HIPAA Compliance

HIPAA Compliant

Our commitment to protecting patient privacy

Effective: January 2026

Our HIPAA Compliance Commitment

E & B Express Courier, LLC ("EBX Couriers") operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and its implementing regulations. We are committed to maintaining the highest standards of privacy and security when handling Protected Health Information (PHI) during the transportation of medical materials.

Encrypted Systems

All data encrypted in transit and at rest using industry-standard protocols

Chain of Custody

Documented tracking from pickup to proof of delivery for complete accountability

Annual Training

100% of staff are HIPAA certified with ongoing compliance education

1. Business Associate Relationship

1.1 HIPAA Business Associate Agreement (BAA)

EBX Couriers executes a Business Associate Agreement with all healthcare providers, laboratories, hospitals, and other Covered Entities that engage our services. The BAA:

  • Defines the permitted uses and disclosures of PHI
  • Establishes our obligations to safeguard PHI
  • Outlines reporting requirements for security incidents
  • Describes termination procedures and PHI return/destruction protocols

Need a Business Associate Agreement?

We execute BAAs with all healthcare partners. Our standard agreement complies with all HIPAA requirements and can be customized to meet your organization's specific needs.

2. PHI We May Access

In the course of providing medical courier services, EBX Couriers may incidentally access or receive PHI, including:

  • Patient names and medical record numbers on shipping labels
  • Specimen identification information
  • Delivery instructions related to patient care urgency
  • Information about the type of medical materials being transported

We implement strict protocols to minimize unnecessary access to PHI and limit disclosure to only what is necessary for delivery fulfillment.

3. HIPAA Security Measures

3.1 Administrative Safeguards

  • Security Officer: Designated privacy and security officer responsible for HIPAA compliance
  • Risk Assessments: Annual HIPAA security risk assessments and mitigation plans
  • Policies and Procedures: Comprehensive written policies covering all HIPAA requirements
  • Workforce Training: Mandatory annual HIPAA training for all employees with documented completion
  • Sanctions Policy: Disciplinary actions for HIPAA violations, up to and including termination
  • Background Checks: Pre-employment screening for all drivers and personnel

3.2 Physical Safeguards

  • Facility Access Controls: Restricted access to facilities with key card systems and surveillance
  • Secure Storage: Locked cabinets for sensitive documents and materials awaiting delivery
  • Vehicle Security: Locked compartments in all delivery vehicles; GPS tracking for asset monitoring
  • Disposal Procedures: Secure shredding of documents containing PHI

3.3 Technical Safeguards

  • Access Controls: Unique user IDs, password requirements, automatic session timeouts
  • Encryption: TLS/SSL encryption for data in transit; AES-256 encryption for data at rest
  • Audit Logs: Comprehensive logging of all PHI access and system activities
  • Transmission Security: Secure communication channels for all electronic PHI exchanges
  • Mobile Device Security: Driver devices encrypted with remote wipe capability

4. Chain of Custody Documentation

EBX Couriers maintains meticulous chain of custody records for all deliveries involving medical materials:

  • Pickup Documentation: Date, time, location, and signature of releasing party
  • Transit Records: GPS tracking data, driver identity, and handling conditions
  • Delivery Confirmation: Proof of delivery with recipient signature or photo verification
  • Retention: All chain of custody records retained for 7 years per HIPAA requirements

5. Workforce Training and Certification

5.1 Initial Training

All new employees complete comprehensive HIPAA training before handling any medical materials:

Training ModuleDurationStatus
HIPAA Privacy Rule2 hours✓ Required
HIPAA Security Rule2 hours✓ Required
PHI Handling Protocols1 hour✓ Required
Breach Response1 hour✓ Required
Chain of Custody1 hour✓ Required

5.2 Ongoing Education

  • Annual refresher training for all workforce members
  • Immediate training following any policy or regulatory changes
  • Regular security awareness reminders and updates
  • Certification verification and documentation maintained in personnel files

6. Breach Notification Procedures

In the unlikely event of a security incident or breach involving PHI:

6.1 Immediate Response

  • Security incident identified and documented
  • Containment measures implemented immediately
  • Designated Security Officer notified within 1 hour
  • Investigation initiated to determine scope and impact

6.2 Notification Timeline

  • To Covered Entity: Notice without unreasonable delay, no later than 10 business days from discovery
  • Content: Description of breach, PHI involved, mitigation steps, and contact information
  • Documentation: Full incident report maintained for 6 years

7. Permitted Uses and Disclosures of PHI

EBX Couriers uses and discloses PHI only as permitted by our Business Associate Agreements:

  • Service Delivery: Using PHI as necessary to fulfill delivery services requested by the Covered Entity
  • Management Activities: Internal operations directly related to contracted services
  • Legal Requirements: Disclosures required by law or as directed by the Covered Entity

We do NOT:

  • Use PHI for marketing purposes
  • Sell PHI to third parties
  • Disclose PHI to unauthorized parties
  • Use PHI for any purpose beyond the scope of our BAA

8. Subcontractors and Downstream Business Associates

Any subcontractors or vendors who may access PHI are required to:

  • Execute a Business Associate Agreement with EBX Couriers
  • Agree to the same HIPAA obligations and restrictions
  • Implement appropriate safeguards for PHI
  • Report any security incidents or breaches immediately

9. Patient Rights

As a Business Associate, we support the rights of individuals regarding their PHI:

  • Access: We provide PHI to Covered Entities upon request to support patient access rights
  • Amendment: We cooperate with Covered Entities to amend PHI as required
  • Accounting of Disclosures: We maintain records and assist Covered Entities in providing accounting of disclosures

Note: Individuals should direct requests to exercise HIPAA rights to their healthcare provider (Covered Entity), not directly to EBX Couriers.

10. Audits and Compliance Verification

EBX Couriers cooperates fully with HIPAA compliance audits and reviews:

  • Covered Entities may audit our HIPAA compliance upon reasonable notice
  • We provide documentation of policies, training records, and security measures
  • We participate in regulatory investigations and audits as required
  • Annual internal audits conducted to ensure ongoing compliance

11. Termination and PHI Return/Destruction

Upon termination of services or expiration of our Business Associate Agreement:

  • All PHI is returned to the Covered Entity or securely destroyed per their instructions
  • Retention of PHI is only permitted if required by law (e.g., 7-year record retention)
  • Certificate of destruction provided upon request
  • Ongoing confidentiality obligations survive termination

12. Contact for HIPAA Matters

For questions about our HIPAA compliance practices or to report a security concern:

Privacy & Security Officer
E & B Express Courier, LLC
Metairie, Louisiana
Email: Exbcouriers@gmail.com
Phone: 337-400-8118
24/7 Incident Hotline: 337-400-8118

Last Updated: January 2026
This HIPAA Compliance Statement is a public-facing summary. Full BAA terms are negotiated individually with each Covered Entity.

base44
Edit with Base44