
Short answer: HIPAA does not ban texting patients. HHS accepts unencrypted email when a warned patient still prefers it, but that guidance does not specifically cover SMS, so plain texting should be a documented decision. Routine or staff texting of PHI needs safeguards: a vendor that signs a BAA, access controls, audit logs, managed devices and a retention approach.
Related guides:
- What is a HIPAA Business Associate Agreement?
- HIPAA Security Rule explained
- HIPAA compliance for telehealth
Key takeaways
- You can text patients who ask for it. Use a secure messaging platform where you can, and if you use plain SMS, warn the patient, record their choice and keep PHI to a minimum.
- That patient preference exception covers communication with that patient. It does not make consumer SMS acceptable for internal clinical messaging or bulk PHI.
- Any texting platform that stores or processes PHI on your behalf is a business associate and needs a signed BAA.
- Your safeguards should cover encryption, unique user access, audit logs, device management, retention and staff training, all documented in a written policy.
Can doctors and healthcare providers text patients?
Yes, doctors can text patients, but how much PHI goes into the message and which channel you use determine what safeguards and permissions you need.
It helps to separate three kinds of messages:
| Message type | Example | Typical PHI level |
|---|---|---|
| Logistics with minimal PHI | "Reminder: you have an appointment tomorrow at 10:00. Reply C to confirm." | Low, but still PHI when linked to a patient and a provider |
| Care coordination | "Your refill request was approved and sent to your pharmacy." | Moderate |
| Clinical detail | Lab results, diagnoses, medication changes, images | High |
An appointment reminder can still be PHI, because it reveals that a specific person is a patient. The Privacy Rule generally permits these communications for treatment and operations, so the real question is whether the channel is reasonable for the content.
Keep each text to the least PHI it needs. The formal minimum necessary standard (45 CFR 164.502(b)) does not apply to disclosures to the patient themselves or to providers for treatment (164.502(b)(2)), but data minimization is still good practice for an exposed channel like SMS. A reminder with the clinic and time is usually enough. Leave out the visit reason, a sensitive specialty and test names, and keep clinical detail for a secure channel unless the patient asked for it by text.
What changes when the patient asks to be texted?
When a patient asks to communicate by text and you use standard SMS, warn the patient first, document their choice and keep the PHI in each message to a minimum.
HHS's position that a provider may send unencrypted messages to a patient who has been warned and still prefers them comes mainly from its guidance on the individual right of access (45 CFR 164.524) and the preamble to the 2013 Omnibus Rule. The confidential communications right (45 CFR 164.522(b)) is separate and usually about more privacy, not less. We are not aware of HHS guidance that applies this position to SMS specifically. For email itself, see our HIPAA compliant email guide.
A workable patient preference flow is below. It is a risk-reduction practice, not a safe harbor, so have counsel review it before you rely on it:
- Ask for the preferred channel at intake or in the portal: SMS, secure app, portal only or phone.
- Warn in plain language that standard text messages are not encrypted end to end, can be read by anyone with access to the phone and may be stored by the carrier.
- Record the choice, the date, the phone number and the version of the warning in the patient record.
- Verify the number before the first PHI message, for example with a confirmation code.
- Honor changes promptly when the patient revokes or updates the preference.
- Limit scope to what the patient agreed to. A patient who opted in to reminders has not necessarily agreed to receive lab results by text.
Marketing texts are a separate matter. They can require a HIPAA authorization, and automated texting can also raise consent rules under other laws, such as the federal Telephone Consumer Protection Act. Treat that as its own legal review.
Is standard SMS HIPAA compliant?
Standard SMS lacks the encryption, access control and audit features the Security Rule expects, so using it for routine PHI is hard to justify. See the patient preference flow above for when it may still be used.
The main risks of plain SMS and consumer messaging:
- No reliable encryption. SMS travels through carrier networks without end-to-end encryption, and messages can be intercepted or retained along the way.
- No organizational control. Messages sit on phones you cannot wipe, lock down or revoke when someone leaves.
- No audit trail. You cannot show who sent what PHI to whom during an investigation.
- Wrong recipient errors. A mistyped or recycled phone number sends PHI to a stranger, which may be a reportable incident under the HIPAA Breach Notification Rule.
- Retention gaps. Clinical texts may belong in the medical record, but copies on a personal phone escape your retention controls.
Telecom carriers transmitting a message are generally treated as conduits rather than business associates. A texting platform or app vendor that stores, processes or routes your PHI is not a conduit, so it needs a BAA.
What safeguards does HIPAA compliant texting need?
HIPAA compliant text messaging needs the same Security Rule safeguards as any other system holding ePHI, applied to the messaging platform, the devices and the people using them.
| Safeguard | What to implement | Security Rule reference |
|---|---|---|
| Encryption | Encryption in transit and at rest on the platform and the device | 45 CFR 164.312(a)(2)(iv), 164.312(e) |
| Access control | Unique user IDs, MFA, automatic logoff, role-based access to conversations | 45 CFR 164.312(a), 164.312(d) |
| Audit logs | Records of who sent, read, forwarded or deleted messages | 45 CFR 164.312(b) |
| Business associate agreement | Signed BAA with the messaging vendor and any vendor it relies on for PHI | 45 CFR 164.502(e), 164.504(e) |
| Device management | Passcodes, device encryption, remote wipe, separation of work data on personal devices | 45 CFR 164.310(d) |
| Retention and disposal | Defined retention period, export of clinical messages to the record, deletion on schedule | 45 CFR 164.310(d), plus state record laws |
| Training | Staff know what may be texted, to whom and through which app | 45 CFR 164.308(a)(5) |
| Risk analysis | Texting workflows included in your risk analysis and risk management plan | 45 CFR 164.308(a)(1) |
Under the current Security Rule, encryption is "addressable": you implement it if reasonable and appropriate, or document why not and use an equivalent measure. For messaging, skipping it is hard to justify. HHS proposed Security Rule changes in January 2025 that would make encryption mandatory with limited exceptions. When this article was published it was still a proposed rule, so check the status of the Federal Register notice before relying on it. Our HIPAA Security Rule update post tracks the proposal. Our HIPAA encryption requirements guide covers the details.
On retention, note that HIPAA's six-year rule (45 CFR 164.316(b)(2)) applies to your policies and compliance documentation. How long you keep clinical messages is usually set by state medical record laws, so document the period you follow.
SMS, secure messaging app or patient portal: which should you use?
Use standard SMS only for low-sensitivity messages or patient-requested communication, a secure messaging app for two-way clinical conversations, and the patient portal for results, records and anything you would not want on a lock screen.
| Factor | Standard SMS | Secure messaging app | Patient portal |
|---|---|---|---|
| Encryption | Not end to end through carriers | Typically end to end or encrypted in transit and at rest | Encrypted in transit and at rest |
| BAA available | Carrier is usually a conduit, so no BAA, but no protection either | Yes, required before use | Yes, through your EHR or portal vendor |
| Audit logs | None you control | Usually yes | Yes |
| Patient effort | None, works on any phone | Requires app install or secure link | Requires account and login |
| Best for | Appointment reminders, "you have a new message" alerts, patient-requested texts | Care team chat, quick clinical questions, after-hours coordination | Lab results, visit summaries, documents, billing |
| Main risk | Interception, wrong number, no record | Shadow use of unapproved apps | Low patient adoption |
A common pattern combines them: an SMS saying "You have a new secure message from your care team" links to the portal or app, and the PHI stays behind the login.
What about texting between clinicians and staff?
Clinician-to-clinician texting of PHI should run through an approved secure messaging platform under a BAA, not personal SMS or consumer chat apps.
The patient preference exception does not apply here, because no patient has accepted the risk. Staff texting each other on personal phones creates PHI copies you cannot audit, retain or wipe.
Hospitals face an additional layer. CMS guidance to Medicare-participating hospitals and critical access hospitals (memo QSO-24-05-Hospital/CAH, February 8, 2024) permits texting patient information and orders among members of the health care team when it is done through a HIPAA compliant secure texting platform and in line with the Conditions of Participation, including medical record requirements. CMS still describes computerized provider order entry as the preferred method for orders. Standard SMS and consumer chat apps are not secure texting platforms. If you serve hospital customers, expect them to ask how your product handles orders and messages.
HealthTech vendors building messaging into a product are business associates, so encryption, role-based access, audit logging and retention belong in the design. If a third-party SMS API will not sign a BAA, keep PHI out of the message body.
What should a texting policy include?
A HIPAA texting policy should state which channels are approved, what content each channel may carry, how patient preferences are captured and how devices and records are managed.
- Approved channels: named platforms for patient texting and internal messaging, with consumer SMS and chat apps explicitly limited.
- Content rules: what may go in an SMS, what must stay in the app or portal, and examples of each.
- Patient preferences: how to request, warn, record, verify and revoke texting preferences.
- Vendor BAAs: a signed BAA for every messaging, SMS gateway and notification vendor that handles PHI, tracked in your vendor inventory.
- Device requirements: passcodes, encryption, mobile device management or app-level controls, and remote wipe.
- Access management: onboarding and offboarding steps for messaging accounts, with MFA required.
- Audit and review: who reviews message logs, how often and what triggers an investigation.
- Retention: how long messages are kept, how clinical content reaches the medical record and how deletion happens.
- Incident handling: what to do when a text goes to the wrong number or a device is lost.
- Training: initial and periodic training with attendance records.
- Annual review: policy approval, version history and an update after any texting incident.
If you are drafting this from scratch, our guide on creating HIPAA policies and procedures explains how to structure, approve and maintain them.
How SecureSlate helps
SecureSlate helps you manage the policy and evidence side of HIPAA compliant texting. You can link your texting policy and patient preference process to the HIPAA safeguards they support, track approval and review of that policy, and record which messaging and SMS vendors have signed BAAs. Where your identity and device management tools are connected, integrations help you collect evidence about the phones and accounts staff use for messaging.
Start your free SecureSlate trial
FAQ
Is it a HIPAA violation to text a patient?
Not by itself. HIPAA does not ban texting patients. Use the patient preference flow above if you send PHI over plain SMS. Violations usually come from texting PHI without safeguards, to the wrong person or through unapproved apps.
Do patients need to sign a consent form to receive texts?
HIPAA does not require a specific signed form for treatment-related texts, but you should warn patients about unencrypted SMS and document their preference. Marketing texts can require a HIPAA authorization, and automated texting may trigger separate consent rules under other laws.
Is iMessage or WhatsApp HIPAA compliant?
End-to-end encryption alone does not make an app HIPAA compliant. Consumer apps typically do not offer a BAA, central audit logs or organizational control over accounts and devices, so they are a poor fit for staff messaging. A patient may still choose to use them after being warned of the risks.
Can we put lab results in a text message?
Only if the patient has specifically requested that and accepted the risk. A safer default is a text saying results are available, with the results themselves behind the portal or secure app login.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds