reasonable and use an equal alternative where one is reasonable. Part 7 is where that decision goes.

HHS's Guidance on Risk Analysis, last reviewed August 12, 2026, sets no required method. It lists the elements any method must cover, and each has a place in the worksheet:

| What HHS says a risk analysis includes | Where it is in this worksheet |
|---|---|
| Scope: all electronic rider information, on every kind of device and media | Parts 1 and 2 |
| Data collection: where information is stored, received, kept, or sent, written down | Part 2 |
| Threats and vulnerabilities you can reasonably expect, written down | Part 3 |
| The security measures you use now, and whether they are set up properly | Part 4 |
| The likelihood of each threat | Parts 3 and 5 |
| The impact if it happens | Parts 3 and 5 |
| A risk level for each threat, with corrective actions | Parts 5 and 6 |
| Written documentation, in any format | Part 8 |
| Periodic review and updates | Part 8 |

A checklist of safeguards alone falls short. HHS's proposed rule of January 6, 2025, citing an April 2018 OCR newsletter, describes a gap analysis as a partial, high-level view of which safeguards are in place or missing, and a risk analysis as a full identification of the risks to all of the information. Part 4 is the gap check. Parts 2, 3, and 5 turn it into a risk analysis.

Keep the finished worksheet, the plan, and the Part 7 decisions for 6 years from the date each was created or last in effect, whichever is later ([45 CFR 164.316(b)(2)(i)](https://www.ecfr.gov/current/title-45/section-164.316)). [NEMT record retention](https://nemtguide.com/guides/nemt-record-retention/) puts that next to your trip record rules.

## Paper, phones, and people in the van

The Security Rule covers electronic information only. A NEMT company still carries most of its risk on paper and in conversation, so the worksheet includes both.

- **Paper.** Covered entities must have safeguards that protect health information in any form, and limit what others overhear or see by accident ([45 CFR 164.530(c)](https://www.ecfr.gov/current/title-45/section-164.530)). Every business associate agreement must require appropriate safeguards against uses the contract does not allow ([45 CFR 164.504(e)](https://www.ecfr.gov/current/title-45/section-164.504)). The breach rules cover protected health information in any form, so a lost clipboard can need a report just like a lost laptop.
- **Phones.** NIST's mobile device guide (SP 800-124 Rev. 2, May 2023) lists the settings that matter: a passcode, auto-lock after a short idle time (it gives 45 seconds and 5 minutes as examples), remote lock, and a wipe after too many wrong tries. It calls remote wipe "a fundamentally unreliable security control" on its own, because a thief can turn the phone off first. Encryption does more. Information encrypted to HHS's standard is not "unsecured" under [45 CFR 164.402](https://www.ecfr.gov/current/title-45/section-164.402), so losing an encrypted phone may not need breach notices. Your broker agreement may still require a report: WellTrans wants any security incident reported within one business day.
- **People.** HIPAA's workforce includes employees, volunteers, trainees, and anyone whose work you directly control, paid or not ([45 CFR 160.103](https://www.ecfr.gov/current/title-45/section-160.103)). Contract drivers you dispatch and direct can count. Put their phones in Part 2 and their training in Part 4.

The [NEMT HIPAA policy template](https://nemtguide.com/templates/nemt-hipaa-policy/) turns the fixes in Part 6 into written rules for drivers and dispatchers.

## How often to update the assessment

The rule sets no calendar. You must review and update your safeguards as needed ([45 CFR 164.306(e)](https://www.ecfr.gov/current/title-45/section-164.306)) and review your documentation periodically, updating it after changes that affect security (164.316(b)(2)(iii)). HHS's guidance says risk analysis should be ongoing. It notes that some organizations redo it yearly and others as needed, for example every three years, depending on their circumstances. It names the changes that call for a fresh look: a security incident, a change in ownership, turnover in key staff or management, and new technology.

A stricter rule is proposed. The Security Rule update HHS proposed on January 6, 2025 (90 FR 898) would require a written risk analysis reviewed at least every 12 months and after changes, plus a written inventory of your technology and a map of how health information moves through it, each reviewed at least every 12 months. HHS's latest regulatory agenda lists a final rule target of July 2027. As of September 30, 2026, the proposal is not final and the current rule applies.

A yearly review date fits today's rule and the proposal's 12-month cycle. Pick a month when trips are lighter and put it on the calendar with your other renewals.

## Using the free HHS tool with this worksheet

HHS's health IT office, working with the Office for Civil Rights, publishes a free Security Risk Assessment Tool aimed at small and medium providers. As of its page update on September 18, 2026:

| What to know | Details |
|---|---|
| Version | 3.7 |
| Formats | A Windows program, or a spreadsheet version for computers that cannot run it |
| Privacy | Everything you enter is stored on your own computer. HHS does not collect, view, or store it. |
| How it works | Seven sections of multiple-choice questions. Each ends with a list of weaknesses, and you rate each related threat for likelihood and impact. |
| Reports | A risk report sorted into low, moderate, high, and critical, and a remediation report with an owner, a due date, and a completion date for each risk |
| New in 3.7 | A question on whether the assessment covers every location, a question on remote access, and a list of review triggers such as mergers, new technology, and security incidents |
| Limits | HHS says using the tool is not required and does not guarantee compliance, and that its survey may not identify every risk |

The tool is written for medical practices. Walk your vans, drivers' phones, and paper through Part 2 of this worksheet first, then enter them in the tool's asset list. Its reports can stand in for Parts 3 to 6.

## What OCR finds in HIPAA security investigations

The HHS Office for Civil Rights runs a Risk Analysis Initiative. Its settlement announced June 18, 2026 was the 14th enforcement action under it. The four cases below show what OCR looks for. Two involve ambulance services, and the other two show risks every NEMT office shares: a former staff member's login and ransomware.

| Case | Announced | What happened | Result |
|---|---|---|---|
| West Georgia Ambulance, an emergency and non-emergency ambulance company | December 30, 2019 | An unencrypted laptop with 500 people's information was lost. OCR found no risk analysis, no security training program, and no Security Rule policies. | $65,000 and a corrective action plan with two years of monitoring |
| Comstar, LLC, a billing company for nonprofit and municipal ambulance services and a business associate of more than 70 covered entities | May 30, 2025 | Ransomware reached the health information of 585,621 people. OCR found no accurate and thorough risk analysis. | $75,000 and a two-year corrective action plan |
| BayCare Health System, a Florida health care provider | May 28, 2025 | The login of a former staff member at a physician's practice with access to BayCare's records was used to open a patient's record, and a stranger then contacted the patient with photos and video of it. OCR cited access controls, risk reduction, and activity review. | $800,000 and a two-year corrective action plan |
| An employer-sponsored group health plan | June 18, 2026 | Ransomware reached the information of 10,023 people. OCR found no accurate and thorough risk analysis before the breach. | $450,000 and a two-year corrective action plan |

The 2025 and 2026 corrective action plans each begin with the same step: a new, thorough risk analysis. In the health plan case, OCR's finding was about the analysis in place before the breach, which is why a dated worksheet matters. For the penalty tiers, see [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/). If something has already gone wrong, follow the steps in [NEMT data breach](https://nemtguide.com/guides/nemt-data-breach/).

## Frequently asked questions

### Does a small NEMT company need a HIPAA risk assessment?

Yes, if HIPAA applies to it. The risk analysis is a required part of the Security Rule for every covered entity and business associate that holds electronic rider information (45 CFR 164.308(a)(1)). A company that signs a broker's business associate agreement usually counts. WellTrans's subcontractor agreement, revised October 16, 2025, requires you to comply with section 164.308, where the risk analysis rule sits.

### How often should I update a HIPAA risk assessment?

The Security Rule sets no fixed schedule. HHS guidance, last reviewed August 12, 2026, calls risk analysis an ongoing process and says some organizations redo it every year and others on longer cycles, such as every three years. It also says to review it after a security incident, a change in ownership, turnover in key staff, or new technology. A yearly date plus those triggers covers most small companies.

### Is the free HHS Security Risk Assessment Tool enough?

It is a solid start, not a guarantee. HHS says using the tool is neither required nor a guarantee of compliance, and version 3.7 (page updated September 18, 2026) reminds users that its questions may not find every risk. Use the tool or this worksheet, add anything specific to your vans, drivers' phones, and paper, and keep the reports with your fix-it plan.

### Does a HIPAA risk assessment have to cover paper manifests?

The Security Rule's risk analysis covers electronic information only. Paper still needs protecting. Covered entities must safeguard health information in any form (45 CFR 164.530(c)), every business associate agreement must require appropriate safeguards (45 CFR 164.504(e)), and a lost manifest can be a reportable breach. This worksheet puts paper on the same list so nothing is missed.

### What is the difference between a HIPAA risk analysis and a HIPAA checklist?

A checklist shows which safeguards you have. HHS calls that a gap analysis, a partial view of your company. A risk analysis goes further. It finds every place rider information lives, names what could go wrong at each one, and rates the likelihood and impact of each threat. In this worksheet, Part 4 is the checklist, and Parts 2, 3, and 5 make it a risk analysis.

### Is this the same as the risk assessment after a data breach?

No. After a specific incident, such as a lost phone or a misdirected email, you run a separate four-factor assessment to decide whether it must be reported (45 CFR 164.402). The Security Rule risk analysis looks at your whole company before anything goes wrong. A good risk analysis makes those incident assessments rarer.

## Official resources

- [HealthIT.gov: Download the free Security Risk Assessment Tool and workbook](https://healthit.gov/privacy-security/security-risk-assessment-tool/)
- [HHS OCR: Guidance on Risk Analysis](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html)
- [NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule, a cybersecurity resource guide](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-66r2.pdf)
- [eCFR: HIPAA Security Rule, 45 CFR Part 164 Subpart C](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C)
- [HHS OCR: Breach portal (report a breach, or see reported breaches)](https://ocrportal.hhs.gov/ocr/breach/)
