Texting is the fastest way to reach a colleague, so it is no surprise that clinical staff use it. A nurse wants to ask a physician about a medication, a therapist needs to confirm a schedule and an administrator wants to alert a department head. The compliance question is what can be sent over text, on what platform and with what safeguards.
This article explains the issues in plain terms. It is general information, not legal advice. Check with your compliance officer or counsel for your specific situation.
The HIPAA Privacy Rule and Security Rule do not contain a flat ban on texting protected health information. They require covered entities and business associates to apply reasonable and appropriate safeguards, and to consider risks to confidentiality, integrity and availability, including during transmission. The Security Rule's transmission security standard calls for guarding against unauthorized access to ePHI sent over electronic networks, and encryption is an addressable specification.
Standard SMS text messages travel through carrier networks without the kind of end-to-end protection that most healthcare compliance programs expect. Messages can also sit in plain view on lock screens, be backed up to personal cloud accounts and remain on phones that are lost or traded in. That is why many organizations prohibit sending PHI by ordinary text.
Minimum necessary: Share only what the recipient needs for the purpose.
Retention and the medical record: Clinical information relevant to resident care may need to become part of the record. Messages scattered across personal phones are hard to retrieve and preserve.
Orders: Facilities and clinicians should follow their state requirements, accreditation standards and CMS guidance about whether and how orders may be communicated by text. Many organizations require orders to be entered through the EMR or a secure platform rather than a standard text.
Patient communication: Residents and families may ask to receive information by text. The Privacy Rule allows individuals to request communications by alternative means, and an organization can send information unencrypted if the individual has been warned of the risks and still prefers it, though documenting that conversation is wise.
Healthcare-focused messaging apps provide encryption, individual accounts, remote wipe, message expiration, audit logs and sometimes integration with the EMR or a directory. Look for a vendor that will sign a business associate agreement.
Many EMR systems have built-in secure messaging, which keeps communication tied to the resident's record.
For complex or sensitive discussions, a call or a message through a secure portal is often better. Texts can be used to prompt action without including PHI, such as "Please call the nurses' station about room 14" rather than clinical detail.
Care coordination messages with the minimum necessary information
Shift handoff questions
Scheduling and staffing changes
Alerts that a result or order awaits review
Resident names combined with diagnoses, medications or test results
Photos of residents, wounds or documents
Screenshots of the EMR
Social security numbers, insurance information or birthdates
Any message that would be harmful if read by the wrong person
Keep it short, and answer questions staff will ask.
Which platform is approved, and how to get access
What types of information may and may not be sent
Whether personal devices may be used, and what controls apply
How messages that belong in the record are preserved
What to do if a message goes to the wrong person
Consequences for noncompliance, stated plainly and applied fairly
Misdirected texts happen. Teach staff to report them right away, recall the message if the platform allows and notify the compliance officer, who can assess whether a breach occurred under the four-factor risk assessment.
Walk through scenarios in a staff meeting. What do you do if a physician texts an order? What if a family member asks you to text a photo of their mother? Practicing responses makes compliance easier on a busy shift.
People use unapproved texting when the approved option is slow or inconvenient. Give staff a secure tool that works as easily as the one they are trying to replace.
UnityCare IT helps healthcare organizations choose and deploy secure messaging, configure mobile device controls and draft practical texting policies. If your staff are texting today without clear guidance, we can help you close the gap.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172