A charge nurse needs a quick answer from a physician. A therapist wants to confirm a transport time. A manager needs to tell a team about a staffing change. In every case, someone reaches for a phone and starts texting. It is fast and familiar, which is exactly why it is so difficult to control.
HIPAA does not prohibit texting, but it does require safeguards around protected health information. This post explains the issues and offers a practical way to give staff a safe option.
The HIPAA Security Rule requires covered entities to protect electronic protected health information in transit, with transmission security controls, and to implement access controls. Standard SMS and iMessage or similar consumer messaging apps present challenges:
Messages may be stored on personal phones, backed up to personal cloud accounts and visible on lock screens
Organizations cannot easily control, retrieve or delete messages when a staff member leaves
Standard SMS is not designed to provide the encryption and audit controls expected for ePHI
There is usually no business associate agreement with a consumer messaging provider
CMS has also addressed texting of orders in guidance to hospitals and other providers, generally indicating that providers should use secure platforms that meet privacy and security requirements, and that texting of patient orders through unsecured text is not acceptable. Your regulatory and legal advisors can help interpret what applies to your type of facility.
Texting with no resident information, such as the schedule changed or I am running ten minutes late
Using a secure messaging platform with encryption, access controls, audit logs and a signed business associate agreement
Communicating with residents or families by text only after assessing the risk and, where appropriate, documenting their preferences, and keeping messages minimal
Sending names, diagnoses, photos of wounds or screenshots of the chart through ordinary texting
Using personal social media messaging for work conversations
Group chats that include people who no longer need to be involved
Taking photos of residents on personal phones and sending them
Sending orders by text outside an approved secure system
When evaluating platforms, ask whether they offer:
End-to-end or strong transport and at-rest encryption
Individual accounts tied to your directory, with multi-factor authentication
Remote wipe or revocation when a device is lost or an employee leaves
Message retention and audit controls that match your policies
Integration with your EHR or call-light workflow where relevant
A signed business associate agreement
Clear handling of attachments such as photos, which may be stored separately from the chat
Ease of use, since a clumsy tool will push staff back to regular texting
Spell out what may be sent by text, which tools are approved and what to do with a message received in the wrong place. Include rules about photos and screenshots.
Demonstrate how to ask a quick question using the approved tool, and how to redirect someone who sends resident details by text.
For facility-owned devices, use mobile device management to enforce screen locks and encryption. For personal phones, define whether a bring-your-own-device program is allowed and what controls are required.
Check compliance periodically, and coach rather than punish at first. Staff are usually trying to help residents, not cause harm, and a fast tool that works is the best incentive.
Begin by asking your teams what they already use. The answer is often surprising, and it tells you which problems the new tool needs to solve. UnityCare IT can help evaluate secure messaging options, configure mobile device management and write policies that staff can follow. Reach out if you would like to start with an assessment.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034