Compliance

HIPAA Risk Assessment Template for NEMT: Phones, Manifests, Email, and Vans

A HIPAA risk assessment template is a worksheet for the risk analysis the Security Rule requires of every covered entity and business associate, including a NEMT company that signs a broker's business associate agreement. You list every place rider information lives, from driver phones and paper manifests to email and broker portals, rate how likely and harmful each threat is, and write a dated plan to fix the worst.

  • The Security Rule requires a risk analysis and a plan that lowers the risks it finds, for covered entities and business associates alike.
  • Start with an inventory of every phone, computer, account, vendor, and paper file that holds rider information, including drivers' own phones.
  • A list of safeguards you have is only a gap check. Rate each threat's likelihood and impact so you know what to fix first.
  • HHS sets no fixed schedule, so pick a yearly review date and redo it after new software, a new broker, a breach, or a key staff change.
  • Keep every version, with its plan, for 6 years. OCR's recent corrective action plans start by ordering an accurate and thorough risk analysis.

Only the title and the template print.

At a NEMT company, rider information does not stay in the office. It sits on the dispatch computer, rides along on every driver’s phone, prints out on the day’s manifests, and moves through email and broker portals. The HIPAA Security Rule asks you to find each of those places, decide what could go wrong at each one, and fix the biggest risks first. This worksheet walks through it in eight parts, in plain terms, and leaves you with the written record the rule requires.

How to use this template

  1. Name who is responsible. Write your security official’s name in Part 1. The Security Rule requires one (45 CFR 164.308(a)(2)), and in a small company it is often the owner. Do the work with your dispatcher and at least one driver, because they know where rider information really goes.
  2. Set the scope before you start. Include every location and device: the office, any home office, the garage, every van, and every phone that opens a trip app, a portal, or work email. That includes drivers’ personal phones. HHS says the scope covers all electronic rider information you create, receive, keep, or send, in every kind of device or media.
  3. Walk the company to fill in Part 2. Sit at the dispatch desk, open each van, look at the apps on each work phone, and list every account and vendor. HHS suggests interviews and reviewing documents to find where the information is, and says to write down what you find.
  4. List what could go wrong in Part 3, one line for each threat to a Part 2 item. The NEMT examples above the table are a starting point.
  5. Mark the safeguards you have now in Part 4: yes, no, or partly. Add a note when the answer is “partly.”
  6. Rate each threat low, medium, or high for likelihood and for impact, and read the risk level from the grid in Part 5.
  7. Write the fixes in Part 6. Every medium and high risk gets a fix, a person, and a due date. The rule requires this risk management step, not only the analysis.
  8. Explain any addressable safeguard you skip in Part 7. Write why it is not reasonable for your company and what you do instead.
  9. Sign Part 8 and file it with your HIPAA records. Put the next review date on your compliance calendar, and redo the worksheet after any change listed in Part 8.

Before you start, read HIPAA for NEMT providers if you are not sure whether you are a covered entity, a business associate, or both.

The template

Part 1: About this assessment

Field Write the entry here in pen
Company legal name
Date started and date finished
Security official (name and title)
People who helped (dispatcher, drivers, billing, IT help)
Your HIPAA role: covered entity, business associate, or both
Brokers and health plans whose business associate agreements you signed
Breach and incident reporting deadline in each agreement
Locations covered (office, home office, garage, vans)
Number of vans, phones, tablets, and computers covered
Date of the last assessment
Date of the next review

Part 2: Where rider information lives

One line for each device, account, vendor, or paper file that holds rider names, addresses, trip times, member numbers, or health details. Mark “company” or “personal” for who owns each device, and note whether a business associate agreement covers each vendor.

No. Item Rider information on it Who uses it Company or personal Where it is kept Vendor and agreement on file
1 Driver phones
2 Tablets or mounted devices in vans
3 Dispatch computer
4 Owner’s laptop or home computer
5 Business email accounts
6 Text messages and chat apps
7 Broker and health plan portals
8 Dispatch or scheduling software
9 Billing software, clearinghouse, or billing service
10 Cloud storage and backups
11 Office phone, voicemail, and fax
12 Printer, scanner, or copier that stores copies
13 Paper manifests and trip logs
14 Signature sheets and forms from facilities
15 File cabinet and stored records
16 Dash cameras and saved video
17 GPS and vehicle tracking records
18 USB drives and external hard drives
19 Old phones and computers not yet wiped
20
21
22

Part 3: Threats and risk ratings

HHS groups threats as natural (floods, tornadoes), human (on purpose or by mistake), and environmental (power failures, water leaks). Start with these NEMT examples:

  • A phone is lost, stolen, or left open on a seat.
  • A phone or laptop has no passcode, no auto-lock, or no encryption.
  • A manifest is left on a dashboard, a clinic counter, or an unlocked van.
  • A driver photographs a manifest or sends rider details in a personal chat.
  • Two people share one login to a broker portal or dispatch account.
  • A driver or dispatcher who left still has a working login.
  • A fake email installs ransomware or steals a password.
  • A text, email, or fax goes to the wrong person.
  • Dispatch runs on one computer with no backup.
  • A fire, flood, storm, or power or internet outage stops dispatch.
  • A rider’s details are discussed where other riders or family can hear.
  • An old phone or computer is sold or recycled without being wiped.
  • A vendor that keeps your trip data has its own breach.
Part 2 No. What could go wrong Weakness that allows it Likelihood (L, M, H) Impact (L, M, H) Risk level (Part 5)

Part 4: Safeguards in place now

Rule numbers are sections of 45 CFR. “Required” and “addressable” follow the rule’s own labels. A section with no label is a standard, which you must meet in a way that fits your company. Mark each line Y (yes), N (no), or P (partly).

People and paperwork

Safeguard Rule Y, N, or P Notes
A security official is named in writing 164.308(a)(2)
Written security policies, reviewed periodically 164.316(a) and (b)(2)(iii), required
A written sanction policy for staff who break the rules 164.308(a)(1)(ii)(C), required
Someone regularly reviews login and activity records for portals and software 164.308(a)(1)(ii)(D), required
Each person can reach only the rider information the job needs 164.308(a)(4)
Logins are removed the day someone leaves 164.308(a)(3)(ii)(C), addressable
Everyone, managers included, gets security training 164.308(a)(5)
Staff know how to report a lost phone or odd email the same day 164.308(a)(6)(ii), required
Exact backup copies of trip and billing records 164.308(a)(7)(ii)(A), required
A written plan to restore lost data and keep rider information protected while systems are down 164.308(a)(7)(ii)(B) and (C), required
Backups and the plan are tested 164.308(a)(7)(ii)(D), addressable
A business associate agreement with each vendor that handles rider information 164.308(b)

Office, vans, and devices

Safeguard Rule Y, N, or P Notes
The office is locked and visitors are supervised 164.310(a)
Screens face away from visitors and riders 164.310(b) and (c)
A list of every phone, tablet, laptop, and drive, and who has it 164.310(d)(2)(iii), addressable
Devices are wiped before reuse, sale, or recycling 164.310(d)(2)(i) and (ii), required

Logins and data

Safeguard Rule Y, N, or P Notes
One login per person on every account, never shared 164.312(a)(2)(i), required
A way to reach trip records in an emergency 164.312(a)(2)(ii), required
Phones and computers lock after a short idle time 164.312(a)(2)(iii), addressable
Phones, laptops, and backups are encrypted 164.312(a)(2)(iv), addressable
Software keeps activity logs 164.312(b)
Strong passwords, plus multi-factor login wherever it is offered 164.312(d)
Rider information is sent through secure portals or encrypted email 164.312(e)

Paper and conversations

Safeguard Rule Y, N, or P Notes
Manifests travel in a closed folder, out of sight 164.530(c) and your agreements
Trip records are stored in a locked cabinet 164.530(c) and your agreements
Paper is shredded once it is no longer needed 164.530(c) and your agreements
Drivers and dispatchers keep rider talk to the minimum, away from other riders 164.530(c) and your agreements

Part 5: Risk level grid

Rate likelihood and impact with the same scale every time. This is one simple scale. HHS lets you choose your own method.

  • Likelihood. Low: not expected in the next year. Medium: could happen in the next year. High: has happened here before, or is expected.
  • Impact. Low: little information about a few riders, fixed within a day. Medium: one rider’s health details exposed, or dispatch down for part of a day. High: many riders’ information exposed, notices to the broker or riders needed, or dispatch down for a day or more.
Likelihood Impact low Impact medium Impact high
Low Low Low Medium
Medium Low Medium High
High Medium High High

Part 6: Risk management plan

Risk (Part 3 line) Risk level Fix Who Cost Due date Done (date, initials)

Part 7: Addressable safeguards you did not adopt

Safeguard Why it is not reasonable and appropriate here What you do instead Date decided

Part 8: Review and sign-off

Update this assessment when any of these happen, and write the date here.

Change Date it happened Assessment updated (date, initials)
New software, app, or vendor that handles rider information
New broker or health plan
New office, home office, or garage
New kind of device, such as tablets in the vans
Security incident or breach
New owner, manager, or dispatcher
Sale or merger of the company
New HIPAA rule or state law

Every item in Part 2 was reviewed. Each threat in Part 3 has a risk level, and each medium or high risk has a fix in Part 6.

Completed by (signature and date) Security official (signature and date) Owner (signature and date)

What HIPAA requires of a risk analysis

The Security Rule has two required steps at its center. First, a risk analysis: “an accurate and thorough assessment of the potential risks and vulnerabilities” to the confidentiality, integrity, and availability of the electronic health information you hold. Second, risk management: security measures that bring those risks down to a reasonable and appropriate level (45 CFR 164.308(a)(1)). Parts 2 to 5 of this worksheet are the analysis. Part 6 is the management.

The rule applies to covered entities and business associates alike (45 CFR 164.302). Broker agreements make the point directly. MTM Health’s standard agreement, in the January 1, 2023 version Pennsylvania posts, requires you to sign its business associate agreement. WellTrans’s subcontractor business associate agreement, revised October 16, 2025, requires you to comply with sections 164.308, 164.310, 164.312, and 164.316, and to complete a privacy and security survey, audit, or attestation if WellTrans asks. A finished worksheet is the answer to that request. See the business associate agreement entry for what those contracts contain.

The rule scales to your size. You choose safeguards based on your size and capabilities, your technology, the cost, and how likely and serious each risk is (45 CFR 164.306(b)). “Addressable” does not mean optional. For each addressable item, you either put it in place, or you write down why it is not reasonable and use an equal alternative where one is reasonable. Part 7 is where that decision goes.

HHS’s Guidance on Risk Analysis, last reviewed August 12, 2026, sets no required method. It lists the elements any method must cover, and each has a place in the worksheet:

What HHS says a risk analysis includes Where it is in this worksheet
Scope: all electronic rider information, on every kind of device and media Parts 1 and 2
Data collection: where information is stored, received, kept, or sent, written down Part 2
Threats and vulnerabilities you can reasonably expect, written down Part 3
The security measures you use now, and whether they are set up properly Part 4
The likelihood of each threat Parts 3 and 5
The impact if it happens Parts 3 and 5
A risk level for each threat, with corrective actions Parts 5 and 6
Written documentation, in any format Part 8
Periodic review and updates Part 8

A checklist of safeguards alone falls short. HHS’s proposed rule of January 6, 2025, citing an April 2018 OCR newsletter, describes a gap analysis as a partial, high-level view of which safeguards are in place or missing, and a risk analysis as a full identification of the risks to all of the information. Part 4 is the gap check. Parts 2, 3, and 5 turn it into a risk analysis.

Keep the finished worksheet, the plan, and the Part 7 decisions for 6 years from the date each was created or last in effect, whichever is later (45 CFR 164.316(b)(2)(i)). NEMT record retention puts that next to your trip record rules.

Paper, phones, and people in the van

The Security Rule covers electronic information only. A NEMT company still carries most of its risk on paper and in conversation, so the worksheet includes both.

  • Paper. Covered entities must have safeguards that protect health information in any form, and limit what others overhear or see by accident (45 CFR 164.530(c)). Every business associate agreement must require appropriate safeguards against uses the contract does not allow (45 CFR 164.504(e)). The breach rules cover protected health information in any form, so a lost clipboard can need a report just like a lost laptop.
  • Phones. NIST’s mobile device guide (SP 800-124 Rev. 2, May 2023) lists the settings that matter: a passcode, auto-lock after a short idle time (it gives 45 seconds and 5 minutes as examples), remote lock, and a wipe after too many wrong tries. It calls remote wipe “a fundamentally unreliable security control” on its own, because a thief can turn the phone off first. Encryption does more. Information encrypted to HHS’s standard is not “unsecured” under 45 CFR 164.402, so losing an encrypted phone may not need breach notices. Your broker agreement may still require a report: WellTrans wants any security incident reported within one business day.
  • People. HIPAA’s workforce includes employees, volunteers, trainees, and anyone whose work you directly control, paid or not (45 CFR 160.103). Contract drivers you dispatch and direct can count. Put their phones in Part 2 and their training in Part 4.

The NEMT HIPAA policy template turns the fixes in Part 6 into written rules for drivers and dispatchers.

How often to update the assessment

The rule sets no calendar. You must review and update your safeguards as needed (45 CFR 164.306(e)) and review your documentation periodically, updating it after changes that affect security (164.316(b)(2)(iii)). HHS’s guidance says risk analysis should be ongoing. It notes that some organizations redo it yearly and others as needed, for example every three years, depending on their circumstances. It names the changes that call for a fresh look: a security incident, a change in ownership, turnover in key staff or management, and new technology.

A stricter rule is proposed. The Security Rule update HHS proposed on January 6, 2025 (90 FR 898) would require a written risk analysis reviewed at least every 12 months and after changes, plus a written inventory of your technology and a map of how health information moves through it, each reviewed at least every 12 months. HHS’s latest regulatory agenda lists a final rule target of July 2027. As of September 30, 2026, the proposal is not final and the current rule applies.

A yearly review date fits today’s rule and the proposal’s 12-month cycle. Pick a month when trips are lighter and put it on the calendar with your other renewals.

Using the free HHS tool with this worksheet

HHS’s health IT office, working with the Office for Civil Rights, publishes a free Security Risk Assessment Tool aimed at small and medium providers. As of its page update on September 18, 2026:

What to know Details
Version 3.7
Formats A Windows program, or a spreadsheet version for computers that cannot run it
Privacy Everything you enter is stored on your own computer. HHS does not collect, view, or store it.
How it works Seven sections of multiple-choice questions. Each ends with a list of weaknesses, and you rate each related threat for likelihood and impact.
Reports A risk report sorted into low, moderate, high, and critical, and a remediation report with an owner, a due date, and a completion date for each risk
New in 3.7 A question on whether the assessment covers every location, a question on remote access, and a list of review triggers such as mergers, new technology, and security incidents
Limits HHS says using the tool is not required and does not guarantee compliance, and that its survey may not identify every risk

The tool is written for medical practices. Walk your vans, drivers’ phones, and paper through Part 2 of this worksheet first, then enter them in the tool’s asset list. Its reports can stand in for Parts 3 to 6.

What OCR finds in HIPAA security investigations

The HHS Office for Civil Rights runs a Risk Analysis Initiative. Its settlement announced June 18, 2026 was the 14th enforcement action under it. The four cases below show what OCR looks for. Two involve ambulance services, and the other two show risks every NEMT office shares: a former staff member’s login and ransomware.

Case Announced What happened Result
West Georgia Ambulance, an emergency and non-emergency ambulance company December 30, 2019 An unencrypted laptop with 500 people’s information was lost. OCR found no risk analysis, no security training program, and no Security Rule policies. $65,000 and a corrective action plan with two years of monitoring
Comstar, LLC, a billing company for nonprofit and municipal ambulance services and a business associate of more than 70 covered entities May 30, 2025 Ransomware reached the health information of 585,621 people. OCR found no accurate and thorough risk analysis. $75,000 and a two-year corrective action plan
BayCare Health System, a Florida health care provider May 28, 2025 The login of a former staff member at a physician’s practice with access to BayCare’s records was used to open a patient’s record, and a stranger then contacted the patient with photos and video of it. OCR cited access controls, risk reduction, and activity review. $800,000 and a two-year corrective action plan
An employer-sponsored group health plan June 18, 2026 Ransomware reached the information of 10,023 people. OCR found no accurate and thorough risk analysis before the breach. $450,000 and a two-year corrective action plan

The 2025 and 2026 corrective action plans each begin with the same step: a new, thorough risk analysis. In the health plan case, OCR’s finding was about the analysis in place before the breach, which is why a dated worksheet matters. For the penalty tiers, see HIPAA for NEMT providers. If something has already gone wrong, follow the steps in NEMT data breach.

Frequently asked questions

Does a small NEMT company need a HIPAA risk assessment?

Yes, if HIPAA applies to it. The risk analysis is a required part of the Security Rule for every covered entity and business associate that holds electronic rider information (45 CFR 164.308(a)(1)). A company that signs a broker's business associate agreement usually counts. WellTrans's subcontractor agreement, revised October 16, 2025, requires you to comply with section 164.308, where the risk analysis rule sits.

How often should I update a HIPAA risk assessment?

The Security Rule sets no fixed schedule. HHS guidance, last reviewed August 12, 2026, calls risk analysis an ongoing process and says some organizations redo it every year and others on longer cycles, such as every three years. It also says to review it after a security incident, a change in ownership, turnover in key staff, or new technology. A yearly date plus those triggers covers most small companies.

Is the free HHS Security Risk Assessment Tool enough?

It is a solid start, not a guarantee. HHS says using the tool is neither required nor a guarantee of compliance, and version 3.7 (page updated September 18, 2026) reminds users that its questions may not find every risk. Use the tool or this worksheet, add anything specific to your vans, drivers' phones, and paper, and keep the reports with your fix-it plan.

Does a HIPAA risk assessment have to cover paper manifests?

The Security Rule's risk analysis covers electronic information only. Paper still needs protecting. Covered entities must safeguard health information in any form (45 CFR 164.530(c)), every business associate agreement must require appropriate safeguards (45 CFR 164.504(e)), and a lost manifest can be a reportable breach. This worksheet puts paper on the same list so nothing is missed.

What is the difference between a HIPAA risk analysis and a HIPAA checklist?

A checklist shows which safeguards you have. HHS calls that a gap analysis, a partial view of your company. A risk analysis goes further. It finds every place rider information lives, names what could go wrong at each one, and rates the likelihood and impact of each threat. In this worksheet, Part 4 is the checklist, and Parts 2, 3, and 5 make it a risk analysis.

Is this the same as the risk assessment after a data breach?

No. After a specific incident, such as a lost phone or a misdirected email, you run a separate four-factor assessment to decide whether it must be reported (45 CFR 164.402). The Security Rule risk analysis looks at your whole company before anything goes wrong. A good risk analysis makes those incident assessments rarer.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter