Every organization that texts eventually faces the retention question, usually at the worst possible moment: a records request, a lawsuit, an audit, or an investigation asking for messages that may or may not still exist. The rules that govern how long text messages must be kept are real, sector-specific, and indifferent to the fact that SMS feels ephemeral. This reference maps the retention landscape across government, healthcare, education, and regulated industry, explains the principles that apply everywhere, and lays out what a defensible text message retention policy looks like in practice.
Key takeaways:
- No law treats "text message" as its own records category; retention follows the content of the message under whichever framework governs your organization.
- Federal agencies retain texts under the Federal Records Act and NARA schedules; state and local governments follow state records schedules.
- HIPAA requires six-year retention of required documentation (45 CFR 164.316), and communications that become part of a medical record follow state medical records rules.
- Litigation holds override every schedule: once litigation is reasonably anticipated, relevant texts must be preserved regardless of policy.
- The only reliable implementation is platform-level archiving; policies that depend on individual phones fail exactly when tested.
The universal principle: content controls, medium does not
Retention law attaches to what a record documents, not to the technology that carried it. A text approving a contract change is a contract record; a text scheduling a coffee is transitory. This principle, uniform across frameworks, has two consequences:
- You cannot solve retention by picking a single number of days for all texts. A one-size purge policy will simultaneously over-retain trivia and destroy records the law required you to keep.
- You can solve retention by classification: archive everything on managed channels, then apply the schedule each content category earns. Central archiving makes the classification workable; device-by-device retention makes it fiction.
Government: the strictest and clearest rules
Federal. The Federal Records Act (44 U.S.C. ch. 31) requires agencies to preserve records documenting their organization, functions, and decisions, and the 2014 amendments explicitly cover electronic messages. Under 44 U.S.C. 2911, business conducted on non-official messaging accounts must be copied or forwarded into official systems within twenty days. Retention periods come from schedules approved by the National Archives and Records Administration: the General Records Schedules assign periods to common categories, and agency-specific schedules cover mission records. Unlawful destruction of federal records carries penalties under 18 U.S.C. 2071. The disclosure side of the same coin is covered in FOIA and text messages.
State and local. Every state operates a records retention scheduling system, typically through the state archives or secretary of state, assigning periods by record series: correspondence classes, fiscal records, personnel actions, public safety communications. Texts about public business are public records in most jurisdictions, including on personal devices per decisions like California's City of San Jose case, and they take the retention period of their content series. Agencies building compliant programs should start with the government SMS compliance requirements guide.
Healthcare: HIPAA's six-year rule and the medical record
Two distinct retention ideas get conflated in healthcare texting, and separating them is the whole game:
- HIPAA documentation retention. The Security Rule and Privacy Rule require covered entities to retain required documentation, policies, procedures, authorizations, risk analyses, for six years from creation or last effective date (45 CFR 164.316(b)(2); 45 CFR 164.530(j)). This is the famous HIPAA six-year rule, and it governs compliance documentation, not every clinical text.
- Medical record retention. HIPAA itself does not set retention periods for medical records; state law does, and periods vary by state and provider type. When a text exchange becomes part of the patient's record, an appointment change that documents care logistics, a symptom report a clinician acted on, it follows the state medical record schedule.
The operational consequence: healthcare texting platforms should archive message content and the compliance documentation around the program, with HIPAA compliance supported through a signed business associate agreement included, encryption in transit and at rest, and access controls, so both retention obligations can be met from one system. Audit trails from the platform also feed the six-year documentation requirement directly.
Education, employment, and regulated industry
- Education. FERPA (20 U.S.C. 1232g) governs access to and disclosure of education records rather than fixed retention periods, but state schedules assign periods to district and institutional records, and texts that document official actions fall into those series.
- Employment. Various federal employment laws impose retention on categories like payroll and personnel actions; a text that documents a schedule change, discipline, or accommodation conversation can become evidence in those categories, which is a reason organizations route such matters to managed channels.
- Financial services. The strictest regime outside government: broker-dealers must preserve business communications under SEC Rule 17a-4, and regulators have brought major enforcement actions over business conducted on unarchived messaging channels. The lesson generalizes: when a regulator requires preservation of business communications, an off-channel text is a violation waiting to be discovered.
- Public companies and litigation generally. The Federal Rules of Civil Procedure treat texts as discoverable electronically stored information, and spoliation sanctions under Rule 37(e) attach when messages that should have been preserved are lost.
Litigation holds: the override switch
Whatever your schedule says, a litigation hold supersedes it. Once litigation, investigation, or audit is reasonably anticipated, the organization must suspend deletion for potentially relevant materials, including texts. Holds fail in predictable ways with SMS: auto-delete settings keep running, custodians leave with their phones, and nobody can suspend what nobody controls. A platform with central archiving turns a hold into a configuration change; a fleet of personal phones turns it into a prayer.
Building a defensible text retention program
| Element | What it looks like |
|---|---|
| Channel policy | Business texting happens on managed, archiving platforms; stray messages get forwarded in promptly |
| Classification | Message categories mapped to your applicable schedule (records series, medical record, transitory) |
| Automatic capture | Every message, participant, timestamp, and delivery event archived without user action |
| Scheduled disposition | Deletion happens by rule at end of retention, and is logged; nothing purges silently |
| Hold capability | One switch suspends disposition for identified custodians or topics |
| Export | Threads export in reviewable formats for requests, audits, and discovery |
| Security | Encryption in transit and at rest, role-based access, audit logs, the posture described in the enterprise SMS security guide |
| Training | Staff know the content-controls rule and the channels policy, with the twenty-day forwarding norm for anything that strays |
Two failure patterns to design against. First, the ephemeral-app trap: disappearing-message apps used for business communication have produced enforcement actions and spoliation findings across sectors; if content is business, auto-delete is a liability setting. Second, the departed-employee gap: retention that lives on individual devices leaves with the individual, while platform archiving survives every offboarding.
Security certifications and archiving depth vary widely across texting vendors; evaluation criteria for organizational buyers are covered in the FRANSiS security overview.
Frequently asked questions
How long do text messages need to be kept?
As long as the content requires under your governing framework: federal texts follow NARA-approved schedules, state and local texts follow state records schedules, HIPAA-required documentation is kept six years under 45 CFR 164.316, medical record content follows state medical records law, and regulated industries like broker-dealers follow their communication preservation rules. There is no single number; content controls.
Are businesses legally required to archive text messages?
It depends on sector. Broker-dealers and certain regulated firms must preserve business communications; healthcare entities must retain compliance documentation and record-content messages; government bodies must retain public-business texts under records laws. Every organization, regulated or not, must preserve relevant texts once litigation is reasonably anticipated, which makes archiving prudent even where no schedule mandates it.
What is the HIPAA text message retention rule?
HIPAA requires covered entities to retain required documentation, policies, authorizations, and similar compliance records, for six years from creation or last effective date (45 CFR 164.316(b)(2)). Retention of clinical message content follows state medical record law when the exchange becomes part of the record. HIPAA compliance is supported by platforms that archive both layers with a signed BAA included.
Do deleted text messages violate retention laws?
Deleting a message before its scheduled retention period expires can violate records statutes and regulatory preservation rules, and deletion after litigation is anticipated risks spoliation sanctions under Rule 37(e) and worse. Deletion at the scheduled end of retention, logged and rule-based, is the compliant pattern.
What should a text message retention policy include?
A managed-channel requirement, content classification mapped to applicable schedules, automatic platform archiving, rule-based disposition with logging, litigation hold capability, export tooling, security controls, and staff training. The test of the policy is operational: can you produce, or defensibly explain the absence of, any business text from the retention window?
Conclusion
Text messages stopped being ephemeral the moment organizations started doing business on them; the law simply caught up. Retention follows content under the schedule that governs your sector, litigation holds trump everything, and the only architecture that reliably complies is central, automatic archiving on managed channels. Build that once, and every future records request, audit, and hold becomes administration instead of crisis.
Need texting with retention built in? Contact the FRANSiS team to see how organizations run compliant messaging with automatic archiving, export, and security controls designed for records obligations.


