A nurse needs a quick answer from a physician. A therapist wants to tell the DON about a change in a resident. A maintenance worker needs to coordinate with a charge nurse. In every case, the fastest tool is the phone in their pocket. Text messaging is convenient, which is exactly why it is used, and why it creates real HIPAA risk when used carelessly.
So can staff text patient information? The honest answer is: sometimes, but only with the right controls.
Ordinary SMS and many consumer messaging apps lack features the HIPAA Security Rule expects for protected health information:
Messages are often not encrypted end to end, and SMS travels through carriers in a form that can be read.
Messages remain on personal phones with no central control, and on the phones of everyone in the thread.
There is no audit trail, and no way to remove messages from a lost phone.
Messages may be backed up to personal cloud accounts.
The organization cannot retrieve messages for investigations or retention.
Consumer apps typically do not sign business associate agreements.
The Security Rule requires access controls, audit controls, integrity protections and transmission security for ePHI. Standard texting meets few of them.
CMS has addressed texting of orders in guidance, stating that texting orders is not permitted unless done through a secure platform. Check current CMS and state guidance and your accreditation requirements, and involve your medical director and compliance officer in setting policy.
Look for tools designed for healthcare communication:
Encryption in transit and at rest.
Individual accounts with strong authentication, including PIN or biometric lock and multi-factor authentication where possible.
Remote wipe of the app and its data if a phone is lost or an employee leaves.
Message expiration or controlled retention.
Audit logs of who sent and read what.
A business associate agreement from the vendor.
The ability to message groups such as a unit or on-call team, and to include physicians who are outside your organization.
Directory integration, so you are not guessing phone numbers.
Some EHRs and nurse call systems also include built-in secure messaging. Ask your vendor what is available before buying something new.
Permitted: messages through the approved secure platform.
Limited: ordinary texts that contain no patient identifiers, such as I need you at the front desk, or running ten minutes late.
Prohibited: patient names, room numbers combined with conditions, photos of residents or wounds and any clinical details sent over standard texting or personal email.
Photos of wounds or residents are a common problem. They should be taken and sent only through approved tools, and not left in a personal camera roll.
If staff use personal phones, the policy should require a screen lock, current software, and installation of the secure messaging app with the ability to wipe that app on departure. Consider a mobile device management approach where appropriate.
Families often ask to text staff. Decide what you will say, and offer a compliant alternative such as a portal or phone call. In some circumstances patients can request unencrypted communication after being warned of the risk, but have this handled under a documented procedure.
Bring up texting in training, give clear examples and explain the secure alternative. Policies fail when the approved tool is harder than the convenient one, so make sure it is easy to use.
Messages that become part of the resident's record may need to be retained or entered in the chart. Decide how that is handled and ensure that your platform supports it.
Assuming a group chat on a consumer app is private.
Allowing screenshots of the EHR to be shared informally.
Forgetting to remove former employees from message groups.
Buying a secure messaging tool but not forbidding the old habit.
UnityCare IT helps healthcare organizations evaluate secure messaging options, configure mobile device protections and write practical policies staff will follow. If texting is already happening in your building, we can help you channel it into something safer.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172