What HIPAA actually requires of a courier
In short
There is no HIPAA certification. HIPAA-compliant courier services means four concrete things: a signed business associate agreement, access controls on protected health information, an audit trail for every handover, and breach notice to your client inside 60 days.
- A business associate is any company that creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity. Carrying a labeled prescription bag or a specimen cooler usually puts you in that category.
- The "mere conduit" exception is real but narrow. It covers carriers that only transport, with no more than random, infrequent access. A courier that photographs labels and keeps patient-level delivery records is doing more than transporting.
- Business associates are directly liable to the HHS Office for Civil Rights, not only to the client who signed the agreement.
- Encryption is "addressable" under the Security Rule, not flatly required. You either implement it or document in writing why an equivalent measure is reasonable in your setting.
- You must notify your covered entity client of a breach without unreasonable delay and no later than 60 calendar days from discovery.
- HIPAA documentation (policies, risk analysis, signed agreements) must be retained six years from creation or last effective date, whichever is later.
Conduit or business associate
This is a summary written for operators, not legal advice. Get a lawyer who knows your state and your contracts to read your agreement before you sign it.
With that said, couriers ask first whether HIPAA applies to them at all. A covered entity is a provider, a health plan or a clearinghouse: a pharmacy, a lab, a hospital. You are almost never one of those. What you can be is a business associate, meaning a company handling PHI on a covered entity's behalf.
Against that sits the conduit exception. The postal service and the large parcel carriers move sealed packages without meaningful access to the contents, and that has consistently been treated as transport rather than handling. The exception is narrow, and the test is access, not intent. Three things push a medical courier out of it:
- You hold identifiable information in your own systems. A manifest line pairing a patient name with an address and a pharmacy is PHI, and it sits in your dispatch system, your driver's phone and probably your email.
- You capture proof that includes PHI. A signature against a patient name, a photo of a prescription label, a note saying the patient was out at dialysis.
- You store it. A conduit moves and forgets. If you can answer a question about a delivery from four months ago, you are maintaining PHI.
In practice most clients will not argue the point. A pharmacy chain hands you an agreement as a condition of the contract and moves on.
What the agreement actually commits you to
The agreement is not a formality you file. It makes four specific obligations enforceable against you, and all four have operational weight.
Safeguards. Administrative, physical and technical safeguards for electronic PHI: a written risk analysis, workforce training, a sanctions policy, access controls. The Security Rule splits these into "required" and "addressable". Addressable does not mean optional. It means you assess it and either implement it or write down why an alternative is reasonable. Encryption in transit sits in that second bucket, which is why "we looked at it and decided not to" with nothing in writing is the worst available answer.
Minimum necessary. You may use and disclose only what the job requires. This is the clause that bites couriers hardest, and the next section is about it.
Subcontractors. If you use 1099 drivers, a partner network for overflow, a third-party dispatch platform or an offshore support team, each needs a written agreement from you carrying the same protections. One missing agreement in that chain is a straightforward finding.
Access and accounting. You must be able to find and produce the PHI you hold about a named individual. If your record of a delivery is a photo in a driver's camera roll, you cannot.
Access control is an operational problem, not an IT one
Minimum necessary sounds like a database permissions question. For a courier it is a question about what the driver can see on a phone. A driver delivering to a home needs the name, the address, the access instructions and whether ID is required at the door. Nobody in the field needs a diagnosis, a drug name, a date of birth, or the other eleven stops' worth of patient detail in the same list. Three controls do most of the work:
- Scope the record to the stop. The driver sees the job in front of them, not the whole day's manifest. This is a configuration decision, and most dispatch tools default the wrong way.
- Make the field app the only place PHI lives. The moment a route goes out as a PDF on WhatsApp or a printed sheet on a clipboard, you have lost both the access control and the audit trail, and you cannot revoke either when the driver leaves.
- Unique logins, no shared devices. Two drivers on one account makes every audit entry useless, because you cannot say who viewed what. Terminating access the day someone leaves is a Security Rule requirement and is impossible with a shared password.
This conflicts with how routes have always been run. Dispatchers want the whole list visible so they can reshuffle. You can keep that and still scope what the driver's phone shows, but it takes a deliberate decision.
The 60-day clock starts when you find out
A breach is an impermissible acquisition, access, use or disclosure of PHI. The regulation presumes any such event is a breach unless you can show a low probability that the information was compromised, assessed against four factors: the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and how far the risk has been mitigated.
For a courier the realistic events are mundane. A cooler left on the wrong doorstep. A bag signed for by a neighbor. A phone lost at a fuel stop. A manifest emailed to the wrong clinic.
You have 60 calendar days from discovery to notify your covered entity client, sooner if the agreement says so, which it usually does. Your client then has its own 60-day clock to notify patients, so a courier that sits on a problem for 55 days has destroyed its client's ability to comply. Discovery means the first day any employee knew or reasonably should have known, not the day it reached your compliance folder.
There is one real escape, and it is worth engineering for. If the PHI was secured to the standard HHS specifies, encrypted rather than merely password-protected, a lost device is not a breach of unsecured PHI and the duty does not arise. A phone with full-disk encryption and remote wipe is an inconvenience. The same phone with a route list in a photo album is a notifiable event.
Most of compliance is proving what happened
Here is the part that gets missed. Almost nothing in the rules asks you to handle a package differently from how a careful courier already handles it. What they ask is that you demonstrate how you handled it, months later, to someone who was not there. An auditor does not watch your driver. They read your record. As far as compliance goes, the record is not documentation of the work. It is the work.
If you cannot reconstruct a delivery from your own system, you did not do it compliantly. You just did not get caught.
Pick a delivery from this morning and try to answer these six questions in five minutes, using only what is in your system:
- Who was assigned the job, and who actually performed it?
- Who viewed the patient's details, and when?
- What time did custody transfer at pickup, and to whom at delivery?
- What proof was captured, and does it contain more PHI than it needed to?
- If the recipient was not the patient, is the reason recorded?
- Can you produce all of that without opening anyone's personal phone?
Most operations fail two or three of those. The usual culprits are a route that went out by email, proof stored as a photo on a device you do not control, and a handover with a scrawled signature but no timestamp. None are handling failures. They are record failures, and they are what turns a clean delivery into an unprovable one.
Which is why electronic proof of delivery matters more in healthcare work than in any other kind of courier operation. The handling was always fine. The proof is what you are selling.
OkPilot keeps the job record, the access trail and the proof attached to the task rather than to a driver's phone, which is the part most pharmacy delivery operations retrofit after their first client audit.
See OkPilot running your own operation
A live walkthrough with a real person, configured to your jobs on the call. About ten minutes. Setup takes around 48 hours.