A charge nurse needs to tell the on-call physician about a change in condition. A therapist wants to alert the DON about a fall. A manager wants to let a team know that Mr. Smith in Room 12 has moved to a different diet. The fastest way, for most people, is a text message on a personal phone.
Convenience is exactly why this is such a common compliance problem. Standard text messages are not designed to protect sensitive information, and once a message is sent, you have little control over where it goes.
HIPAA does not ban texting. It requires that covered entities and business associates apply appropriate safeguards to protected health information, including when it is transmitted. The Security Rule addresses transmission security, access controls, audit controls and device and media controls. Whether a given method is acceptable depends on whether you have assessed the risk and put reasonable protections in place.
HHS and other regulators have indicated over the years that organizations should evaluate the risks of texting and have policies that govern it. CMS has also addressed texting of orders in its guidance, and expectations have evolved, so check current guidance and your state requirements when writing policy.
Lack of encryption control. Standard SMS messages are not end-to-end encrypted. Some consumer apps encrypt messages, but the organization cannot manage or audit them.
Messages linger. Texts remain on phones, in backups and in cloud accounts, long after they are needed.
Lost or stolen phones. A personal phone without a passcode or with synced messages on a tablet can expose information.
Wrong recipient. Autocomplete and group threads make it easy to send information to the wrong person.
No audit trail. If an incident occurs, the facility cannot reconstruct what was sent or by whom.
Departing employees. When someone leaves, the organization cannot retrieve or delete PHI from their personal phone.
Records requirements. Messages that contain orders or clinical information may belong in the medical record.
Several platforms are designed for healthcare. Look for:
Encryption in transit and at rest
Individual accounts with strong authentication
Administrator controls, including remote wipe and message retention settings
Audit logs
A business associate agreement from the vendor
The ability to integrate with or document in the record where needed
If your EMR includes secure messaging or task assignment, use it where possible. It keeps communication in a system already built for PHI.
For urgent clinical matters, a phone call remains a good choice. Some facilities use secure paging systems for alerts.
Even with approved tools, limit what you send. Use the least information needed. A message such as "Please call me about the resident in 12" reveals little compared with a message including name, diagnosis and medication.
A workable policy is short and specific. Cover:
Approved tools. Name what staff may use for PHI, and state that unapproved apps and standard SMS are not allowed for it.
Prohibited content. For example, no photos of residents or wounds on personal camera rolls, and no medical orders by ordinary text.
Personal devices. If staff use their own phones, require a passcode, current updates, and acceptance of remote wipe of work data. Consider whether you will allow this at all.
Retention and deletion. Say how long messages are kept and where clinical information must be documented.
Photos and video. Many violations involve photos. Provide an approved method for wound photos or incident documentation and prohibit personal use.
Reporting. Tell staff to report mistakes, such as a message sent to the wrong person, immediately and without fear.
Offboarding. Ensure that access to approved apps is removed when someone leaves.
Policies that ban texting without offering an alternative tend to be ignored. Pick a tool, train staff, keep it fast, and make sure it works on the devices people carry. Many facilities find that staff adopt a secure app readily when it genuinely saves time.
Do we know what messaging tools staff currently use for work?
Is there a written policy, and have staff been trained on it?
Do we have a secure option that people actually like?
Can we remove access from lost phones or departed employees?
UnityCare IT helps care organizations evaluate secure messaging options, set up mobile device management and write practical policies that staff will follow. If you suspect texting of resident information is happening informally, a candid conversation is a good start.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172