Patient messaging · Guide
The real rules for HIPAA compliant texting
Patients expect a text back. Clinics that build texting on a personal phone or an unsecured app are taking on more risk than they realize. This guide covers what HIPAA actually requires for text messages with patients, and where clinics most often get it wrong.
The short answer
HIPAA compliant texting means the platform is covered by a signed Business Associate Agreement, applies the safeguards the HIPAA Security Rule requires, and is used with patient consent and only the minimum necessary detail. Standard carrier SMS sent from a personal phone typically doesn’t meet that bar on its own. The compliance comes from the agreement, the safeguards, and how the clinic actually texts.
01 · Definition
What counts as texting PHI
A text message becomes protected health information the moment it ties a patient’s identity to anything about their care: an appointment, a treatment name, a photo, a dosage, a balance owed. “See you Thursday at 2” tied to a known patient at a known clinic already qualifies. That’s why a text thread deserves the same scrutiny as a phone call or an email, even though it feels informal, a principle covered in more depth in our guide to a HIPAA compliant CRM.
The platform matters, but so does the habit. A fully compliant platform used by staff who paste chart notes into a text thread is still a problem. The rules apply to the message itself, regardless of which software carries it.
02 · Certification
There is no HIPAA certified texting app
As with any other software category, no government body certifies a texting platform as HIPAA compliant. The U.S. Department of Health and Human Services doesn’t test or approve messaging apps in advance (U.S. Department of Health and Human Services). A platform marketing itself as “HIPAA certified” is using a term with no official meaning.
A legitimate vendor offers a signed Business Associate Agreement and a plain description of the safeguards behind the product instead. Ask for both directly.
03 · Consent
Consent comes before the first message
Patients have rights under HIPAA that touch texting directly. Under the Privacy Rule, an individual can request that a covered provider communicate with them by an alternative means, including unencrypted text, once they understand and accept the risk that comes with it (U.S. Department of Health and Human Services). The provider isn’t required to guess. The request, and the fact the patient accepted the risk, belongs on record.
In practice, that means getting clear agreement before the first clinical text goes out, being specific about what kind of messages the patient is opting into, and giving them a straightforward way to opt out. A patient who agreed to appointment reminders didn’t necessarily agree to anything else.
04 · Encryption
Why standard SMS is a grey area
Carrier SMS isn’t encrypted end to end, and it was never built with PHI in mind. That alone doesn’t make it automatically off-limits. HHS guidance on unencrypted email says the Privacy Rule doesn’t prohibit it for treatment-related communication when that’s what the patient chose, as long as reasonable safeguards apply and the patient understood the risk (U.S. Department of Health and Human Services). Clinics and compliance counsel commonly apply the same reasoning to text messages.
The pattern most clinics land on is a platform that layers a secured, logged channel over the number patients already text, so the message a patient receives looks like ordinary SMS while the record of it lives somewhere access-controlled and audited.
05 · Safeguards
The safeguards a texting platform needs
The same three categories from the HIPAA Security Rule apply here: administrative, physical, and technical (U.S. Department of Health and Human Services). For a texting tool specifically, the technical piece shows up first: encryption at rest, access tied to individual staff logins, and a log of who sent or read a given message.
A Business Associate Agreement with the platform isn’t optional if PHI will pass through it. That agreement should also name any subprocessor, such as the underlying carrier or cloud infrastructure, that can technically access the message content.
06 · Minimum necessary
Keep the message operational
Minimum necessary applies to what you type as much as who can see it. A reminder, a link to reschedule, a request for a photo update: these are operational and low risk. A full explanation of a diagnosis or a treatment plan belongs in a call or a portal message rather than a text thread a patient’s family member might glance at on a lock screen.
The patient still gets the full picture; the channel just matches how sensitive the content is.
- ✓Reminders and confirmations: fine for text.
- ✓Balance-due links and reschedule requests: fine for text.
- ✓Diagnosis detail or treatment specifics: better as a call or a secured portal message.
07 · Med spas
Where clinics slip up on photos and groups
Aesthetic clinics text more photos than most practices: before-and-afters, progress shots, a patient asking whether something looks right. Each one is PHI the moment it’s tied to a name, and a photo sent from a personal phone to a personal phone has no audit trail and no safeguard behind it at all.
Group texts carry a second, quieter risk: a staff member replies to the wrong thread, or a patient’s message lands in a shared team inbox where people who never needed to see it can. A unified inbox that ties every channel to one patient record, with permissions by role, closes both gaps at once.
08 · One inbox
Calls, texts, and DMs in one thread
Health Hue Hub’s Conversations module brings SMS, calls, web chat, and social messages into one inbox tied to the patient record, with role-based permissions, built-in consent and opt-out handling, and an audit trail on every message and call.
None of that replaces reading the Business Associate Agreement yourself, confirming which plan it actually covers, or checking anything HIPAA-specific with your own compliance counsel. It does mean the texting, the calendar, and the patient record aren’t three separate systems each carrying their own risk.
FAQ
Questions
Is regular SMS ever HIPAA compliant?
Do we need a patient’s consent before texting them?
Can front desk staff text patients from their personal phones?
What if a patient texts our clinic first?
Can we send before-and-after photos by text?
Does a group text or team chat about a patient count?
What happens when a patient asks to stop receiving texts?
Sources
- U.S. Department of Health and Human Services · Business Associate Contracts, Sample Provisions
- U.S. Department of Health and Human Services · Summary of the HIPAA Security Rule
- U.S. Department of Health and Human Services · Does the HIPAA Privacy Rule Permit Health Care Providers to Use E-mail to Discuss Health Issues With Patients?
- U.S. Department of Health and Human Services · Minimum Necessary Requirement
