HIPAA and Texting: What Staff Can and Cannot Send

Texting is the fastest way to reach a colleague, so it is no surprise that clinical staff use it. A nurse wants to ask a physician about a medication, a therapist needs to confirm a schedule and an administrator wants to alert a department head. The compliance question is what can be sent over text, on what platform and with what safeguards.

This article explains the issues in plain terms. It is general information, not legal advice. Check with your compliance officer or counsel for your specific situation.

What HIPAA actually says

The HIPAA Privacy Rule and Security Rule do not contain a flat ban on texting protected health information. They require covered entities and business associates to apply reasonable and appropriate safeguards, and to consider risks to confidentiality, integrity and availability, including during transmission. The Security Rule's transmission security standard calls for guarding against unauthorized access to ePHI sent over electronic networks, and encryption is an addressable specification.

Standard SMS text messages travel through carrier networks without the kind of end-to-end protection that most healthcare compliance programs expect. Messages can also sit in plain view on lock screens, be backed up to personal cloud accounts and remain on phones that are lost or traded in. That is why many organizations prohibit sending PHI by ordinary text.

Other rules to keep in mind

Minimum necessary: Share only what the recipient needs for the purpose.

Retention and the medical record: Clinical information relevant to resident care may need to become part of the record. Messages scattered across personal phones are hard to retrieve and preserve.

Orders: Facilities and clinicians should follow their state requirements, accreditation standards and CMS guidance about whether and how orders may be communicated by text. Many organizations require orders to be entered through the EMR or a secure platform rather than a standard text.

Patient communication: Residents and families may ask to receive information by text. The Privacy Rule allows individuals to request communications by alternative means, and an organization can send information unencrypted if the individual has been warned of the risks and still prefers it, though documenting that conversation is wise.

Safer options

Secure messaging platforms

Healthcare-focused messaging apps provide encryption, individual accounts, remote wipe, message expiration, audit logs and sometimes integration with the EMR or a directory. Look for a vendor that will sign a business associate agreement.

Messaging inside the EMR

Many EMR systems have built-in secure messaging, which keeps communication tied to the resident's record.

Phone calls and secure portals

For complex or sensitive discussions, a call or a message through a secure portal is often better. Texts can be used to prompt action without including PHI, such as "Please call the nurses' station about room 14" rather than clinical detail.

What staff can usually send, and what they should not

Generally acceptable on an approved secure platform

Care coordination messages with the minimum necessary information

Shift handoff questions

Scheduling and staffing changes

Alerts that a result or order awaits review

Avoid on ordinary SMS or personal messaging apps

Resident names combined with diagnoses, medications or test results

Photos of residents, wounds or documents

Screenshots of the EMR

Social security numbers, insurance information or birthdates

Any message that would be harmful if read by the wrong person

Write a clear policy

Keep it short, and answer questions staff will ask.

Which platform is approved, and how to get access

What types of information may and may not be sent

Whether personal devices may be used, and what controls apply

How messages that belong in the record are preserved

What to do if a message goes to the wrong person

Consequences for noncompliance, stated plainly and applied fairly

Handle mistakes

Misdirected texts happen. Teach staff to report them right away, recall the message if the platform allows and notify the compliance officer, who can assess whether a breach occurred under the four-factor risk assessment.

Train with real examples

Walk through scenarios in a staff meeting. What do you do if a physician texts an order? What if a family member asks you to text a photo of their mother? Practicing responses makes compliance easier on a busy shift.

Provide the tool, not just the rule

People use unapproved texting when the approved option is slow or inconvenient. Give staff a secure tool that works as easily as the one they are trying to replace.

UnityCare IT helps healthcare organizations choose and deploy secure messaging, configure mobile device controls and draft practical texting policies. If your staff are texting today without clear guidance, we can help you close the gap.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172