A nurse needs to reach a physician quickly about a resident's change in condition. A text message is the obvious route, and for many clinicians it is the preferred one. HIPAA does not ban texting, but it does require safeguards for protected health information. Standard SMS and many consumer messaging apps do not provide them, which is why this question comes up so often.
This article sets out the key considerations and a practical approach. It is general guidance, not legal advice.
The HIPAA Security Rule applies to ePHI that is transmitted over electronic networks. Covered entities must implement technical safeguards, including transmission security, to guard against unauthorized access to ePHI in transit. Access control, audit controls and integrity are also relevant. Rather than naming technologies, the rule requires you to assess risk and choose reasonable safeguards.
HHS has said that the rules do not prohibit the use of text messaging but that covered entities must use appropriate safeguards. The practical issue is whether a given method is secure enough, and whether you can manage and audit it.
Messages travel through carriers in ways that are not designed for confidentiality
Copies are stored on phones, in cloud backups and on other devices linked to the same account
Lost or stolen phones expose message history
There is no central control, so you cannot remove messages when an employee leaves
You cannot easily produce an audit trail
Messages can be sent to the wrong number by mistake
Consumer apps vary. Some use strong encryption in transit but still lack the administrative controls, business associate agreements and audit features that covered entities generally need.
Is the content encrypted in transit and at rest?
Will the vendor sign a business associate agreement?
Can administrators control who has accounts, and disable them immediately when someone leaves?
Can messages be remotely wiped from lost devices?
Are there auto-delete or retention settings that match your policies?
Does it provide audit logs?
Can it reach the clinicians who need to receive messages, including outside providers?
Is it integrated with the EHR, or does it at least avoid copying data into places you cannot control?
Write a short policy that answers:
Many organizations allow minimal information through approved secure tools only, and prohibit PHI in regular SMS and personal apps. Define what counts, including names, dates of birth, room numbers combined with conditions, photos and medication information.
Name them. If staff do not have a good approved option, they will use whatever is convenient.
Provider orders sent by text raise additional clinical and regulatory questions, and many organizations and regulators discourage them. CMS has addressed texting of orders in the past, so check the current expectations with your medical director, compliance officer and counsel, and make sure your policy is consistent with your state's requirements.
Images of wounds or documents are particularly sensitive. Specify an approved method for clinical photos, such as a secure app that stores images in the record rather than the phone's camera roll.
Explain how access is removed, how lost devices are reported and how secure messaging accounts are disabled.
Use approved tools, and do not move a conversation to personal text for convenience
Double-check recipients before sending
Include only the minimum necessary information
Keep screens locked, and do not leave message previews visible on lock screens
Report mistakes right away, such as a message sent to the wrong person
Secure messaging platforms designed for healthcare provide encrypted messaging, directories, role-based groups and audit trails. Some EHR systems include their own messaging features. Evaluate options with clinicians who will use them, because adoption depends on speed and ease.
Include messaging in your HIPAA risk analysis and in annual training. Revisit the policy when you add tools or when staff habits change.
UnityCare IT can help you evaluate secure messaging options, configure them with your existing systems and write a policy that your clinical team will actually follow.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034