Can Staff Text Resident Information? A HIPAA Messaging Guide

A nurse needs to tell the physician about a change in condition. A charge nurse wants to send a photo of a wound to the wound care consultant. A family member texts the administrator and gets a quick reply with details. Text messaging is quick, familiar and often the path of least resistance, which is why it is one of the most common HIPAA problem areas in healthcare.

What does HIPAA say about texting?

HIPAA does not ban texting. The Privacy Rule allows disclosure of PHI for treatment, and the Security Rule is technology-neutral. What it requires is that covered entities apply reasonable and appropriate safeguards to ePHI wherever it is stored or transmitted. That includes access controls, transmission security, audit controls and policies and procedures for devices.

Standard SMS text messages are not encrypted in a way that gives you control over them, they live on personal phone carriers' systems and can be forwarded or backed up to personal cloud accounts, and messages usually remain on the device indefinitely. Consumer messaging apps may offer encryption, but they typically lack the administrative controls and business associate agreements that a healthcare organization needs.

The risks in plain terms

Lost or stolen phones with resident information and no remote wipe.

Wrong recipient errors, such as sending a message to the wrong contact.

No audit trail that you can retrieve if a question arises.

Personal backups that copy messages to cloud accounts you cannot manage.

Medical record gaps, because clinical communications that affect care should be reflected in the record, and text threads sitting on private phones are not.

Mixed personal and professional contacts, which makes mistakes more likely.

What good looks like: secure messaging

Most healthcare organizations settle on a secure messaging platform designed for clinical use. Features to look for:

Encryption in transit and at rest.

Individual user accounts tied to your staff directory, with the ability to deactivate access immediately when someone leaves.

Remote wipe or the ability to keep data inside a managed container, so messages are not stored in the phone's general storage.

Message expiration and retention settings that match your policy.

Audit logs and the ability to retrieve messages when needed.

Support for photos and attachments within the secure app, rather than the phone's camera roll.

A signed business associate agreement with the vendor.

Read receipts and escalation options, which help clinicians know that a message was received.

Some EMR platforms include secure messaging features. Ask your vendor what is available before buying another tool.

Write a clear messaging policy

A short policy that staff can actually follow includes:

Which tools are approved for communicating about residents, and which are not.

The minimum necessary rule: use initials or resident identifiers sparingly and share only what is needed.

A ban on sending PHI through regular SMS, personal email or consumer chat apps.

Rules for photos: use only approved apps, never the default camera app for clinical images, and delete from personal devices.

How to handle physician orders. Many organizations have rules about when text orders are or are not acceptable, so check your policy, your medical director's expectations and applicable state and CMS requirements.

What to do if a message goes to the wrong person: report it right away so the privacy officer can assess it.

What happens when someone leaves the organization or loses a phone.

Mobile device management

If staff use personal phones, consider a bring-your-own-device approach with a managed work profile that separates work apps and data from personal content, enforces a screen lock and allows remote removal of work data only. This respects employee privacy while protecting resident information. Be sure policy and consent are clear.

Family communication

Families often want quick updates by text. Where the resident or personal representative has requested it, the Privacy Rule permits communication through a method they choose, as long as they are warned about the risks of unencrypted messaging and you document their preference. Keep content minimal, and prefer a secure family portal or phone call for clinical details.

Train and reinforce

Policy only works if staff understand the reason behind it. Include messaging in orientation and annual HIPAA training. Give examples from daily life: this is how you would ask a question about a resident without naming them, and this is how you share a wound photo through the approved app.

Getting started

Offer a tool that is faster than texting, and adoption will follow. UnityCare IT can help you evaluate secure messaging options, configure mobile device management and draft a policy that matches how your teams actually communicate.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172