How Apex Courier Logistics Group LLC, DBA Apex Medical OC operates as a HIPAA Business Associate. A principal-signed Business Associate Agreement is executed before any service involving Protected Health Information begins. This statement is a summary written for procurement review; the executed Business Associate Agreement governs in the event of any conflict.
Apex Courier Logistics Group LLC, DBA Apex Medical OC (“Apex”), California Entity No. B20260171016, acts as a Business Associate to its covered-entity clients: hospitals, clinics, physician groups, occupational health practices, laboratories, and health plans, as those terms are used in 45 CFR Parts 160 and 164.
In performing specimen transport, on-site collection, and compliance program administration, Apex creates, receives, maintains, and transmits Protected Health Information on behalf of those covered entities. Apex is therefore directly liable under the HIPAA Security Rule and under the Breach Notification Rule, and is liable under the Privacy Rule for the uses and disclosures set out in its Business Associate Agreements, as provided by the HITECH Act and the Omnibus Rule.
Where Apex moves a sealed, labeled specimen or a sealed document packet without accessing its contents, Apex functions in a conduit capacity for that leg of the work. Apex does not rely on the conduit exception as a shield: because our platform generates custody records, telemetry, and notifications that can associate a specimen with an individual, Apex treats itself as a full Business Associate for the entire engagement and signs a Business Associate Agreement accordingly.
Apex does not begin any service that involves Protected Health Information until a written Business Associate Agreement has been executed between Apex and the covered entity. There is no pilot, no trial run, and no first pickup ahead of signature.
This HIPAA Statement is a plain-language summary written for procurement review. It is not itself a contract. In the event of any conflict or inconsistency between this statement and the executed Business Associate Agreement, the executed Business Associate Agreement governs, together with the HIPAA Privacy, Security, and Breach Notification Rules.
The Minimum Necessary standard at 45 CFR 164.502(b) requires that a use or disclosure of PHI be limited to the minimum reasonably needed for the purpose. Apex implements that standard architecturally rather than by policy statement alone.
Specimens in Apex custody are identified in the field by barcode or QR code rather than by patient name on the label face. The operator who picks up, transports, and delivers the specimen sees an identifier, a run number, a temperature band, and a destination. The operator does not need the patient’s name to do the job, and so is not given it.
The practical result is that the highest-risk surface in medical courier work, the label in a stranger’s hand, carries the least information. Where a covered entity’s own workflow requires a named label, Apex will accept it, but the Apex-generated record remains identifier-first.
Mapped in plain language to 45 CFR 164.308. Apex maintains a designated security official responsible for the development and implementation of security policy, and a designated privacy contact for HIPAA-related inquiries. Apex conducts and documents a risk analysis of the systems that hold or transmit PHI, and applies risk management measures proportionate to the findings.
Workforce access is authorized on a role basis before any account is issued, reviewed on change of role, and terminated promptly on separation. Apex maintains an incident response procedure covering identification, containment, investigation, notification, and remediation. Contingency planning covers daily backups, restoration testing, and a documented procedure for operating during an emergency so that specimen custody and cold chain are not interrupted.
Mapped to 45 CFR 164.310. Specimens and any accompanying documents are secured in the vehicle in a locked or otherwise controlled compartment and are not left unattended in an unsecured setting. Refrigeration is active, powered independently of the vehicle ignition, and monitored, so custody and condition are maintained even when a vehicle is stopped.
Workstations and mobile devices that can reach PHI are access-controlled, screen-locked, and encrypted. Device and media controls cover issuance, reassignment, and the sanitization or destruction of media at end of life. Paper custody-and-control forms, where a client workflow still uses them, are handled sealed, are transferred only to the intended recipient, and are not photographed or copied outside the documented process.
Mapped to 45 CFR 164.312. Apex states its posture exactly as follows, and claims nothing beyond it:
Apex does not hold and does not claim SOC 2, ISO 27001, or HITRUST certification. The SHA-256 seal is an integrity and tamper-evidence control. It is not by itself proof of authenticity, and Apex does not represent it as tamper-proof or as determinative in any proceeding. Temperature evidence rests on NIST-traceable probe calibration, which is a calibration traceability statement about the instrument, not a certification of the cold chain.
Every Apex operator, dispatcher, and administrative user completes HIPAA privacy and security training before being granted access to any system or route that involves PHI, and completes refresher training on a recurring basis and whenever a material change in policy, system, or law warrants it. Training covers the Minimum Necessary standard, the barcode-first custody design, permitted and prohibited uses and disclosures, device handling, social engineering, and the duty to report a suspected incident immediately.
Apex maintains a written sanction policy. Failure to follow privacy or security policy results in discipline proportionate to the conduct, up to and including termination of employment or contract and, where warranted, referral to law enforcement. Training completion and sanction records are documented and retained. Every workforce member is also bound by a written confidentiality obligation that survives the end of the engagement.
Where Apex engages a subcontractor that creates, receives, maintains, or transmits PHI on Apex’s behalf, that subcontractor is itself a business associate under 45 CFR 164.308(b) and 164.502(e)(1)(ii), and Apex obtains satisfactory written assurances through a Business Associate Agreement that flows down the same restrictions and conditions that apply to Apex under its agreement with the covered entity.
This applies to cloud hosting and database infrastructure, clinical form providers, notification providers, voice-capture tooling, and any relief or overflow courier used to perform a covered service. Apex does not place PHI with a vendor that will not sign a Business Associate Agreement. The sales CRM is deliberately outside this chain: no PHI and no regulated testing data are synchronized into it. A current subprocessor list is available to covered entities on request, and Apex will provide notice of a material change to the subprocessor set where the Business Associate Agreement requires it.
Apex complies with the Breach Notification Rule at 45 CFR Part 164 Subpart D as it applies to a business associate.
Access to and modification of records that contain or reference PHI is written to an audit log capturing the acting user, the action, the record, and a UTC timestamp. Audit logs are retained on the schedule in Section 11 and are producible to a covered entity on request under the Business Associate Agreement.
When a run closes, the chain-of-custody packet, including timestamps, geofence-verified arrival and departure events, temperature readings logged every 60 seconds, operator identity, and the proof-of-delivery signature, is committed and sealed with a SHA-256 hash. Recomputing the hash of a produced record and comparing it to the stored value demonstrates whether the record has changed since sealing. That is the entire claim: the seal makes alteration tamper-evident. Apex does not describe the seal as tamper-proof, and does not represent that it establishes authenticity or admissibility on its own.
Apex retains compliance and custody records for 7 years, which meets or exceeds the applicable federal minimums for the record types Apex handles, and retains records under legal hold or open audit until the hold is released. PHI is retained only as long as necessary for the permitted purpose or as required by law or by the Business Associate Agreement.
On termination of a Business Associate Agreement, Apex returns or destroys all PHI received from, or created or received on behalf of, the covered entity, and retains no copies, to the extent feasible. Where return or destruction is not feasible, for example where PHI is embedded in a sealed compliance record that Apex is legally required to retain, Apex notifies the covered entity, extends the protections of the Business Associate Agreement to that information for as long as it is retained, and limits further uses and disclosures to the purposes that make return or destruction infeasible. Destruction, where performed, follows methods that render PHI unreadable and unreconstructable, and is documented.
Any individual, workforce member, client, or subcontractor who believes that PHI handled by Apex has been used or disclosed improperly, or that an Apex safeguard has failed, should report it immediately. Reports may be made by telephone to 888-494-4409, toll-free and answered 24/7, by email to chris@apexmedicaloc.com, or in writing to the registered office below. Reports are accepted anonymously.
Apex does not retaliate against any person for reporting a suspected privacy or security concern, for filing a complaint, for participating in an investigation, or for opposing a practice believed to be unlawful under HIPAA. An individual also has the right to file a complaint with the covered entity that holds the direct relationship, and with the Office for Civil Rights of the United States Department of Health and Human Services. Because the covered entity, not Apex, owns the designated record set, requests for access to or amendment of a health record should be directed to that entity, and Apex will support it in responding within the timeframes the Privacy Rule requires.
Business Associate Agreements for execution, HIPAA notices, breach correspondence, and any notice intended to be effective under an executed Business Associate Agreement must be sent to the registered office and mailing address below. Notice to a driver, a dispatcher, or the dispatch telephone line is not effective legal notice.
Apex Courier Logistics Group LLC, DBA Apex Medical OC. This statement is a summary for procurement review and is not a contract; the executed Business Associate Agreement governs in the event of any conflict. Governed by the laws of the State of California, venue Orange County. NDASA membership is a trade association membership and is not a certification.