Cybersecurity: 24/7/365

Blog

HIPAA and Texting Patients: What's Allowed
by 4MEDNET Team
June 10, 2026
HIPAA Compliance

A patient texts your front desk number: "Did my biopsy come back?" The medical assistant knows the answer. It is on the screen in front of her.

What she does next is a compliance decision, and most practices have never told her what the right answer is. So she guesses, and she usually guesses in the direction of being helpful.

Texting is now how patients expect to reach a healthcare provider. The rules are more permissive than most practices assume — and stricter in one place they usually miss.

Is SMS texting HIPAA compliant?

Standard SMS is not secure. It is not encrypted end to end, carriers retain copies, and messages appear on a lock screen where anyone holding the phone can read them.

But HIPAA does not ban unsecured channels. The HIPAA Security Rule requires you to assess risk and apply reasonable safeguards — it does not dictate a technology. And the Privacy Rule contains a provision most practices have never read that changes the answer entirely.

Under the right to request confidential communications, a patient may ask you to contact them by alternative means, and a covered entity must accommodate reasonable requests. OCR has been consistent on what follows: if a patient wants to receive their health information by an unencrypted channel, you may honour that, provided you have warned them of the risk and they still prefer it.

So the sequence is: the patient asks, you explain the risk in plain language, they confirm, you document it. After that, texting that patient is a permitted disclosure — not a violation.

What you cannot do is decide unilaterally that texting protected health information is fine because it is convenient for the practice. The security rules put that choice with the patient, documented, not with the front desk.

What you can send via text without any of that

A large amount of routine patient communication contains no clinical detail at all, and appointment reminders are the obvious case.

"This is a reminder of your appointment on Tuesday at 2pm. Reply C to confirm" discloses very little. Reminders fall under treatment and healthcare operations, and practices have sent them by text for years.

Safe to send without a documented preference on file:

  • Appointment reminders, confirmations, and reschedule prompts
  • "Your results are ready, please log in to the portal" — the notification, not the result
  • General practice notices: closures, flu clinic dates, new hours
  • Billing notices that say a statement is available, without describing services

Keep the specifics out. The rule of thumb that holds up: a stranger reading the text message over the patient's shoulder should learn nothing about their health. Naming the department can be enough to fail that test — an appointment reminder from an oncology clinic discloses more than one from a family practice.

That stranger is not hypothetical. A phone sitting face-up on a kitchen counter shows message previews to everyone in the room, and a shared family device puts patient information in front of whoever picks it up. Unauthorized access to a text message rarely involves a hacker — it involves an unauthorized individual who simply had the phone.

How to send HIPAA compliant text messages

For anything containing real clinical content, use a secure message service rather than ordinary SMS text. Patient portals with text notification, secure messaging built into your EHR, and dedicated platforms all work.

Whatever you choose needs the same four things any system handling PHI needs:

  • A business associate agreement with the vendor. Ordinary carrier SMS has no BAA behind it, which is a large part of why plain texting cannot carry clinical detail.
  • Encryption in transit and at rest.
  • Access controls — individual logins, and the ability to remove someone's access the day they leave.
  • An audit trail recording the sender, the recipient, and the time, so you can reconstruct who disclosed what.

Write the policies and procedures down and train to them. Staff need to know which channel to use for which message, and what to do when a patient texts a clinical question to the general practice line — which they will, regardless of what you tell them.

Have an answer ready for that case. Something like: "I can't share results by text, but I've sent them to your portal and Dr. Chen will call you this afternoon." It is responsive without being a disclosure.

Text messaging best practices

Once the channel decisions are made, a short set of habits carries most of the HIPAA compliance weight:

  • Send the minimum. Never put a diagnosis, test result, or medication in an ordinary text message. If the message needs clinical detail, it needs the portal.
  • Verify the number before the first send, and again when a patient says they changed it. Texting patient information to a reassigned number is a disclosure to a stranger.
  • Use a practice number, never a personal one. A clinician texting from their own mobile creates a record nobody can audit and a number patients keep using at midnight.
  • Document the preference. When a patient asks to receive information by text, record the request, the risk warning, and the date in the chart.
  • Time your sends. Automated messages outside reasonable hours generate complaints and, under TCPA, exposure.
  • Review the log quarterly. Look at what staff actually send text messages about, not what the policy says they send.

The part practices miss: staff texting each other

Most attention goes to patient-facing messages. The larger unmanaged risk is internal.

Clinical staff text each other about patients constantly, because it is faster than anything else available. "Room 4 is the diabetic with the foot ulcer, needs a dressing change." That is protected health information sitting in two personal phones, backed up to two personal cloud accounts, visible on two lock screens, and completely outside your access controls.

When someone leaves the practice, all of it walks out with them. There is no audit trail and no way to retrieve it.

Give staff a HIPAA-compliant alternative, because prohibition alone will not work against a habit this useful. A clinical messaging platform, or your EHR's internal messaging if it has any. The requirement is the same one that applies to any system touching patient information: encryption, individual accounts, and protection against unauthorized access. Then cover personal devices explicitly in your BYOD policy, since that is where the exposure actually lives.

TCPA: the law that is stricter than HIPAA here

This is where practices get caught, because it is a different statute with different rules and much easier private enforcement.

The Telephone Consumer Protection Act governs automated texts to mobile numbers regardless of content. It does not care whether your message contains PHI. It cares whether you had consent to send an automated text at all.

The distinction that matters: messages about treatment sit on much firmer ground than messages that market something. An appointment reminder is treatment-related. A text about a promotional offer on cosmetic services is marketing, and marketing requires prior express written consent.

Practical protections:

  • Capture text consent at registration, with the mobile number and a date, and keep it
  • Include opt-out instructions and honour them immediately — an unauthorized send after an opt-out is the classic claim
  • Keep marketing texts entirely separate from treatment texts, with their own consent
  • Re-verify numbers periodically, because numbers get reassigned and the new holder did not consent to anything

TCPA damages run per message and attract class actions. A practice can comply with HIPAA perfectly and still have a serious TCPA problem.

Is there a new HIPAA rule this year?

Nothing new is in force. The proposed Security Rule overhaul from January 2025 remains a proposal, with a final-rule target around July 2027 that has already moved once.

If finalised as written it would tighten the privacy and security expectations around electronic communications — mandatory encryption with narrow exceptions, and written documentation of the systems that handle PHI. Our summary of the proposed Security Rule changes covers it. Do not rebuild your texting programme around a rule that is not final, but do not assume unencrypted channels get easier either.

A workable policy

Four decisions cover most practices.

Reminders and portal notifications go by ordinary text, with no clinical detail and an opt-out in the flow. This is the bulk of your volume and the lowest risk. Automating it is also where practices recover the most front-desk time, as we cover in AI appointment scheduling.

Clinical content goes through the portal or a secure platform, always.

A patient who specifically requests plain text gets a documented risk warning, a recorded preference, and then gets what they asked for.

Staff-to-staff clinical messages use an approved tool, never personal SMS.

Put those four rules on one page, train the front desk on the results question specifically, and you have covered the situations that actually arise. The alternative is what most practices have now — a medical assistant deciding privacy and security policy on her own, one text at a time.

Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.

Tags:
Share:
HIPAACybersecurityManaged ITRansomwareComplianceEHRData BreachAI AutomationBackup & DR
4MEDNET
Contact Us
Ready to secure your practice?
Schedule a free IT assessment today
Book Your Free IT Assessment