Medcurity Get Compliance Help

Can You Text Patients Under HIPAA? Messaging Rules & Compliance

Quick Answer: Standard SMS texting is NOT HIPAA compliant and should not be used for PHI. You can text patients only using HIPAA-compliant platforms (like Twilio, Teladoc, or your EHR's secure messaging), with proper encryption, patient consent, and audit trails. Violating this can result in OCR fines up to $100+ per violation.

Why Standard Text Messaging Isn't HIPAA Compliant

SMS (Short Message Service) texting through standard carriers like AT&T or Verizon is fundamentally incompatible with HIPAA because:

Security Vulnerabilities

What HIPAA Requires for Texting

If you send PHI via text, you must ensure:

Recent OCR Action: In 2023, the HHS Office for Civil Rights settled a case against a healthcare provider for sending PHI via standard SMS text messages. The provider paid $475,000 and agreed to implement secure messaging. This is a clear signal that OCR is actively enforcing text messaging rules.

Compliant vs. Non-Compliant Texting Examples

Communication Method HIPAA Compliant? Notes
Standard SMS from personal phone NO No encryption, creates breach risk
Standard SMS from clinic phone NO Still unencrypted regardless of sender device
Encrypted messaging app (WhatsApp, Signal, iMessage with encryption) NO* Personal apps lack HIPAA safeguards and BAA
EHR secure messaging (Epic, Cerner portal) YES Encrypted, audit logs, vendor has BAA
HIPAA-compliant SMS (Twilio, Updox, Citrix) YES Encrypted, patient consent required, audit trail
Patient portal secure messaging YES Encrypted, logs maintained, patient authenticated

Note: Even encrypted consumer apps (WhatsApp, Signal, iMessage) aren't HIPAA compliant because they lack Business Associate Agreements and weren't designed with healthcare privacy controls in mind. They should never be used for PHI.

What You CAN Text Patients About

Non-Protected Information (No PHI)

You can send standard SMS for these purposes without HIPAA concerns:

Information You CANNOT Text

Best Practice: If you're unsure whether something contains PHI, don't send it via standard text. Use your secure patient portal or HIPAA-compliant messaging platform instead. The risk of a breach far outweighs the convenience of SMS.

How to Implement HIPAA-Compliant Texting

Step 1: Choose a Compliant Platform

Step 2: Get Patient Consent

Obtain written consent that includes:

Step 3: Establish Clear Policies

Step 4: Maintain Audit Trails

Frequently Asked Questions

Can we use WhatsApp, Signal, or Telegram for HIPAA compliance?

No. Even though these apps have strong encryption, they are not HIPAA compliant because:

  • Vendors don't have Business Associate Agreements with covered entities
  • They lack the administrative/physical safeguards HIPAA requires
  • No audit trails or message logging for compliance
  • Data may be stored on personal devices outside your control
  • OCR has explicitly stated personal messaging apps are not HIPAA compliant

Using them for PHI creates a breach risk. Stick to platforms designed for healthcare.

What happens if we text PHI by mistake?

If you accidentally text PHI via non-compliant SMS:

  • Document the incident immediately with details (date, time, message content, recipient)
  • Contact the recipient and request they delete the message
  • Assess if it's a reportable breach (generally low-risk for single accidental message)
  • Review your policies to prevent recurrence
  • If breach threshold met (500+), notify OCR and state AG
  • Notify affected patient within 60 days if breach determination made

One accidental text is generally not a reportable breach if handled properly, but repeated violations could result in OCR enforcement action.

Do patients have to accept text messaging?

No. Patients cannot be forced to receive texts, but you can require consent as a condition of using the practice:

  • Obtain written consent before texting any patient
  • Make it clear texting is optional
  • Provide alternative communication methods (phone, portal, email)
  • Allow patients to revoke consent at any time
  • Document their choice in the medical record

If a patient declines texting, you must honor that choice and use other communication methods.

Is texting better or worse than email for HIPAA?

Both require security measures, but they have different risks:

  • Standard Email: Plain text email is NOT HIPAA compliant (requires encryption like S/MIME or PGP)
  • Standard SMS: Not HIPAA compliant without encryption
  • Patient Portal Secure Messaging: HIPAA compliant (encrypted, audit logs, authentication)
  • EHR Secure Email: HIPAA compliant when properly configured

Patient portal messaging is generally the safest option because it keeps communication in one secure system with built-in logging.

What's the difference between transactional and appointment reminder texts?

Appointment Reminder SMS (Low-Risk):

  • "You have an appointment tomorrow at 2 PM"
  • No PHI, just scheduling information
  • Standard SMS is acceptable (though HIPAA-compliant is better)
  • Does not require patient consent for security (may need telemarketing compliance)

Transactional/Clinical Texts (High-Risk):

  • Lab results, medication refills, treatment updates
  • Contains PHI and requires HIPAA-compliant platform
  • Requires explicit patient consent
  • Must use encrypted messaging with audit trail

Ready to Implement Secure Patient Texting?

Medcurity helps healthcare organizations evaluate and implement HIPAA-compliant texting solutions. We'll assess your current practices, select the right platform, and train your staff on secure messaging.

Get a Secure Texting Assessment