Texting Resident Information: What Is Allowed and What Is Risky

A nurse needs to tell the physician that a resident's blood pressure is trending up. A supervisor wants to tell a scheduler which aide is covering room 20. A therapist wants to send a photo of a wound to the care team. The fastest way is a text message, and staff do it every day. But is it allowed?

The short answer is that HIPAA does not prohibit texting protected health information (PHI), but it does require reasonable safeguards, and standard text messages on personal phones often do not provide them. Here is how to think about it.

What HIPAA expects

The Security Rule requires appropriate safeguards for electronic PHI, including access controls, audit controls, integrity protection and transmission security. The Privacy Rule requires you to limit uses and disclosures to the minimum necessary, except for treatment. Your risk analysis should address how PHI is communicated, and your policies should reflect the decisions you make.

Ordinary SMS text messages are generally not encrypted end to end, can be read on lock screens, stay on personal phones after someone leaves and are not centrally logged. Consumer messaging apps vary widely, and many are controlled by companies that you have no agreement with. If PHI goes through a service acting as a business associate, you may need a Business Associate Agreement.

The main risks

Messages sent to the wrong person because of a mistyped number or autocomplete

Lost or stolen phones, and phones shared with family members

No ability to delete or recall information from a device you do not control

Lock-screen previews showing resident names and details

Staff leaving with conversations and photos on their personal devices

Orders or clinical information that never reach the official record

No audit trail for investigations

Safer alternatives

Secure messaging platforms

Many healthcare-focused messaging apps provide encryption, individual accounts, remote wipe, message expiration, audit logs and often a Business Associate Agreement. Some integrate with the EHR or with nurse call and scheduling systems. They are designed for exactly this use.

EHR-based messaging

Many EHR platforms include secure messaging tools that keep communication within the system and part of the record.

Secure email and portals

For communication outside your organization, encrypted email or a patient portal gives protection and logging. Do not put PHI in regular, unencrypted email unless your policy permits it after risk consideration.

Phone calls

For urgent matters, a phone call may be the simplest and safest choice, followed by documentation in the record.

Guidance for staff

A practical set of rules might say:

Never include resident names, birth dates, diagnoses or other identifiers in standard text messages or consumer chat apps

Use only the approved secure messaging tool for clinical communication

Turn off lock-screen previews for work messages

Double-check the recipient before sending

Do not photograph residents with a personal phone unless your policy specifically allows it, and then only with the approved app

Move important clinical information into the official record, not just a text thread

Report misdirected messages immediately, so the incident can be assessed under your breach process

Families and residents

Residents and family members sometimes ask to communicate by text. HIPAA permits communicating with individuals by the means they request, but you should warn them about the risks of unencrypted messages and document their preference. Keep the content limited to scheduling and general information when possible. Make sure your staff know who is allowed to receive information about a resident and what the resident has authorized.

Clinical orders

Regulatory and accreditation bodies have their own expectations regarding how orders are received and documented. Check with your medical director, pharmacy partner and compliance lead before allowing orders to be sent by text, and use only platforms that meet your requirements.

Putting it in place

Survey how staff currently communicate. You may be surprised.

Choose a secure platform that fits your workflow and budget.

Write a short policy defining approved tools and prohibited practices.

Train staff with realistic examples.

Make the approved option at least as convenient as the risky one.

Review use periodically and adjust.

Where we fit in

UnityCare IT helps care organizations evaluate and deploy secure messaging, mobile device management and policies that fit how staff really communicate. If you would like help comparing options, we can talk through your needs and set up a pilot with one unit.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034