Telehealth runs on text messages. The visit happens on video, but almost everything around it, the confirmation, the intake link, the tech check, the waiting-room nudge, the summary, the pharmacy notice, the follow-up, arrives by SMS because that is the channel patients actually read. The regulatory question is not whether texting is permitted. It is what may be sent, to whom, with what consent, and where the line falls between logistics and clinical care. This explainer walks the rules by name, then organizes them around the three phases of a telehealth encounter.
The Rules That Govern Telehealth Texting
- HIPAA Privacy Rule, 45 CFR Part 164 Subpart E. Governs uses and disclosures of protected health information. Text messages containing PHI are disclosures and must be permitted by the rule, typically as treatment, payment, or health care operations.
- HIPAA Security Rule, 45 CFR Part 164 Subpart C. Applies to electronic PHI and requires administrative, physical, and technical safeguards, including access controls, audit controls, and a documented risk analysis. Encryption is an addressable implementation specification, meaning it must be implemented or a documented equivalent alternative adopted, not simply skipped.
- Right to confidential communications and alternative means. The Privacy Rule gives individuals the right to request receipt of communications by alternative means or at alternative locations, and covered health care providers must accommodate reasonable requests. If a patient asks that no telehealth texts go to a shared phone, that request is a legal obligation, not a courtesy.
- OCR guidance on patient-requested unencrypted communication. The HHS Office for Civil Rights has long taken the position that individuals may receive communications through unencrypted channels if they request it after being warned of the risk. The warning and the request should be documented. This does not relieve the provider of Security Rule duties for its own systems.
- Business Associate Agreement requirement, 45 CFR 164.308(b) and 164.502(e). Any vendor that creates, receives, maintains, or transmits PHI on the provider's behalf, including a messaging platform, must be under a signed BAA.
- Minimum necessary standard. Limit PHI in each message to what the purpose requires. "Your appointment with the clinic is confirmed" satisfies most logistics needs without disclosing a diagnosis or specialty.
- Breach Notification Rule, 45 CFR Part 164 Subpart D. An impermissible disclosure by text, a message to the wrong number, an unsecured device, requires breach risk assessment and, where applicable, notification.
- End of COVID-19 telehealth enforcement discretion. During the public health emergency, OCR exercised enforcement discretion for good-faith provision of telehealth over non-public-facing remote technologies. That discretion has since expired. Ordinary HIPAA rules apply to telehealth today, which is why consumer video and consumer messaging tools without a BAA are no longer a defensible arrangement.
- 42 CFR Part 2. Substance use disorder treatment records from Part 2 programs carry heightened consent restrictions. Even a text confirming an appointment can reveal that a person is receiving SUD treatment, so Part 2 programs should treat message content and channel selection as consent-governed.
- Ryan Haight Act and DEA telemedicine prescribing rules. Controlled substance prescribing via telemedicine is governed by federal in-person evaluation requirements and their telemedicine exceptions, subject to DEA rulemaking. Text messaging is not a prescribing modality and cannot substitute for a required evaluation.
- State licensure and standard of care. The clinician generally must be licensed where the patient is located, and the standard of care does not relax because the encounter is remote. Texting cannot become the encounter.
- State consent-to-telehealth requirements. Many states require informed consent to telehealth, sometimes documented before the first visit. Text can deliver and collect that consent; it does not replace the requirement.
- TCPA and FCC healthcare rules. The Telephone Consumer Protection Act restricts autodialed calls and texts to wireless numbers. The FCC has recognized an exemption for certain healthcare messages to wireless numbers with defined limits on purpose, frequency, and opt-out, while other messages, notably marketing, require prior express written consent. Appointment logistics and treatment messages sit in a different posture than promotional content.
- Information Blocking rules under the 21st Century Cures Act. Practices that unreasonably interfere with access, exchange, or use of electronic health information can constitute information blocking. Refusing to send results or records by a patient's chosen channel, or building friction into access, carries risk in the other direction.
For platform selection criteria, see our overview of HIPAA compliant telehealth platforms and the operational detail in our guide to HIPAA compliant text messaging.
Before the Visit
This is the highest-value and lowest-risk phase for texting, because most of it is logistics.
- Scheduling and confirmation. Two-way texting lets patients confirm, reschedule, or cancel without a phone tree. Keep content minimal necessary: date, time, modality, and a way to change it.
- Intake and forms. Send a secure link to intake, insurance, and history forms rather than the data itself. Links to authenticated portals move PHI collection inside a controlled system.
- Consent to telehealth. Where state law requires documented consent, text delivery of the consent document with electronic signature capture creates both the record and the timestamp.
- Technology check. A short pre-visit message asking the patient to test camera, microphone, and connection prevents the most common cause of failed visits. Include the fallback number.
- Visit link delivery. Send the join link close to the appointment, tied to the individual visit, not a reusable room. Note that a link plus a name plus a specialty clinic can itself disclose PHI, so consider generic sender identity and avoid naming specialized service lines.
- Reminders. Staged reminders reduce no-shows, and the FCC healthcare treatment recognizes appointment and health-care-related messages differently from marketing. Honor opt-outs immediately and keep per-message limits and frequency caps documented.
- Confidential communication requests. Capture, at registration, whether the patient wants texts at all, at which number, and with what level of detail. This is where the Privacy Rule alternative-means right gets operationalized.
During the Visit
Texting during a telehealth encounter is a support channel, not a care channel.
- Virtual waiting room messages. "The clinician is running about ten minutes behind, please stay on the line" prevents abandonment. A status text meaningfully reduces abandonment.
- Connection failures. When video drops, text is the only reliable path back. A pre-scripted recovery message with a new link and a callback number should be one tap for staff.
- Fallback to phone. Policy should define when a failed video visit converts to audio-only or reschedules, since coverage, documentation, and in some cases billing differ. Communicate the change by text and document it.
- Sharing instructions mid-visit. Dosing instructions, exercise links, or an educational resource can be texted during the visit so the patient has it in writing. Keep clinical detail in the record and the portal; keep the text pointed at retrievable resources.
- Why clinical decision-making does not happen over text. Standard-of-care rules, licensure requirements, prescribing rules including the Ryan Haight Act framework, and documentation obligations all assume an actual encounter. Diagnosing or triaging symptoms by text collapses those safeguards and creates a record that cannot show what the clinician evaluated. Text routes patients to care; it does not deliver it.
After the Visit
- Visit summaries and care instructions. Send a notice that the summary is available in the portal rather than pasting the clinical content into SMS, unless the patient has requested detailed texts after being informed of the risk and that request is documented.
- Prescription pickup notices. "Your prescription was sent to your pharmacy" is high-value and low-detail. Naming a specific medication increases disclosure risk on a shared phone, and for Part 2 programs it can reveal treatment status.
- Follow-up scheduling. Two-way texting closes the loop that phone tag loses, and it is where most follow-up attrition happens.
- No-show recovery. A same-day message with a one-tap rebooking option recovers visits that a voicemail will not.
- Satisfaction follow-up. Short surveys work well by text. Treat survey and outreach content as distinct from treatment messages for TCPA purposes, and keep marketing consent separate from treatment communication.
- Records and results access. If a patient asks for results or records, the Information Blocking rules make delay and friction a compliance problem. Text can carry the notification and the secure access link.
What to Send and What to Withhold
| Appropriate to text | Not appropriate to text |
|---|---|
| Appointment confirmations, reminders, and reschedule options | Diagnoses, test results detail, or clinical assessments in message body |
| Secure links to intake forms, portal, and visit join page | Full intake data collected in the SMS thread itself |
| Technology check instructions and fallback phone number | Reusable visit links shared across patients |
| Waiting-room delay and reconnection messages | Symptom triage or clinical decision-making by text |
| Notice that a visit summary is available in the portal | Pasted clinical notes absent a documented patient request |
| Prescription-ready and pharmacy notices without medication detail | Controlled substance prescribing or dose changes |
| Follow-up scheduling and no-show rebooking | Specialty or program identifiers that reveal sensitive treatment |
| Consent documents and e-signature links | Marketing content sent under treatment-message consent |
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
Is texting patients about telehealth visits allowed under HIPAA?
Yes, when it is done within the rules. The Privacy Rule permits disclosures for treatment, payment, and health care operations, the minimum necessary standard limits how much PHI a message contains, and the Security Rule requires safeguards for electronic PHI including access controls and a documented risk analysis. Any messaging vendor handling PHI must be under a Business Associate Agreement under 45 CFR 164.308(b) and 164.502(e). Patients also have the right to request communications by alternative means, and reasonable requests must be accommodated.
Did the COVID-19 telehealth flexibility change texting rules permanently?
No. During the public health emergency, the HHS Office for Civil Rights exercised enforcement discretion for good-faith telehealth provided over non-public-facing remote technologies. That discretion has expired, so ordinary HIPAA Privacy and Security Rule requirements apply to telehealth communication today. Practically, that means consumer video and consumer messaging apps used without a Business Associate Agreement are no longer a defensible arrangement, and organizations that adopted them during the emergency should have migrated to platforms covered by a BAA.
Can a patient consent to receiving unencrypted text messages?
OCR guidance has long recognized that individuals may receive communications through unencrypted channels if they request it after being warned of the risk. The provider should document both the warning and the request, and note the patient's preferred number and level of detail. That consent addresses the transmission channel to the patient; it does not waive the provider's Security Rule obligations for its own systems, its risk analysis, its access and audit controls, or its Business Associate Agreement requirements.
Do telehealth appointment reminders require TCPA consent?
The Telephone Consumer Protection Act restricts autodialed texts to wireless numbers, and the FCC has recognized an exemption for certain healthcare-related messages with defined limits on purpose, frequency, and opt-out handling, while other messages, particularly marketing, require prior express written consent. In practice, providers document how each phone number was obtained, distinguish treatment and appointment messages from promotional content, keep separate consent records for each, honor opt-outs immediately, and retain the consent evidence.
Can a clinician diagnose or prescribe by text message?
No. State licensure and standard-of-care rules assume an actual clinical encounter, and controlled substance prescribing via telemedicine is governed by the Ryan Haight Act framework and DEA telemedicine rules, which text messaging cannot satisfy. Substance use disorder programs face further consent restrictions under 42 CFR Part 2. Texting is appropriate for scheduling, logistics, secure links, instructions the patient can retrieve, and routing patients into care. Clinical assessment, diagnosis, and prescribing belong in a documented encounter.
Text the Logistics. Keep the Care in the Visit.
FRANSiS gives telehealth programs a two-way texting layer for confirmations, intake links, tech checks, waiting-room updates, summaries, and follow-up, with consent and opt-out tracking, audit logging, role-based access, compliance supported and a signed BAA included, and an AI Powered Helper answering routine scheduling and access questions so staff handle the clinical ones. See healthcare texting solutions or Contact us to map it to your visit workflow.


