top of page

HIPAA & Confidentiality Policy

A legal disclaimer

Effective Date: [06/21/2026]
Last Updated: [06/21/2026]

1. Purpose

 

This HIPAA and Confidentiality Policy establishes the standards followed by Battle Tested Specimen Collections to protect the privacy and confidentiality of all health information, personal information, and sensitive data collected during the provision of mobile drug screen and specimen collection services. Battle Tested Specimen Collections is committed to handling all information with the highest level of care, discretion, and compliance with applicable federal and Washington State privacy laws. This policy applies to all staff, contractors, and representatives of Battle Tested Specimen Collections.

 

 

2. HIPAA Applicability

 

2.1 Are We a Covered Entity?
The Health Insurance Portability and Accountability Act (HIPAA) applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with standard transactions. Drug screen collection services operate in a unique position with respect to HIPAA:

— Battle Tested Specimen Collections is not a healthcare provider in the traditional sense and does not bill health insurance for collection services
— Workplace drug testing information collected under DOT regulations is specifically excluded from HIPAA protections under 45 CFR Part 164 — DOT drug testing results are governed by 49 CFR Part 40 confidentiality requirements instead
— However Battle Tested Specimen Collections voluntarily adopts HIPAA-equivalent privacy standards for all health-related information we handle as a best practice and professional standard

 

2.2 Our Commitment
Regardless of technical HIPAA applicability Battle Tested Specimen Collections treats all donor and client health information with HIPAA-equivalent protections. We believe every person deserves the highest standard of health information privacy.

 

 

3. What Information We Protect

 

Battle Tested Specimen Collections collects and handles the following categories of sensitive information that are subject to this policy:

Personal Health Information:
— Drug screen specimen results (non-negative and confirmed results)
— Medical conditions disclosed by donors during the collection process
— Prescription medications disclosed to the MRO
— Alcohol test results
— Specimen validity findings

 

Personal Identifying Information:
— Full legal name and date of birth
— Government-issued ID information
— Contact information including phone number and email address
— Collection address
— Social Security Number (when required for certain collections)

 

Employer and Business Information:
— Company drug testing program details
— Employee testing records
— Employer contact information
— Account and billing information

 

 

4. How We Protect Your Information

 

Battle Tested Specimen Collections implements the following safeguards to protect all sensitive information:

4.1 Administrative Safeguards
— All collection documentation is handled only by authorized Collector personnel
— Access to client and donor records is restricted on a need-to-know basis
— All personnel with access to sensitive information are trained on confidentiality requirements
— Confidentiality obligations are incorporated into all contractor and vendor agreements
— Security practices are reviewed and updated regularly

 

4.2 Physical Safeguards
— Physical collection documents including CCFs and collection records are stored in a locked, secure location
— Completed collection documents are not left unattended in vehicles or public spaces
— Documents awaiting destruction are stored securely until destroyed
— Physical records are destroyed by shredding when retention periods expire

 

4.3 Technical Safeguards
— Digital records are stored in password-protected, encrypted systems
— Our website uses SSL/TLS encryption for all data transmission
— Client portal access requires authenticated login through our secure Wix Members Area
— Electronic CCF systems (FormFox and eChain) use secure, encrypted connections
— Payment information is processed through PCI-compliant payment processors and is never stored by Battle Tested Specimen Collections directly
— Electronic devices used for business purposes are password protected

 

5. Authorized Disclosures

 

Battle Tested Specimen Collections will only disclose donor or client information to the following authorized parties:

 

5.1 Standard Authorized Disclosures

RecipientWhat Is DisclosedWhy

The DonorTheir own collection information and resultsTheir right to their own information

Employer of RecordCollection status and MRO-verified resultsTesting program management

Laboratory PartnerCCF and specimen documentationSpecimen analysis

MROCollection documentation and non-negative resultsResult review and verification

DISA Global SolutionsCollection and account informationTPA program management

 

5.2 Legal Disclosures
Battle Tested Specimen Collections may disclose information without donor or employer consent in the following circumstances:
— When required by federal or Washington State law
— In response to a valid court order or subpoena
— To comply with a regulatory audit or investigation by DOT, FMCSA, or other authorized regulatory body
— To report a crime committed on our premises or against our personnel
— When necessary to prevent serious and imminent harm to the donor or others

 

5.3 Prohibited Disclosures
Battle Tested Specimen Collections will never disclose donor or client information to:
— Coworkers or other employees of the donor's employer without proper authorization
— Family members or personal contacts of the donor without explicit written consent
— Third party companies for marketing or commercial purposes
— Any party not listed in Section 5.1 without proper legal authorization

 

6. DOT Confidentiality Requirements

 

For DOT-mandated collections Battle Tested Specimen Collections strictly follows the confidentiality requirements of 49 CFR Part 40:

— Drug test results may only be released to the employer, MRO, SAP, and other parties specifically authorized by 49 CFR Part 40
— Results may not be disclosed to the general public
— Results may not be used for purposes other than those authorized under 49 CFR Part 40
— Donors must consent in writing before results are released to any party not authorized under 49 CFR Part 40
— All personnel with access to DOT drug test results are informed of the confidentiality requirements of 49 CFR Part 40

 

 

7. Washington State Privacy Protections

 

In addition to federal requirements Battle Tested Specimen Collections complies with the following Washington State privacy laws:

 

7.1 Washington My Health MY Data Act (MHMD)
The MHMD Act governs the collection, use, and sharing of consumer health data in Washington State. Battle Tested Specimen Collections complies with MHMD requirements including:
— Collecting only the health data necessary to provide the requested services
— Not selling consumer health data to third parties
— Providing donors with the right to access and delete their health data subject to regulatory retention requirements
— Maintaining a clear and accessible privacy policy

 

7.2 Washington Data Breach Notification Law (RCW 19.255)
In the event of a data breach that compromises personal information Battle Tested Specimen Collections will:
— Investigate the breach promptly
— Notify affected individuals within 30 days of discovering the breach as required by Washington State law
— Notify the Washington State Attorney General if the breach affects more than 500 Washington residents
— Take immediate steps to contain and remediate the breach

 

7.3 Washington Consumer Protection Act
Battle Tested Specimen Collections complies with the Washington Consumer Protection Act (RCW 19.86) which prohibits unfair or deceptive practices in the collection and use of consumer information.

 

 

8. Employer Confidentiality Obligations

 

Employers who receive drug test results through Battle Tested Specimen Collections have independent confidentiality obligations. Battle Tested Specimen Collections advises all employer accounts to:

— Restrict access to drug test results to only those with a legitimate need to know
— Store drug test results in a secure, separate file from general personnel records
— Not disclose drug test results to coworkers, supervisors without a need to know, or other unauthorized parties
— Follow all applicable federal and Washington State confidentiality requirements for workplace drug testing
— Consult legal counsel regarding their specific confidentiality obligations under applicable law

 

Battle Tested Specimen Collections is not liable for confidentiality breaches caused by employer mishandling of drug test results.

 

 

9. Breach of Confidentiality Protocol

 

In the event of a suspected or confirmed breach of confidentiality Battle Tested Specimen Collections follows this protocol:

 

Step 1 — Identify and Contain
Upon discovering a potential breach the Collector immediately takes steps to contain the breach and prevent further unauthorized disclosure.

 

Step 2 — Assess
The nature and scope of the breach is assessed including what information was disclosed, to whom, and under what circumstances.

 

Step 3 — Notify
Affected individuals are notified as required by applicable law. Washington State law requires notification within 30 days of discovering a breach. Notification includes:
— What information was involved
— What happened
— What steps are being taken to address the breach
— What affected individuals can do to protect themselves

 

Step 4 — Remediate
Immediate steps are taken to remediate the breach and prevent recurrence including security upgrades, process changes, and additional training as appropriate.

 

Step 5 — Document
The breach, the response, and all remediation steps are documented and retained for a minimum of 5 years.

 

 

10. Data Retention & Destruction

 

All sensitive information is retained only as long as required by applicable law or legitimate business need:

 

Record Type/Retention Period/Destruction Method

  • DOT collection records

    • 5 years minimum

      • Secure shredding / encrypted deletion

  • Non-DOT collection records

    • 2 years minimum

      • Secure shredding / encrypted deletion

  • Confirmed positive / refusal records

    • 5 years

      • Secure shredding / encrypted deletion

  • Employer account records

    • Duration of account + 2 years

      • Secure shredding / encrypted deletion

  • Payment records

    • As required by tax law

      • Encrypted deletion

  • Breach documentation

    • 5 years

      • Encrypted deletion

 

Records are destroyed securely at the end of their retention period. Physical documents are shredded and electronic records are permanently deleted using secure deletion methods.

 

 

11. Donor Rights Under This Policy

 

Donors have the following rights regarding their information under this policy:

— Right to Access — Request a copy of the personal information Battle Tested Specimen Collections holds about you
— Right to Correction — Request correction of inaccurate or incomplete information
— Right to Deletion — Request deletion of your information subject to regulatory retention requirements
— Right to Know — Request information about how your data is used and who it has been shared with
— Right to Notification — Be notified in the event of a breach that affects your personal information

 

To exercise any of these rights contact us at info@battletestedwa.com or (206) 939-0335. We will respond to all requests within 30 days.

 

 

12. Third Party Vendors & Partners

 

Battle Tested Specimen Collections works with the following third party vendors and partners who may have access to client or donor information:

 

Partner/Role/Data Access

  • DISA Global Solutions

    • TPA — manages employer accounts and random pools

      • Employer account data, collection records

  • MedTox (LabCorp)

    • Laboratory — processes specimens

      • Donor CCF and specimen data

  • FormFox

    • eCCF system for DISA collections

      • Collection documentation

  • eChain / MyMedTox

    • eCCF system for MedTox collections

      • Collection documentation

  • Wix

    • Website, booking, and client portal

      • Client contact and booking data

  • Wix Payments

    • Payment processing

      • Payment authorization data

 

All third party partners are required to maintain appropriate privacy and security standards. Battle Tested Specimen Collections is not responsible for the privacy practices of third party partners beyond our contractual requirements.

 

 

13. Regulatory Compliance

 

This HIPAA and Confidentiality Policy complies with:

— 49 CFR Part 40 — DOT drug testing confidentiality requirements
— HHS Mandatory Guidelines for Federal Workplace Drug Testing Programs
— Washington My Health MY Data Act (MHMD)
— Washington Data Breach Notification Law (RCW 19.255)
— Washington Consumer Protection Act (RCW 19.86)
— HIPAA Privacy Rule best practices (voluntarily adopted)
— PCI DSS payment card industry data security standards (through Wix Payments)

 

 

14. Policy Review

 

This policy is reviewed annually and updated as needed to reflect changes in applicable law, regulatory requirements, or business practices. The most current version of this policy is always available at www.battletestedwa.com.

 

 

15. Contact Us

 

For questions about this policy, to exercise your privacy rights, or to report a privacy concern please contact us:

 

Battle Tested Specimen Collections
DBA of Battle Tested LLC
14900 Interurban Ave. S
Suite 271 #10005
Tukwila, WA 98168

 

📞 (206) 939-0335
📧 info@battletestedwa.com
🌐 www.battletestedwa.com

 

Veteran Owned & Operated | King County & South King County, Washington

bottom of page