A dermatology practice in the Midwest thought they were doing patients a favor. Front desk staff texted appointment reminders, lab results, and even photos of healing surgical sites — all through their personal iPhones. No encryption. No consent forms. No audit trail. When a patient filed a complaint with OCR after a text containing her biopsy results went to a wrong number, the practice discovered just how expensive convenience can get.
If your organization texts patients — or wants to — you need to understand exactly what makes HIPAA compliant texting with patients legal, safe, and defensible. This isn't optional. It's the difference between modern patient engagement and a six-figure settlement.
Why Standard Texting Fails the HIPAA Test
Standard SMS — the kind built into every smartphone — was never designed for healthcare. Messages travel in plaintext across carrier networks. They sit unencrypted on devices. They get backed up to personal cloud accounts. And they can land on a lock screen visible to anyone walking by.
Under the HIPAA Security Rule, covered entities must implement technical safeguards for any electronic protected health information (ePHI) they transmit. Standard texting violates at least three of those safeguards: encryption in transit, access controls, and audit logging. HHS has been clear about this in published guidance on its Security Rule guidance page.
I've seen organizations rationalize it a hundred different ways. "The patient texted us first." "We only send appointment times, not diagnoses." "Our staff deletes the messages afterward." None of these arguments hold up under an OCR investigation.
What Counts as PHI in a Text Message?
This trips people up constantly. PHI isn't just a diagnosis or lab result. It's any individually identifiable health information. A text that says "Your appointment with Dr. Martinez is Tuesday at 2pm" contains a patient's name (by being sent to their number), a provider name, and a date of service. That's PHI.
Even appointment reminders can trigger HIPAA obligations when they reveal the type of provider. A message from "City Behavioral Health" or "Lakeside Oncology" discloses the nature of treatment just by showing the sender's name on a lock screen.
The Three Pillars of HIPAA Compliant Texting with Patients
Making texting HIPAA compliant isn't about finding a magic app. It requires three things working together: technology, policy, and documentation.
1. Encryption and Technical Safeguards
The platform you use must encrypt messages both in transit and at rest. It must provide unique user authentication — no shared logins. It must generate audit logs that track who sent what, when, and to whom. And it must allow for remote wipe capability in case a device is lost or stolen.
This is why you can't use iMessage, WhatsApp, or standard SMS for PHI. Even platforms with end-to-end encryption may lack the audit controls and business associate agreement (BAA) requirements that HIPAA demands.
2. Patient Consent and the Right to Opt Out
Before you send any text containing PHI, you need documented patient consent. Not a verbal "sure, you can text me" at the front desk. A signed authorization that specifies what types of information will be communicated via text, the risks of electronic communication, and the patient's right to revoke consent at any time.
HHS addressed this directly in its guidance: patients can request communication by alternative means under 45 CFR § 164.522(b), which you can review at law.cornell.edu. Your organization needs a process for honoring those requests.
3. Policies Your Staff Actually Follow
Technology without policy is a liability. Your workforce needs written guidelines on what can be texted, what can't, who is authorized to send messages, and what to do if a message goes to the wrong person. That last part — your breach response protocol — matters more than most practices realize.
Every member of your staff who touches patient communication needs HIPAA training that covers texting specifically. Our HIPAA Fundamentals course walks through electronic communication requirements in detail, and it's built for the non-technical staff members who most often make these mistakes.
What Happens When Texting Goes Wrong: Real Enforcement Actions
OCR doesn't issue fines specifically labeled "illegal texting." But texting violations surface in breach investigations all the time, wrapped into larger findings about insufficient safeguards, lack of risk analysis, and workforce training failures.
Consider the $1.5 million settlement HHS reached with CardioNet in 2017. The case centered on an unencrypted device containing ePHI — the same kind of vulnerability that exists on every personal phone your staff uses to text patients. The core finding? CardioNet failed to conduct a thorough risk analysis and implement sufficient safeguards for ePHI.
Or look at the University of Rochester Medical Center's $3 million settlement in 2019. Lost unencrypted devices — including smartphones — exposed ePHI. OCR's investigation revealed the organization had failed to encrypt mobile devices despite prior awareness of the risk. The full resolution agreement is available on the HHS enforcement page.
These cases should keep you up at night if your staff is texting patients on personal devices without encryption, BAAs, or formal policies.
Can You Text Patients at All? A Quick-Answer Guide
Can you text appointment reminders? Yes — if you use a HIPAA-compliant platform, limit the information disclosed, have patient consent, and have a BAA with the texting vendor.
Can you text lab results or clinical information? Yes — but only through an encrypted, BAA-covered platform with documented patient consent. The risk is higher, so your policies need to be tighter.
Can your staff use personal phones to text patients? Only if those phones are enrolled in a mobile device management (MDM) system, the texting occurs through a compliant application (not native SMS), and the organization maintains audit and remote-wipe capability. In practice, most small practices can't meet these requirements.
Do you need a BAA with your texting platform vendor? Absolutely. If a vendor stores, transmits, or has access to PHI on your behalf, they are a business associate. No BAA means no compliance — period.
Choosing a Texting Platform: What to Demand
I'm not going to recommend specific vendors. But I will tell you the exact checklist your compliance officer should use when evaluating one:
- Willing to sign a BAA — if they hesitate, walk away immediately.
- AES 256-bit encryption in transit and at rest.
- Role-based access controls so front desk staff and clinicians have different permissions.
- Automatic message expiration or archiving that meets your retention policy.
- Complete audit logs with timestamps, sender/recipient IDs, and message content.
- Remote wipe capability for lost or compromised devices.
- Two-factor authentication for all users.
If a vendor checks every box, you still need to document your evaluation in your risk analysis. OCR wants to see that you made a deliberate, informed decision — not that you just picked the first app that showed up in a Google search.
Remote Workers Make This Even Harder
The shift toward remote and hybrid healthcare work has multiplied texting risks. Staff working from home use personal devices on shared Wi-Fi networks. The lines between personal and professional communication blur fast.
If your organization employs remote workers who communicate with patients electronically, you need training designed specifically for that scenario. Our HIPAA Training for Remote Healthcare Workers covers mobile device security, home office safeguards, and the texting-specific pitfalls that remote staff encounter daily.
Dental Practices: You're Not Exempt
I single out dental offices because they're among the worst offenders I've encountered. Small teams, informal cultures, and the perception that "we're just a dental office" lead to rampant unsecured texting. Confirming appointments, sharing X-ray images, discussing treatment plans — all over standard SMS.
Dental practices are covered entities under HIPAA. Full stop. The same rules apply. If you run a dental office and your team texts patients, our HIPAA Training for Dental Offices was built to address exactly these workflows.
Your Action Plan for This Quarter
Here's what I'd do if I walked into your practice tomorrow:
- Audit every channel your staff uses to communicate with patients. You'll find texts on personal phones you didn't know about.
- Get consent forms updated to address text communication explicitly — type of information, risks, opt-out process.
- Evaluate your texting platform against the checklist above. If you don't have a platform and staff are using SMS, stop immediately.
- Confirm your BAA with the texting vendor is signed, current, and covers all the services you actually use.
- Train your entire workforce — not just clinicians. The front desk receptionist who sends the most texts often has the least HIPAA training.
- Document everything in your risk analysis. OCR looks for evidence of deliberate decision-making, not perfection.
HIPAA compliant texting with patients isn't a luxury feature or a nice-to-have. It's a baseline requirement for any covered entity that wants to communicate the way patients expect in 2026 — without handing OCR a reason to investigate. Get the technology right, get the policies in writing, and get your people trained. The practices that do this well don't just avoid fines. They build the kind of patient trust that no app can manufacture.