Use of Med-Stop websites, services, and applications requires you to review this HIPAA and DOT Privacy Statement.
Med-Stop HIPAA and DOT Privacy Statement
Med-Stop is committed to protecting personal information, health-related information, drug and alcohol testing information, occupational medical information, and other sensitive records processed through Med-Stop websites, services, applications, and tools.
Med-Stop provides services in areas that may include DOT-regulated drug and alcohol testing, occupational medical testing, Medical Review Officer services, laboratory result processing, employer compliance management, random selection programs, and related documentation. Because these services may involve different legal frameworks, not every record handled by Med-Stop is governed by HIPAA in the same way.
Important distinction: DOT-regulated testing is not handled only under HIPAA
A significant part of Med-Stop's work involves DOT-regulated drug and alcohol testing and related compliance records. DOT-regulated testing is governed by the U.S. Department of Transportation rules, including 49 CFR Part 40 and the applicable DOT agency regulations, such as FMCSA, FAA, FRA, FTA, PHMSA, and USCG rules.
DOT rules establish specific requirements for how drug and alcohol testing is conducted, how results are reviewed and reported, how records are maintained, and when testing information must or may be released. In many DOT-regulated situations, drug and alcohol testing information must be reported or released according to DOT rules, and written employee authorization is not required when the disclosure is required by 49 CFR Part 40 or other applicable DOT or USCG drug and alcohol testing regulations.
For this reason, DOT-regulated drug and alcohol testing records are not treated simply as ordinary HIPAA medical records. When DOT rules require a result, refusal, cancellation, safety-sensitive status, or other testing information to be reported to an employer, Medical Review Officer, Substance Abuse Professional, DOT agency, or other authorized party, Med-Stop and related service agents may process and disclose that information as required or permitted by DOT regulations.
This does not mean that Med-Stop treats DOT-regulated testing information as unprotected. DOT testing information is sensitive and confidential. Med-Stop applies administrative, technical, and physical safeguards to protect such information and limits access and disclosure to authorized users and legally permitted purposes.
When HIPAA may apply
HIPAA, the Health Insurance Portability and Accountability Act, applies to covered entities such as health plans, health care clearinghouses, and certain health care providers that conduct covered electronic transactions. HIPAA may also apply to business associates that create, receive, maintain, or transmit protected health information on behalf of a covered entity or another business associate.
Med-Stop may act as a business associate when it performs services for a HIPAA covered entity or another business associate and the service involves protected health information. In those cases, Med-Stop handles protected health information according to applicable HIPAA requirements and any applicable Business Associate Agreement or other written agreement.
In other cases, Med-Stop may process health-related, occupational testing, employment, or DOT-regulated information under DOT rules, employer authorization, service agreements, consent forms, recordkeeping requirements, laboratory or Medical Review Officer processes, or other applicable legal and regulatory requirements instead of, or in addition to, HIPAA.
Protected health information
When Med-Stop handles protected health information under HIPAA, Med-Stop is committed to protecting the confidentiality, integrity, and availability of that information. Med-Stop uses administrative, technical, and physical safeguards designed to protect protected health information from unauthorized access, use, disclosure, alteration, or destruction.
The purpose of this statement is to explain, in general terms, how Med-Stop protects health-related information and how HIPAA and DOT rules may apply differently depending on the service, record type, user, and legal relationship involved.
Business associates
A business associate is a person or entity that performs certain functions or services for a HIPAA covered entity, or for another business associate, that involve the creation, receipt, maintenance, or transmission of protected health information.
When Med-Stop acts as a business associate, Med-Stop uses and discloses protected health information only as permitted by the applicable agreement, as needed to provide the services, or as required or permitted by law. Med-Stop also requires appropriate safeguards for protected health information and, where applicable, requires subcontractors that handle protected health information on Med-Stop's behalf to protect that information.
Med-Stop may enter into Business Associate Agreements with covered entities or business associates when required by HIPAA and appropriate for the service being provided.
DOT drug and alcohol testing information
DOT-regulated drug and alcohol testing information may include test requests, chain of custody information, alcohol testing forms, laboratory results, Medical Review Officer determinations, refusals to test, cancellations, split specimen information, return-to-duty and follow-up testing information, Substance Abuse Professional information, and related compliance records.
DOT rules require certain information to be reported to employers, Medical Review Officers, Substance Abuse Professionals, service agents, and government agencies in specific circumstances. DOT rules also include confidentiality and record release requirements that are separate from HIPAA.
When Med-Stop processes DOT-regulated testing information, Med-Stop follows applicable DOT requirements and provides access or disclosure only to authorized users, required parties, or legally permitted recipients.
Employer responsibility for DOT compliance
Employers remain responsible for their own DOT compliance obligations, including determining whether employees are subject to DOT testing rules, ensuring required testing is performed, maintaining required records, obtaining required notices or authorizations where applicable, and using testing information in accordance with DOT and other applicable laws.
Unless Med-Stop expressly agrees otherwise in a separate written agreement, Med-Stop does not act as the employer's DOT Third-Party Administrator, Consortium, compliance officer, legal advisor, or regulatory consultant. Med-Stop provides systems and services that support testing and compliance workflows, but the employer remains responsible for its own compliance program.
Your rights and access to records
Your rights to access, review, correct, or receive copies of records may depend on the type of record, the service involved, whether HIPAA applies, whether DOT rules apply, and the role of the person or organization requesting the record.
When HIPAA applies, individuals may have rights to access and request corrections to protected health information, subject to applicable legal limitations.
When DOT rules apply, employees may have rights to obtain certain testing records from laboratories, Medical Review Officers, employers, or service agents as provided by DOT regulations. Some DOT testing information may also be required to be released to employers or other authorized parties without separate written authorization when DOT rules require or permit that release.
Med-Stop will respond to access, correction, and record requests according to applicable HIPAA requirements, DOT regulations, employer agreements, service agreements, legal requirements, and record retention obligations.
Disclosure of information
Med-Stop may disclose protected health information, DOT-regulated testing information, occupational medical information, or other sensitive information when authorized by the individual, employer, customer, service agreement, or applicable law.
Med-Stop may also disclose information when required or permitted by HIPAA, DOT regulations, FMCSA, FAA, FRA, FTA, PHMSA, USCG, HHS, SAMHSA, state law, court order, subpoena, administrative request, government investigation, audit, inspection, or other legal process.
For DOT-regulated testing, Med-Stop may disclose information to employers, Medical Review Officers, Substance Abuse Professionals, laboratories, collection sites, service agents, DOT agencies, or other authorized parties when required or permitted by DOT rules.
Med-Stop does not sell protected health information or DOT-regulated testing information.
HIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards for protecting medical records and other individually identifiable health information. The Privacy Rule applies to covered entities and, through business associate requirements, to business associates that handle protected health information on behalf of covered entities or other business associates.
The Privacy Rule sets limits and conditions on certain uses and disclosures of protected health information and gives individuals certain rights regarding their health information, including rights to access records and request corrections, subject to applicable limitations.
HIPAA Security Rule
The HIPAA Security Rule establishes national standards for protecting electronic protected health information that is created, received, used, or maintained by a covered entity or business associate.
The Security Rule requires appropriate administrative, physical, and technical safeguards to help ensure the confidentiality, integrity, and availability of electronic protected health information.
State laws and other requirements
State privacy, medical record, employment, occupational health, laboratory, and drug testing laws may also apply to certain information or services. When state law is more restrictive or provides additional protections, Med-Stop will follow applicable state law to the extent required.
Different rules may apply depending on whether the record is a HIPAA protected health record, a DOT-regulated drug and alcohol testing record, an occupational medical record, an employer compliance record, or another type of record.
Med-Stop safeguards
Med-Stop uses administrative, technical, and physical safeguards designed to protect sensitive information processed through Med-Stop systems. These safeguards may include access controls, user authentication, role-based permissions, encryption, network protections, monitoring, backup procedures, secure hosting environments, and incident response procedures.
Physical security of data
Med-Stop uses secure hosting and data center environments with restricted physical access, environmental controls, backup power, fire protection, and other facility safeguards appropriate to the services provided.
Encrypted data transfer
Med-Stop websites, services, applications, and tools use encryption technologies such as SSL/TLS to help protect sensitive information transmitted over the Internet. Unencrypted transfer of protected health information or other sensitive information is restricted where technically and operationally possible.
Network protection
Med-Stop uses network and application security controls designed to protect Med-Stop systems from unauthorized access, misuse, and intrusion. These controls may include firewalls, monitoring, logging, access restrictions, and other security technologies.
Backup of data
Med-Stop uses backup and recovery processes designed to support business continuity, data recovery, and protection against accidental loss, system failure, unauthorized alteration, or disaster. Backup data is protected using appropriate access controls and security measures.
Contingency planning
Med-Stop maintains contingency and recovery procedures designed to support system availability, data backup, disaster recovery, and response to system emergencies.
Complaints
If you believe Med-Stop has not properly protected your protected health information, DOT-regulated testing information, or other sensitive information, you may file a complaint with Med-Stop. Click here to submit your request.
You may also have the right to file a complaint with the Office for Civil Rights in the U.S. Department of Health and Human Services if your complaint involves HIPAA-protected information. Med-Stop will not retaliate against you for filing a complaint.
Contact information
If you have questions or concerns regarding Med-Stop's handling of protected health information, DOT-regulated testing information, privacy practices, security practices, or Business Associate Agreements, please contact Med-Stop's Privacy and Security Officer as specified on the Contact page. For full contact information, please click here.