Can You Text Patients Under HIPAA? Messaging Rules & Compliance
Why Standard Text Messaging Isn't HIPAA Compliant
SMS (Short Message Service) texting through standard carriers like AT&T or Verizon is fundamentally incompatible with HIPAA because:
Security Vulnerabilities
- No encryption: Standard SMS is sent unencrypted over carrier networks where it can be intercepted
- Stored in plain text: Messages are visible in phone bill records and carrier logs
- No authentication: Anyone with access to the patient's phone can read messages
- Backup exposure: Texts are often backed up to cloud services like iCloud or Google Drive without encryption
What HIPAA Requires for Texting
If you send PHI via text, you must ensure:
- End-to-end encryption (messages encrypted in transit and at rest)
- Patient written consent to receive texts
- Audit logs documenting all messages sent
- Secure device access (password/PIN protection)
- Data destruction protocols after treatment ends
- Business Associate Agreements with your messaging vendor
Compliant vs. Non-Compliant Texting Examples
| Communication Method | HIPAA Compliant? | Notes |
|---|---|---|
| Standard SMS from personal phone | NO | No encryption, creates breach risk |
| Standard SMS from clinic phone | NO | Still unencrypted regardless of sender device |
| Encrypted messaging app (WhatsApp, Signal, iMessage with encryption) | NO* | Personal apps lack HIPAA safeguards and BAA |
| EHR secure messaging (Epic, Cerner portal) | YES | Encrypted, audit logs, vendor has BAA |
| HIPAA-compliant SMS (Twilio, Updox, Citrix) | YES | Encrypted, patient consent required, audit trail |
| Patient portal secure messaging | YES | Encrypted, logs maintained, patient authenticated |
Note: Even encrypted consumer apps (WhatsApp, Signal, iMessage) aren't HIPAA compliant because they lack Business Associate Agreements and weren't designed with healthcare privacy controls in mind. They should never be used for PHI.
What You CAN Text Patients About
Non-Protected Information (No PHI)
You can send standard SMS for these purposes without HIPAA concerns:
- Appointment reminders: "You have an appointment tomorrow at 2 PM. Arrive 15 minutes early." (No clinical info)
- Billing/payment reminders: "Your co-pay balance is due. Please call to pay."
- General health information: "Take your medications as prescribed" (if not specific to their condition)
- Administrative notifications: "We've moved to a new location. Our new address is..."
Information You CANNOT Text
- Diagnosis, treatment plans, or medications
- Lab results or imaging reports
- Mental health conditions or psychiatric records
- Substance abuse treatment information
- HIV status or STI results
- Any clinical assessment or medical advice specific to that patient
How to Implement HIPAA-Compliant Texting
Step 1: Choose a Compliant Platform
- EHR Integration: Epic MyChart, Cerner HealtheLife (most secure and already BAA-covered)
- Dedicated Healthcare SMS: Twilio, Updox, Citrix ShareFile Secure Email, Kiteworks
- Practice Management: Check if your PM system has secure messaging (Athenahealth, AdvancedMD)
Step 2: Get Patient Consent
Obtain written consent that includes:
- Explanation that SMS carries some privacy risk (not zero-risk)
- Confirmation they understand their phone number will be used
- Acknowledgment they can revoke consent anytime
- Signature/electronic acknowledgment in their chart
Step 3: Establish Clear Policies
- Define what can and cannot be communicated via text
- Require HIPAA-compliant platform use only
- Document all texting activities in patient charts
- Implement device security (phone password/PIN required)
- Train all staff on texting protocols
Step 4: Maintain Audit Trails
- Keep logs of all messages sent (sender, recipient, timestamp, content summary)
- Store logs separately from the messages themselves
- Review logs regularly for any unauthorized access
- Retain for compliance period (6+ years)
Frequently Asked Questions
No. Even though these apps have strong encryption, they are not HIPAA compliant because:
- Vendors don't have Business Associate Agreements with covered entities
- They lack the administrative/physical safeguards HIPAA requires
- No audit trails or message logging for compliance
- Data may be stored on personal devices outside your control
- OCR has explicitly stated personal messaging apps are not HIPAA compliant
Using them for PHI creates a breach risk. Stick to platforms designed for healthcare.
If you accidentally text PHI via non-compliant SMS:
- Document the incident immediately with details (date, time, message content, recipient)
- Contact the recipient and request they delete the message
- Assess if it's a reportable breach (generally low-risk for single accidental message)
- Review your policies to prevent recurrence
- If breach threshold met (500+), notify OCR and state AG
- Notify affected patient within 60 days if breach determination made
One accidental text is generally not a reportable breach if handled properly, but repeated violations could result in OCR enforcement action.
No. Patients cannot be forced to receive texts, but you can require consent as a condition of using the practice:
- Obtain written consent before texting any patient
- Make it clear texting is optional
- Provide alternative communication methods (phone, portal, email)
- Allow patients to revoke consent at any time
- Document their choice in the medical record
If a patient declines texting, you must honor that choice and use other communication methods.
Both require security measures, but they have different risks:
- Standard Email: Plain text email is NOT HIPAA compliant (requires encryption like S/MIME or PGP)
- Standard SMS: Not HIPAA compliant without encryption
- Patient Portal Secure Messaging: HIPAA compliant (encrypted, audit logs, authentication)
- EHR Secure Email: HIPAA compliant when properly configured
Patient portal messaging is generally the safest option because it keeps communication in one secure system with built-in logging.
Appointment Reminder SMS (Low-Risk):
- "You have an appointment tomorrow at 2 PM"
- No PHI, just scheduling information
- Standard SMS is acceptable (though HIPAA-compliant is better)
- Does not require patient consent for security (may need telemarketing compliance)
Transactional/Clinical Texts (High-Risk):
- Lab results, medication refills, treatment updates
- Contains PHI and requires HIPAA-compliant platform
- Requires explicit patient consent
- Must use encrypted messaging with audit trail
Ready to Implement Secure Patient Texting?
Medcurity helps healthcare organizations evaluate and implement HIPAA-compliant texting solutions. We'll assess your current practices, select the right platform, and train your staff on secure messaging.
Get a Secure Texting Assessment