HIPAA and Bloodborne Pathogen Basics Every Medical Courier Needs

What HIPAA, OSHA's Bloodborne Pathogens Standard, and DOT Category B packaging rules actually require of couriers, sourced to HHS, OSHA, and PHMSA.

MedCourierPath Editorial Team
7 min read

Medical Courier Launch Kit: the 90-day path, templates, scripts, and your state's filing agency, in one document.

See the kit →
In This Article

Medical couriers sit under two main federal rule sets. HIPAA, administered by the U.S. Department of Health and Human Services, governs the protected health information printed on specimen labels, requisitions, and pharmacy paperwork you carry. OSHA's Bloodborne Pathogens Standard, 29 CFR 1910.1030, governs your occupational exposure to blood and other potentially infectious materials. A third layer, the Department of Transportation's Category B packaging rules for UN 3373 biological substances, covers how routine patient specimens are packaged for transport. You do not need to memorize the regulations, but a courier who can explain all three in plain language walks into client meetings with an immediate advantage.

This article explains what each rule set actually requires of a courier, where the official sources live, and what training clients expect to see. It is educational information, not legal or medical advice, and the regulations themselves always control.

Why does HIPAA apply to a courier who never opens a package?

HIPAA's Privacy and Security Rules protect individually identifiable health information held or transmitted by covered entities (providers, health plans, clearinghouses) and their business associates. The rules are administered and enforced by the HHS Office for Civil Rights, with official guidance at hhs.gov/hipaa.

A courier never needs to open anything to encounter protected health information. It is printed on the outside of the work: specimen labels carry patient names and dates of birth, lab requisitions carry diagnoses and test orders, pharmacy delivery manifests carry patient names, facility names, and medication details. If you can read it while doing your job, you are handling PHI.

Independent couriers who serve covered entities typically function as business associates or as subcontractors of one. In practice that means:

  • You will be asked to sign a business associate agreement (BAA). It is a standard contract obligating you to safeguard PHI, report breaches, and limit use of the information to the courier service itself. HHS publishes sample business associate provisions on its website.
  • You need reasonable safeguards on the road. Manifests face down, no photographing labels, vehicle locked at every stop, deliveries handed to authorized staff rather than left in open areas, and no discussion of what you carry with anyone outside the job.
  • You need to report problems fast. A lost manifest, a package delivered to the wrong facility, or a break-in involving specimen paperwork is the kind of event your client's compliance office must hear about from you immediately, not discover later.

What counts as PHI on a typical route?

Assume the following are all protected: patient names, dates of birth, medical record numbers, account numbers, test orders, diagnoses, medication names tied to a patient, and facility paperwork that links any of those together. The safe operating habit is simple: treat every document and label on your route as confidential, keep it out of sight, and hand it only to the people meant to receive it. Couriers do not need to parse the regulation's eighteen identifier categories; they need habits that would make any of them hard to leak.

What is a business associate agreement in plain language?

A BAA is the contract that extends HIPAA obligations from a covered entity to the vendors that touch PHI on its behalf. For a courier it typically promises that you will use the information only to perform deliveries, safeguard it, train the people who handle it, report security incidents and breaches, and return or destroy information when the engagement ends. Signing one is routine in this industry. Refusing to sign one usually ends the conversation, because your client cannot legally hand PHI-bearing work to an unwilling vendor. Read it, keep a copy, and honor it.

What does OSHA's Bloodborne Pathogens Standard actually require?

The Bloodborne Pathogens Standard, 29 CFR 1910.1030, published by the Occupational Safety and Health Administration at osha.gov, applies to occupational exposure to blood and other potentially infectious materials (OPIM). It was written with healthcare workers in mind, and it reaches anyone whose job can reasonably be anticipated to involve contact with those materials, which is why specimen couriers and the companies that employ them build their practices on it. Its core requirements:

  • An exposure control plan. A written plan identifying which tasks carry exposure risk and how the employer minimizes it. If you operate as a company, even a company of one with contract drivers, this document is yours to maintain and clients may ask to see it.
  • Universal precautions. The operating assumption that all human blood and OPIM are infectious, every time, regardless of source.
  • Engineering and work practice controls. For a courier this translates to: never open specimen packaging, transport specimens in rigid secondary containers, keep food and drink away from transport containers, and use gloves and a spill kit if a leak occurs rather than bare-handing it.
  • Training. Initial bloodborne pathogen training, and annual refreshers, covering how pathogens spread, what to do about spills, and how exposure incidents are handled. Online BBP courses are inexpensive and widely available; keep the certificate where you can produce it.
  • Hepatitis B vaccination and post-exposure follow-up. The standard requires employers to make the hepatitis B vaccine available to employees with occupational exposure and to provide a confidential medical evaluation after an exposure incident. Discuss your own situation with a healthcare provider.

What is UN 3373 Category B, and does the courier package it?

Routine patient specimens (blood draws, urine, swabs headed for diagnostic testing) generally ship as "Biological Substance, Category B" under UN 3373. The packaging rule, 49 CFR 173.199 in the U.S. hazardous materials regulations administered by the Pipeline and Hazardous Materials Safety Administration (phmsa.dot.gov), requires triple packaging: a leakproof primary container, leakproof secondary packaging with absorbent material, and rigid outer packaging marked with the UN 3373 diamond.

The lab or the collecting facility normally does the packaging, not the courier. The courier's obligations are practical: recognize what compliant packaging looks like, never open or repackage it, keep it upright and secured, maintain any required temperature range, and know that a leaking package is an exception event to report, not a mess to quietly fix. Category A substances (materials capable of causing permanent disability or life-threatening disease, shipped under stricter rules) are a different tier that ordinary route couriers should not be handling without specific hazmat training.

What training do clients actually ask for, and where do you get it?

The standard courier package is: a bloodborne pathogen certificate renewed annually, a HIPAA awareness certificate, and client-specific onboarding (their custody procedures, their software, their site rules). Both BBP and HIPAA awareness courses are available online from many commercial training providers, typically taking an hour or two each. No specific brand of training is required by regulation for couriers; what matters to clients is that the training happened, it is current, and you can produce the certificate. Some lab clients also train couriers on their own specimen handling procedures, and pharmacy clients commonly add signature-capture and controlled-substance handling rules.

What should happen after a spill or an exposure incident?

An exposure incident is contact with blood or OPIM through broken skin, eyes, nose, or mouth. The response pattern, drawn from the OSHA standard and standard industry practice:

  1. Wash the affected area immediately (soap and water for skin, flush for eyes or mucous membranes).
  2. Seek a medical evaluation promptly. The standard requires employers to make a confidential post-exposure evaluation available.
  3. Report the incident to the client the same day and document it in writing: what happened, when, where, what was involved.
  4. For a leak without exposure: glove up, contain with your spill kit, do not open packaging, isolate the package, and call the client for instructions before completing the delivery.

Couriers who handle an exception this way tend to keep the contract. The event itself is rarely what ends a relationship; an undocumented, unreported version of the same event usually is. The Medical Courier Launch Kit includes a printable exception and incident report template built around exactly this pattern.

Where do the official sources live?

  • HIPAA rules and guidance: U.S. Department of Health and Human Services, hhs.gov/hipaa
  • Bloodborne Pathogens Standard, 29 CFR 1910.1030: OSHA, osha.gov
  • Category B packaging, 49 CFR 173.199: PHMSA, phmsa.dot.gov
  • CDC guidance on specimen handling and universal precautions: cdc.gov

Bookmark the originals. Client requirements and training vendors change; the source regulations move slowly and are always the reference that settles a question.

Frequently asked questions

Do independent couriers really have to sign business associate agreements?

If you carry work that includes protected health information for a covered entity or its contractor, expect a BAA as a condition of the contract. It is standard, and providers generally cannot hand PHI-bearing work to a vendor without one.

Is one bloodborne pathogen course enough forever?

No. The OSHA standard is built around annual refresher training, and clients typically ask for a certificate dated within the last year.

Can a courier transport Category A infectious substances?

Not without specific hazmat training and packaging arrangements that go beyond routine courier work. Ordinary diagnostic specimens are Category B; if a client ever describes something as Category A, that is a specialized shipment with its own rules, and the honest answer is to confirm the requirements before accepting it.

Does HIPAA prevent me from telling anyone what I do?

You can describe your work. What you cannot do is share the who and the what of it: patient names, facilities tied to patients, test details, or anything that identifies an individual. "I run specimen routes for regional labs" is fine; naming what you picked up for whom is not.

Medical Courier Launch Kit

Build the file that wins medical routes.

A 90-day launch path, the credential and insurance stack labs screen for, printable chain-of-custody and temperature log templates, outreach scripts, a rate-floor worksheet, and a 50-state agency directory with guided fill-ins.

  • The 90-day launch path
  • Credential stack checklist
  • Insurance guide
  • Templates
  • Client outreach scripts and a one-page compliance packet outline
  • Rate-floor worksheet

$99 once · instant delivery · 30-day money-back guarantee

Disclaimer: MedCourierPath is an independent information publisher. We are not a courier company, law firm, insurance agency, or government agency, and nothing here is legal, financial, or medical advice. Requirements vary by state, county, and client, and they change; always confirm current requirements with the relevant agency, your insurance professional, and each client contract before acting. We make no promises about contracts, income, or business results.

Read our full disclaimer

MedCourierPath Editorial Team

Researched and edited by the MedCourierPath Editorial Team. We are an independent publisher, not a courier company or government agency, and we cite the authority behind every requirement.

How we research and review our content

Related Guides

MedCourierPath
Get the Launch Kit for $99