HIPAA and Texting: What Care Teams Can and Cannot Send

A nurse needs an answer from a physician now. A supervisor wants to tell an aide about a resident's change in condition. A quick text seems like the fastest way. Yet standard SMS messages travel unencrypted through carrier networks, sit on personal phones and cannot be centrally controlled, which is why they are a persistent HIPAA concern.

The answer is not to ban communication. It is to give staff a fast, secure way to do it, and rules that make sense.

What HIPAA actually says

HIPAA does not prohibit texting outright. The Privacy Rule allows use and disclosure of PHI for treatment, payment and health care operations, and the Security Rule requires reasonable and appropriate safeguards for electronic PHI, including access controls, audit controls and transmission security. Standard SMS and consumer chat apps usually cannot meet these safeguards because they lack encryption you control, access management and audit trails.

HHS has addressed the use of text messaging in guidance and FAQs, and CMS has taken positions on texting of patient orders in hospital and long-term care contexts. Check current guidance with your compliance officer, since it applies differently to orders than to routine coordination.

The risks of ordinary texting

Messages may remain on personal phones indefinitely, and on backups and cloud accounts.

Lost or stolen phones can expose message history.

Staff who leave keep their copies.

Messages can be sent to the wrong person with no way to retract them.

There is no organizational audit trail or retention.

Messages can be intercepted or visible on lock screens.

What staff can usually text

Messages without identifiable resident information are generally low risk, for example:

Schedule changes and shift coverage requests.

Running late or parking notices.

General facility announcements.

Still, ask staff to avoid names, room numbers combined with conditions, and other details that could identify a resident.

What staff should not send through regular text

Names, diagnoses, medications or other PHI.

Photos of residents, wounds or documents.

Orders or clinical decisions, unless your organization has approved a compliant platform.

Login credentials or passcodes.

Information about a resident's condition to family members through personal texts.

Choose a secure messaging platform

Look for tools designed for healthcare with:

End-to-end or strong transport and storage encryption.

A signed business associate agreement.

Role-based access and the ability to remove users immediately.

Remote wipe of messages on lost devices.

Message retention and audit logging settings.

Features for photos, group threads and read receipts.

Integration with your directory so accounts match staff records.

Passcode or biometric lock and auto-logout.

Adoption matters. A secure app that is slow or clumsy will be ignored in favor of regular texting, so involve nurses and aides in choosing it.

Write a clear messaging policy

Keep it short and specific.

Which tools are approved, and for what types of communication.

What can never be sent by regular text or personal apps.

How to report a misdirected message or lost device.

How long messages are kept and who can access them.

Expectations for personal phones used with approved apps.

Sanctions for violations, applied consistently.

Train with real examples

Use short, realistic scenarios in training. For example: a nurse wants to ask the doctor about a medication change. What is the right tool? What should the message include, and what should it leave out? Repeat the training at hire and annually.

Communicating with families

Families often prefer text updates. If you offer them, use a platform that supports consent, secure delivery or portals, and be careful to verify identity before sharing details. Residents or representatives may request communication by unencrypted channels after being warned about the risks, and you should document those requests with the help of your compliance officer.

What to do after a mistake

If PHI is sent through an unapproved channel, document it, ask the recipient to delete it, assess whether it is a reportable breach and use it as a coaching opportunity. Ignoring repeated mistakes teaches staff that rules are optional.

Quick checklist

Do we provide an approved secure messaging tool?

Does the vendor sign a business associate agreement?

Do staff know what never goes in a regular text?

Is there a way to wipe messages on a lost phone?

Is the policy reviewed yearly?

How UnityCare IT can help

UnityCare IT helps healthcare and senior-living organizations evaluate secure messaging options and write practical policies. If your staff are texting around the rules, we can help you make the right way the easy way.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172