HIPAA Compliance
HIPAA CompliantOur commitment to protecting patient privacy
Effective: January 2026
Our HIPAA Compliance Commitment
E & B Express Courier, LLC ("EBX Couriers") operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and its implementing regulations. We are committed to maintaining the highest standards of privacy and security when handling Protected Health Information (PHI) during the transportation of medical materials.
Encrypted Systems
All data encrypted in transit and at rest using industry-standard protocols
Chain of Custody
Documented tracking from pickup to proof of delivery for complete accountability
Annual Training
100% of staff are HIPAA certified with ongoing compliance education
1. Business Associate Relationship
1.1 HIPAA Business Associate Agreement (BAA)
EBX Couriers executes a Business Associate Agreement with all healthcare providers, laboratories, hospitals, and other Covered Entities that engage our services. The BAA:
- Defines the permitted uses and disclosures of PHI
- Establishes our obligations to safeguard PHI
- Outlines reporting requirements for security incidents
- Describes termination procedures and PHI return/destruction protocols
2. PHI We May Access
In the course of providing medical courier services, EBX Couriers may incidentally access or receive PHI, including:
- Patient names and medical record numbers on shipping labels
- Specimen identification information
- Delivery instructions related to patient care urgency
- Information about the type of medical materials being transported
We implement strict protocols to minimize unnecessary access to PHI and limit disclosure to only what is necessary for delivery fulfillment.
3. HIPAA Security Measures
3.1 Administrative Safeguards
- Security Officer: Designated privacy and security officer responsible for HIPAA compliance
- Risk Assessments: Annual HIPAA security risk assessments and mitigation plans
- Policies and Procedures: Comprehensive written policies covering all HIPAA requirements
- Workforce Training: Mandatory annual HIPAA training for all employees with documented completion
- Sanctions Policy: Disciplinary actions for HIPAA violations, up to and including termination
- Background Checks: Pre-employment screening for all drivers and personnel
3.2 Physical Safeguards
- Facility Access Controls: Restricted access to facilities with key card systems and surveillance
- Secure Storage: Locked cabinets for sensitive documents and materials awaiting delivery
- Vehicle Security: Locked compartments in all delivery vehicles; GPS tracking for asset monitoring
- Disposal Procedures: Secure shredding of documents containing PHI
3.3 Technical Safeguards
- Access Controls: Unique user IDs, password requirements, automatic session timeouts
- Encryption: TLS/SSL encryption for data in transit; AES-256 encryption for data at rest
- Audit Logs: Comprehensive logging of all PHI access and system activities
- Transmission Security: Secure communication channels for all electronic PHI exchanges
- Mobile Device Security: Driver devices encrypted with remote wipe capability
4. Chain of Custody Documentation
EBX Couriers maintains meticulous chain of custody records for all deliveries involving medical materials:
- Pickup Documentation: Date, time, location, and signature of releasing party
- Transit Records: GPS tracking data, driver identity, and handling conditions
- Delivery Confirmation: Proof of delivery with recipient signature or photo verification
- Retention: All chain of custody records retained for 7 years per HIPAA requirements
5. Workforce Training and Certification
5.1 Initial Training
All new employees complete comprehensive HIPAA training before handling any medical materials:
| Training Module | Duration | Status |
|---|---|---|
| HIPAA Privacy Rule | 2 hours | ✓ Required |
| HIPAA Security Rule | 2 hours | ✓ Required |
| PHI Handling Protocols | 1 hour | ✓ Required |
| Breach Response | 1 hour | ✓ Required |
| Chain of Custody | 1 hour | ✓ Required |
5.2 Ongoing Education
- Annual refresher training for all workforce members
- Immediate training following any policy or regulatory changes
- Regular security awareness reminders and updates
- Certification verification and documentation maintained in personnel files
6. Breach Notification Procedures
In the unlikely event of a security incident or breach involving PHI:
6.1 Immediate Response
- Security incident identified and documented
- Containment measures implemented immediately
- Designated Security Officer notified within 1 hour
- Investigation initiated to determine scope and impact
6.2 Notification Timeline
- To Covered Entity: Notice without unreasonable delay, no later than 10 business days from discovery
- Content: Description of breach, PHI involved, mitigation steps, and contact information
- Documentation: Full incident report maintained for 6 years
7. Permitted Uses and Disclosures of PHI
EBX Couriers uses and discloses PHI only as permitted by our Business Associate Agreements:
- Service Delivery: Using PHI as necessary to fulfill delivery services requested by the Covered Entity
- Management Activities: Internal operations directly related to contracted services
- Legal Requirements: Disclosures required by law or as directed by the Covered Entity
We do NOT:
- Use PHI for marketing purposes
- Sell PHI to third parties
- Disclose PHI to unauthorized parties
- Use PHI for any purpose beyond the scope of our BAA
8. Subcontractors and Downstream Business Associates
Any subcontractors or vendors who may access PHI are required to:
- Execute a Business Associate Agreement with EBX Couriers
- Agree to the same HIPAA obligations and restrictions
- Implement appropriate safeguards for PHI
- Report any security incidents or breaches immediately
9. Patient Rights
As a Business Associate, we support the rights of individuals regarding their PHI:
- Access: We provide PHI to Covered Entities upon request to support patient access rights
- Amendment: We cooperate with Covered Entities to amend PHI as required
- Accounting of Disclosures: We maintain records and assist Covered Entities in providing accounting of disclosures
Note: Individuals should direct requests to exercise HIPAA rights to their healthcare provider (Covered Entity), not directly to EBX Couriers.
10. Audits and Compliance Verification
EBX Couriers cooperates fully with HIPAA compliance audits and reviews:
- Covered Entities may audit our HIPAA compliance upon reasonable notice
- We provide documentation of policies, training records, and security measures
- We participate in regulatory investigations and audits as required
- Annual internal audits conducted to ensure ongoing compliance
11. Termination and PHI Return/Destruction
Upon termination of services or expiration of our Business Associate Agreement:
- All PHI is returned to the Covered Entity or securely destroyed per their instructions
- Retention of PHI is only permitted if required by law (e.g., 7-year record retention)
- Certificate of destruction provided upon request
- Ongoing confidentiality obligations survive termination
12. Contact for HIPAA Matters
For questions about our HIPAA compliance practices or to report a security concern:
Privacy & Security Officer
E & B Express Courier, LLC
Metairie, Louisiana
Email: Exbcouriers@gmail.com
Phone: 337-400-8118
24/7 Incident Hotline: 337-400-8118
Last Updated: January 2026
This HIPAA Compliance Statement is a public-facing summary. Full BAA terms are negotiated individually with each Covered Entity.