Compliance & Security
Built for HIPAA-Regulated Environments
NEMA NETWORK handles protected health information as part of its core workflow. Every architectural decision reflects that responsibility. Here's exactly what we do to protect patient data and keep your facility compliant.
HIPAA Compliant · BAAs Available for All Facility Customers
Business Associate Agreements: NEMA NETWORK signs a BAA with every healthcare facility customer before onboarding begins. If you need a BAA as part of your procurement process, email support@nemanetwork.com and we'll send it for review.
HIPAA Compliance
- Business Associate Agreements (BAAs) — signed with every facility customer prior to onboarding. PHI does not flow through our platform without a BAA in place.
- Minimum necessary PHI — we collect only the patient information required to coordinate transport: name, pickup address, destination, and transport type. No diagnosis codes, insurance data, or clinical notes.
- PHI shared with providers is limited to what the trip requires — the assigned or eligible NEMT provider sees the patient name, pickup and destination, transport type, and transport-relevant notes (e.g. oxygen or isolation precautions). Providers do not have access to diagnoses, billing information, insurance data, or medical records.
- Digital trip records — all completed trips are documented with timestamps, provider identity, and status milestones. Records are retained to support CMS discharge documentation and audit requirements.
- PHI-free real-time architecture — real-time push signals sent to provider devices contain only a territory identifier and an opaque ride ID. Patient name, address, and transport details are never included in push payloads or notification channels; they are fetched only on authenticated API calls after the provider opens the app.
Data Security
- Encryption in transit — all data transmitted between browsers, the API, and the database is encrypted via TLS 1.2+. Patient addresses and names are never sent over unencrypted connections.
- Encryption at rest — all database records, including patient transport data, are encrypted at rest using AES-256.
- Role-based access control (RBAC) — facility staff see only their facility's trips. Providers see only their own assigned trips. Administrators have separately scoped access. No cross-facility data visibility.
- Full audit logging — every access to patient transport records is logged with user identity, timestamp, and action. Logs are retained and available for compliance review.
- Two-factor authentication — TOTP-based 2FA is available for all user accounts. Administrators can require 2FA for their facility's users.
- Secure session management — sessions use HMAC-signed, short-lived tokens. Sessions expire after inactivity and are revocable by administrators.
- Login rate limiting and brute-force protection — failed login attempts are tracked in a persistent, distributed store. Accounts are temporarily locked after repeated failures, and account-wide rate limits backstop credential-stuffing attacks across multiple IP addresses.
- Controlled account onboarding — there is no public self-signup. Every new facility or provider account is activated only through an admin-issued, single-use invite token. Tokens expire and are invalidated immediately on use, preventing reuse or interception.
Provider Credentialing
- Document verification before activation — every NEMT operator must submit a Certificate of Insurance (COI), W-9, vehicle inspection report, and driver credentials before being permitted to accept trips. Documents are reviewed and approved by NEMA NETWORK staff; no provider is active on the platform without a complete, reviewed compliance file.
- Automated COI expiry monitoring — Certificates of Insurance are tracked for expiration. Providers receive automated renewal reminders 14 days before their policy lapses. If a policy expires without renewal, the provider's compliance status is automatically flagged and NEMA NETWORK administrators are notified — preventing uninsured operators from remaining active on the platform.
- Human review on every approval decision — document screening is assisted by automated extraction tools, but all pass/fail compliance decisions are made by a NEMA NETWORK administrator, not by automated systems. No provider is approved or suspended solely by algorithmic determination.
Data Retention
- HIPAA-compliant retention periods — PHI associated with transport records is retained for a minimum of 6 years in accordance with HIPAA requirements.
- Configurable retention policies — administrators can configure data retention windows and run anonymization passes for records beyond the retention window.
- Data deletion on request — facility customers may request deletion of their PHI in accordance with applicable law. Contact support@nemanetwork.com with deletion requests.
Infrastructure
- US-based data storage — all data, including PHI, is stored in US-based infrastructure. No cross-border data transfer.
- Subprocessor transparency — NEMA NETWORK uses a small number of subprocessors (database, error monitoring, log management). A full subprocessor list is available on request.
- Error and incident monitoring — system errors are captured and monitored in real time. Security incidents are investigated promptly and reported to affected facility customers as required by law.
Questions & BAA Requests
For BAA requests, security questionnaires, subprocessor lists, or any compliance-related questions, contact us directly: