Compliance

NEMT HIPAA Policy Template: Phones, Manifests, Texting, and Breach Reporting

A NEMT HIPAA policy template is a short written rulebook for how your drivers, dispatchers, and office staff handle rider information: who may see it, how phones and paper manifests are protected, what goes in a text, who gets trained, and who calls the broker when something goes wrong. HIPAA requires these policies in writing, kept for 6 years.

  • Most companies that run broker trips are business associates or subcontractors, so the HIPAA Security Rule applies to them directly.
  • Name one security official in writing, and give every person their own login to every portal and app.
  • Properly encrypted phones keep a lost device from becoming a reportable HIPAA breach, though brokers may still want to hear about it.
  • Your broker agreement sets the real reporting clock. WellTrans wants a breach reported within one business day, not the 60 days HIPAA allows.
  • Keep the policy, training records, and incident records for 6 years from the date each was created or last in effect.

Only the title and the template print.

A trip manifest holds exactly what HIPAA protects: a rider’s name, address, and phone number next to the place they go for care. Your drivers carry that all day, on a phone or a clipboard. This template turns the HIPAA rules into one short policy that drivers, dispatchers, and office staff can read, sign, and follow. It is sized for a company with one to ten vans running broker, health plan, or facility trips.

How to use this template

  1. Settle your HIPAA status first. Work through the three tests in HIPAA for NEMT providers and mark the result in Part 1. Most companies running broker trips are business associates or subcontractors of one.
  2. Pull every business associate agreement you signed. Copy each reporting deadline and contact into Part 1. The shortest deadline becomes your company’s deadline.
  3. Name your security official. HIPAA requires one person responsible for these policies (45 CFR 164.308(a)(2)). In a small company it is often the owner.
  4. Do the risk analysis. This policy says what everyone does. The risk analysis, which HIPAA also requires, finds where rider information lives and what could go wrong. Use the HIPAA risk assessment template or the free Security Risk Assessment Tool from HHS’s health IT office.
  5. Fill in every blank. Where a broker agreement is stricter than a rule here, write the stricter rule in.
  6. Train, then sign. Everyone reads the policy, is trained on it, and signs Part 16 before touching rider information.
  7. Keep it and review it. Keep each version for 6 years, and review it every year and after any new broker, app, office, or incident.

The template

Part 1: Policy details

Field Entry
Company name
Effective date
Last reviewed
Security official (name, phone, email)
Privacy official, if we are a covered entity (name, phone)
Backup contact when the security official is away
Our HIPAA status (covered entity, business associate, or subcontractor of a business associate)
This policy applies to Owners, employees, contract drivers, attendants, dispatchers, trainees, and volunteers

Reporting deadlines from our agreements

Broker, plan, or facility Report a breach within Report a security incident within Who to call or email Agreement date

Part 2: What this policy protects

“Rider information” is anything that identifies a rider together with their trips, health, or payment, whether it is on paper, on a screen, or spoken. It includes:

  • names with pickup or drop-off addresses
  • phone numbers, dates of birth, Medicaid or health plan numbers, and trip or authorization numbers
  • the clinic, doctor, or program a rider goes to, and appointment times
  • wheelchair, stretcher, oxygen, or escort needs, weight with mobility equipment, and notes about a condition
  • signed trip logs, rider signatures, GPS records of a rider’s trips, claims, and payment statements
  • photos or video that show a rider’s face

When in doubt, treat it as rider information.

Part 3: Share only what the job needs

  1. Use and share only the rider information needed for the task in front of you.
  2. Drivers get the pickup and drop-off, the times, the assistance level, the equipment, and a contact number. Drivers do not need a diagnosis.
  3. We share rider information only with the rider, the broker or plan that sent the trip, the facility the trip serves, our vendors listed in Part 11, and anyone else our broker agreement allows.
  4. Never look up a rider or a trip out of curiosity.
  5. Never sell rider information or use rider lists for marketing.
  6. Send any request for rider information from police, lawyers, reporters, or other outsiders to the security official. Do not answer it yourself.

Part 4: Phones, tablets, and computers

  1. Every device that shows rider information has a passcode, fingerprint, or face sign-in, and locks itself after ______ minutes.
  2. Encryption is turned on for every phone, tablet, and laptop.
  3. Remote locate and wipe is turned on, and the security official knows how to use it.
  4. Rider information stays in the trip or broker app. No screenshots or photos of manifests, and no copies in notes, personal email, or chat groups.
  5. Automatic system and app updates stay on.
  6. Screens face away from riders and visitors. Lock the dispatch computer every time you step away.
  7. Drivers who use a personal phone for trips follow every rule in this part, and delete the work apps and any rider information on their last day.
  8. The security official keeps a list of which device each person has. Before any device is sold, recycled, or given to someone else, it is wiped.
  9. A lost or stolen device is reported to the security official at once, as Part 13 explains.

Part 5: Paper manifests, trip logs, and signatures

  1. Carry paper manifests and trip logs in a closed folder.
  2. Never leave paperwork in an unlocked vehicle, and keep it out of sight in a locked one.
  3. Bring used manifests and signed trip logs to the office at the end of each shift, and file them in a locked cabinet.
  4. Keep trip records as long as our longest contract requires: ______ years.
  5. When paper may be thrown away, shred it so it cannot be read or put back together. Never put it in the trash or recycling. Blacking out names does not count as destroying it.

For what a manifest should hold, see the daily manifest template.

Part 6: Calls, texts, and email

  1. Texts and voicemails to riders give only our company name, the pickup time and place, the vehicle, and a callback number.
  2. Leave out the clinic, the doctor, the reason for the trip, and any member or trip ID.
  3. Use the company’s texting or dispatch tool for rider messages where we provide one.
  4. Never email a manifest, trip list, or rider record unless the email is encrypted or goes through the broker’s portal.
  5. If a rider asks to be contacted a certain way, such as only by phone, write it in the rider’s profile and follow it.
  6. Before discussing a trip by phone, confirm you are speaking with the rider, the facility, the broker, or someone the rider or broker has approved.

For message wording, see HIPAA texting for NEMT.

Part 7: In the vehicle and at the dispatch desk

  1. Never discuss one rider’s trip, destination, or health with another rider.
  2. Speak quietly about trip details in lobbies, waiting rooms, and on the phone in public.
  3. Over the radio or in a group call, use the rider’s first name and pickup time, not a full name with a destination.
  4. Visitors to the office never see the dispatch screen or the trip board.

Part 8: Photos, video, and social media

  1. Never post anything about a rider, a trip, or a facility visit online, even without a name.
  2. Take photos on a trip only when the broker or dispatch requires them, such as damage after an accident. Keep them in the company app and avoid riders’ faces.
  3. Vehicle camera footage is rider information. Only ______ may view it, and it is deleted after ______ days unless an incident needs it.

Part 9: Logins and access

  1. Everyone has their own login to every broker portal, dispatch system, and company email. Never share a login or a password.
  2. Passwords are at least ______ characters and are not reused. Turn on multi-factor login everywhere it is offered.
  3. Access matches the job. Drivers see their own trips. Billing staff see claims.
  4. When someone leaves or changes jobs, the security official removes their access that day and collects badges, keys, and company devices.
  5. Every ______ months, the security official reviews who has access and checks login records for anything unusual.
  6. Emergency access: the master passwords are kept ______, and only ______ may use them.

Part 10: Backups and emergencies

  1. Trip and rider records are backed up ______ (how often), and a copy is kept ______ (where).
  2. The security official tests restoring from the backup every ______ months.
  3. If the dispatch system or phones go down, dispatch runs from the backup manifest printed ______, and the security official restores the system from the backup.

Part 11: Vendors who handle rider information

No vendor gets rider information until it signs a business associate agreement with us.

Vendor What rider information it handles Agreement signed (date) Where the copy is kept
Billing service
Dispatch or GPS software
Cloud storage or email
IT support
Answering service
Factoring company
Shredding company

For what each agreement must say, use the business associate agreement checklist.

Part 12: Training

  1. Everyone is trained on this policy before first access to rider information, and every year after.
  2. The security official sends a short security reminder every ______ months, such as a warning about a fake email going around.
  3. Training is recorded below and kept for 6 years.
Name Date Topic Trainer Signature

The HIPAA training guide covers what to teach.

Part 13: Report every problem the same day

Report any of these to the security official right away, by phone, during the same shift:

  • a lost or stolen phone, tablet, laptop, or paperwork
  • a manifest or trip log left behind, or handed to the wrong person
  • a text, email, or fax sent to the wrong person
  • someone seeing rider information who should not have
  • a strange email, login alert, or pop-up on a work device
  • rider information posted or shared online

Do not wait until you are sure something went wrong. Nobody is punished for reporting a problem in good faith.

The security official then:

  1. Contains it: locks or wipes the device, recalls or deletes the message, and gets the paper back.
  2. Checks the deadlines in Part 1 and reports to each broker or plan on time.
  3. Writes a risk assessment covering what information was involved, who got it, whether it was actually viewed, and what was done to reduce the risk.
  4. Records it in the log below, and fixes the cause.
  5. If we are a covered entity, sends the notices to riders and HHS that the breach rules require.
Date found Found by What happened Riders affected (how many) Device encrypted? Broker told (date and how) Risk assessment result Fix made Date closed

For a crash, fall, or rider injury, use the incident report form instead.

Part 14: Consequences for breaking this policy

What happened Examples Result
An honest mistake, reported right away A text sent to the wrong number Retraining
Carelessness A manifest left in an unlocked van, a shared password Written warning and retraining
Repeated carelessness A second warning within ______ months Suspension or removal from the schedule
Deliberate misuse Looking up trips out of curiosity, posting about a rider, taking rider lists Termination, and a report to the broker

The security official writes down every consequence applied and keeps the record for 6 years.

Part 15: Records and review

  1. Keep these for 6 years from the date each was created or last in effect, whichever is later: this policy and every earlier version, risk analyses, training records, the incident log and risk assessments, business associate agreements, and records of consequences applied.
  2. Review this policy every year and after any new broker, app, office, or incident. Write the date in Part 1.

Part 16: Staff acknowledgment

I have read this policy, completed training on it, and agree to follow it. I understand that breaking it can lead to discipline, up to and including termination.

Name Role Date trained Signature

The HIPAA rule behind each part

The Security Rule applies to covered entities and business associates alike. It lets you fit safeguards to your size, your systems, your costs, and your risks (45 CFR 164.306(b)). Some steps are required. Others are addressable, which means you put them in place when reasonable and appropriate, or write down why not and use an equal alternative (164.306(d)).

Part Rule, in 45 CFR What it asks of you
1. Security official 164.308(a)(2) Name the person responsible for the security policies
2. What is protected 160.103, 164.514(b) Protected health information in any form. Names, addresses, dates, phone numbers, plan numbers, and full-face photos are all identifiers.
3. Minimum necessary 164.502(b), 164.502(a)(3) Limit information to the minimum needed. A business associate may use and share it only as its agreement allows.
4. Devices 164.310(b) to (d), 164.312(a)(2) Workstation use and security, disposal and reuse (required), device tracking, automatic logoff and encryption (addressable)
5. Paper 164.530(c) for covered entities, and your business associate agreement Reasonable safeguards for information in every form
6. Messages 164.312(e), 164.502(b), 164.522(b) Guard information sent over networks. Covered health care providers must honor reasonable requests to be contacted another way.
9. Logins 164.312(a)(2)(i), 164.308(a)(3) and (a)(4), 164.308(a)(1)(ii)(D) A unique login for each person (required), access that fits the job, removing access when someone leaves, and regular review of activity records (required)
10. Backups 164.308(a)(7) Backups, disaster recovery, and an emergency plan (required). Testing is addressable.
11. Vendors 164.308(b), 164.504(e) Written agreements with every subcontractor that handles the information
12. Training 164.308(a)(5), and 164.530(b) for covered entities Security awareness training for the whole workforce, managers included
13. Incidents 164.308(a)(6), 164.402, 164.410 Identify, respond to, reduce the harm of, and document every security incident
14. Consequences 164.308(a)(1)(ii)(C), 164.530(e) Apply sanctions to staff who break the policies (required)
15. Records 164.316(b), 164.530(j) Written policies, kept 6 years, reviewed periodically and updated as needed

“Workforce” in HIPAA means employees, volunteers, trainees, and anyone else whose work you directly control, paid or not (45 CFR 160.103). Contract drivers you dispatch and direct can count, so Part 1 covers them.

A written policy does not replace the risk analysis. The Security Rule requires an accurate and thorough assessment of the risks to the electronic rider information you hold, and security measures that bring them down to a reasonable level (164.308(a)(1)(ii)(A) and (B)). The free Security Risk Assessment Tool from HHS’s health IT office is built for small and medium-sized providers (page updated September 18, 2026).

Breach deadlines to write into Part 1

A breach is a use or disclosure the rules do not allow that compromises the information. It is presumed to be one unless a written risk assessment shows a low probability that the information was compromised (45 CFR 164.402). You carry the burden of proving that a notice was not needed (164.414), which is why Part 13 has you write the assessment down.

Who Must tell Deadline Source
Your company, as a business associate The broker or covered entity Without unreasonable delay and within 60 calendar days of discovery 45 CFR 164.410
Your company, under WellTrans WellTrans’s HIPAA compliance officer, in writing One business day for a breach, a use or disclosure the agreement does not allow, or a security incident. Also by phone right away if misuse is imminent. Subcontractor business associate agreement, revised October 16, 2025
Your company, under WellTrans WellTrans’s HIPAA privacy and security officer, at (800) 486-7647 Within 48 hours of learning of a breach of confidentiality, privacy, or security Account setup agreement in the same packet, revised October 16, 2025
Your company, under Modivcare Your provider relations contact or Modivcare’s privacy officer Immediately, for any security breach involving member information 2025 annual provider compliance training
Your company, under MTM Health MTM Any breach of member health or personal information. The deadline is in the business associate agreement you sign, so copy it into Part 1. Standard agreement, January 1, 2023
A covered entity Each rider affected Without unreasonable delay and within 60 calendar days of discovery 45 CFR 164.404
A covered entity HHS 500 or more people: at the same time as the rider notices. Fewer than 500: within 60 days after the end of the calendar year. 45 CFR 164.408
A covered entity Prominent media in the state More than 500 residents of one state: within 60 calendar days 45 CFR 164.406

A breach counts as discovered on the first day anyone on your staff, other than the person who caused it, knows about it or should have. That is why Part 13 asks for a report during the same shift.

Encryption changes the outcome. The breach notice rules cover only “unsecured” information. HHS guidance published on August 24, 2009 says electronic information encrypted to the standard in NIST Special Publication 800-111, with the key kept separate, is not unsecured. Paper that is shredded or destroyed so it cannot be read or reconstructed counts as destroyed, and HHS specifically excludes redaction. Your broker may still want to hear about a lost device, since WellTrans’s agreement covers security incidents as well as breaches. For a full response plan, see NEMT data breach.

What broker agreements add

Your agreements often go further than HIPAA. Examples as of September 2026:

  • MTM Health’s standard agreement (January 1, 2023, as Pennsylvania posts it) requires you to keep member health and personal information confidential, report breaches to MTM, and sign its business associate agreement. Driver training must include HIPAA.
  • MTM Health in Virginia (handbook dated May 2026, approved August 10, 2026) requires HIPAA training before a driver transports members. Drivers must not display or discuss member health information with unauthorized people, including other members on the same ride. Its manifests list the member’s full name and phone number, both addresses and times, the doctor’s name and phone number, the level of assistance, any escort, and the member’s weight with mobility equipment.
  • WellTrans (agreement revised October 16, 2025) requires you to follow the Security Rule sections on administrative, physical, and technical safeguards and on written policies. It limits you to the minimum necessary, requires business associate agreements with billing and factoring companies that receive your trip logs or manifests, and wants access to member records within five business days of a request. When the agreement ends, you return or destroy the information and certify it. Staff get HIPAA training at hire and every year, with proof on request. The account setup agreement in the same packet adds a report to WellTrans’s HIPAA privacy and security officer within 48 hours of learning of a breach, so meet both clocks.
  • Modivcare (2025 annual provider training) lists improper disclosures such as posting members’ trip records on social media, sending unencrypted emails about member records or complaints, looking up trip records “just for fun,” and discussing one member’s trip with another rider. Its safeguards include keeping member information out of view, using privacy screens, never storing it in unlocked vehicles, disposing of paperwork properly, and password-protecting devices.

If you are a covered entity

If your company is a covered entity, for example because it bills Medicaid or health plans directly for services that count as health care, this policy covers the security and breach basics but not everything. You also need:

  • a privacy official and a contact for complaints (45 CFR 164.530(a))
  • a notice of privacy practices (164.520)
  • ways for riders to see and get copies of their records, ask for corrections, get a list of certain disclosures, and ask for restrictions or another way to be contacted (164.522 to 164.528)
  • a complaint process, with each complaint and its outcome documented (164.530(d))
  • steps to reduce the harm of any improper disclosure, and a ban on retaliation against anyone who complains (164.530(f) and (g))
  • the notices to riders, HHS, and the media in the deadline table above

For how to tell whether you are one, see HIPAA covered entity. For what counts as protected information, see protected health information.

What may change in 2027

HHS proposed a major update to the Security Rule on January 6, 2025 (90 FR 898). As proposed, it would remove the difference between required and addressable safeguards, require encryption of all electronic rider information at rest and in transit with limited exceptions, require multi-factor login, and require written plans to restore critical systems and data within 72 hours.

HHS’s regulatory agenda lists the final rule as a long-term action with a target of July 2027. Compliance with a new or changed standard is generally due 180 days after the rule takes effect (45 CFR 160.105). As of September 28, 2026 the proposal is not final, and the current rule applies. Parts 4 and 9 already ask for encryption and multi-factor login wherever you can turn them on, two of the proposal’s main changes.

Frequently asked questions

Does a small NEMT company need a written HIPAA policy?

Yes, if it is a covered entity or a business associate. The Security Rule requires written policies and procedures, kept for 6 years and reviewed periodically (45 CFR 164.316). Broker agreements say the same thing in their own words. WellTrans's subcontractor business associate agreement, revised October 16, 2025, requires you to follow the Security Rule sections on safeguards and on written policies.

Is my NEMT company a covered entity or a business associate?

If you run trips for a broker or health plan that sends you member information, you are usually its business associate or a subcontractor of one. Modivcare's 2025 provider training calls its transportation providers subcontractors of a business associate, and MTM Health's standard agreement requires you to sign its business associate agreement. If you bill Medicaid or plans directly, you may also be a covered entity.

Can drivers keep trip manifests on their personal phones?

The Security Rule does not ban personal phones. It requires safeguards on any device that holds rider information, fitted to your size and risks (45 CFR 164.306). In practice that means a passcode, auto-lock, encryption, a unique login to the trip app, and no screenshots or photos of manifests. The driver deletes the work apps and any rider information on the last day of work.

What can a driver put in a text to a rider?

Only what the rider needs to meet the van: your company name, the pickup time and place, and a callback number. Leave out the clinic, the doctor, the reason for the trip, and any member ID. HIPAA requires you to limit rider information to the minimum needed for the purpose (45 CFR 164.502(b)), and Modivcare lists unencrypted email about member records as an improper disclosure.

How fast must I report a lost phone or other breach?

Under HIPAA, a business associate tells the covered entity without unreasonable delay and within 60 calendar days of discovery (45 CFR 164.410). Your broker agreement is usually stricter. WellTrans requires a report within one business day, and Modivcare's training says to report any security breach immediately. The clock starts on the first day any employee, other than the person who caused it, knows or should have known.

Is the HIPAA Security Rule changing in 2027?

It may. HHS proposed a stricter Security Rule on January 6, 2025, with encryption of all electronic rider information, multi-factor login, and restoring critical systems within 72 hours. HHS's regulatory agenda lists July 2027 as its target for a final rule. As of September 28, 2026 the proposal is not final, and the current rule applies.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter