Legal

HIPAA & Data Protection Statement

Effective date: September 10, 2026

Built for protected health information. The TNC & NEMT platform and kiosk handle patient names, trip details, mobility and medical needs, signatures and photos. That is protected health information (PHI) under HIPAA. We sign a Business Associate Agreement (BAA) with every client whose platform carries PHI, and the platform is hosted on cloud infrastructure covered by the host's own BAA. Data is encrypted in transit and at rest, access is role-based and logged, and PHI is never used for anything other than running your trips.

1. Our role

When you run NEMT, ambulance or air ambulance trips on a platform we build and host, you are a HIPAA covered entity (or a business associate of one) and we are your business associate. Before any PHI is loaded, we will sign a BAA with you that meets 45 CFR 164.504(e). If you host the platform yourself, our BAA covers only the support access we retain.

2. What PHI the platform holds

  • Rider name, phone, address and date of birth
  • Pickup and destination (often a medical facility)
  • Appointment times and standing-order schedules
  • Level of service and needs: wheelchair, stretcher, bariatric, oxygen, isolation, escort
  • Payer, member ID and authorization numbers
  • Trip timestamps, mileage, signatures and photos captured by drivers and crews
  • Kiosk bookings entered by facility staff or patients

3. Safeguards

Technical

  • TLS 1.2+ for all connections; AES-256 encryption at rest
  • Role-based access: dispatchers, drivers, facility users and administrators see only what their role requires
  • Unique logins, multi-factor authentication for admin and dispatch accounts, automatic session timeout
  • Audit logs of who viewed, created or changed PHI, retained for 6 years
  • Encrypted, tested backups with daily snapshots
  • Driver and crew apps do not store PHI on the device after the trip closes; photos and signatures upload and are removed locally

Administrative

  • A named security officer is designated in your platform agreement and BAA
  • Workforce HIPAA training on hire and annually
  • Access removed the same day a user is terminated
  • Annual risk analysis under 45 CFR 164.308(a)(1)
  • Written incident-response plan; breach notification to you within 5 business days of discovery, and never later than the 60 days HIPAA allows

Physical

  • Cloud hosting in data centers with SOC 2 / ISO 27001 controls, covered by the provider's own BAA
  • Kiosk hardware runs in locked kiosk mode, shows no prior bookings, and clears the screen after each session and on timeout

4. Data use and ownership

Your PHI is yours. We use it only to operate, support and secure your platform, and as your BAA permits. We do not sell it, use it for marketing, or share it with other clients. De-identified, aggregate usage statistics may be used to improve the platform.

5. Subcontractors

We flow down BAA obligations to every subcontractor that touches PHI, including our hosting provider and our notification and mapping vendors. A current list is available on request.

6. Your responsibilities

You remain responsible for your own HIPAA program: training your dispatchers, drivers and facility users; assigning and removing user accounts; setting facility-portal permissions; your Notice of Privacy Practices; and BAAs with your own brokers, MCOs and facilities.

7. Termination

At the end of the agreement, we return your PHI in a standard export format and destroy our copies within 30 days, certified in writing, except where law requires longer retention.

8. Questions

Security or privacy questions: contact@thewolfoftransportation.com · (305) 539-9920