Trust & Compliance

The controls a lab director and a compliance officer both sign off on

Compliance isn’t a feature we bolt on — it’s the product. Here’s exactly how we handle PHI, custody, temperature, credentials, incidents, and your data.

HIPAA posture

Vitalis operates as a Business Associate; a BAA is executed before any protected health information is handled. PHI is handled on a minimum-necessary basis: the platform carries only what a run requires, identifiers are masked by default, and access to unmasked PHI is role-gated and written to an audit trail. Notifications are status-only — a patient name, diagnosis, or specimen detail never appears in an SMS or email.

Chain of custody

The platform logs every transfer of a specimen who-to-who with a signature, a timestamp, and GPS coordinates. Tamper-evident seal numbers are recorded at pickup and verified at each subsequent handoff; a seal mismatch is flagged automatically. A custody-gap detector surfaces missing signatures, broken sequences, unauthorized recipients, and missing readings — and a complete custody manifest is available on demand for a shipment.

Temperature controls

The platform routes cold-chain shipments on one of four validated lanes — ambient, refrigerated, frozen, and ultra-frozen — each with a defined acceptable range. Temperature is logged at every handoff and compared against that range; an out-of-range reading is flagged in real time against the specimen’s stability window. Ultra-frozen shipments ship on dry ice with the correct hazard marking.

Driver training & credentials

Every Vitalis courier will carry current HIPAA and bloodborne-pathogen training, with cold-chain and dry-ice certification tracked per courier. The platform enforces capability at assignment: a shipment requiring refrigeration, frozen handling, dry ice, or STAT eligibility is only ever assigned to a courier whose credentials cover it, and expired training blocks assignment.

Incident response

The platform captures temperature excursions, custody gaps, seal mismatches, and failed deliveries as incidents with a severity, an owner, and an escalation path. When service is active, clients are notified per their agreement, corrective action is recorded, and incidents are resolved with a documented root cause. Nothing is closed silently.

Portal & platform security

The public tracking surface is authorized by an opaque, single-purpose token — no login, no account enumeration, and no access to any other shipment. The browser only ever talks to same-origin API routes under a strict Content-Security-Policy; the tenant API base and its credentials never reach the client. Operator and client portals are separately authenticated and tenant-scoped.

Data privacy

Data is tenant-isolated: one tenant can never see another tenant’s shipments, facilities, recipients, or records. PHI fields are masked at rest in the surfaces that display them and revealed only with a role and a logged reason. We retain what we must for the custody record and no more, and we honor the data-handling and retention terms set in each agreement.

Reviewing us as a vendor? Our Terms, Privacy, and medical-courier policies are public, and we’ll provide a BAA and our custody and temperature SOPs on request.

Request our compliance packet

Put these controls to work for your facility

Start with a route assessment — we scope the route and share our BAA and custody and temperature SOPs before anything moves.