Blog Home
Texting 101

HIPAA-Compliant Texting Checklist: What Healthcare Practices Need to Know

Alia Paavola
10
minute read
Table of contents:

Text is fast, easy, and efficient. 91% of Americans own a smartphone and more than 90% of texts are opened within 3 minutes of receipt. No wonder the majority of healthcare practices and patients prefer text over cumbersome phone or email.

But few practices stop to ask whether their texting app protects patient data. Standard texting apps like iMessage, WhatsApp, and Google Messages, while convenient, are not HIPAA-compliant and can put your practice at risk. 

The gap between what healthcare practices do and what the law requires is where violations happen. Secure, HIPAA-compliant text platforms close that gap.

This HIPAA-compliant texting checklist walks you through every requirement you need to know, from encryption to patient consent. Your practice will know exactly where it stands.

Key Takeaways

  • Standard texting apps like iMessage and WhatsApp are not HIPAA-compliant. Any text sent on standard platforms that contains Protected Health Information (PHI) is a potential violation.
  • A text containing a patient's name and an appointment time is PHI and qualifies as a message that requires HIPAA-compliance.
  • HIPAA-compliant texting requires five features: a signed Business Associate Agreement (BAA), end-to-end encryption, access controls, audit logs, and documented patient consent.
  • Violations can result in fines of up to $1.5 million per violation category annually. Most healthcare practices are exposed to these fines without knowing it. 
  • The fix isn't complicated. Use a HIPAA-compliant platform that will handle most of the technical requirements right out of the box. 

What Counts as PHI Under HIPAA in a Text Message?

Protected Health Information (PHI) under HIPAA constitutes two elements: (1) any information that can identify a patient and (2) any of that patient's health-related data. Patient identifiers combined with health-related data trigger HIPAA the moment that information appears in a text.

The PHI rule: Include only what the message actually requires, nothing more.

  • Compliant: "Hi, you have an appointment tomorrow at 1 pm. Reply YES to confirm."
  • Not compliant: "James Wilson, your yearly physical with Dr. Smith is tomorrow at 1 pm."

PHI examples that trigger HIPAA:

  • A patient's first name combined with an appointment at a medical specialty. "Brenda, your appointment at Main St. Dermatology is Wednesday at 4:00 pm."
  • A name linked to a prescription refill. "Dave, your refill #144415 is ready for pickup."
  • Photos and metadata like phone logs, timestamps, and sender/recipient threads that link a patient to a particular medical facility also require HIPAA compliance.

The HIPAA-Compliant Texting Checklist

  1. Use a Secure Messaging Platform

Standard SMS can't be made compliant. A HIPAA-compliant platform must be built specifically for HIPAA and include the following required technical features:

  • End-to-end encryption in transit and at rest.
  • Unique user logins.
  • Role-based access controls.
  • Audit logging.
  • Remote wipe or auto-delete.
  • Automatic session timeouts.

For a provider's texting service to be considered HIPAA-compliant, at minimum they must sign a BAA, provide audit logs, and offer encryption before sending any patient data through their platform. Gold-standard HIPAA-compliant texting platforms like Textline offer even more.

Textline is a HIPAA-compliant, two-way messaging platform built especially for healthcare. Encryption, audit logs, access controls, remote wipe, automatic timeouts, and a signed BAA are included right out of the box.

See How Textline Keeps You Compliant

  1. Sign a Business Associate Agreement (BAA)

A Business Associate Agreement (BAA) is a HIPAA required contract between a covered entity and any vendor that handles PHI on its behalf. 

Without a signed BAA, using a third-party texting platform to send PHI constitutes a HIPAA violation. If a vendor won't sign a BAA, you'll be in violation if you use their platform for PHI or any identifiable patient communication.

  1. Obtain Written Patient Consent

HIPAA requires documented patient consent before sending PHI via text. Verbal consent is not sufficient. Patients must be informed of the risks of receiving PHI by text and given the option to opt out.

Exercise best practice and always get patient opt-in permission before sending texts. Include the consent in your new patient intake records. All patient consent forms should go through an annual review. 

  1. Apply the Minimum Necessary Principle

The Rule: Every text containing patient information should include only the minimum necessary information for that specific communication. When in doubt, send less. For example, an appointment reminder only needs to state the day and time.

Neutral appointment reminders without clinical detail are lower risk. The same standard – minimal necessary information – should be applied to all internal staff messages about patients.

  1. Implement Access Controls

Establish a practice standard that only authorized staff is able to send or view PHI messages. Audit trails are unenforceable when all staff share accounts.

Set up role-based permissions that require unique logins. Limit access to what each staff member actually needs. Protect your practice and add an additional layer of protection with multi-factor authentication.

  1. Enable Audit Logs

Only use a text platform that logs all message activity. Include who sent what, when, and to whom. HIPAA requires audit logs for compliance. 

Audit logs are the primary tool for investigating a potential breach. Logs must be retained and accessible for a minimum of six years under HIPAA record retention rules.

  1. Enforce Device Security

Any electronic device that's used to send patient messages must be encrypted and password-protected. Strengthen security by enabling automatic screen lock and session time-out on all electronic devices.

Remote wipe capability is required in the event a device is lost or stolen. Prohibit your staff from using personal devices for patient communication unless a Mobile Device Management (MDM) solution is in place. 

  1. Train Staff Thoroughly and Regularly

Administrative safeguards require ongoing staff training on HIPAA texting policies. All training must be documented. A verbal briefing isn't sufficient for compliance purposes.

Staff training should cover:

  • What counts as PHI.
  • The Minimum Necessary Principle.
  • Which texting platforms are approved.
  • What to do if a message is sent in error.
  • How to handle a potential breach.
  • The consequences of a breach.
  1. Review and Update Policies Regularly

HIPAA-compliance is not a one-time setup. Policies must be reviewed regularly as regulations and technology evolve.

Conduct an annual risk assessment that includes texting workflows. Document any changes to approved platforms, consent procedures, or staff responsibilities.

Healthcare texting checklist showing nine areas to review for secure patient messaging.

Why Standard SMS Is Not HIPAA-Compliant

A common misconception among healthcare practices is to assume that texting is fine if the patient is okay with it. This casual attitude puts your practice at risk of violation.

Standard SMS lacks audit logs, access controls, automatic timeout, and a signed BAA – all features that are required for HIPAA-compliance.

Even if messages are deleted on standard text platforms, messages can still reside on a carrier's servers or in cloud backups. This puts a healthcare practice at risk of a HIPAA violation. 

Consumer apps like WhatsApp and Facebook Messenger carry these risks. Patient consent does not make standard text platforms safe and HIPAA-compliant.

What Happens If You Are Not Compliant?

Many healthcare practices are exposed through common everyday texting habits or lack of quality staff training, not from malicious intent. Even with the best of intentions, you can be fined if you, your staff, or practice aren't compliant. Office of Civil Rights (OCR) investigations can be triggered by a single patient complaint.

Be aware of the HIPAA violation penalty tiers:

  • Tier 1: Unknowing violation – $100 to $50,000 per violation.
  • Tier 2: Reasonable cause – $1,000 to $50,000 per violation.
  • Tier 3: Willful neglect, corrected – $10,000 to $50,000 per violation.
  • Tier 4: Willful neglect, not corrected – $50,000 per violation, up to $1.5 million annually per category.

In case of breaches, the practice is obligated to notify affected patients, the U.S. Department of Health and Human Services (HHS), and in some cases, media outlets within 60 days of the discovery of the breach.

Example of a HIPAA Violation Settlement

In April 2026, The Office of Civil Rights (OCR) announced the settlement of a case where Regional Women's Health Group, LLC (RWHG) "failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI."  As a result of RWHG's failure to conduct the risk analysis, a data breach affected 37,989 patients whose names, addresses, SSN's, dates of birth, driver's license numbers, medical conditions, medications, and lab results were exposed. RWHG was fined $320,000 and ordered to OCR monitoring for two years.

Common HIPAA Texting Mistakes to Avoid

  • Using personal mobile phones for patient communication without Mobile Device Management (MDM) in place.
  • Assuming verbal patient consent is sufficient. Consent must be written, documented, and stored.
  • Assuming that because a patient texted first, the practice can respond via standard SMS with PHI. Whenever a text contains PHI a practice must use HIPPA-compliant text.
  • Using a vendor that has not signed a BAA. The term, "HIPAA-friendly" is not the same as HIPAA-compliant.
  • Sharing more patient detail than necessary in a message. Keep patient data as minimal as possible.
  • Not training staff when a new platform is introduced or the current platform is revised. Staff need to be aware of how PHI breaches can result in serious consequences.

Ensure your practice and patient information are secure. Periodically review this HIPAA-compliant texting checklist to avoid HIPAA related errors. 

Compliance Is Not a One-Time Setup

This HIPAA-compliant texting checklist is your starting point. Compliance is an ongoing practice, not a box to tick just once.

Textline, one of the most secure HIPAA-compliant two-way messaging platforms on the market, was built specifically for healthcare from the ground up. Essential encryption, audit logs, access controls, remote wipe, and a signed BAA are all included to protect your practice.

‍See How Textline Keeps You Compliant

Frequently Asked Questions

Do I need a BAA with every texting vendor I use?

Yes, to ensure HIPAA-compliance, you need a Business Associate Agreement (BAA) with each and every texting vendor who handles PHI data. You must have a signed BAA with any vendor who manages, processes, or stores patient data. 

Even if the vendor transmits encrypted PHI data that can't be viewed, you need a BAA. Standard messaging services such as WhatsApp or iMessage won't sign a BAA. Using a text service without a BAA puts your practice at serious legal risk and open to heavy fines.

Can patients text us first and make it compliant?

When a patient texts you first, they show preference for text messaging and conditionally agree to receiving a reply through the same channel. Still, adhere to best practices and promptly reply that standard text messaging is not secure. In your reply, avoid including any personal identifiers or PHI until you get the patient switched to your secure platform.

Standard texting is only HIPAA-compliant when there is no PHI data. If texts include any PHI such as patient identifying information, clinical details, or two-way healthcare issues, your communication must be in a HIPAA-compliant texting platform. Refer to the above HIPAA SMS checklist to make sure your practice is compliant.

What is the difference between encrypted and HIPAA-compliant texting?

Knowing the difference between encrypted-only and HIPAA-compliant texting is critical to the security of your healthcare practice.

When texting is only encrypted, like with iMessage or WhatsApp, others can't read the message. But encrypted-only texting doesn't have the features or meet the legal standards required by federal healthcare privacy law. HIPAA-compliant texting requires encryption plus legal agreements such as BAA, access controls, remote wipe, and audit logs.

You face heavy fines if you share patient information in standard encrypted apps. Protect your healthcare practice and keep patient information secure by only using HIPAA-compliant texting platforms.

Does HIPAA apply to internal staff messages, not just patient-facing texts?

Yes, HIPAA law applies to any and all internal staff messaging that contains Protected Health Information (PHI). Whenever a text includes a patient's name, medical condition, billing details, address, or other identifiable information, HIPAA law applies. 

If staff texts office notifications such as vacation schedules or in-services and there is no PHI – HIPAA does not apply. Texts such as generic appointment reminders that don't include specific patient information and can't be traced back to an individual also do not fall under HIPAA law.

Start texting now

Create a free account today.
Get Started
No credit card required

Earn commission for referrals

Get paid for each customer you bring to Textline.