Most practices that get texting wrong do not lack security tools; they lack a written rule. A staff member texts a patient from a personal phone because nothing said not to. A front desk types a diagnosis into a reminder because no policy defined what a reminder may contain. HIPAA anticipates exactly this: the Security Rule requires covered entities to implement policies and procedures (45 CFR 164.316) and to train their workforce on them (45 CFR 164.308(a)(5)). A texting policy is where those requirements meet the most-used communication channel in the building.

Below is a model policy you can adapt. It is a template, not legal advice; have your privacy officer and counsel tailor it to your state, specialty, and systems.

Before You Adapt It: The Regulatory Anchors

The policy's sections map to specific safeguards:

  • Risk analysis (45 CFR 164.308(a)(1)): texting must appear in your security risk analysis as an assessed channel.
  • Business associates (45 CFR 164.502(e); 164.308(b)): the texting platform transmits PHI on your behalf and requires a signed BAA. Our explainer on business associate agreements covers what the contract must do.
  • Transmission security (45 CFR 164.312(e)): standard SMS is unencrypted in transit across carrier networks, which is why the policy restricts message content rather than pretending the channel is secure.
  • Access and audit controls (45 CFR 164.312(a), (b)): texting happens on identified accounts with reviewable logs, not personal devices.
  • TCPA consent (47 U.S.C. 227): automated texts require prior express consent, documented, with opt-outs honored immediately.

The full requirements picture is in our pillar guide to HIPAA-compliant text messaging.

Model Policy: Text Messaging of Patient Information

Policy title: Text Messaging and Patient Communication Policy Applies to: All workforce members, including employed and contracted staff, students, and volunteers Effective date / review cycle: [Date]; reviewed at least annually and upon material system changes

1. Purpose

This policy establishes the conditions under which [Practice Name] workforce members may use text messaging in connection with patient care and operations, in support of compliance with the HIPAA Privacy and Security Rules (45 CFR Parts 160 and 164) and the Telephone Consumer Protection Act (47 U.S.C. 227).

2. Approved Channel

2.1. All patient-facing text messaging shall occur exclusively through [Platform Name], the practice's approved texting platform, with which the practice maintains a signed business associate agreement.

2.2. Texting patients from personal mobile numbers, personal messaging applications, or any unapproved channel is prohibited, regardless of patient preference or urgency.

2.3. Workforce access to the platform shall be through individual, identified accounts. Shared logins are prohibited.

3. Permitted and Prohibited Content

3.1. Permitted content in outbound texts is limited to logistics: appointment dates, times, locations, arrival and document instructions, links to the patient portal or secure forms, billing notifications without clinical detail, and operational notices.

3.2. The following shall not appear in any standard text message: diagnoses or conditions; test or lab results; medication names or changes; treatment details; and any content that would disclose the nature of care beyond the fact of an appointment.

3.3. Clinical content shall be communicated by telephone, in person, or through the secure patient portal. Texts may direct patients to those channels.

3.4. Workforce members shall not provide clinical advice by text. Clinical questions received by text shall be escalated per Section 6.

4. Consent and Opt-Out

4.1. Prior express consent for texting shall be obtained and documented before automated messages are sent, normally at intake or scheduling, using the practice's approved consent language.

4.2. Patients shall be informed that standard text messaging is not encrypted and that they may withdraw consent at any time.

4.3. Opt-out requests (including STOP replies) shall be honored immediately and recorded in the platform. No workforce member shall re-enroll an opted-out patient without new documented consent.

5. Devices and Accounts

5.1. Patient texting shall not be conducted from personal SMS applications. Where workforce members access the approved platform from mobile devices, those devices shall meet the practice's device security requirements, including screen lock and prompt reporting of loss or theft.

5.2. Lost or stolen devices with platform access shall be reported to the [Privacy/Security Officer] the same day, and access shall be revoked pending review.

6. Two-Way Messages and Escalation

6.1. Inbound patient texts shall be monitored during business hours, with automated handling permitted for routine scheduling matters.

6.2. Messages indicating a clinical question shall be routed to clinical staff for response by telephone or portal. Messages indicating an emergency shall be answered with direction to emergency services, and staff shall follow the practice's emergency communication procedure.

7. Records and Audit

7.1. Text message records maintained in the platform are practice records and shall be retained consistent with the practice's retention schedule.

7.2. The [Privacy/Security Officer] shall review platform audit logs at least [quarterly] for unauthorized use, and texting shall be included in the practice's periodic security risk analysis.

8. Training and Enforcement

8.1. All workforce members shall receive training on this policy at hire and at least annually (45 CFR 164.308(a)(5)).

8.2. Violations shall be subject to the practice's sanction policy (45 CFR 164.308(a)(1)(ii)(C)), up to and including termination, and shall be evaluated under the breach notification procedures where PHI may have been compromised.

Rolling the Policy Out

A policy binder no one reads changes nothing. Three implementation steps carry the weight:

  1. Train with examples, not clauses. Show the reminder that passes and the reminder that fails; staff remember contrasts. Templates written to the policy, like a vetted reminder library, make the right behavior the easy behavior.
  2. Make the approved channel more convenient than the workaround. Personal-phone texting happens when the sanctioned tool is slower. A platform that automates reminders and drafts routine replies removes the temptation.
  3. Audit gently and early. A quarterly log review that catches drift in month three prevents the entrenched habit an auditor would find in year two.

Frequently Asked Questions

Does HIPAA require a written texting policy?

HIPAA requires written policies and procedures implementing the Security Rule's safeguards (45 CFR 164.316) and workforce training on them. If texting touches PHI in your practice, and reminders alone mean it does, a written policy governing that channel is part of meeting those requirements.

Can staff ever text patients from personal phones?

A defensible policy prohibits it. Personal SMS offers no BAA coverage, no audit trail, no access controls, and no retention, which fails multiple Security Rule safeguards at once. The fix is making the approved platform fast enough that the workaround loses its appeal.

What texting content does a policy typically permit?

Logistics only: appointment details, arrival instructions, portal and form links, billing notices without clinical detail, and operational announcements. Diagnoses, results, medications, and treatment content are excluded from standard SMS and routed to secure channels.

How often should the policy be reviewed?

At least annually, and whenever systems or workflows materially change, a new platform, a new location, a new message type. Pair the review with your periodic security risk analysis so the documents stay consistent.

Is a texting policy enough to make texting compliant?

No single artifact is. Compliance is the program: the signed BAA, the risk analysis covering the channel, documented consent, trained staff, audit review, and the policy binding it together. The policy is the piece that turns intentions into enforceable rules.

A Platform That Makes the Policy Easy

FRANSiS is built to match a policy like this one: signed BAA included, logistics-only templates, documented consent and opt-outs, per-user accounts with audit trails, and an AI Powered Helper that keeps routine replies inside the approved channel. See the healthcare solutions page or contact us to pair the policy with the platform.