Built for HIPAA-Regulated Environments

NEMA NETWORK handles protected health information as part of its core workflow. Every architectural decision reflects that responsibility. Here's exactly what we do to protect patient data and keep your facility compliant.

HIPAA Compliant · BAAs Available for All Facility Customers
Business Associate Agreements: NEMA NETWORK signs a BAA with every healthcare facility customer before onboarding begins. If you need a BAA as part of your procurement process, email support@nemanetwork.com and we'll send it for review.

HIPAA Compliance

  • Business Associate Agreements (BAAs) — signed with every facility customer prior to onboarding. PHI does not flow through our platform without a BAA in place.
  • Minimum necessary PHI — we collect only the patient information required to coordinate transport: name, pickup address, destination, and transport type. No diagnosis codes, insurance data, or clinical notes.
  • PHI is not shared with providers beyond what is necessary — NEMT providers see pickup and destination details only. They do not have access to patient records, billing information, or clinical history.
  • Digital trip records — all completed trips are documented with timestamps, provider identity, and status milestones. Records are retained to support CMS discharge documentation and audit requirements.

Data Security

  • Encryption in transit — all data transmitted between browsers, the API, and the database is encrypted via TLS 1.2+. Patient addresses and names are never sent over unencrypted connections.
  • Encryption at rest — all database records, including patient transport data, are encrypted at rest using AES-256.
  • Role-based access control (RBAC) — facility staff see only their facility's trips. Providers see only their own assigned trips. Administrators have separately scoped access. No cross-facility data visibility.
  • Full audit logging — every access to patient transport records is logged with user identity, timestamp, and action. Logs are retained and available for compliance review.
  • Two-factor authentication — TOTP-based 2FA is available for all user accounts. Administrators can require 2FA for their facility's users.
  • Secure session management — sessions use signed, short-lived tokens. Sessions expire after inactivity and are revocable by administrators.

Data Retention

  • HIPAA-compliant retention periods — PHI associated with transport records is retained for a minimum of 6 years in accordance with HIPAA requirements.
  • Configurable retention policies — administrators can configure data retention windows and run anonymization passes for records beyond the retention window.
  • Data deletion on request — facility customers may request deletion of their PHI in accordance with applicable law. Contact support@nemanetwork.com with deletion requests.

Infrastructure

  • US-based data storage — all data, including PHI, is stored in US-based infrastructure. No cross-border data transfer.
  • Subprocessor transparency — NEMA NETWORK uses a small number of subprocessors (database, error monitoring, log management). A full subprocessor list is available on request.
  • Error and incident monitoring — system errors are captured and monitored in real time. Security incidents are investigated promptly and reported to affected facility customers as required by law.

Questions & BAA Requests

For BAA requests, security questionnaires, subprocessor lists, or any compliance-related questions, contact us directly:

support@nemanetwork.com