Texting Patient Information: What HIPAA Does and Does Not Allow

A nurse needs to reach a physician quickly about a resident's change in condition. A text message is the obvious route, and for many clinicians it is the preferred one. HIPAA does not ban texting, but it does require safeguards for protected health information. Standard SMS and many consumer messaging apps do not provide them, which is why this question comes up so often.

This article sets out the key considerations and a practical approach. It is general guidance, not legal advice.

What the rules require

The HIPAA Security Rule applies to ePHI that is transmitted over electronic networks. Covered entities must implement technical safeguards, including transmission security, to guard against unauthorized access to ePHI in transit. Access control, audit controls and integrity are also relevant. Rather than naming technologies, the rule requires you to assess risk and choose reasonable safeguards.

HHS has said that the rules do not prohibit the use of text messaging but that covered entities must use appropriate safeguards. The practical issue is whether a given method is secure enough, and whether you can manage and audit it.

Why standard text messages are risky

Messages travel through carriers in ways that are not designed for confidentiality

Copies are stored on phones, in cloud backups and on other devices linked to the same account

Lost or stolen phones expose message history

There is no central control, so you cannot remove messages when an employee leaves

You cannot easily produce an audit trail

Messages can be sent to the wrong number by mistake

Consumer apps vary. Some use strong encryption in transit but still lack the administrative controls, business associate agreements and audit features that covered entities generally need.

Questions to ask about any messaging tool

Is the content encrypted in transit and at rest?

Will the vendor sign a business associate agreement?

Can administrators control who has accounts, and disable them immediately when someone leaves?

Can messages be remotely wiped from lost devices?

Are there auto-delete or retention settings that match your policies?

Does it provide audit logs?

Can it reach the clinicians who need to receive messages, including outside providers?

Is it integrated with the EHR, or does it at least avoid copying data into places you cannot control?

Building a messaging policy

Write a short policy that answers:

What may be sent?

Many organizations allow minimal information through approved secure tools only, and prohibit PHI in regular SMS and personal apps. Define what counts, including names, dates of birth, room numbers combined with conditions, photos and medication information.

Which tools are approved?

Name them. If staff do not have a good approved option, they will use whatever is convenient.

What about orders?

Provider orders sent by text raise additional clinical and regulatory questions, and many organizations and regulators discourage them. CMS has addressed texting of orders in the past, so check the current expectations with your medical director, compliance officer and counsel, and make sure your policy is consistent with your state's requirements.

What about photos?

Images of wounds or documents are particularly sensitive. Specify an approved method for clinical photos, such as a secure app that stores images in the record rather than the phone's camera roll.

What happens at departure or loss?

Explain how access is removed, how lost devices are reported and how secure messaging accounts are disabled.

Practical tips for staff

Use approved tools, and do not move a conversation to personal text for convenience

Double-check recipients before sending

Include only the minimum necessary information

Keep screens locked, and do not leave message previews visible on lock screens

Report mistakes right away, such as a message sent to the wrong person

Options to consider

Secure messaging platforms designed for healthcare provide encrypted messaging, directories, role-based groups and audit trails. Some EHR systems include their own messaging features. Evaluate options with clinicians who will use them, because adoption depends on speed and ease.

Review and train

Include messaging in your HIPAA risk analysis and in annual training. Revisit the policy when you add tools or when staff habits change.

UnityCare IT can help you evaluate secure messaging options, configure them with your existing systems and write a policy that your clinical team will actually follow.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034