Cybersecurity: 24/7/365

A patient texts your front desk number: "Did my biopsy come back?" The medical assistant knows the answer. It is on the screen in front of her.
What she does next is a compliance decision, and most practices have never told her what the right answer is. So she guesses, and she usually guesses in the direction of being helpful.
Texting is now how patients expect to reach a healthcare provider. The rules are more permissive than most practices assume — and stricter in one place they usually miss.
Standard SMS is not secure. It is not encrypted end to end, carriers retain copies, and messages appear on a lock screen where anyone holding the phone can read them.
But HIPAA does not ban unsecured channels. The HIPAA Security Rule requires you to assess risk and apply reasonable safeguards — it does not dictate a technology. And the Privacy Rule contains a provision most practices have never read that changes the answer entirely.
Under the right to request confidential communications, a patient may ask you to contact them by alternative means, and a covered entity must accommodate reasonable requests. OCR has been consistent on what follows: if a patient wants to receive their health information by an unencrypted channel, you may honour that, provided you have warned them of the risk and they still prefer it.
So the sequence is: the patient asks, you explain the risk in plain language, they confirm, you document it. After that, texting that patient is a permitted disclosure — not a violation.
What you cannot do is decide unilaterally that texting protected health information is fine because it is convenient for the practice. The security rules put that choice with the patient, documented, not with the front desk.
A large amount of routine patient communication contains no clinical detail at all, and appointment reminders are the obvious case.
"This is a reminder of your appointment on Tuesday at 2pm. Reply C to confirm" discloses very little. Reminders fall under treatment and healthcare operations, and practices have sent them by text for years.
Safe to send without a documented preference on file:
Keep the specifics out. The rule of thumb that holds up: a stranger reading the text message over the patient's shoulder should learn nothing about their health. Naming the department can be enough to fail that test — an appointment reminder from an oncology clinic discloses more than one from a family practice.
That stranger is not hypothetical. A phone sitting face-up on a kitchen counter shows message previews to everyone in the room, and a shared family device puts patient information in front of whoever picks it up. Unauthorized access to a text message rarely involves a hacker — it involves an unauthorized individual who simply had the phone.
For anything containing real clinical content, use a secure message service rather than ordinary SMS text. Patient portals with text notification, secure messaging built into your EHR, and dedicated platforms all work.
Whatever you choose needs the same four things any system handling PHI needs:
Write the policies and procedures down and train to them. Staff need to know which channel to use for which message, and what to do when a patient texts a clinical question to the general practice line — which they will, regardless of what you tell them.
Have an answer ready for that case. Something like: "I can't share results by text, but I've sent them to your portal and Dr. Chen will call you this afternoon." It is responsive without being a disclosure.
Once the channel decisions are made, a short set of habits carries most of the HIPAA compliance weight:
Most attention goes to patient-facing messages. The larger unmanaged risk is internal.
Clinical staff text each other about patients constantly, because it is faster than anything else available. "Room 4 is the diabetic with the foot ulcer, needs a dressing change." That is protected health information sitting in two personal phones, backed up to two personal cloud accounts, visible on two lock screens, and completely outside your access controls.
When someone leaves the practice, all of it walks out with them. There is no audit trail and no way to retrieve it.
Give staff a HIPAA-compliant alternative, because prohibition alone will not work against a habit this useful. A clinical messaging platform, or your EHR's internal messaging if it has any. The requirement is the same one that applies to any system touching patient information: encryption, individual accounts, and protection against unauthorized access. Then cover personal devices explicitly in your BYOD policy, since that is where the exposure actually lives.
This is where practices get caught, because it is a different statute with different rules and much easier private enforcement.
The Telephone Consumer Protection Act governs automated texts to mobile numbers regardless of content. It does not care whether your message contains PHI. It cares whether you had consent to send an automated text at all.
The distinction that matters: messages about treatment sit on much firmer ground than messages that market something. An appointment reminder is treatment-related. A text about a promotional offer on cosmetic services is marketing, and marketing requires prior express written consent.
Practical protections:
TCPA damages run per message and attract class actions. A practice can comply with HIPAA perfectly and still have a serious TCPA problem.
Nothing new is in force. The proposed Security Rule overhaul from January 2025 remains a proposal, with a final-rule target around July 2027 that has already moved once.
If finalised as written it would tighten the privacy and security expectations around electronic communications — mandatory encryption with narrow exceptions, and written documentation of the systems that handle PHI. Our summary of the proposed Security Rule changes covers it. Do not rebuild your texting programme around a rule that is not final, but do not assume unencrypted channels get easier either.
Four decisions cover most practices.
Reminders and portal notifications go by ordinary text, with no clinical detail and an opt-out in the flow. This is the bulk of your volume and the lowest risk. Automating it is also where practices recover the most front-desk time, as we cover in AI appointment scheduling.
Clinical content goes through the portal or a secure platform, always.
A patient who specifically requests plain text gets a documented risk warning, a recorded preference, and then gets what they asked for.
Staff-to-staff clinical messages use an approved tool, never personal SMS.
Put those four rules on one page, train the front desk on the results question specifically, and you have covered the situations that actually arise. The alternative is what most practices have now — a medical assistant deciding privacy and security policy on her own, one text at a time.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.