"Secure texting" is one of the most loosely used terms in healthcare technology, applied to everything from encrypted clinician chat apps to ordinary SMS sent with good intentions. The looseness matters, because organizations make compliance decisions based on the label. So here is a precise working definition: secure texting in healthcare is text-based messaging conducted through a system that provides encryption in transit and at rest, authenticated access, audit logging, organizational message control, and a vendor bound by a business associate agreement (BAA). A message is not secure because it feels private or because the app is popular; it is secure because a specific, checkable list of safeguards surrounds it. This article unpacks each element, distinguishes the categories the term gets applied to, and maps the definition to what HIPAA actually requires. It is general information, not legal advice.
Key takeaways:
- Secure texting is defined by safeguards, not by app category: encryption in transit and at rest, authentication, audit logs, organizational control, and a signed BAA.
- The HIPAA Security Rule at 45 CFR 164.312 supplies the safeguard categories; the BAA requirement comes from the Privacy Rule at 45 CFR 164.502(e).
- Standard SMS between phones is not secure texting, but a governed platform can still use SMS to reach patients compliantly, because the platform, not the carrier hop, is what gets governed.
- Clinician-to-clinician secure messaging and patient-facing secure texting are different products solving different problems; conflating them causes bad purchases.
- Consumer apps with strong encryption still fail the definition when they lack BAAs, organizational control, and auditability.
The five elements, unpacked
1. Encryption in transit and at rest. Messages must be protected while moving between systems, typically TLS 1.3 for transport, and while stored, typically 256-bit AES. The Security Rule treats encryption as an addressable specification at 45 CFR 164.312(a)(2)(iv) and 164.312(e)(2)(ii), meaning an organization must implement it or document why an equivalent alternative suffices; in modern practice, encryption is the expected baseline.
2. Authenticated access. Only identified, authorized users reach the message store: unique user IDs, strong authentication, and automatic session controls, reflecting 45 CFR 164.312(a) and (d). A shared login or an unlocked personal phone fails this element regardless of the app behind it.
3. Audit logging. The system records who sent, read, and exported what, and when, satisfying the audit controls standard at 45 CFR 164.312(b). If an organization cannot reconstruct a conversation's history for a compliance review, the messaging is not secure in any regulatory sense.
4. Organizational control. The organization, not the individual, owns the channel: it can provision and deprovision users, enforce policies, retain and produce records, and keep conversations when staff leave. This is what separates a governed platform from a clinician's personal messaging habits.
5. A vendor under BAA. Any vendor storing or transmitting protected health information (PHI) for a covered entity is a business associate under 45 CFR 160.103 and must sign a BAA per 45 CFR 164.502(e). This element is binary and non-negotiable, and it is where popular consumer apps exit the conversation, as our analyses of WhatsApp and similar tools show in detail.
A useful test: if you cannot answer "who has access, what was sent, and where is the BAA" in an afternoon, whatever you are using is not secure texting.
What secure texting is not
Not ordinary SMS between phones. Carrier SMS offers no end-user encryption at rest, no organizational audit trail, and no BAA. A clinician texting a patient from a personal phone is outside the definition entirely.
Not "any encrypted app." Consumer apps can encrypt superbly and still fail elements two through five: no organizational authentication, no employer-accessible audit logs, no admin control, no BAA. Encryption is one element of five, not a synonym for the whole.
Not a portal. Patient portals are secure but are a destination the patient must remember to visit. Secure texting is defined by the message reaching the person in their native messaging flow, with the security carried by the platform behind it.
Not automatically compliant. Secure texting describes a system's capabilities. Compliance describes an organization's practices: consent, minimum necessary drafting under 45 CFR 164.502(b), training, and correct configuration. A secure platform used carelessly still produces violations.
The two product categories the term covers
Because "secure texting" names a property rather than a product, two distinct product families both legitimately claim it:
| Dimension | Clinician-to-clinician secure messaging | Patient-facing secure texting |
|---|---|---|
| Users | Credentialed staff inside the organization | Patients and community members |
| App requirement | Staff install and authenticate | None; patients use native texting |
| Typical uses | Care team coordination, consults, alarms | Reminders, results notices, intake, two-way questions |
| Security model | Closed encrypted network | Governed platform, minimum necessary content, consent |
| Governance anchor | Directory and role integration | BAA, consent records, audit logs, opt-out handling |
The clinician-side category is examined in our guide to what HIPAA actually requires for secure chat between doctors. The patient-facing category has a structural constraint the clinician side does not: patients will not install an app, so the platform must deliver security around ordinary texting, through governed infrastructure, consent management, content discipline, and auditability, the architecture described step by step in how HIPAA-compliant SMS works.
How a governed platform makes patient texting secure
The apparent paradox, secure texting over SMS, resolves once the unit of analysis shifts from the message hop to the system:
- The organization's side is fully governed: authenticated staff access, role controls, audit logs, retention, and a vendor under BAA with encryption in transit (TLS 1.3) and at rest (256-bit AES).
- Consent is captured and enforced: patients opt in, choose the channel, and can stop at any time, with the platform enforcing opt-outs automatically.
- Content is disciplined: templates carry minimum necessary information, so the SMS leg exposes as little as a lock screen would reveal anyway. Sensitive detail moves behind authentication when needed.
- Conversations are one record: every inbound and outbound message, including automation, is logged and reviewable.
Automation lives comfortably inside this frame: an AI Powered Helper answers routine questions from approved content, completes scheduling and intake tasks, and escalates clinical matters to staff, with every exchange inheriting the platform's logging and controls. This is the model FRANSiS operates, with HIPAA compliance supported and a signed BAA included; the complete regulatory picture lives in the HIPAA-compliant text messaging pillar guide.
A buyer's checklist against the definition
- Encryption in transit and at rest, stated plainly with standards named.
- Unique authenticated accounts for staff, with role-based access and session controls.
- Audit logs covering send, read, export, and administrative actions.
- Admin provisioning, deprovisioning, retention, and policy enforcement.
- A signed BAA offered as part of the service, before PHI flows.
- Consent capture, STOP handling, and quiet-hours controls for patient messaging.
- Template and content governance, including for any automated replies.
- Escalation paths that put humans in the loop for clinical content.
Any vendor conversation that cannot close this list quickly is telling you the label is doing the work the safeguards should.
Frequently asked questions
What is secure texting in healthcare?
Text-based messaging conducted through a system providing encryption in transit and at rest, authenticated access, audit logging, organizational control, and a vendor bound by a business associate agreement. It is defined by that checkable safeguard list, not by app category or reputation.
Is regular SMS considered secure texting?
Phone-to-phone SMS is not: it lacks encryption at rest, auditability, organizational control, and a BAA. However, a governed platform can compliantly reach patients over SMS by carrying the security in the system: consent, minimum necessary content, logging, and a vendor under BAA.
Is an encrypted consumer app the same as secure texting?
No. Encryption satisfies one of five elements. Consumer apps typically fail authentication under organizational control, audit logging, admin governance, and the BAA requirement, which is why tools like WhatsApp cannot be used for PHI regardless of their encryption quality.
What does HIPAA require for texting patients?
A business associate agreement with the messaging vendor under 45 CFR 164.502(e), Security Rule safeguards including access controls, audit controls, and transmission security under 45 CFR 164.312, minimum necessary content, and patient consent practices, with opt-outs honored. The safeguards attach to the organization and platform, not the patient's phone.
What is the difference between secure messaging and a patient portal?
A portal is a secure destination patients must visit; secure texting delivers the interaction into the patient's native messaging flow while the platform behind it carries the safeguards. Portals excel at document storage; texting excels at reach, speed, and two-way conversation.
Conclusion
"Secure texting" stops being a slippery term the moment it is defined as a checklist: encryption both ways, authenticated access, audit logs, organizational control, and a BAA. Hold every product, and every internal habit, against those five elements, and the category sorts itself: clinician networks on one side, governed patient messaging on the other, and consumer apps politely excused from the room. Precision here is not pedantry; it is the difference between a label and a defensible program.
Want secure texting that meets the definition, not just the label? Contact the FRANSiS team to see governed patient messaging with a signed BAA included, full audit trails, and an AI Powered Helper working inside the safeguards.


