The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting individually identifiable health information. Its Privacy Rule limits how protected health information (PHI) can be used and disclosed, and its Security Rule requires safeguards for electronic PHI. NEMT providers handle PHI constantly: rider names tied to dialysis clinics, behavioral health appointments and diagnoses on trip authorizations.
Most NEMT providers are business associates of the health plans and brokers they serve and must sign business associate agreements, train staff, secure devices and software, and report breaches. A driver texting a manifest to a personal phone or leaving trip sheets in an unlocked van is a reportable incident. Our guide to HIPAA compliance in NEMT lists the practical steps, and covered entity versus business associate explains which one you are.
← Browse all NEMT glossary terms
Running an NEMT company? Find or claim your listing in the NEMT provider directory, or start with the guide to starting a medical transportation business.
