Care teams need to communicate quickly. A nurse wants to ask a physician about a lab value. An aide needs to tell a supervisor about a resident's change in condition. A therapist wants to coordinate a schedule. Texting from a personal phone is fast and familiar, which is exactly why it is so common and so risky.
HIPAA does not forbid texting outright, but it does require safeguards. Here is how to think about messaging and how to give staff a tool that is both quick and compliant.
The HIPAA Security Rule requires covered entities and business associates to implement safeguards to protect the confidentiality, integrity and availability of electronic protected health information, including when it is transmitted. Transmission security calls for protection against unauthorized access to ePHI sent over a network. The Privacy Rule's minimum necessary standard also applies to communications.
The rules are technology-neutral, so the question is whether your messaging method has reasonable and appropriate safeguards, based on your risk analysis.
Regular SMS and many consumer messaging apps have several weaknesses for PHI:
Messages may not be encrypted end to end in the way your policy requires
They are stored on personal phones and in carrier or cloud backups you do not control
There is no central way to retain, audit or delete them
A lost or stolen phone may expose conversation history
Messages can be sent to the wrong number easily
When staff leave, the information leaves with them
Group chats can include people who should not be there
These issues complicate your ability to meet access control, audit and retention expectations.
Several categories of tools are designed for healthcare messaging.
Purpose-built secure messaging apps provide encryption, user authentication, remote wipe, message expiration and audit logs. They typically require a business associate agreement with the vendor. Look for options that integrate with your EHR or directory.
Many electronic health record systems include secure communication features that keep messages inside the record system. This keeps information in one place and under existing access controls.
For communication with families and outside providers, secure portals or encrypted email can be appropriate, with identity verification built in.
Facility-owned phones with a managed messaging app give you more control than personal devices.
A clear, short policy helps staff do the right thing. Cover these points:
Approved tools: Name the apps and systems staff may use for PHI
Prohibited methods: State that regular text messages and consumer apps are not to be used for PHI
Minimum necessary: Share only what is needed, using initials or room numbers where your policy allows, though identifiers are still PHI in context
Orders: Specify whether and how orders may be communicated, according to your medical staff rules and applicable regulations
Personal devices: Set requirements such as screen lock, encryption, remote wipe and installation of management tools
Lost devices: Require immediate reporting
Retention: Explain how messages that become part of the record are preserved
Photos: Prohibit photos of residents or records on personal devices unless a specific approved process exists
Staff will use whatever is easiest. If the secure tool is slow or hard to log into, they will go back to text. To encourage adoption:
Choose a tool that is simple and works on devices staff already use
Provide short training and a quick reference guide
Set up groups for each unit and shift
Make sure physicians and consultants are enrolled too
Respond promptly when messages are sent so the tool proves useful
Technology controls help, but so does supervision. Remind staff regularly, address violations consistently and fairly, and review whether the approved tool meets real needs.
There will be moments when staff must reach someone quickly and the approved channel is unavailable. Define what to do: call by phone, use a designated backup, and document afterward. A realistic policy is more likely to be followed than an impossible one.
Messaging should appear in your HIPAA risk analysis, with documented decisions about acceptable tools and residual risks.
UnityCare IT helps healthcare organizations choose, deploy and support secure messaging tools and write practical policies for staff. If texting is happening informally in your facility, we can help you move it to a safer channel.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172