How Apex Courier Logistics Group LLC, DBA Apex Medical OC collects, uses, retains, and protects information. Read Section 02 first: ordinary business data is governed by this policy, and Protected Health Information is governed by HIPAA, the Apex HIPAA Statement, and the executed Business Associate Agreement.
This Privacy Policy is issued by Apex Courier Logistics Group LLC, DBA Apex Medical OC (“Apex,” “we,” “us”), a California limited liability company, California Entity No. B20260171016, with its registered office at 15 Enterprise, Suite #250-C, Aliso Viejo, CA 92656 and its operational and dispatch hub in Mission Viejo, CA 92691.
It explains how Apex handles information in connection with our public website, our sales and intake process, our dispatch and notification systems, and the operational records generated by clinical logistics and compliance-testing work. It applies to visitors to the Apex website and anyone who submits the service request form; business contacts at prospective, current, and former client organizations, including procurement officers, lab directors, safety managers, and designated employer representatives; individuals who contact Apex dispatch by telephone, SMS, or email; and authorized client personnel who access Apex portals, reports, or chain-of-custody exports.
This policy does not govern Protected Health Information, which is addressed in Section 02, and it does not govern the internal personnel records of Apex employees and contractors, which are handled under a separate internal policy.
This is the most important distinction in this document, and procurement reviewers should read it first. Apex handles two structurally different streams of information, and they are governed by different legal instruments.
Practically, this means a hospital or clinic client should evaluate Apex against the HIPAA Statement and the negotiated Business Associate Agreement for anything touching patient data, and against this policy for everything else. Consumer deletion rights under California law do not reach PHI held by Apex as a business associate, and they do not reach federally regulated drug and alcohol testing records. See Section 09.
Apex collects the following categories, and no others, in the ordinary course of business.
Apex does not knowingly collect biometric identifiers, precise consumer geolocation from personal devices, government identification numbers, or financial account numbers through this website.
Information described above is used only for the following purposes:
Apex does not sell personal information, does not share personal information for cross-context behavioral advertising, and does not use business-contact data to build advertising profiles. Marketing communications, where sent at all, go to business contacts about services relevant to their organization and carry an unsubscribe mechanism.
Apex uses third-party service providers to operate. We name the categories honestly rather than claiming an all-in-house stack we do not have. A current, specifically named subprocessor list is available to clients and to procurement reviewers on request.
Any subprocessor that may create, receive, maintain, or transmit PHI on behalf of Apex is engaged under a written Business Associate Agreement that flows down the same obligations Apex owes to the covered entity. Apex does not permit PHI to be processed by a vendor that will not sign one. Subprocessors are permitted to use information only to perform services for Apex and are prohibited from using it for their own purposes.
Retention is set by the purpose and by regulation, not by convenience.
Records under legal hold, or subject to an open audit, investigation, or dispute, are retained until the hold is released regardless of the schedule above. Backup media are purged on a rolling cycle, so deletion from live systems may precede deletion from backups by a short interval.
Apex states its security posture precisely, and states its limits just as precisely. The following controls are in place:
Apex does not claim SOC 2, ISO 27001, or HITRUST certification, and no statement here should be read as such a claim. The SHA-256 seal is a tamper-evidence control: it demonstrates that a record has or has not changed since sealing, and it is not by itself a guarantee of authenticity or an evidentiary determination. No system of transmission or storage is perfectly secure, and Apex cannot guarantee absolute security.
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights below with respect to personal information Apex holds about you as a business.
To exercise a right, contact us using Section 12. We will verify your identity in proportion to the sensitivity of the request, which for a business contact usually means confirming control of the email address or telephone number on file. An authorized agent may submit a request with written permission and, where required, a verified power of attorney. We respond within 45 days and may extend once by a further 45 days with notice.
Where Apex performs specimen collection, program administration, or transport in connection with an employer’s drug and alcohol testing program, the resulting records are not consumer records subject to deletion at the request of the tested individual.
Federally regulated testing records are governed by 49 CFR Part 40 and the applicable operating administration rules, together with the retention obligations those rules impose. Non-federal testing records are governed by the client employer’s written policy and program, and by the service agreement between Apex and that employer. In both cases Apex acts at the direction of the employer or its Third Party Administrator, and Apex will not delete, alter, or suppress a required testing record on the request of the tested individual.
An individual who wants to access, question, or correct a testing record should contact the employer’s Designated Employer Representative or, for federally regulated results, the Medical Review Officer of record. Rights available to tested individuals under Part 40, including the right to request a test of the split specimen, are described on the DOT Compliance Statement. Apex will assist an employer in responding to such a request but is not the custodian of record for the employer’s program.
The Apex website and services are directed to healthcare organizations, employers, laboratories, and government buyers. They are not directed to children. Apex does not knowingly collect personal information from anyone under 16 years of age through this website, and does not sell or share the personal information of consumers under 16 under any circumstance.
Where a specimen belonging to a minor is transported for a covered entity, any associated identifiers are PHI, handled under HIPAA and the Business Associate Agreement rather than under this policy, and are subject to the barcode-first minimization design described in the HIPAA Statement. If you believe a child has provided information to us through the website, contact us using Section 12 and we will delete it.
Apex may revise this policy to reflect changes in law, technology, subprocessors, or operations. When we do, we will update the Last updated date at the top of this page and post the revised version here.
Where a change is material and affects an active client relationship, we will give notice to the client administrative contacts on file before the change takes effect, and where a click-to-agree acceptance is required, we will request renewed acceptance and record it as described in Section 03. Continued use of the website or of Apex services after the effective date of a revision constitutes acceptance of the revised policy for ordinary business data. Superseded versions are retained so that any acceptance record can be matched to the exact text in force at the time.
Privacy questions, access, deletion, and correction requests, and authorized agent submissions should be directed to Apex in writing. Use the registered office address below for any request you want treated as formal written notice.
Email: chris@apexmedicaloc.com with “Privacy Request” in the subject line. Telephone: 888-494-4409, toll-free, 24/7. Mail: the registered office address in the contact block below.
Requests concerning PHI should identify the covered entity involved so that Apex can route the request to that entity, which is the party with the direct obligation to the individual under the HIPAA Privacy Rule.
All legal notices, privacy requests, service of process, and formal correspondence concerning this Privacy Policy must be sent to the registered office and mailing address below. Notices sent only to the operational hub, to a driver, or to a dispatch line are not effective notice under this policy.
Apex Courier Logistics Group LLC, DBA Apex Medical OC. This Privacy Policy is governed by the laws of the State of California, and the parties submit to the exclusive venue of the state and federal courts located in Orange County, California. NDASA membership is a trade association membership and is not a certification.