Texting Resident Information: What Is Safe for Care Teams?

A charge nurse needs to tell the on-call physician about a change in condition. A therapist wants to alert the DON about a fall. A manager wants to let a team know that Mr. Smith in Room 12 has moved to a different diet. The fastest way, for most people, is a text message on a personal phone.

Convenience is exactly why this is such a common compliance problem. Standard text messages are not designed to protect sensitive information, and once a message is sent, you have little control over where it goes.

What HIPAA Expects

HIPAA does not ban texting. It requires that covered entities and business associates apply appropriate safeguards to protected health information, including when it is transmitted. The Security Rule addresses transmission security, access controls, audit controls and device and media controls. Whether a given method is acceptable depends on whether you have assessed the risk and put reasonable protections in place.

HHS and other regulators have indicated over the years that organizations should evaluate the risks of texting and have policies that govern it. CMS has also addressed texting of orders in its guidance, and expectations have evolved, so check current guidance and your state requirements when writing policy.

Why Ordinary Texting Is Risky

Lack of encryption control. Standard SMS messages are not end-to-end encrypted. Some consumer apps encrypt messages, but the organization cannot manage or audit them.

Messages linger. Texts remain on phones, in backups and in cloud accounts, long after they are needed.

Lost or stolen phones. A personal phone without a passcode or with synced messages on a tablet can expose information.

Wrong recipient. Autocomplete and group threads make it easy to send information to the wrong person.

No audit trail. If an incident occurs, the facility cannot reconstruct what was sent or by whom.

Departing employees. When someone leaves, the organization cannot retrieve or delete PHI from their personal phone.

Records requirements. Messages that contain orders or clinical information may belong in the medical record.

Safer Approaches

Secure messaging platforms

Several platforms are designed for healthcare. Look for:

Encryption in transit and at rest

Individual accounts with strong authentication

Administrator controls, including remote wipe and message retention settings

Audit logs

A business associate agreement from the vendor

The ability to integrate with or document in the record where needed

Messaging inside the EMR

If your EMR includes secure messaging or task assignment, use it where possible. It keeps communication in a system already built for PHI.

Phone calls and paging

For urgent clinical matters, a phone call remains a good choice. Some facilities use secure paging systems for alerts.

Minimum necessary content

Even with approved tools, limit what you send. Use the least information needed. A message such as "Please call me about the resident in 12" reveals little compared with a message including name, diagnosis and medication.

Build a Texting Policy

A workable policy is short and specific. Cover:

Approved tools. Name what staff may use for PHI, and state that unapproved apps and standard SMS are not allowed for it.

Prohibited content. For example, no photos of residents or wounds on personal camera rolls, and no medical orders by ordinary text.

Personal devices. If staff use their own phones, require a passcode, current updates, and acceptance of remote wipe of work data. Consider whether you will allow this at all.

Retention and deletion. Say how long messages are kept and where clinical information must be documented.

Photos and video. Many violations involve photos. Provide an approved method for wound photos or incident documentation and prohibit personal use.

Reporting. Tell staff to report mistakes, such as a message sent to the wrong person, immediately and without fear.

Offboarding. Ensure that access to approved apps is removed when someone leaves.

Make the Right Way the Easy Way

Policies that ban texting without offering an alternative tend to be ignored. Pick a tool, train staff, keep it fast, and make sure it works on the devices people carry. Many facilities find that staff adopt a secure app readily when it genuinely saves time.

Quick Self-Check

Do we know what messaging tools staff currently use for work?

Is there a written policy, and have staff been trained on it?

Do we have a secure option that people actually like?

Can we remove access from lost phones or departed employees?

How UnityCare IT Can Help

UnityCare IT helps care organizations evaluate secure messaging options, set up mobile device management and write practical policies that staff will follow. If you suspect texting of resident information is happening informally, a candid conversation is a good start.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172