A nurse needs to tell the physician that a resident's blood pressure is trending up. A supervisor wants to tell a scheduler which aide is covering room 20. A therapist wants to send a photo of a wound to the care team. The fastest way is a text message, and staff do it every day. But is it allowed?
The short answer is that HIPAA does not prohibit texting protected health information (PHI), but it does require reasonable safeguards, and standard text messages on personal phones often do not provide them. Here is how to think about it.
The Security Rule requires appropriate safeguards for electronic PHI, including access controls, audit controls, integrity protection and transmission security. The Privacy Rule requires you to limit uses and disclosures to the minimum necessary, except for treatment. Your risk analysis should address how PHI is communicated, and your policies should reflect the decisions you make.
Ordinary SMS text messages are generally not encrypted end to end, can be read on lock screens, stay on personal phones after someone leaves and are not centrally logged. Consumer messaging apps vary widely, and many are controlled by companies that you have no agreement with. If PHI goes through a service acting as a business associate, you may need a Business Associate Agreement.
Messages sent to the wrong person because of a mistyped number or autocomplete
Lost or stolen phones, and phones shared with family members
No ability to delete or recall information from a device you do not control
Lock-screen previews showing resident names and details
Staff leaving with conversations and photos on their personal devices
Orders or clinical information that never reach the official record
No audit trail for investigations
Many healthcare-focused messaging apps provide encryption, individual accounts, remote wipe, message expiration, audit logs and often a Business Associate Agreement. Some integrate with the EHR or with nurse call and scheduling systems. They are designed for exactly this use.
Many EHR platforms include secure messaging tools that keep communication within the system and part of the record.
For communication outside your organization, encrypted email or a patient portal gives protection and logging. Do not put PHI in regular, unencrypted email unless your policy permits it after risk consideration.
For urgent matters, a phone call may be the simplest and safest choice, followed by documentation in the record.
A practical set of rules might say:
Never include resident names, birth dates, diagnoses or other identifiers in standard text messages or consumer chat apps
Use only the approved secure messaging tool for clinical communication
Turn off lock-screen previews for work messages
Double-check the recipient before sending
Do not photograph residents with a personal phone unless your policy specifically allows it, and then only with the approved app
Move important clinical information into the official record, not just a text thread
Report misdirected messages immediately, so the incident can be assessed under your breach process
Residents and family members sometimes ask to communicate by text. HIPAA permits communicating with individuals by the means they request, but you should warn them about the risks of unencrypted messages and document their preference. Keep the content limited to scheduling and general information when possible. Make sure your staff know who is allowed to receive information about a resident and what the resident has authorized.
Regulatory and accreditation bodies have their own expectations regarding how orders are received and documented. Check with your medical director, pharmacy partner and compliance lead before allowing orders to be sent by text, and use only platforms that meet your requirements.
Survey how staff currently communicate. You may be surprised.
Choose a secure platform that fits your workflow and budget.
Write a short policy defining approved tools and prohibited practices.
Train staff with realistic examples.
Make the approved option at least as convenient as the risky one.
Review use periodically and adjust.
UnityCare IT helps care organizations evaluate and deploy secure messaging, mobile device management and policies that fit how staff really communicate. If you would like help comparing options, we can talk through your needs and set up a pilot with one unit.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034