Guides
Which HIPAA records must a US specimen courier keep, and for how long?
Medical courier business operations records: which HIPAA files to keep, from business associate agreements to chain-of-custody logs, and how long each must survive.
What to take away
- Medical courier business operations run on a short list of records: business associate agreements, driver confidentiality sign-offs, training logs, chain-of-custody logs, and electronic protected health information safeguards.
- No single federal rule states a retention period for every courier document. HIPAA sets the duties; HHS records practice and state law set the clocks.
- Business associate agreements should stay for the life of the contract plus six years after it ends.
- Driver confidentiality sign-offs and training records should be kept for at least six years after the driver leaves.
- Chain-of-custody logs should be held for at least six years, and longer where a state health department, CLIA lab contract, or payer audit requires it.
- Electronic protected health information records need access logs, encryption records, and risk analyses kept under the Security Rule, not just a filing cabinet.
What the HIPAA Privacy Rule and Security Rule require a courier to hold
A specimen courier is usually a business associate, not a covered entity. That single fact decides which records you must hold. The Privacy Rule governs how protected health information is used and disclosed, including the limited ways a courier may see a patient name, test order, or requisition.
The HIPAA Privacy Rule requirements apply to the information you carry and to the records that prove you handled it correctly.
The Security Rule covers the electronic side. Any ePHI you create, receive, or transmit falls under the Security Rule requirements for safeguarding electronic protected health information. A scanned requisition, a dispatch note with a patient identifier, and a delivery photo all count. That means written policies, assigned responsibility, and evidence you followed them.
The summary of Privacy Rule laws and regulations helps define which documents count as covered. In practice, a courier's covered records are the ones that link a patient, a specimen, and a route. If a document can identify a patient or a test, treat it as protected.
HIPAA does not publish one retention table for couriers. Instead, it sets minimum duties, and other rules fill the calendar. State health departments, CLIA lab contracts, and payer agreements often demand longer holds than HIPAA alone. Build your schedule to the longest clock that applies to a given client.
A courier that also draws or processes specimens may hold a CLIA certificate. That adds records for proficiency testing, personnel, and quality control. Keep those separate from HIPAA files so an inspector can find them fast.
Business associate agreements and the retention period behind them
A business associate agreement, or BAA, is the contract that lets a courier touch protected health information for a covered entity. Every lab, hospital, clinic, and imaging center you serve should have one on file before the first pickup. The BAA must describe permitted uses, require safeguards, and set breach reporting duties.
The retention period for a BAA is not stated in HIPAA as a fixed number of years. The practical rule: keep each signed BAA for the life of the contract plus six years after termination. Six years matches the HIPAA documentation window and satisfies most audits. If a client contract names a longer period, follow the contract.
Store BAAs by client, not by date alone. When a lab changes ownership or a hospital system merges, you need the version that was in force on the pickup date. A signed PDF with a version number and an effective date saves hours during a records request.
Do not let a BAA sit in an email inbox. Move it to a controlled folder with a renewal date. A missing BAA is the first finding in most HIPAA reviews of courier firms.
When you negotiate rates and liability, the BAA belongs with the rest of the paperwork. Treat it the way you treat your medical courier operations: signed, dated, and retrievable.
Driver confidentiality sign-offs and workforce training records
Every driver, dispatcher, and billing clerk who can see patient information should sign a confidentiality agreement. The sign-off confirms the person read your HIPAA policies and understands the penalties for a disclosure. Keep the signed page, not just a note that it happened.
New hires should sign before their first route. A driver who handles a specimen without a signed agreement creates a gap an auditor will notice. The same file should hold a background check where client contracts require one.
Training records need dates, topics, and attendee names. Annual HIPAA refresher training is the common standard, and many lab contracts require it. Keep each driver's training log for at least six years after employment ends.
A one-page log works. List the driver, the training date, the topic, and the trainer. Attach the sign-in sheet. If you use an online course, export the completion certificate into the same folder.
Terminated drivers still matter. Keep the confidentiality sign-off, training log, and any incident reports for six years after the last day worked. If a dispute or breach claim arrives later, that file is your defense.
Your onboarding sequence should mirror a compliance checklist for new owners, with the signed forms collected before the first specimen moves.
Chain-of-custody logs and how long each entry must survive
A chain-of-custody log tracks a specimen from pickup to delivery. It records who had the item, when, and where it went next. For couriers, the log is both an operations tool and a legal record.
Each entry needs the date and time, the pickup location, the receiving location, the handler's name or ID, and the condition of the package. If a specimen is temperature-sensitive, log the temperature check. If a seal is broken, note it and notify the client.
The retention period for chain-of-custody logs should be at least six years. Many labs and state health departments ask for longer, and some contracts require seven years. When two rules conflict, keep the longer one. A log that disappears after two years can cost you a client and a defense.
Electronic logs are fine if they are backed up and access-controlled. A dispatch app that overwrites old entries is not a record system. Export a read-only copy on a schedule and store it where drivers cannot edit it.
Paper logs still appear on rural routes and in hospital courier work. Scan them weekly. Keep the paper for one year, then rely on the scan if your policy allows, unless a client contract says otherwise.
Logs also feed your daily routine. The SOP checklist for daily operations should include a custody log review at the end of each shift.
Electronic protected health information records under the Security Rule
The Security Rule asks for more than a signed policy. It expects evidence: a risk analysis, a risk management plan, access controls, and audit logs. Each of those produces a record you must keep.
A risk analysis identifies where ePHI could be lost or exposed. Do one in writing, update it when you add software or routes, and keep each version. The retention period for risk analyses should be at least six years, matching the HIPAA documentation window.
Access logs show who opened a dispatch record or a scanned requisition. Keep them for at least six years. If a breach is suspected, the log is how you prove what happened and when.
Encryption records matter for laptops, phones, and dispatch tablets. Keep the device inventory, the encryption method, and the date each device was wiped or retired. Retired devices should have a wipe record on file.
Incident and breach records need their own folder. A breach log should show the date discovered, the people notified, and the corrective step. Keep breach records for at least six years, and longer if a state law or client contract requires it.
A written contingency plan, including backups and disaster recovery, is also a Security Rule record. Test the plan, then keep the test results. An untested plan is hard to defend.
How HHS records management practice sets a retention model
HHS does not run courier businesses, but its own records policy is a useful model. The HHS policy for records management treats records as evidence of activity, with defined schedules and destruction rules. Couriers can borrow that logic without copying federal schedules wholesale.
The HHS approach separates temporary records from permanent ones. A courier can do the same: keep operational logs for six years, keep corporate records like formation papers and tax filings longer, and destroy what has no legal or client value on a set date.
Destruction needs a record too. Note what was destroyed, when, and who approved it. A shred certificate or a deletion log protects you if a client later asks why a file is gone.
Records requests can reach a courier through several doors. A patient, a lawyer, or a reporter may file a request with a covered entity, which then touches your files through the FOIA process that shows how records requests reach a courier's files. Your BAA should say who answers such requests and how fast.
State rules sit on top of the federal model. Texas, California, Florida, New York, and Illinois each set their own health record and laboratory timelines. Check the state health department for every state you drive in, and note the longest period in your schedule.
A medical courier business operations retention schedule
Use this table as a starting draft. Adjust the years upward when a client contract or state rule demands more. The column on the right names the record that proves you complied.
| Document | Minimum retention period | Why it applies |
|---|---|---|
| Business associate agreement | Contract term plus 6 years | HIPAA documentation window and client audits |
| Driver confidentiality sign-off | 6 years after employment ends | Workforce confidentiality proof |
| HIPAA training log | 6 years after training | Annual training and client contract terms |
| Chain-of-custody log | 6 years, longer if a lab or state requires | Specimen tracking and dispute defense |
| Risk analysis and updates | 6 years per version | Security Rule evidence |
| Access and audit logs | 6 years | Breach investigation and Security Rule |
| Breach and incident records | 6 years, longer under state law | Notification and corrective action proof |
| Device encryption and wipe records | Life of device plus 6 years | ePHI safeguard evidence |
| Vehicle and temperature logs | 3 to 6 years | Client contract and specimen integrity |
| Corporate and tax records | 7 years or permanent | IRS and state business rules |
Before you file anything, run this checklist:
- Is a signed BAA on file for every covered entity client?
- Does each driver have a confidentiality sign-off and a dated training log?
- Are chain-of-custody logs exported and stored where drivers cannot edit them?
- Is there a current written risk analysis for ePHI systems?
- Are access logs, breach records, and device wipe records kept for six years?
- Does the schedule reflect the longest state or contract period you operate under?
- Is there a written destruction log for records you remove?
A retention schedule only works if someone owns it. Name one person to review the table each year and update it when a contract or state rule changes. That review is a record too.
Keep the schedule next to your financial files. The same discipline that governs your medical courier services applies to HIPAA records: capture the date, the owner, and the reason.
Finally, measure whether the system works. Late logs, missing sign-offs, and overdue renewals should show up in the metrics owners should track monthly. A retention schedule that no one checks is just paper.
Common questions
How long must a specimen courier keep a business associate agreement? Keep each signed BAA for the life of the contract plus six years after it ends. If a client contract names a longer period, follow the client contract.
Do chain-of-custody logs have a federal retention period? HIPAA does not set a single number for custody logs. Six years is the practical floor, and lab contracts or state health departments often require longer.
Are driver confidentiality sign-offs required by HIPAA? HIPAA requires workforce confidentiality and training, and a signed sign-off is the usual proof. Keep it for six years after the driver leaves.
What ePHI records does the Security Rule require a courier to keep? Keep the risk analysis, access logs, encryption and device wipe records, and breach files. Six years is the working retention period for each.
Can a courier destroy old records? Yes, once the longest applicable period ends. Record what was destroyed, when, and who approved it, so a later request can be answered.
Does state law override the six-year schedule? State health record and laboratory rules can require longer holds. Check every state you operate in and keep the longest period that applies.
