Patient messaging · Guide

The real rules for HIPAA compliant texting

Patients expect a text back. Clinics that build texting on a personal phone or an unsecured app are taking on more risk than they realize. This guide covers what HIPAA actually requires for text messages with patients, and where clinics most often get it wrong.

The short answer

HIPAA compliant texting means the platform is covered by a signed Business Associate Agreement, applies the safeguards the HIPAA Security Rule requires, and is used with patient consent and only the minimum necessary detail. Standard carrier SMS sent from a personal phone typically doesn’t meet that bar on its own. The compliance comes from the agreement, the safeguards, and how the clinic actually texts.

01 · Definition

What counts as texting PHI

A text message becomes protected health information the moment it ties a patient’s identity to anything about their care: an appointment, a treatment name, a photo, a dosage, a balance owed. “See you Thursday at 2” tied to a known patient at a known clinic already qualifies. That’s why a text thread deserves the same scrutiny as a phone call or an email, even though it feels informal, a principle covered in more depth in our guide to a HIPAA compliant CRM.

The platform matters, but so does the habit. A fully compliant platform used by staff who paste chart notes into a text thread is still a problem. The rules apply to the message itself, regardless of which software carries it.

02 · Certification

There is no HIPAA certified texting app

As with any other software category, no government body certifies a texting platform as HIPAA compliant. The U.S. Department of Health and Human Services doesn’t test or approve messaging apps in advance (U.S. Department of Health and Human Services). A platform marketing itself as “HIPAA certified” is using a term with no official meaning.

A legitimate vendor offers a signed Business Associate Agreement and a plain description of the safeguards behind the product instead. Ask for both directly.

03 · Consent

Consent comes before the first message

Patients have rights under HIPAA that touch texting directly. Under the Privacy Rule, an individual can request that a covered provider communicate with them by an alternative means, including unencrypted text, once they understand and accept the risk that comes with it (U.S. Department of Health and Human Services). The provider isn’t required to guess. The request, and the fact the patient accepted the risk, belongs on record.

In practice, that means getting clear agreement before the first clinical text goes out, being specific about what kind of messages the patient is opting into, and giving them a straightforward way to opt out. A patient who agreed to appointment reminders didn’t necessarily agree to anything else.

04 · Encryption

Why standard SMS is a grey area

Carrier SMS isn’t encrypted end to end, and it was never built with PHI in mind. That alone doesn’t make it automatically off-limits. HHS guidance on unencrypted email says the Privacy Rule doesn’t prohibit it for treatment-related communication when that’s what the patient chose, as long as reasonable safeguards apply and the patient understood the risk (U.S. Department of Health and Human Services). Clinics and compliance counsel commonly apply the same reasoning to text messages.

The pattern most clinics land on is a platform that layers a secured, logged channel over the number patients already text, so the message a patient receives looks like ordinary SMS while the record of it lives somewhere access-controlled and audited.

05 · Safeguards

The safeguards a texting platform needs

The same three categories from the HIPAA Security Rule apply here: administrative, physical, and technical (U.S. Department of Health and Human Services). For a texting tool specifically, the technical piece shows up first: encryption at rest, access tied to individual staff logins, and a log of who sent or read a given message.

A Business Associate Agreement with the platform isn’t optional if PHI will pass through it. That agreement should also name any subprocessor, such as the underlying carrier or cloud infrastructure, that can technically access the message content.

06 · Minimum necessary

Keep the message operational

Minimum necessary applies to what you type as much as who can see it. A reminder, a link to reschedule, a request for a photo update: these are operational and low risk. A full explanation of a diagnosis or a treatment plan belongs in a call or a portal message rather than a text thread a patient’s family member might glance at on a lock screen.

The patient still gets the full picture; the channel just matches how sensitive the content is.

  • ✓Reminders and confirmations: fine for text.
  • ✓Balance-due links and reschedule requests: fine for text.
  • ✓Diagnosis detail or treatment specifics: better as a call or a secured portal message.

07 · Med spas

Where clinics slip up on photos and groups

Aesthetic clinics text more photos than most practices: before-and-afters, progress shots, a patient asking whether something looks right. Each one is PHI the moment it’s tied to a name, and a photo sent from a personal phone to a personal phone has no audit trail and no safeguard behind it at all.

Group texts carry a second, quieter risk: a staff member replies to the wrong thread, or a patient’s message lands in a shared team inbox where people who never needed to see it can. A unified inbox that ties every channel to one patient record, with permissions by role, closes both gaps at once.

08 · One inbox

Calls, texts, and DMs in one thread

Health Hue Hub’s Conversations module brings SMS, calls, web chat, and social messages into one inbox tied to the patient record, with role-based permissions, built-in consent and opt-out handling, and an audit trail on every message and call.

None of that replaces reading the Business Associate Agreement yourself, confirming which plan it actually covers, or checking anything HIPAA-specific with your own compliance counsel. It does mean the texting, the calendar, and the patient record aren’t three separate systems each carrying their own risk.

See the unified inbox

A look at how texts, calls, and social messages land in one place, tied to the patient record.

FAQ

Questions

Is regular SMS ever HIPAA compliant?
It can be part of a compliant setup, but standard carrier SMS alone isn’t encrypted end to end and carries no audit trail. It becomes workable when it runs through a platform with a signed Business Associate Agreement, logging, and access controls, and when the patient has agreed to that channel knowing the risk.
Do we need a patient’s consent before texting them?
Get it before the first clinical message. HHS guidance expects patients to be told the risk of unencrypted messages, and texting rules outside HIPAA also expect permission. Say what they’re opting into (appointment reminders, or more), record the agreement, and give them a simple way to stop.
Can front desk staff text patients from their personal phones?
This is one of the most common gaps in a clinic’s setup. A personal phone has no Business Associate Agreement behind it, no access controls, and no audit trail. If a staff member leaves, the message history leaves with them.
What if a patient texts our clinic first?
An inbound text doesn’t waive any of the underlying requirements. Reply through a platform your clinic has a Business Associate Agreement with, and confirm consent for the type of messages you plan to send going forward, beyond that one reply.
Can we send before-and-after photos by text?
Only through a platform with the right agreement and access controls behind it, and only once the patient understands the photo is being sent that way. A photo sent personal-phone-to-personal-phone has no protection behind it at all.
Does a group text or team chat about a patient count?
Yes. If the message ties an identifiable patient to anything about their care, it’s PHI regardless of how many people are on the thread. Route it through a platform with access controls instead of an ordinary group chat.
What happens when a patient asks to stop receiving texts?
Honour it immediately and record that the opt-out happened. A texting platform built for healthcare should handle this automatically rather than relying on someone to remember to update a spreadsheet.

Sources

Keep reading

Related guides

HIPAA compliant CRM, explainedWhat a patient engagement platform doesMedical answering service: what it coversPatient management software, explained