Back to HIPAA

HIPAA Compliant Texting: When You Can Text Patients and How to Do It Safely

HIPAA compliant texting illustration: patient SMS, a secure messaging app and a patient portal feeding into a protected system

Short answer: HIPAA does not ban texting patients. HHS accepts unencrypted email when a warned patient still prefers it, but that guidance does not specifically cover SMS, so plain texting should be a documented decision. Routine or staff texting of PHI needs safeguards: a vendor that signs a BAA, access controls, audit logs, managed devices and a retention approach.

Related guides:

Key takeaways

  • You can text patients who ask for it. Use a secure messaging platform where you can, and if you use plain SMS, warn the patient, record their choice and keep PHI to a minimum.
  • That patient preference exception covers communication with that patient. It does not make consumer SMS acceptable for internal clinical messaging or bulk PHI.
  • Any texting platform that stores or processes PHI on your behalf is a business associate and needs a signed BAA.
  • Your safeguards should cover encryption, unique user access, audit logs, device management, retention and staff training, all documented in a written policy.

Can doctors and healthcare providers text patients?

Yes, doctors can text patients, but how much PHI goes into the message and which channel you use determine what safeguards and permissions you need.

It helps to separate three kinds of messages:

Message type Example Typical PHI level
Logistics with minimal PHI "Reminder: you have an appointment tomorrow at 10:00. Reply C to confirm." Low, but still PHI when linked to a patient and a provider
Care coordination "Your refill request was approved and sent to your pharmacy." Moderate
Clinical detail Lab results, diagnoses, medication changes, images High

An appointment reminder can still be PHI, because it reveals that a specific person is a patient. The Privacy Rule generally permits these communications for treatment and operations, so the real question is whether the channel is reasonable for the content.

Keep each text to the least PHI it needs. The formal minimum necessary standard (45 CFR 164.502(b)) does not apply to disclosures to the patient themselves or to providers for treatment (164.502(b)(2)), but data minimization is still good practice for an exposed channel like SMS. A reminder with the clinic and time is usually enough. Leave out the visit reason, a sensitive specialty and test names, and keep clinical detail for a secure channel unless the patient asked for it by text.

What changes when the patient asks to be texted?

When a patient asks to communicate by text and you use standard SMS, warn the patient first, document their choice and keep the PHI in each message to a minimum.

HHS's position that a provider may send unencrypted messages to a patient who has been warned and still prefers them comes mainly from its guidance on the individual right of access (45 CFR 164.524) and the preamble to the 2013 Omnibus Rule. The confidential communications right (45 CFR 164.522(b)) is separate and usually about more privacy, not less. We are not aware of HHS guidance that applies this position to SMS specifically. For email itself, see our HIPAA compliant email guide.

A workable patient preference flow is below. It is a risk-reduction practice, not a safe harbor, so have counsel review it before you rely on it:

  1. Ask for the preferred channel at intake or in the portal: SMS, secure app, portal only or phone.
  2. Warn in plain language that standard text messages are not encrypted end to end, can be read by anyone with access to the phone and may be stored by the carrier.
  3. Record the choice, the date, the phone number and the version of the warning in the patient record.
  4. Verify the number before the first PHI message, for example with a confirmation code.
  5. Honor changes promptly when the patient revokes or updates the preference.
  6. Limit scope to what the patient agreed to. A patient who opted in to reminders has not necessarily agreed to receive lab results by text.

Marketing texts are a separate matter. They can require a HIPAA authorization, and automated texting can also raise consent rules under other laws, such as the federal Telephone Consumer Protection Act. Treat that as its own legal review.

Is standard SMS HIPAA compliant?

Standard SMS lacks the encryption, access control and audit features the Security Rule expects, so using it for routine PHI is hard to justify. See the patient preference flow above for when it may still be used.

The main risks of plain SMS and consumer messaging:

  • No reliable encryption. SMS travels through carrier networks without end-to-end encryption, and messages can be intercepted or retained along the way.
  • No organizational control. Messages sit on phones you cannot wipe, lock down or revoke when someone leaves.
  • No audit trail. You cannot show who sent what PHI to whom during an investigation.
  • Wrong recipient errors. A mistyped or recycled phone number sends PHI to a stranger, which may be a reportable incident under the HIPAA Breach Notification Rule.
  • Retention gaps. Clinical texts may belong in the medical record, but copies on a personal phone escape your retention controls.

Telecom carriers transmitting a message are generally treated as conduits rather than business associates. A texting platform or app vendor that stores, processes or routes your PHI is not a conduit, so it needs a BAA.

What safeguards does HIPAA compliant texting need?

HIPAA compliant text messaging needs the same Security Rule safeguards as any other system holding ePHI, applied to the messaging platform, the devices and the people using them.

Safeguard What to implement Security Rule reference
Encryption Encryption in transit and at rest on the platform and the device 45 CFR 164.312(a)(2)(iv), 164.312(e)
Access control Unique user IDs, MFA, automatic logoff, role-based access to conversations 45 CFR 164.312(a), 164.312(d)
Audit logs Records of who sent, read, forwarded or deleted messages 45 CFR 164.312(b)
Business associate agreement Signed BAA with the messaging vendor and any vendor it relies on for PHI 45 CFR 164.502(e), 164.504(e)
Device management Passcodes, device encryption, remote wipe, separation of work data on personal devices 45 CFR 164.310(d)
Retention and disposal Defined retention period, export of clinical messages to the record, deletion on schedule 45 CFR 164.310(d), plus state record laws
Training Staff know what may be texted, to whom and through which app 45 CFR 164.308(a)(5)
Risk analysis Texting workflows included in your risk analysis and risk management plan 45 CFR 164.308(a)(1)

Under the current Security Rule, encryption is "addressable": you implement it if reasonable and appropriate, or document why not and use an equivalent measure. For messaging, skipping it is hard to justify. HHS proposed Security Rule changes in January 2025 that would make encryption mandatory with limited exceptions. When this article was published it was still a proposed rule, so check the status of the Federal Register notice before relying on it. Our HIPAA Security Rule update post tracks the proposal. Our HIPAA encryption requirements guide covers the details.

On retention, note that HIPAA's six-year rule (45 CFR 164.316(b)(2)) applies to your policies and compliance documentation. How long you keep clinical messages is usually set by state medical record laws, so document the period you follow.

SMS, secure messaging app or patient portal: which should you use?

Use standard SMS only for low-sensitivity messages or patient-requested communication, a secure messaging app for two-way clinical conversations, and the patient portal for results, records and anything you would not want on a lock screen.

Factor Standard SMS Secure messaging app Patient portal
Encryption Not end to end through carriers Typically end to end or encrypted in transit and at rest Encrypted in transit and at rest
BAA available Carrier is usually a conduit, so no BAA, but no protection either Yes, required before use Yes, through your EHR or portal vendor
Audit logs None you control Usually yes Yes
Patient effort None, works on any phone Requires app install or secure link Requires account and login
Best for Appointment reminders, "you have a new message" alerts, patient-requested texts Care team chat, quick clinical questions, after-hours coordination Lab results, visit summaries, documents, billing
Main risk Interception, wrong number, no record Shadow use of unapproved apps Low patient adoption

A common pattern combines them: an SMS saying "You have a new secure message from your care team" links to the portal or app, and the PHI stays behind the login.

What about texting between clinicians and staff?

Clinician-to-clinician texting of PHI should run through an approved secure messaging platform under a BAA, not personal SMS or consumer chat apps.

The patient preference exception does not apply here, because no patient has accepted the risk. Staff texting each other on personal phones creates PHI copies you cannot audit, retain or wipe.

Hospitals face an additional layer. CMS guidance to Medicare-participating hospitals and critical access hospitals (memo QSO-24-05-Hospital/CAH, February 8, 2024) permits texting patient information and orders among members of the health care team when it is done through a HIPAA compliant secure texting platform and in line with the Conditions of Participation, including medical record requirements. CMS still describes computerized provider order entry as the preferred method for orders. Standard SMS and consumer chat apps are not secure texting platforms. If you serve hospital customers, expect them to ask how your product handles orders and messages.

HealthTech vendors building messaging into a product are business associates, so encryption, role-based access, audit logging and retention belong in the design. If a third-party SMS API will not sign a BAA, keep PHI out of the message body.

What should a texting policy include?

A HIPAA texting policy should state which channels are approved, what content each channel may carry, how patient preferences are captured and how devices and records are managed.

  • Approved channels: named platforms for patient texting and internal messaging, with consumer SMS and chat apps explicitly limited.
  • Content rules: what may go in an SMS, what must stay in the app or portal, and examples of each.
  • Patient preferences: how to request, warn, record, verify and revoke texting preferences.
  • Vendor BAAs: a signed BAA for every messaging, SMS gateway and notification vendor that handles PHI, tracked in your vendor inventory.
  • Device requirements: passcodes, encryption, mobile device management or app-level controls, and remote wipe.
  • Access management: onboarding and offboarding steps for messaging accounts, with MFA required.
  • Audit and review: who reviews message logs, how often and what triggers an investigation.
  • Retention: how long messages are kept, how clinical content reaches the medical record and how deletion happens.
  • Incident handling: what to do when a text goes to the wrong number or a device is lost.
  • Training: initial and periodic training with attendance records.
  • Annual review: policy approval, version history and an update after any texting incident.

If you are drafting this from scratch, our guide on creating HIPAA policies and procedures explains how to structure, approve and maintain them.

How SecureSlate helps

SecureSlate helps you manage the policy and evidence side of HIPAA compliant texting. You can link your texting policy and patient preference process to the HIPAA safeguards they support, track approval and review of that policy, and record which messaging and SMS vendors have signed BAAs. Where your identity and device management tools are connected, integrations help you collect evidence about the phones and accounts staff use for messaging.

Start your free SecureSlate trial

FAQ

Is it a HIPAA violation to text a patient?

Not by itself. HIPAA does not ban texting patients. Use the patient preference flow above if you send PHI over plain SMS. Violations usually come from texting PHI without safeguards, to the wrong person or through unapproved apps.

HIPAA does not require a specific signed form for treatment-related texts, but you should warn patients about unencrypted SMS and document their preference. Marketing texts can require a HIPAA authorization, and automated texting may trigger separate consent rules under other laws.

Is iMessage or WhatsApp HIPAA compliant?

End-to-end encryption alone does not make an app HIPAA compliant. Consumer apps typically do not offer a BAA, central audit logs or organizational control over accounts and devices, so they are a poor fit for staff messaging. A patient may still choose to use them after being warned of the risks.

Can we put lab results in a text message?

Only if the patient has specifically requested that and accepted the risk. A safer default is a text saying results are available, with the results themselves behind the portal or secure app login.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Oct 2, 2026 · HIPAA

HIPAA Permitted Uses and Disclosures: When PHI Can Be Shared Without Authorization

Oct 2, 2026 · HIPAA

Who Does HIPAA Apply To? A Decision Guide for HealthTech and SaaS Founders

Sep 29, 2026 · HIPAA

After SOC 2: The Compliance Roadmap for HealthTech Companies

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?