A HIPAA audit checklist for messaging is a review of your texting and communication tools against the same control areas the HHS Office for Civil Rights (OCR) uses in its Audit Protocol: administrative safeguards, physical safeguards, technical safeguards, and the organizational and breach notification requirements that sit alongside them. If a text message ever contains protected health information (PHI), the channel it travels through is in scope for all of these controls, not only encryption.
In many organizations the EHR gets audited closely while messaging is treated as an afterthought. That is worth reconsidering. Texting is often the channel with the least oversight and the most staff touching it directly, which makes it a common place for gaps to hide.
How the OCR Audit Protocol maps to messaging
The OCR Audit Protocol organizes its review around the Privacy Rule, Security Rule, and Breach Notification Rule. Applied to a messaging system, the relevant control areas break down like this.
| Control area | Citation | What to check in your messaging tool |
|---|---|---|
| Access control | 45 CFR 164.312(a) | Unique user IDs, role-based permissions, automatic session logoff on shared devices |
| Audit controls | 45 CFR 164.312(b) | Logs of who sent, viewed, or exported messages containing PHI, and when |
| Transmission security | 45 CFR 164.312(e) | Safeguards against unauthorized access to PHI in transit. Encryption is an addressable implementation specification at 164.312(e)(2)(ii), so either implement it or document an equivalent alternative and why |
| Device and media controls | 45 CFR 164.310(d) | Policy for staff personal phones, including remote wipe or account revocation on offboarding |
| Risk analysis | 45 CFR 164.308(a)(1) | Documented assessment of where PHI enters the messaging system and how it could be exposed |
| Workforce training | 45 CFR 164.308(a)(5) | Staff trained specifically on texting practices, not only general HIPAA training |
| Business associate agreement | 45 CFR 164.502(e) | A signed BAA with the messaging vendor covering the specific service in use |
| Breach notification readiness | 45 CFR Part 164, Subpart D | A documented process for identifying and reporting a messaging-related exposure |
Building the checklist step by step
Start with a scope decision: which messages actually contain PHI. Appointment confirmations that only reference a date and a first name may carry less risk than messages that include diagnosis, treatment, or billing detail. Document that distinction, because it drives everything else on the checklist. For the exact line-item version of this scoping exercise, see the HIPAA SMS compliance checklist.
Next, confirm the technical safeguards on the platform itself: encryption in transit, role-based access, and audit logging that captures message-level activity, not only login events. Ask a vendor to show an audit log rather than only describe it. If the platform cannot produce a record of who accessed a specific PHI-containing thread, that is a gap worth closing before an audit request arrives.
Then move to policy. Every organization sending PHI by text needs a written texting policy that staff are trained on, not a general HIPAA policy that mentions texting in passing. A HIPAA texting policy template is useful as a starting structure, but it still needs to reflect your actual workflow, your actual vendor, and your actual staff roles.
Finally, confirm the contractual layer: a signed BAA that names the messaging service specifically, current retention settings that match your organization's retention policy, and a documented process for what happens if a message is sent to the wrong number or a device is lost. This last point is where many organizations discover they have a technical safeguard in place but no operational plan behind it.
What auditors actually ask for
An OCR audit request typically asks for documentation, not only a system walkthrough: a risk analysis, policies and procedures, training records, BAAs with every vendor in scope, and audit logs covering a specific window of time. If a BAA for the messaging vendor cannot be produced quickly, that gap tends to surface before anyone looks at encryption settings. Build an internal audit checklist around producing these documents on demand, not only around the technology working correctly day to day.
Common gaps found during internal reviews
A few patterns show up repeatedly when organizations run this checklist for the first time. The first is a BAA that was signed years ago for a texting product the organization no longer uses in the same way, because the vendor added features or changed plan tiers without a new agreement being executed. The second is audit logs that exist at the account level but do not capture message-level detail, which means the organization can show that someone logged in but not what they actually accessed once inside.
The third common gap is staff using a mix of approved and unapproved channels, where a compliant platform is in place but individual staff members occasionally text patients from personal devices when the approved system is slow or unfamiliar. A checklist review should include a conversation with frontline staff, not only a review of vendor contracts, since policy gaps often surface in how people actually work rather than in what the written policy says.
Turning the checklist into a recurring process
A checklist that only gets reviewed once, at implementation, loses value quickly as staff, vendors, and workflows change. Set a recurring calendar review, at minimum annually and ideally tied to the same schedule as the broader Security Rule risk analysis required under 45 CFR 164.308(a)(1), so messaging does not fall out of sync with the rest of the organization's compliance calendar. Assign a named owner for the messaging checklist specifically, distinct from whoever owns the overall risk analysis, so texting does not get folded into a general review and lose the specific attention it needs.
Keep a simple record of each review: the date it was conducted, who participated, what gaps were found, and what was done to close them. This record becomes valuable in two directions. It demonstrates to an OCR investigator that the organization has an active, ongoing compliance process rather than a one-time setup, and it gives the compliance team its own history to reference when evaluating whether a previously identified gap has actually been resolved or has quietly resurfaced.
Where messaging platform choice comes in
The strongest audit checklist still depends on the underlying platform supporting the controls it asks for. A general consumer texting app typically offers no audit log, no role-based access, and no BAA, though this varies and should be confirmed per vendor, which puts every item on this checklist at risk before policy is even considered. For an overview of what a platform built for regulated messaging looks like from the ground up, see FRANSiS's HIPAA compliant text messaging overview.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
What is a HIPAA audit checklist for messaging?
It is a structured review of texting and communication tools against the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule control areas that HHS OCR uses in audits: access control, audit logging, transmission security, device controls, risk analysis, training, BAAs, and breach readiness, all applied specifically to how an organization texts.
Does HIPAA specifically mention text messaging?
No. HIPAA is technology-neutral and does not name SMS or any specific channel. The Security Rule's safeguards apply to any system that creates, receives, maintains, or transmits PHI, which includes text messaging whenever PHI is part of the message content.
What documents should be ready before an OCR audit?
At minimum: a current risk analysis, written policies and procedures covering messaging specifically, staff training records, signed BAAs with every messaging vendor, and audit logs showing access activity for the period requested. Missing or outdated BAAs are a recurring gap organizations find during their own reviews.
Do appointment reminder texts need to be included in a HIPAA audit?
If the reminder includes information beyond a date, time, and generic confirmation, such as a provider name tied to a specialty or a reason for visit, treat it as PHI and include it in the audit scope. When in doubt, apply the stricter standard rather than assuming a message is too minor to matter.
How often should a messaging HIPAA audit checklist be reviewed?
Review it at least annually and any time vendors change, a new messaging use case is added, or after any security incident involving communications. The Security Rule requires an ongoing risk analysis process, not a one-time review, per 45 CFR 164.308(a)(1).
Can staff text patients from personal phones under HIPAA?
Only if policy explicitly allows it and covers device security, such as passcodes, remote wipe capability, and restrictions on storing PHI locally on the device. Most organizations find it easier to audit and control a dedicated platform than to manage PHI risk across personal devices.
What is the difference between a HIPAA audit and a HIPAA risk analysis?
A risk analysis is an internal, ongoing process required under 45 CFR 164.308(a)(1) to identify where PHI could be exposed. An audit, whether internal or from OCR, is a review that checks whether the risk analysis, policies, and controls actually hold up against the requirements. The checklist is the review tool; the risk analysis is the underlying work.
Who is responsible for the messaging audit checklist, IT or compliance?
Both. IT typically owns the technical safeguards, such as encryption and access controls, while compliance owns the policy, training, and documentation. The checklist works well when both teams review it together, since a technically secure platform used without the right policy still creates risk.
Build your messaging audit on a platform designed for it
FRANSiS supports compliance for healthcare texting, with access controls, audit logging, and a signed BAA included, so compliance teams are not retrofitting safeguards onto a general texting app. Contact us to walk through how it fits your existing audit process.
Related guides: Is Texting HIPAA Compliant? HIPAA Text Messaging Rules


