On this page
- What does HIPAA compliant texting actually mean?
- Why is standard SMS a risk for patient information?
- What may go in an SMS and what belongs in a secure patient portal?
- How does the minimum necessary idea apply to texts?
- What consent do you need before texting patients?
- Does your patient messaging software vendor need a business associate agreement?
- How do you set up a compliant texting program step by step?
- Worked example: sizing a consent catch-up (hypothetical)
- Checklist: is your practice ready to text patients?
- Common mistakes with HIPAA compliant texting
- Next step
HIPAA does not prohibit texting patients, and it does not certify any texting product. HIPAA compliant texting means the practice has assessed the risk, documented patient consent and preferences, kept message content to the minimum, signed a business associate agreement with its texting vendor, and moved anything clinical to a secure channel such as a patient portal. Standard SMS is fine for a bare appointment reminder and wrong for a lab result. This is general information, not legal advice.
Key takeaways
- HIPAA allows practices to text patients, but it expects safeguards, documented decisions and limited content.
- No texting product is HIPAA certified, because no official certification exists; compliance depends on how the practice and vendor use the tool.
- A texting vendor that stores or transmits patient information for a practice is generally a business associate and should sign a BAA.
- Standard SMS suits logistics such as date, time and a reply option, while diagnoses, results and treatment details belong in a secure patient portal or a phone call.
- HIPAA and the TCPA are separate laws, so a practice needs both privacy safeguards and proper consent and opt-out handling for texts.
- Staff texting patient details from personal phones is one of the most common and most avoidable risks.
HIPAA compliant texting is not a product you buy. It is a way of texting patients that keeps message content minimal, documents consent, runs through a vendor that has signed a business associate agreement, and moves anything clinical to a secure channel. HIPAA does not ban texting, and standard SMS is acceptable for a bare reminder such as a date and time. It is the wrong place for a diagnosis or a lab result. This guide explains where the lines are, in plain English. It is general information and not legal advice, so confirm your policies with a healthcare attorney or compliance advisor.
What does HIPAA compliant texting actually mean?
HIPAA is the Health Insurance Portability and Accountability Act, the federal law that protects patient health information in the United States. Two of its rules matter most for texting.
The Privacy Rule governs when protected health information, or PHI, may be used and disclosed. PHI is health information that can be tied to an individual and is held by a covered entity, such as a medical or dental practice, or by its business associates. A text that says a named person has an appointment at a named clinic can be PHI.
The Security Rule requires covered entities to protect electronic PHI with administrative, physical and technical safeguards. It asks each organization to analyze its own risks and apply safeguards that are reasonable for its size and situation. It includes a transmission security standard, under which encryption is an "addressable" specification. Addressable does not mean optional. It means the practice must assess whether the safeguard is reasonable and appropriate, and if it decides not to implement it, document why and what it does instead.
Nothing in either rule says "do not text patients." The U.S. Department of Health and Human Services, which enforces HIPAA, publishes its guidance at hhs.gov/hipaa. What the rules do require is thought, safeguards and documentation. So a working definition is this: HIPAA compliant texting is texting that your practice has risk-assessed, limited in content, covered with the right agreements and consent, and written into policy that staff are trained to follow.
It also helps to say what the term does not mean. It does not mean a product is "HIPAA certified." No government agency certifies software for HIPAA, and no official certification exists. A vendor can build features that support compliance. The practice still has to use them properly.
Why is standard SMS a risk for patient information?
SMS, the ordinary text messaging built into every mobile phone, was designed for convenience, not confidentiality. Four properties matter:
- It is not encrypted end to end. Messages pass through carrier networks and may be stored along the way.
- It appears on lock screens. A preview can be read by anyone near the phone: a coworker, a family member, a stranger on a train.
- Phone numbers change hands. A number you have on file may now belong to someone else.
- You cannot recall it. Once sent, a message sits on the recipient's device indefinitely.
None of this makes SMS forbidden. It makes SMS suitable for low-sensitivity content. That is the practical core of the whole topic: decide what is safe to say in a channel that might be seen by someone other than the patient, and send everything else another way.
What may go in an SMS and what belongs in a secure patient portal?
The table below reflects a conservative approach that many practices adopt. Your own risk analysis and legal advice should set your final policy.
| Content | Standard SMS | Secure patient portal or phone call |
|---|---|---|
| Appointment date, time and practice name | Generally acceptable, kept minimal | Also fine |
| Confirm, cancel or reschedule replies | Yes | Yes |
| Office closure, running late, directions | Yes | Yes |
| "You have a new secure message" notice with a login link | Yes | Not applicable |
| Reason for the visit or procedure name | No | Yes |
| Test and lab results | No | Yes |
| Diagnoses, medications, treatment plans | No | Yes |
| Clinical photos | No | Yes |
| Balance due with a secure payment link | Minimal wording only, no service detail | Yes |
| Itemized statement showing services received | No | Yes |
| Insurance member ID, Social Security number, full date of birth | No | Yes |
| Intake and medical history forms | Send a link to a secure form, not the questions | Yes |
A pattern runs through the right-hand column. SMS works well as a notification layer that points to a secure place. "You have a new message from Lakeside Family Practice. Log in to read it" carries almost no information, yet it gets the patient to the portal, where the real content is protected by a login.
Consider the practice name itself. For a general dentist or family physician, the name reveals little. For some specialties, such as behavioral health, oncology or fertility, the fact that someone is a patient is itself sensitive. Those practices often use a neutral sender name or even less detail in reminders.
How does the minimum necessary idea apply to texts?
The Privacy Rule contains a minimum necessary standard: when using or disclosing PHI, a covered entity should make reasonable efforts to limit it to the minimum needed for the purpose. The standard has formal exceptions. For example, it does not apply to disclosures to the patient themselves or to disclosures for treatment. A practice is therefore not technically bound by it when texting a patient their own information.
It is still the best design principle for SMS, for a simple reason. You cannot be sure the patient is the only person who will see the message. So write every template as if a stranger might read it over the patient's shoulder. Ask of each word: does the patient need this, in this channel, to take the next step? An appointment reminder text needs a first name, a date, a time, the practice name and a reply option. It does not need the provider's specialty, the procedure or preparation instructions that reveal the procedure.
Compare two versions:
Hi Maria, this is a reminder of your appointment at Lakeside Family Practice on Tue, Oct 6 at 2:30 PM. Reply C to confirm or R to reschedule.
Hi Maria Gonzalez, reminder of your diabetes follow-up and A1C review with Dr. Patel on Tue, Oct 6 at 2:30 PM. Please bring your glucose log.
The first does the job. The second discloses a diagnosis to anyone who glances at the phone. For wording and timing ideas that stay on the right side of this line, see appointment reminder texts that reduce no-shows.
What consent do you need before texting patients?
Two different bodies of law apply, and practices often mix them up.
Under HIPAA, patients have the right to request that a practice communicate with them by alternative means or at alternative locations, and practices must accommodate reasonable requests. HHS guidance on email explains that a patient may choose to receive unencrypted messages after being warned of the risk. Many compliance advisors apply the same reasoning to text messages, but HHS guidance on that point concerns email, so ask your own advisor how to apply it. The safe practice is to tell patients in plain words that texts are not fully secure, ask whether they want them, and record the answer.
Under the TCPA, the Telephone Consumer Protection Act, the Federal Communications Commission regulates calls and texts sent to mobile phones using automated systems. The FCC treats marketing texts more strictly than informational ones, and marketing texts generally require prior express written consent. Healthcare messages receive somewhat different treatment under FCC rules, with conditions attached. Do not build your program on an exemption. Get clear consent, keep proof, and honor opt-outs. The TCPA is separate from HIPAA, and complying with one does not satisfy the other.
Good patient consent for texting has these features:
- It is collected in writing or electronically, on the intake form or a digital form, with a date.
- It names the phone number and says what kinds of messages will be sent.
- It states that standard text messages are not encrypted and may be seen by others.
- It separates care-related messages, such as reminders and recalls, from promotional messages, with a separate opt-in for the latter.
- It explains how to stop: reply STOP, or tell the front desk.
- It is stored where staff and systems can check it before sending.
Promotional texts need extra care. HIPAA has its own rules on using PHI for marketing, and some marketing communications require the patient's written authorization. A reminder that a patient is due for their own cleaning or checkup is generally viewed as a treatment communication. A text promoting a new cosmetic service is different. Get advice before sending promotions to a patient list.
Does your patient messaging software vendor need a business associate agreement?
Usually, yes. Under HIPAA, a business associate is a person or company that creates, receives, maintains or transmits PHI on behalf of a covered entity. Patient messaging software that stores your conversations, contact lists and appointment details fits that definition. The practice must have a written business associate agreement, commonly called a BAA, with the vendor. The BAA commits the vendor to safeguard the information, report breaches and limit its own use of the data.
Vendors sometimes point to the "conduit exception." That exception is narrow. It covers services that merely transport information, such as the postal service or a telecommunications carrier, with no more than transient access. A platform that keeps message history on its servers is not a mere conduit.
Questions worth asking any texting vendor:
- Will you sign a BAA, and may we see it before we buy?
- Is message data encrypted in storage and between our staff's browsers or apps and your servers?
- Does each staff member get an individual login, and can we require strong authentication?
- Is there an audit log showing who viewed or sent what?
- Can we set retention periods and export or delete data?
- How do you handle opt-outs and consent records?
- Do you handle 10DLC registration for our number?
That last item is about deliverability, not privacy. 10DLC is the carrier system for business texting from ordinary 10-digit numbers. Businesses register their brand and messaging campaign with The Campaign Registry, usually through their texting provider, and unregistered traffic is likely to be filtered or blocked. Our 10DLC registration guide walks through it.
For transparency about our own product: Talos Connect is designed to support HIPAA-conscious workflows, and a BAA is part of onboarding for healthcare clients. It provides two-way business texting with a shared team inbox, templates, and scheduling with automated reminders. It is not "HIPAA certified," because nothing is, and it does not replace your own policies and training.
How do you set up a compliant texting program step by step?
- Include texting in your HIPAA risk analysis. Write down what you plan to send, to whom, through which system, and what could go wrong.
- Choose a managed platform and sign the BAA. Move patient texting off personal phones and onto one system with individual logins.
- Write a short texting policy. Cover what may and may not be sent by SMS, who may send, how consent is recorded, and what to do when a patient texts clinical details.
- Collect and record consent. Add texting consent to intake, and run a catch-up campaign for existing patients.
- Build minimal templates. Draft reminders, confirmations, recall notices, portal notifications and payment notices. Have your compliance lead approve each one.
- Register for 10DLC. Describe your message types accurately in the campaign registration.
- Set up opt-out handling. STOP must work automatically, and a verbal request at the desk must reach the same record.
- Train the team. Show real examples of acceptable and unacceptable messages. Repeat the training for new hires.
- Verify numbers. Confirm the mobile number at each visit, since numbers get reassigned.
- Audit regularly. Sample sent messages each quarter and check them against the policy.
Worked example: sizing a consent catch-up (hypothetical)
The figures below are hypothetical and exist only to show the arithmetic. Substitute your own counts.
Suppose a practice has 3,000 active patients. Of those, 2,400 have a mobile number on file. A records check finds documented texting consent for 1,560 of them.
Consent coverage is 1,560 divided by 2,400, which is 65 percent. That leaves 2,400 minus 1,560, or 840 patients with a mobile number and no documented consent.
Suppose the practice sees 45 patients a day, and about 35 percent of arriving patients are in the missing-consent group at first. That is roughly 16 patients a day who can be asked at check-in. Over 21 working days, 16 times 21 equals 336 patients a month. At that pace, which will slow as the group shrinks, the front desk would work through most of the 840 in about three months without sending a single text to a patient who has not agreed.
Now the message volume. With 45 appointments a day and two reminders each, the practice sends 90 reminders a day, or 90 times 21, which is 1,890 a month. If the quarterly audit samples 5 percent of one month's messages, that is about 95 messages to review, a task of an hour or so. Numbers like these turn "be compliant" into a staffing plan.
Checklist: is your practice ready to text patients?
- Texting is covered in your written HIPAA risk analysis.
- A business associate agreement with the texting vendor is signed and filed.
- Staff use individual logins on a managed platform, not personal phones.
- Consent is documented per patient, with date and phone number.
- Care messages and promotional messages have separate opt-ins.
- Every template has been reviewed for minimal content.
- STOP and verbal opt-outs both update the same record.
- A written policy says what staff do when a patient texts clinical information.
- Clinical content is routed to a secure patient portal or a phone call.
- Your number is registered for 10DLC.
- Lost or stolen devices with access to the platform can be locked out quickly.
- Message audits are scheduled, and results are recorded.
Common mistakes with HIPAA compliant texting
Believing a vendor's badge settles the question. A "HIPAA compliant" logo on a website is marketing. Your BAA, settings, policy and training are what count.
Staff texting from personal phones. It feels helpful and fast. It also puts patient information in a personal message thread the practice cannot see, secure or delete. This is one of the most common gaps, and a managed shared inbox closes it.
Free-typing clinical detail into a reply. Templates are usually clean. The risk is the ad hoc reply: "Your biopsy came back fine!" Train staff to answer clinical questions with "Please check the portal" or a phone call.
Treating HIPAA and the TCPA as one thing. A practice can have a signed BAA and still send texts without proper consent, or have perfect consent and no BAA. Check both.
Revealing the condition through the sender or the link. A neutral message loses its value if the link preview or sender name announces a specialty clinic. Test how your messages look on a locked phone.
No plan for wrong numbers. When someone replies "wrong person," stop texting that number, correct the record and follow your incident procedure to decide whether any further step is required.
Ignoring inbound texts after hours. Patients reply to reminders at night. An unread "I am having chest pain" is a safety problem. Set an auto-reply that says the inbox is not monitored for emergencies and that tells patients to call 911 in an emergency. If you use an after-hours AI text agent, confine it to logistics and apply the same rules as your answering service.
If you want the rule-by-rule version of this topic, our sister company Talk Is Cheap maintains a detailed reference on HIPAA compliant communications across phone, voicemail, text and fax. For the IT side of the same problem, such as device encryption, access control and risk assessments, TMG publishes a HIPAA compliance guide for healthcare IT.
Next step
If you want patient texting that is organized, minimal by default and backed by a BAA, see how Talos Connect works for medical offices. Then contact us and tell us what you send today and how. We will show you the templates, consent capture and shared inbox, and we will be direct about what belongs in a text and what should stay in your portal.
Frequently asked questions
Is it a HIPAA violation to text a patient?
Not by itself. HIPAA permits communication with patients, including by text, when the practice applies reasonable safeguards. Problems arise when texts include more health detail than needed, go to the wrong number, are sent from unmanaged personal phones, or pass through a vendor with no business associate agreement. Content and process decide compliance, not the channel alone.
Is there such a thing as HIPAA certified texting software?
No. The U.S. Department of Health and Human Services does not certify software, and no official HIPAA certification exists for products. A vendor can offer features that support compliance, such as access controls, audit logs and a business associate agreement. The practice is still responsible for its own risk analysis, policies, training and message content.
Can an appointment reminder text include the patient's name and the doctor's name?
Appointment reminders are generally treated as permitted treatment communications. Keep them minimal: first name, date, time, practice name and a way to confirm or reschedule. Consider whether the practice name itself reveals a condition, as it might for some specialties, and leave out the reason for the visit, procedure names and anything clinical.
Do I need patient consent before sending texts?
You should obtain and document it. HIPAA expects practices to respect patient communication preferences, and the Telephone Consumer Protection Act, a separate federal law, has its own consent rules for texts, which are stricter for marketing messages. Record how and when each patient agreed, what they agreed to receive, and honor opt-out requests promptly.
What should never be sent by standard SMS?
Avoid diagnoses, test results, medication names, treatment plans, clinical photos, insurance or Social Security numbers, and detailed billing information tied to a service. Standard SMS is not encrypted end to end and messages can appear on a lock screen. Use the text to tell the patient a secure message is waiting, and put the detail in the portal.
Does my texting vendor need to sign a BAA?
In most cases, yes. A vendor that creates, receives, maintains or transmits protected health information on your behalf is a business associate under HIPAA. A platform that stores your patient conversations does not fit the narrow conduit exception that applies to carriers merely transporting data. Get the agreement signed before sending patient messages.
What if a patient texts us clinical information first?
You cannot control what patients send, but you can control your reply. Do not continue the clinical conversation over SMS. Acknowledge the message, move the discussion to a phone call or secure portal, and document the exchange per your policy. If the message suggests an emergency, follow your emergency protocol and direct the patient to call 911.
See how Talos Connect would handle your calls, texts and scheduling. Request a demo or read about the AI receptionist.



