HIPAA and Texting: Safer Ways for Care Teams to Message

Care teams need to communicate quickly. A nurse wants to ask a physician about a lab value. An aide needs to tell a supervisor about a resident's change in condition. A therapist wants to coordinate a schedule. Texting from a personal phone is fast and familiar, which is exactly why it is so common and so risky.

HIPAA does not forbid texting outright, but it does require safeguards. Here is how to think about messaging and how to give staff a tool that is both quick and compliant.

What the Rules Say

The HIPAA Security Rule requires covered entities and business associates to implement safeguards to protect the confidentiality, integrity and availability of electronic protected health information, including when it is transmitted. Transmission security calls for protection against unauthorized access to ePHI sent over a network. The Privacy Rule's minimum necessary standard also applies to communications.

The rules are technology-neutral, so the question is whether your messaging method has reasonable and appropriate safeguards, based on your risk analysis.

Why Standard Text Messages Are a Problem

Regular SMS and many consumer messaging apps have several weaknesses for PHI:

Messages may not be encrypted end to end in the way your policy requires

They are stored on personal phones and in carrier or cloud backups you do not control

There is no central way to retain, audit or delete them

A lost or stolen phone may expose conversation history

Messages can be sent to the wrong number easily

When staff leave, the information leaves with them

Group chats can include people who should not be there

These issues complicate your ability to meet access control, audit and retention expectations.

Better Options

Several categories of tools are designed for healthcare messaging.

Secure Messaging Platforms

Purpose-built secure messaging apps provide encryption, user authentication, remote wipe, message expiration and audit logs. They typically require a business associate agreement with the vendor. Look for options that integrate with your EHR or directory.

EHR-Integrated Messaging

Many electronic health record systems include secure communication features that keep messages inside the record system. This keeps information in one place and under existing access controls.

Patient Portal and Secure Email

For communication with families and outside providers, secure portals or encrypted email can be appropriate, with identity verification built in.

Managed Devices

Facility-owned phones with a managed messaging app give you more control than personal devices.

Writing a Practical Texting Policy

A clear, short policy helps staff do the right thing. Cover these points:

Approved tools: Name the apps and systems staff may use for PHI

Prohibited methods: State that regular text messages and consumer apps are not to be used for PHI

Minimum necessary: Share only what is needed, using initials or room numbers where your policy allows, though identifiers are still PHI in context

Orders: Specify whether and how orders may be communicated, according to your medical staff rules and applicable regulations

Personal devices: Set requirements such as screen lock, encryption, remote wipe and installation of management tools

Lost devices: Require immediate reporting

Retention: Explain how messages that become part of the record are preserved

Photos: Prohibit photos of residents or records on personal devices unless a specific approved process exists

Adoption Is Everything

Staff will use whatever is easiest. If the secure tool is slow or hard to log into, they will go back to text. To encourage adoption:

Choose a tool that is simple and works on devices staff already use

Provide short training and a quick reference guide

Set up groups for each unit and shift

Make sure physicians and consultants are enrolled too

Respond promptly when messages are sent so the tool proves useful

Monitor and Reinforce

Technology controls help, but so does supervision. Remind staff regularly, address violations consistently and fairly, and review whether the approved tool meets real needs.

Emergencies and Edge Cases

There will be moments when staff must reach someone quickly and the approved channel is unavailable. Define what to do: call by phone, use a designated backup, and document afterward. A realistic policy is more likely to be followed than an impossible one.

Include It in Your Risk Analysis

Messaging should appear in your HIPAA risk analysis, with documented decisions about acceptable tools and residual risks.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations choose, deploy and support secure messaging tools and write practical policies for staff. If texting is happening informally in your facility, we can help you move it to a safer channel.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172