

NEMT Entrepreneur provides expert insights, strategies, and resources to help non-emergency medical transportation professionals grow their businesses. Get industry-leading advice to succeed in NEMT.
Most NEMT companies are not covered entities. They’re usually business associates. The fast test is simple: if you handle PHI for a hospital, health plan, Medicaid program, or broker, you’re likely a business associate for that trip. If the ride is private-pay and no covered healthcare party is involved, HIPAA may not apply.
Here’s the short version:
What I’d check first: who booked the ride, who is paying, what PHI is being shared, and whether a BAA is already signed.
Quick comparison
| Trip source | Who usually hires you | Your usual HIPAA role | Main document to check |
|---|---|---|---|
| Brokered Medicaid trip | Broker | Business Associate | BAA with broker |
| Hospital discharge | Hospital or health system | Business Associate | BAA with facility |
| MCO direct trip | Health plan / MCO | Business Associate | BAA with MCO |
| Private-pay trip | Patient or family | Often outside HIPAA | Service terms / privacy notice |
If you want one plain-English takeaway, it’s this: don’t label your whole company once and move on. Review the role at the trip level.
For NEMT, the main question is pretty simple: are you handling PHI for a covered entity, or are you operating on your own?
That one distinction shapes who controls the data, who has HIPAA duties, and who needs to sign a BAA.
A covered entity is a healthcare provider, health plan, or clearinghouse that creates, receives, or bills for healthcare data electronically. In NEMT, that usually means the hospital, Medicaid plan, or dialysis center that orders the ride.
That matters because the trip source controls who holds the PHI and who must sign the BAA.
This role usually changes by trip type, not by vehicle.
A business associate is a person or company that handles PHI for a covered entity. If you receive a trip manifest with a patient's name, address, Medicaid ID, and appointment time, you're handling PHI for that entity. That makes you a business associate.
Your dispatch software, cloud host, and overflow sub-hauler can also be business associates if they touch PHI.
The conduit exception does not fit NEMT. Why not? Because NEMT companies store and use trip data. They don't just pass sealed records through.
The table below shows how the two roles differ in day-to-day work. Use it to match each role to the trip you're actually running.
| Role | Typical NEMT Example | Who They Work For | PHI Access | Main HIPAA Duties | BAA Required? |
|---|---|---|---|---|---|
| Covered Entity (CE) | Hospital, Medicaid plan, dialysis center | Patients and members | Full clinical and payment records | Privacy Rule, Security Rule, Breach Notification | Initiates BAAs with vendors |
| Business Associate (BA) | NEMT company, broker, dispatch software | Covered entities or other BAs | Trip-related PHI (name, address, destination, Medicaid ID) | Security Rule and BAA-specific privacy and breach duties | Signs BAAs with CEs and subcontractors |
Next, apply these roles to broker work, discharge trips, Medicaid trips, and private-pay service.
NEMT HIPAA Roles: Covered Entity vs Business Associate by Trip Type
The same NEMT company can wear different HIPAA hats based on who set up the ride and what information moved with it. That’s where people often get tripped up. On paper, it may look like “just transportation.” In practice, the HIPAA role can shift from one trip to the next.
When a health plan hires a broker like ModivCare or MTM to run transportation benefits, the broker acts as a business associate (BA) for the health plan. If that broker then sends your NEMT company a trip manifest with the patient’s name, Medicaid ID, pickup address, and appointment type, your company becomes a downstream BA.
That means you need a signed BAA with the broker, not only with the health plan. The chain looks like this: health plan → broker → NEMT provider → software vendor. Each step in that chain needs its own BAA.
If a hospital or health system hires your company straight from the source to take a patient home after discharge, your company is a Business Associate. In that setting, the PHI can include the patient’s identity, destination, timing, mobility needs, and any handling instructions tied to the ride.
Medicaid trips usually work in a similar way. Under federal standards at 42 CFR § 431.53, Medicaid transportation providers usually sit inside this chain: State Medicaid program → broker → NEMT provider. For most NEMT companies, that puts them in the downstream BA role.
Private-pay is different. If a patient’s family calls your company and pays out of pocket for a ride to a doctor’s appointment, and no health plan, hospital, or Medicaid program is involved in arranging or paying for that trip, HIPAA may not apply.
That said, this is not a free pass to get sloppy with data. State consumer data laws may still apply, and HIPAA-style privacy and security steps are still the professional baseline in medical transportation.
Use the table below to match the trip source with the right HIPAA role.
| Trip Type | Who Hires NEMT | Covered Entity Involved? | NEMT Role | PHI Typically Shared | Contract Check |
|---|---|---|---|---|---|
| Brokered Medicaid/MCO | Broker (e.g., ModivCare, MTM) | Yes (Health Plan or State) | Downstream business associate | Name, Medicaid ID, medical destination, mobility needs | BAA with broker |
| Hospital Discharge | Hospital or Health System | Yes (The Hospital) | Business associate | Discharge details, mobility needs, timing, destination | BAA with facility |
| Managed Care (MCO Direct) | Insurance Company / MCO | Yes (The MCO) | Business associate | Name, insurance ID, appointment type and location | BAA with MCO |
| Private-Pay | Patient or Family Member | No | Service provider outside HIPAA | Name, address, phone number | Service agreement / privacy notice |
Once a trip puts your company in BA territory, your contracts and day-to-day work need to line up with that role.
For brokered Medicaid trips, hospital discharge trips, and MCO trips, your company needs a signed BAA with the entity hiring you. That could be a broker, hospital, clinic, dialysis center, or health plan.
The same rule applies to your software stack. If your software provider or cloud vendor handles PHI, they need a BAA too.
Before you sign, read the fine print. This is where companies get tripped up. Pay close attention to breach-notice deadlines and subcontractor terms. Many brokers want notice within 10 to 72 hours, which is much shorter than HIPAA’s federal 60-day window.
Drivers need the details required to do the trip safely: a pickup address, drop-off location, and any mobility or safety notes. They do not need a diagnosis code or a patient’s full medical history.
A simple way to set this up is to keep your controls centered on these five areas:
Use the checklist below to make each HIPAA duty somebody’s clear job, not everybody’s vague job.
| Task | Covered Entity Concern | Business Associate Concern | Who Handles It | How Often |
|---|---|---|---|---|
| BAA Management | Must sign with all business associates | Must sign with subcontractors and vendors | Owner | Continuous |
| HIPAA Training | Direct regulatory requirement | Contractual and legal obligation | All staff (drivers and dispatch) | At hire, then annually |
| Risk Analysis | Security Rule compliance | Required to protect covered entity data | Owner / Security Officer | Annually |
| OIG Exclusion Screening | Mandatory for billing privileges | Required by broker contracts | Owner / Compliance Officer | Monthly |
| Device Security | Unauthorized PHI access | Encryption and remote-wipe capability | IT/Security Lead | Continuous |
| Trip Note Review | Privacy Rule compliance | Minimum necessary access | Dispatch | Every trip |
| Breach Assessment | Regulatory reporting liability | Contractual reporting windows | Owner / Compliance Officer | As needed |
After looking at the main trip types, the test is pretty simple: if your company handles PHI for a hospital, health plan, Medicaid program, or broker acting for them, you’re likely working as a Business Associate. HIPAA doesn’t hinge on your industry by itself. It depends on your role and the relationship tied to that trip. That’s why the same company can be a BA on one trip and outside HIPAA on another. The review has to happen at the trip level, not by slapping one label on the whole company.
In NEMT, you’re a business associate if you create, receive, maintain, or transmit protected health information (PHI) for a covered entity.
That can include patient names, home addresses, appointment details, or even information that points to a medical condition.
If you provide trips for a broker, health plan, or healthcare provider, you’ll often fall into this role, especially if you’re working under a contract that includes a Business Associate Agreement.
Handling PHI before a BAA is signed creates immediate HIPAA risk and can lead to a serious compliance violation.
A BAA needs to be in place before any vendor or partner creates, receives, maintains, or transmits PHI on your behalf. Without that agreement, the rules for permitted disclosures, security safeguards, and breach reporting simply are not there. That leaves a dangerous gap.
If a vendor needs PHI but will not sign a BAA, do not move forward.
Yes. An NEMT company can wear different HIPAA hats depending on the setup.
When it works with brokers, hospitals, or health plans that share protected health information, the company usually acts as a Business Associate.
But private-pay trips are a different story. If no Covered Entity is involved, the role can be harder to pin down. That's why it helps to map each workflow with care.


