Texting

HIPAA texting and patient messaging: what is allowed?

Patients expect texts. Regulators expect controls. The gap is where many practices get surprised.

Is regular SMS HIPAA compliant?

Standard SMS is not encrypted end-to-end in a way that satisfies typical HIPAA risk analyses for PHI. Some clinics send non-PHI reminders (“Your appointment is Tuesday at 2”) through commercial SMS with patient consent—but the moment you include diagnosis, results, or detailed clinical content, you need a HIPAA-aligned channel.

iMessage, WhatsApp, and team chat

Consumer messaging apps are convenient and risky: personal devices, no central audit log, and no BAA with the platform. Team chat inside your EHR or a HIPAA-ready communication stack is easier to defend.

What a safer texting workflow looks like

  • Patient consent documented for the channel you use
  • Minimum necessary content in messages
  • Staff trained not to photograph screens or forward PHI to personal phones
  • Audit logs retained for the systems that actually carry PHI

Bundle chat with email and forms

When secure chat lives next to HIPAA email and intake forms, front desk staff have one habit—not six workarounds.

Gmail + HIPAA: what clinics do instead · Book a consult

Next step

Questions after reading?

Book a consult or take the risk check—no sales pitch required.