Every specimen your couriers pick up carries your patients' information with it.
The tube label and the requisition form usually show the patient's name, the test ordered, and the ordering doctor. Under HIPAA, all of that is protected health information (PHI). In many cases, that makes your courier responsible for protecting it too, and your lab responsible for making sure they do.
Many labs only find out how well a courier handles PHI when something goes wrong.
A specimen goes missing, or an auditor asks how you oversee your vendors, and the courier can't produce the records you need.
In this article, we'll cover when a courier counts as a Business Associate under HIPAA, where patient information shows up in delivery records, what your business associate agreement (BAA) should require, and what a courier's delivery records should be able to prove.
This article is general information, not legal advice. Every operation is different, so talk to a healthcare lawyer about your specific situation.
Key takeaways
- If a courier records, stores, or sends patient information for your lab, HIPAA likely treats them as a Business Associate. That means your lab needs a BAA with them before sharing that information.
- Patient information doesn't stay on the tube label. It often ends up in your couriers' manifests, driver notes, delivery photos, and delivery software.
- The easiest way to lower your risk is to keep patient details out of courier records. Ask couriers to track each specimen by its barcode or accession number instead of the patient's name.
- A signed BAA only protects your lab if the courier can actually follow it. Check how they secure their systems, report incidents, and manage their own partners.
- Your couriers' delivery records should show who had each specimen, when, and where at every handoff. That applies to their own drivers and any partners they use.
When Is Your Specimen Courier a Business Associate Under HIPAA?
Your lab is a covered entity under HIPAA. HIPAA also applies to your Business Associates. A Business Associate is a company that handles patient information on your behalf. Handling includes creating, receiving, storing, or sending that information.
Before you share patient information with a Business Associate, you need a BAA in place. Without one, your lab can be held responsible for the disclosure, even if the courier never misuses the information.
The exception for couriers that only carry packages
HIPAA has a narrow exception for companies that only move information from one place to another. Regulators call it the conduit exception. The U.S. Postal Service is the standard example, and some private couriers can qualify too.
The idea is simple. If a courier picks up a sealed bag, drops it at your lab, and never sees, records, or stores anything about what's inside, they're acting a lot like a mail carrier. In that case, they may not be a Business Associate.
When couriers usually count as Business Associates
Most specimen couriers do more than carry sealed bags. Once a courier writes down or stores patient information, the exception gets much harder to rely on. Here are some common examples:
- Their manifests list patient names or the tests ordered.
- Their drivers scan or take photos of requisition forms at pickup.
- Their dispatchers type specimen or patient details into delivery software.
- They keep delivery records that connect a patient to your lab or a doctor.
- They also handle tasks for you like sorting specimens, managing collection kits, or bringing results back to doctors' offices.
In each of these cases, the courier is keeping or sending patient information. That's usually what makes a courier a Business Associate.
Why a BAA is only the starting point
Even when a courier might qualify for the exception, most labs require a BAA from every specimen courier as a matter of policy. That's a sensible default.
But a signed BAA only protects your lab if the courier can actually do what it says. So the more useful question is whether each courier's operation can keep those promises. Your legal team can decide how a courier should be classified. Your compliance and operations teams need to check that the courier can follow through.
Paper counts too. HIPAA's security rules focus on electronic information, but its privacy and breach rules also cover paper. If a courier loses a bag of paper requisition forms, that can still be a breach your lab has to deal with.
Where Patient Information Shows Up in Courier Delivery Records
It's easy to think of PHI as the label on the tube. But your patients' information often ends up in the paperwork, apps, and photos around each delivery too. Those are the records you'll need to see if something goes wrong.
Here are the most common places it appears, and what to ask your couriers to do about it:
Home pickups are easy to overlook. A pickup at a doctor's office doesn't say anything about a specific patient. A pickup at someone's house does, because the address alone shows that person used a lab service.
Ask couriers to keep patient details out of their records
HIPAA expects Business Associates to use only the patient information they need to do the job. This is called the minimum necessary standard.
For a courier, the job is to pick up the specimen, deliver it on time, and prove who had it along the way. To do that, a driver needs a pickup address, a time window, a specimen or bag ID, and a drop-off location. They almost never need the patient's name.
The simplest approach is to have couriers track each specimen by its barcode or accession number. Your LIS already links that number to the patient, so the courier's records don't have to. If a driver's phone gets lost, far less of your patients' information is at risk. Ask your legal team how your specific IDs are treated, since some numbers can still count as PHI.
What Your BAA Should Require Couriers to Do
A BAA is a contract, but most of what it covers happens in the courier's daily operations. The exact terms will depend on your lab. Here's what to look for in the agreement, and what to check before you sign.
Protect patient information in their systems
HIPAA's Security Rule asks Business Associates to protect any patient information they keep electronically. When you review a courier, ask whether they:
- Have done a risk assessment. They should know where patient information lives in their operation and what could go wrong, and update that review when their systems change.
- Control who can see what. Every dispatcher and driver should have their own login, and each person should only see the deliveries they work on.
- Secure driver phones. Phones should lock with a passcode, and the courier should be able to act quickly if one is lost or stolen.
- Train their team. Drivers and dispatchers should know what counts as patient information and what to do if something goes wrong.
- Keep written policies. HIPAA requires Business Associates to keep this documentation for six years. Ask to see it.
Report problems to your lab quickly
Your BAA should require couriers to report breaches and security incidents to you. Common examples are a lost cooler, a stolen driver phone, or a specimen delivered to the wrong place.
HIPAA requires Business Associates to notify the covered entity without unreasonable delay, and no later than 60 days after discovering a breach. Many labs set a much shorter deadline in their BAA. You'll also want the courier's records to have enough detail to explain what happened.
Hold their partners to the same standard
Ask each courier whether they hand specimens to subcontracted couriers during busy periods. If they do, those subcontractors may need to sign a BAA with the courier. The same applies to any software vendor that stores patient information for them. If a subcontractor causes a breach, it's still your patients' information.
Give your lab access to records
Your BAA should give you access to relevant delivery records when you need them, including during an HHS investigation. It should also require the courier to return or destroy any patient information when the contract ends. Both are much easier when the courier's records don't contain patient details in the first place.
What Your Couriers' Delivery Records Should Prove, and How Onfleet Helps
HIPAA doesn't give labs a checklist for courier delivery records. But when a specimen goes missing or an auditor asks how you oversee your couriers, the questions are almost always the same:
- Who picked up the specimen, and was it the courier's own driver or a partner?
- When and where was it picked up?
- Which specimens or bags were in the pickup?
- Where did it go along the way, and did anyone else handle it?
- When and where was it delivered, and who received it?
- What condition was it in when it arrived?
If you can get those answers for any delivery in a few minutes, your lab is in a strong position. If they're spread across paper logs, text messages, and each courier's separate system, an audit or investigation will be slow and stressful.
This gets harder when you work with several couriers. Each one may track different details and store them in a different place. Your patients see one lab, so every courier should create the same record.
How Onfleet supports HIPAA-ready specimen delivery
Onfleet is an AI-powered delivery orchestration platform that labs use to manage specimen pickups and deliveries with their internal drivers and third-party delivery partners. It gives your lab a complete delivery record for every specimen, without storing patient information.
- A chain of custody for every handoff. Drivers scan specimen or bag barcodes at pickup and drop-off. Each scan is timestamped and tied to the driver and location.
- Proof of delivery you can rely on. Drivers can capture photos, signatures, and notes, based on what each type of delivery requires.
- One view of every courier. Your team can track every specimen run as it happens, whether your own drivers or a delivery partner handles it. Records are captured the same way for both, so every courier is held to the same standard.
- Records you can pull when you need them. Delivery data is stored in one place, so you can look up a specific delivery or export records for an audit.
- Security built for healthcare. Onfleet offers a BAA, has a SOC 2 Type II report, and uses a no-PHI data model, which means it's designed not to store protected health information.
When you need more capacity, Onfleet Connect gives you access to 150+ vetted couriers, and their deliveries show up in the same view as your own drivers. AI-powered route optimization can also re-plan routes when STAT pickups come in, so tight lab cutoffs are easier to hit.
How Bayshore HealthCare stays audit-ready
Bayshore HealthCare delivers medications and medical supplies to patients across Canada under strict government contracts, and those deliveries are audited regularly. Auditors can pick out a batch of orders, sometimes 14 at a time, and ask for proof of delivery on each one. Bayshore pulls that proof straight from Onfleet.
Some of Bayshore's deliveries carry heavy documentation rules. Narcotics and controlled substances need a three-point chain of custody and ID verification at the door. With Onfleet, Bayshore grew from about 300 to 2,000 orders a day while keeping those records ready for auditors across every location.
Bayshore delivers medications, not lab specimens. But when an auditor asks your lab to prove what happened to a specific delivery, you'll face the same question. Read the full case study.
If your lab is part of a larger network of hospitals, labs, and clinics, read our guide to managing last-mile delivery across a health system.
Want to see how Onfleet can help your lab keep every specimen courier accountable Contact our sales team to talk through your workflows and security requirements or start a free trial.
Frequently Asked Questions About HIPAA Compliance for Lab Specimen Couriers
Does a lab need a business associate agreement (BAA) with its specimen courier?
In most cases, yes. A lab usually needs a BAA with its specimen courier if the courier records, stores, or sends patient information on the lab's behalf. That includes manifests with patient names, photos of requisition forms, or patient details in delivery software. HIPAA has a narrow exception for couriers that only carry sealed packages, but most labs require a BAA from every courier as policy. Your legal team can confirm how each courier should be classified. Onfleet offers a BAA to healthcare customers and uses a no-PHI data model, so labs can run specimen delivery without storing patient information in the platform.
How can a lab check whether its specimen couriers are HIPAA compliant?
A lab can check whether its specimen couriers are HIPAA compliant by reviewing how each courier handles patient information day to day, beyond the signed BAA. Ask whether they've done a risk assessment, how they control access to delivery records, how they secure driver phones, how quickly they report incidents, and whether their own subcontractors sign BAAs. Then ask for sample delivery records to see what they actually capture. Labs that manage specimen delivery on Onfleet can see every delivery from their internal drivers and delivery partners in one place, with the same records for each.
What should a chain of custody record for lab specimen delivery include?
A chain of custody record for lab specimen delivery should show who picked up each specimen, when and where it was picked up, which specimens or bags were included, every handoff along the way, and when, where, and by whom it was received. Many labs also want a record of the specimen's condition on arrival. The record should look the same no matter which courier handled the run. Onfleet captures timestamped barcode scans at pickup and drop-off, real-time location tracking, and proof of delivery such as photos, signatures, and notes for internal drivers and delivery partners alike.
Can proof-of-delivery photos create HIPAA risk for labs?
Yes, proof-of-delivery photos can create HIPAA risk for labs if a tube label, requisition form, or patient name is visible in the picture. That photo becomes patient information stored in the courier's records. Labs should ask couriers to photograph the sealed bag or the drop-off location, and never the specimen labels or paperwork. Onfleet lets you set proof-of-delivery requirements by delivery type, so you can require a photo of the drop-off or a signature from the receiving lab without capturing patient details.
What should labs look for in specimen delivery software?
Labs should look for specimen delivery software that creates a complete chain of custody without storing patient information. Key features include barcode scanning at every handoff, timestamped and location-tracked delivery records, flexible proof of delivery, one view of internal drivers and delivery partners, and easy access to records for audits. On the security side, ask whether the vendor will sign a BAA and whether it has a SOC 2 Type II report. Onfleet offers all of these, along with AI-powered route optimization for STAT pickups and access to 150+ vetted couriers through Onfleet Connect.