Nurses text each other about shift swaps. A therapist sends a quick question to the director of nursing. A physician replies to an update by text. Texting is built into daily life, and in a busy care environment it is hard to ban. But standard text messages and personal messaging apps raise real privacy questions when resident information is involved.
This post explains the HIPAA considerations and gives practical options. It is general information, not legal advice.
No. HIPAA does not ban texting PHI. It requires covered entities and business associates to implement reasonable safeguards for electronic PHI, including protection against unauthorized access during transmission and storage. The question is whether the way you text meets those requirements and your own risk analysis.
No encryption guarantees. Standard SMS messages are not designed for secure transmission of sensitive information.
Messages live on personal devices. Phones are lost, upgraded, shared with family and backed up to personal cloud accounts.
No central control. The facility cannot easily remove messages from a departing employee's phone.
Limited auditing. You cannot track who saw what.
Wrong recipient errors. A message to the wrong number is a potential impermissible disclosure.
Messages become part of the record. Clinical information that guides care may belong in the medical record, but a text on a personal phone is not in it.
Screen notifications. Message previews appear on lock screens in public.
Many vendors offer messaging apps built for healthcare, with encryption, access controls, remote wipe and message retention. Make sure the vendor will sign a business associate agreement. Some EHR systems include secure messaging, which keeps communication tied to the record.
Encryption in transit and at rest
Individual user accounts with MFA or device biometrics
Automatic screen lock and session timeouts
Remote wipe of the app or messages
Message expiration and retention controls
Audit trails
Directory of verified staff, to reduce wrong-recipient mistakes
Integration with the EHR where possible
A simple, practical policy should answer:
What is allowed? Define which tools are approved for messages involving PHI, and which are not.
What can be sent? Many facilities limit standard texting to non-clinical logistics, such as "call me when you can" or schedule changes, with no resident identifiers.
What about orders? Clinical orders should follow your medical staff's and regulators' requirements and be documented in the record. Check applicable rules and your medical director's guidance before permitting orders by text.
What about photos? Pictures of wounds or residents on personal phones are a significant risk. Provide an approved method for clinical photos that stores them securely and not in a personal gallery.
Personal devices. If staff use their own phones, specify minimum security: screen lock, updates and the ability to remove work data.
Reporting. Tell staff what to do if they text the wrong person or lose a phone.
Retention. Define how long messages are kept and how they are deleted.
HIPAA's minimum necessary standard applies. Even through a secure app, include only the information needed for the purpose. Use initials or room numbers only when appropriate, though remember that these may still be identifiers.
Residents and families sometimes prefer text. HIPAA allows communication by unencrypted email or text if the individual has been warned of the risks and still prefers it, but you should document that preference. Keep content limited, and avoid sensitive details, relying on a secure portal or phone call for those.
A policy no one reads will not help. Include texting in orientation and refresher training, and give concrete examples of acceptable and unacceptable messages. Make the approved option easy, since people will use whatever is fastest.
If staff already text about residents, treat it as a risk to include in your security risk analysis and plan for improvement. Document the decision, whether you adopt a secure tool or restrict content.
UnityCare IT can help you select and deploy secure messaging tools, set up mobile device protections and write a clear texting policy for your team. If texting is happening informally today, we can help bring it under control.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034