The controls a lab director and a compliance officer both sign off on
Compliance isn’t a feature we bolt on — it’s the product. Here’s exactly how we handle PHI, custody, temperature, credentials, incidents, and your data.
HIPAA posture
Vitalis operates as a Business Associate; a BAA is executed before any protected health information is handled. PHI is handled on a minimum-necessary basis: the platform carries only what a run requires, identifiers are masked by default, and access to unmasked PHI is role-gated and written to an audit trail. Notifications are status-only — a patient name, diagnosis, or specimen detail never appears in an SMS or email.
Chain of custody
The platform logs every transfer of a specimen who-to-who with a signature, a timestamp, and GPS coordinates. Tamper-evident seal numbers are recorded at pickup and verified at each subsequent handoff; a seal mismatch is flagged automatically. A custody-gap detector surfaces missing signatures, broken sequences, unauthorized recipients, and missing readings — and a complete custody manifest is available on demand for a shipment.
Temperature controls
The platform routes cold-chain shipments on one of four validated lanes — ambient, refrigerated, frozen, and ultra-frozen — each with a defined acceptable range. Temperature is logged at every handoff and compared against that range; an out-of-range reading is flagged in real time against the specimen’s stability window. Ultra-frozen shipments ship on dry ice with the correct hazard marking.
Driver training & credentials
Every Vitalis courier will carry current HIPAA and bloodborne-pathogen training, with cold-chain and dry-ice certification tracked per courier. The platform enforces capability at assignment: a shipment requiring refrigeration, frozen handling, dry ice, or STAT eligibility is only ever assigned to a courier whose credentials cover it, and expired training blocks assignment.
Incident response
The platform captures temperature excursions, custody gaps, seal mismatches, and failed deliveries as incidents with a severity, an owner, and an escalation path. When service is active, clients are notified per their agreement, corrective action is recorded, and incidents are resolved with a documented root cause. Nothing is closed silently.
Portal & platform security
The public tracking surface is authorized by an opaque, single-purpose token — no login, no account enumeration, and no access to any other shipment. The browser only ever talks to same-origin API routes under a strict Content-Security-Policy; the tenant API base and its credentials never reach the client. Operator and client portals are separately authenticated and tenant-scoped.
Data privacy
Data is tenant-isolated: one tenant can never see another tenant’s shipments, facilities, recipients, or records. PHI fields are masked at rest in the surfaces that display them and revealed only with a role and a logged reason. We retain what we must for the custody record and no more, and we honor the data-handling and retention terms set in each agreement.
Reviewing us as a vendor? Our Terms, Privacy, and medical-courier policies are public, and we’ll provide a BAA and our custody and temperature SOPs on request.
Request our compliance packetPut these controls to work for your facility
Start with a route assessment — we scope the route and share our BAA and custody and temperature SOPs before anything moves.