HIPAA and Medical Deliveries: What Managers Need to Know

How HIPAA applies to couriers that carry PHI, why a BAA matters, and the safeguards a compliant medical delivery partner should have in place.
If your courier handles specimens, records, or anything that identifies a patient, HIPAA is in play. Understanding how it applies helps you choose a partner that protects patients — and shields your organization from liability. This is a plain-language overview, not legal advice; confirm specifics with your compliance officer.
Why couriers are covered
A courier that transports Protected Health Information (PHI) on your behalf is typically a business associate under HIPAA. That means they have real obligations to safeguard the data they carry — and you have an obligation to put an agreement in place before sharing it.
The Business Associate Agreement (BAA)
The BAA is the contract that makes the relationship compliant. It should spell out:
- How the courier may use and disclose PHI (only to perform the delivery).
- The safeguards they'll maintain to protect it.
- Breach-notification duties if something goes wrong.
- Return or destruction of PHI when the relationship ends.
No BAA, no PHI. If a provider won't sign one, that's a dealbreaker — sharing PHI without it puts the exposure on you.
Safeguards a compliant courier should have
HIPAA groups protections into administrative, physical, and technical safeguards. In courier terms, look for:
- Administrative: workforce training, access limited to those who need it, documented policies.
- Physical: sealed containers, secure vehicles, controlled handoffs to named recipients.
- Technical: access-controlled systems, audit trails, and secure handling of any digital PHI (like delivery records).
The minimum-necessary principle
Only the information needed to complete the delivery should travel with it or appear on a manifest. Full clinical detail rarely needs to be exposed to a driver — labels and records should carry the minimum necessary to route and deliver safely.
Proof, custody, and breach readiness
Compliance isn't only about preventing problems — it's about being able to show what happened. A strong partner maintains chain-of-custody records, proof of delivery, and audit trails, and has a defined process to notify you quickly if PHI is ever exposed.
Questions to ask before you sign
- Will you sign a BAA?
- How is PHI protected in transit and in your systems?
- Who has access to delivery records, and is that access logged?
- What's your breach-notification process and timeline?
- How do you train drivers on privacy and handling?
Ready247 operates with HIPAA awareness built in — BAAs with clients, trained drivers, chain-of-custody on every shipment, and access-controlled records with proof of delivery. It's the posture your patients expect and your compliance team can stand behind.
Ready to move it the right way?
Request an on-demand or scheduled medical pickup across Greater Boston.


