Open 24/7, online and by phone. A real dispatcher answers, day or night. No phone tree, no answering service. (323) 744-1900
Power House Courier
๐Ÿ“ž (323) 744-1900

Open 24/7. A real dispatcher answers, day or night.

Get a Free Quote โ†—
Homeโ€บBlogโ€บMedical Courier
๐Ÿฅ Medical Courier

How to Choose a HIPAA-Compliant Medical Courier (With a BAA Checklist)

HHS treats couriers that only transport sealed PHI as conduits, but storage, scanning or portals can make a courier a business associate. Here is how to decide, what a BAA…

๐Ÿ“… September 30, 2026ยทโฑ 9 min read
How to Choose a HIPAA-Compliant Medical Courier (With a BAA Checklist)

To choose a HIPAA compliant courier, first decide whether the courier will act as a business associate that needs a signed agreement, or as a conduit that only moves sealed items. Then check what HIPAA doesn’t cover: bloodborne pathogens training, specimen packaging rules, chain of custody and temperature records.

There’s no government seal to look for. HHS says it does not endorse or otherwise recognize private “certifications” for the Security Rule, so a badge on a vendor’s website proves little. What you can verify is the contract, the training records and the paperwork a courier produces on every run.

This is logistics guidance, not legal advice. Your privacy officer or counsel should make the final call on whether you need a business associate agreement (BAA).

Need this delivered today?

Power House Courier runs HIPAA-compliant, UN3373-certified specimen and medical deliveries 24/7 across California, Arizona and Texas. A dispatcher answers in under 15 minutes.

See our medical courier service โ†’

TL;DR

  • HHS says couriers that act “merely as conduits” for protected health information, with only random or infrequent access, are not business associates and don’t need a BAA.
  • HHS describes the conduit exception as limited to transmission-only services, for paper or electronic PHI, so a courier that stores, scans or manages records is likely a business associate.
  • A BAA must cover ten elements listed by HHS, including safeguards, breach reporting, subcontractor flow-down and return or destruction of PHI at termination.
  • A business associate must report a breach of unsecured PHI to you no later than 60 calendar days after discovery, and many BAAs set a shorter deadline.
  • OSHA requires bloodborne pathogens training at initial assignment and at least annually for employees with occupational exposure, which HIPAA doesn’t address.

Business associate or conduit

Start here, because the answer decides whether you need a BAA at all.

HHS answered this directly in a long-standing FAQ. The Privacy Rule does not require business associate contracts with organizations “such as the US Postal Service, certain private couriers and their electronic equivalents that act merely as conduits” for protected health information (PHI). A conduit, in HHS’s words, “transports information but does not access it other than on a random or infrequent basis” as needed to deliver it or as required by law.

A driver who picks up a sealed specimen bag or a closed records box and drops it at the lab is moving PHI without reading it.

The exception is narrow, though. In a later FAQ about cloud providers, HHS said the conduit exception “is limited to transmission-only services for PHI (whether in electronic or paper form)”, including temporary storage incident to that transmission, and that any access by a conduit is “only transient in nature.” An entity that maintains PHI for storage is a business associate even if it never looks at it.

For couriers, that points to a practical line. The HHS FAQs don’t list courier scenarios one by one, so treat the following as our reading, and confirm it with your privacy officer:

  • Point-to-point transport of sealed specimens or closed containers generally fits the conduit description.
  • Holding records overnight in a courier’s facility, scanning documents, sorting charts, or running a records retrieval service goes beyond transient access and looks like business associate work.
  • A courier app or portal that stores patient names, MRNs or requisition images on the courier’s systems may also move the relationship out of conduit territory.

Some hospitals and labs ask every medical courier to sign a BAA anyway. That’s a reasonable risk decision, but a signed BAA doesn’t turn a van into a compliance program. The rest of this guide covers what to verify either way.

What a BAA with a courier must contain

The contract requirements live at 45 CFR 164.504(e), which opens with the words “A contract between the covered entity and a business associate must:” HHS restates them in plain terms on its business associate contracts page. Paraphrasing HHS’s list, a written BAA must:

  1. Set the permitted and required uses and disclosures of PHI by the courier.
  2. Bar other uses or disclosures except as the contract allows or law requires.
  3. Require appropriate safeguards, including Security Rule compliance for electronic PHI.
  4. Require the courier to report unauthorized uses or disclosures, including breaches of unsecured PHI.
  5. Make PHI available for patient access, amendment and accounting requests, as the contract specifies.
  6. Require compliance with Privacy Rule obligations the courier carries out for you.
  7. Make the courier’s practices, books and records available to HHS.
  8. Require return or destruction of PHI at termination, if feasible.
  9. Flow the same restrictions down to any subcontractor with access to PHI.
  10. Let you terminate if the courier violates a material term.

Item nine matters more for couriers than for most vendors. Some courier companies hand overflow, long-distance legs or after-hours calls to subcontracted drivers or partner carriers. Ask who those subcontractors are and whether they’ve signed matching terms.

HHS notes its sample provisions may not be enough for a binding contract under state law, so have counsel review the final document.

Minimum necessary and breach reporting

The minimum necessary standard asks covered entities to take reasonable steps to limit uses, disclosures and requests of PHI to what’s needed for the purpose, according to HHS guidance on 45 CFR 164.502(b) and 164.514(d). For a courier, that’s easy to apply. The driver needs a pickup address, a delivery address, a contact, and a tracking or requisition number. The driver doesn’t need a diagnosis, and a manifest can often work without full patient names.

If your manifests show more than that, fix it on your side first.

Breach reporting has fixed deadlines. Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI “without unreasonable delay and in no case later than 60 calendar days after discovery.” A breach counts as discovered on the first day the business associate knew, or through reasonable diligence would have known, about it. The HHS Breach Notification Rule page explains the rest of the chain: covered entities notify affected individuals within 60 days of discovery, notify HHS, and notify prominent media when a breach affects more than 500 residents of a state or jurisdiction.

Sixty days is the legal ceiling. HHS’s sample BAA suggests parties may want “a stricter timeframe” for the business associate to report. Ask for one. For a courier, a lost tote or a misdelivered records box should reach your privacy office the same day.

Requirements HIPAA doesn’t cover

HIPAA governs information. The specimen itself, and the person carrying it, fall under other rules.

Bloodborne pathogens training

OSHA’s bloodborne pathogens standard, 29 CFR 1910.1030, applies to occupational exposure to blood or other potentially infectious materials. Employers with exposed employees need a written exposure control plan, must make hepatitis B vaccination available within 10 working days of initial assignment, and must train at initial assignment and at least annually after that. Whether a given driver has “reasonably anticipated” exposure depends on the duties, so ask the courier how it has assessed that and what training its drivers receive.

Specimen packaging by road

Category B specimens (UN3373) moving by road fall under 49 CFR 173.199, which requires triple packaging and the UN3373 mark. It also says each person who offers or transports a Category B substance under that section “must know about the requirements of this section.” Your lab usually packs the specimen. The courier should still recognize a correct package and know what to do with a leaking one.

Chain of custody and temperature records

No single federal rule sets a courier chain of custody format, but your lab’s accreditation, study protocols or client contracts may. Expect a signature or scan at each handoff with times, and for temperature-sensitive material, a log from pickup to delivery. Our guide to temperature logs, HIPAA and chain of custody goes into what a usable record looks like.

Insurance, screening and facility access

Insurance limits, background checks, drug screening and vendor credentialing are set by your own policies and contracts rather than by HIPAA. Ask for certificates of insurance naming your organization where your contract requires it, and ask how drivers are screened before they get access to your loading dock or specimen room. If your hospital runs a vendor credentialing program, confirm the courier’s drivers can meet it.

A HIPAA compliant courier checklist

Use this table as a starting point and adjust it to your own policies.

Item What to ask for Why it matters
Conduit or BA decision Written description of what the courier will do with PHI (transport only, storage, scanning, portal) Determines whether a BAA is required
BAA Signed agreement covering the ten HHS elements, with a short breach reporting deadline 45 CFR 164.504(e)
Subcontractors List of partner carriers or contract drivers and proof of matching terms BAA flow-down requirement
HIPAA awareness training Training content and dates for drivers and dispatchers Supports safeguards and minimum necessary handling
Bloodborne pathogens Exposure control plan and annual training records where exposure is anticipated 29 CFR 1910.1030
UN3373 knowledge How drivers learn 173.199 requirements and handle damaged packages 49 CFR 173.199
Chain of custody Sample proof of delivery with handoff times and signatures Accreditation and audit trail
Temperature control Sample temperature log and equipment used Specimen integrity
Insurance Certificates of insurance matching your contract limits Liability for loss or damage
Screening and credentialing Background check and drug screen policy; ability to meet your vendor credentialing Facility access
Incident response Named contact and written steps for lost, misdelivered or damaged items Breach clock starts at discovery

Questions to ask in a vendor interview

These are the questions we’d want answered if we were on your side of the table:

  • Will your drivers ever hold our items overnight, and where?
  • Do you store any patient identifiers in your app or portal, and for how long?
  • Which runs go to subcontractors, and have they signed the same terms you’ll sign with us?
  • Walk me through what happens in the first hour after a driver reports a missing tote.
  • What bloodborne pathogens and UN3373 training do drivers complete, and when was it last done?
  • Can you show a real (redacted) chain of custody record and temperature log from a recent run?

At Power House Courier we run medical courier service with 24/7 dispatch, and we expect these questions from hospitals and labs. If you’re still deciding whether you need a specialist at all, our comparison of a medical courier vs. a regular courier covers the differences, and our California medical courier page covers statewide coverage.

Related guides: once compliance checks out, how medical courier pricing works helps you compare quotes. Our biological sample transport guide covers packaging and chain of custody, and if you are hiring drivers in-house, see what medical courier training involves.

Frequently asked questions

Do I need a BAA with my medical courier?

It depends on what the courier does. HHS says couriers acting merely as conduits, with only random or infrequent access to PHI, aren’t business associates. If the courier stores, scans or manages records, or keeps patient data in its systems, it likely is one. Some providers sign BAAs with couriers either way. Your privacy officer should decide.

Is there an official HIPAA certification for couriers?

No. HHS says it does not endorse or otherwise recognize private organizations’ “certifications” regarding the Security Rule, and such certifications don’t relieve anyone of their legal obligations. A courier’s training certificate may still be useful evidence of training, but judge vendors on their contract terms, records and procedures rather than a badge.

How fast must a courier report a lost specimen with patient information?

If the courier is a business associate and the loss is a breach of unsecured PHI, the legal outer limit is 60 calendar days after discovery under 45 CFR 164.410. That’s a ceiling, not a target. You can write a much shorter deadline into the BAA, and operationally you want to hear about it the same day.

Does OSHA’s bloodborne pathogens standard apply to couriers?

It applies to employees with reasonably anticipated occupational exposure to blood or other potentially infectious materials. Whether that includes a courier’s drivers depends on their duties and the employer’s exposure assessment. Where it applies, the employer needs an exposure control plan, training at assignment and annually, and hepatitis B vaccination offered within 10 working days.

What should a courier’s chain of custody record show?

At minimum, who handed the item over, who received it, and when, for every handoff from pickup to delivery. For temperature-sensitive specimens, add the temperature record for the whole trip. Your lab’s accreditation or study protocol may require more, so share those requirements with the courier before the first run.

Does a BAA cover a courier’s subcontractors?

It should. HHS lists subcontractor flow-down as a required element: the business associate must make sure any subcontractor with access to PHI agrees to the same restrictions and conditions. Ask the courier which runs go to partner carriers or contract drivers and request proof that those parties signed matching terms.

Need this delivered today?

Power House Courier runs HIPAA-compliant, UN3373-certified specimen and medical deliveries 24/7 across California, Arizona and Texas. A dispatcher answers in under 15 minutes.

See our medical courier service โ†’

Sources

To talk through a courier setup for your facility, call dispatch at (323) 744-1900 or request a quote.

Last reviewed: September 2026 by the Power House Courier dispatch team.

Power House Courier
Power House Courier

Critical logistics across the USA โ€” same day courier, medical, legal, AoG, and nationwide trucking. Available 24/7.

๐Ÿ“– Keep Reading

Related Articles

Ready for same day courier service
or same day trucking across the USA?

Power House Courier โ€” critical logistics for AoG, organ transport, legal, medical & nationwide freight. Available every hour of every day.

WhatsApp Text (323) 744-1900 Email Us