Quick answer: HIPAA-compliant text messaging means sending texts that involve protected health information (PHI) only through a platform that signs a Business Associate Agreement (BAA), protects messages with encryption in transit (TLS 1.3) and at rest (256-bit AES), restricts access to authorized staff, and keeps an audit log of every message. Standard SMS on its own meets none of those requirements, which is why texting patients from a personal phone or a consumer messaging app creates immediate violation risk. This guide walks through the six required safeguards, the HIPAA text messaging rules in plain English, a step-by-step workflow for texting patients, and a checklist for choosing a compliant platform.

Book a 15-min walkthrough

What makes text messaging HIPAA-compliant?

Standard SMS was never designed to carry health data. Messages pass through carrier infrastructure without encryption, can be stored indefinitely on devices your organization does not control, and leave no auditable trail. HIPAA requires covered entities and their business associates to protect PHI wherever it lives, including in transit.

A compliant messaging platform addresses this by building the required technical and administrative safeguards directly into the product. The six non-negotiable requirements are:

  • Signed Business Associate Agreement (BAA). The platform vendor is legally a Business Associate under HIPAA. Before any PHI is transmitted, your organization and the vendor must execute a written BAA. Without it, every message containing PHI is a potential violation, regardless of how the platform is configured.
  • Encryption in transit and at rest. Messages in motion must be protected using TLS 1.3; messages stored on servers must be protected using 256-bit AES encryption. Both layers are required.
  • Access controls and user authentication. Only authorized staff should be able to send, read, or export PHI through the platform. Role-based permissions and strong authentication prevent unauthorized access.
  • Audit logging. Every message sent or received, every login, and every administrative change must be logged with a timestamp and user identifier so your organization can demonstrate compliance during a review or breach investigation.
  • Documented patient consent. Before sending any message that contains or could contain PHI, you must obtain and document the patient's written consent to receive communications via that channel.
  • Minimum-necessary standard. Each message should contain only the PHI actually required to fulfill the communication purpose. Sending a full medical history in an appointment reminder violates this principle even if every other safeguard is in place.

For a deeper look at how these requirements apply to the apps your team evaluates, see our guide to HIPAA-compliant texting apps.

HIPAA text messaging rules in plain English

HIPAA does not ban texting. It sets conditions on how PHI can move over any channel, and three rules do most of the work for text messaging:

  • The Privacy Rule governs when PHI may be used or disclosed. For texting, it means you need documented consent for the channel, you must honor a patient's request to be contacted a certain way, and every message must follow the minimum-necessary standard.
  • The Security Rule requires technical safeguards for electronic PHI: encryption, access controls, integrity protections, and audit logging. This is the rule that standard carrier SMS cannot satisfy on its own and that a compliant platform is built to meet.
  • The Breach Notification Rule requires you to notify affected patients, and in larger incidents regulators and media, within 60 days of discovering a breach. Unencrypted PHI on a lost or compromised device is generally treated as a reportable breach, which is exactly the exposure personal-phone texting creates.

One point trips up many teams: no platform can make your organization compliant by itself. HIPAA compliance is supported by the platform's safeguards and a signed BAA, and completed by your own policies, staff training, and documentation. Regulators evaluate the whole program, not just the software.

The Business Associate Agreement: why it is the starting point

Many healthcare organizations configure their messaging platform correctly in every technical respect but never execute a BAA, and that alone converts every PHI-bearing message into a reportable breach. The BAA is a contract that obligates the vendor to protect PHI to the same standard HIPAA imposes on covered entities, to report breaches to your organization, and to return or destroy PHI when the relationship ends.

When evaluating vendors, request the BAA before signing any service agreement. Review it for: the scope of PHI the vendor is permitted to use, their breach notification timeline (HIPAA requires notification within 60 days of discovery), and whether their subcontractors, including cloud infrastructure providers, are also covered under downstream agreements.

FRANSiS™ executes a BAA with every healthcare customer as a condition of onboarding. The agreement is issued before your first message is configured.

Common implementation mistakes healthcare teams make

Even well-intentioned organizations routinely create compliance risk through practices that feel harmless in the moment:

  • Using personal staff phones. When a care coordinator texts a patient from their personal number, even with good intent, that message lives on a personal device outside your organization's access controls and audit logging. It also creates a direct liability because there is no BAA covering that channel.
  • Bulk-messaging from a shared shortcode without proper 10DLC registration. Carriers can block or filter messages from numbers not registered through the 10DLC process. Unregistered traffic also creates TCPA exposure. Read our 10DLC registration guide to understand the full requirements.
  • Storing opt-in consent informally. A verbal "yes" at the front desk is not auditable. Consent records must be documented, time-stamped, and retrievable on demand.
  • Including more PHI than necessary. An appointment reminder that includes a patient's diagnosis, medication list, or insurance ID exceeds the minimum-necessary standard. Keep messages focused on the single piece of information the patient needs to act.
  • Failing to configure a message retention or deletion policy. PHI stored indefinitely increases breach surface. Your platform should support configurable retention windows aligned to your organization's policies.

How to text patients under HIPAA: a step-by-step workflow

If your team is asking how to text patients without violating HIPAA, the safe workflow looks the same in almost every organization. Work through it in order; skipping a step is where violations start.

  1. Execute a BAA with your messaging vendor first. No PHI moves through any platform until the agreement is signed and on file.
  2. Capture written, channel-specific consent. Ask the patient to authorize text communication specifically, record the date and scope, and store the record where it can be retrieved during an audit.
  3. Verify the number before the first message. A confirmation message that asks the patient to reply keeps PHI from landing on a stranger's phone because of a typo or a reassigned number.
  4. Apply the minimum-necessary standard to every message. "You have an appointment Tuesday at 2pm, reply C to confirm" works. Adding the reason for the visit does not.
  5. Route sensitive detail to secure retrieval. For lab results, diagnoses, or billing detail, text a notification that information is ready and direct the patient to a secure channel to view it.
  6. Honor opt-outs immediately and log them. A patient who replies STOP must stop receiving messages, and the opt-out must be recorded with a timestamp.
  7. Train staff and review audit logs on a schedule. Documented training and periodic log review are what demonstrate a working compliance program if your organization is ever reviewed.

Real healthcare use cases that require HIPAA-compliant messaging

Once the compliance infrastructure is in place, two-way SMS opens communication workflows that phone calls and patient portals consistently underperform on:

  • Appointment reminders and confirmations. Patients can confirm, reschedule, or ask follow-up questions without navigating a phone tree. Staff spend less time on outbound calls.
  • Post-discharge follow-up. A structured sequence of messages after discharge, checking on recovery progress, surfacing warning signs, routing urgent responses to clinical staff, supports continuity of care without requiring a phone call for every patient.
  • Prescription and lab result notifications. Alerting patients that a result is available and directing them to a secure channel to retrieve it keeps PHI off the message itself while still closing the communication loop promptly.
  • Care gap outreach. Preventive care reminders, flu vaccines, annual screenings, chronic disease check-ins, can be sent at scale to defined patient populations without the cost of phone-based outreach.
  • Billing and payment prompts. Balance reminders and payment confirmations communicated over a compliant channel reduce aging accounts receivable without exposing financial PHI on an unprotected medium.

For a side-by-side look at how these workflows perform across different platforms, see our comparison of the best texting platforms for medical practices.

How to choose a HIPAA-compliant text messaging platform

Vendors describe themselves as "HIPAA-compliant" with very different levels of substance behind the claim. Use this checklist during evaluation and ask for evidence, not assurances:

  • A BAA offered in writing, before onboarding, with subcontractors and cloud infrastructure covered under downstream agreements.
  • Encryption in transit (TLS 1.3) and at rest (256-bit AES) stated explicitly in security documentation, not implied.
  • Role-based access controls so front-desk staff, clinicians, and administrators see only what their role requires.
  • Exportable audit logs covering messages, logins, and administrative changes, so you can produce records on demand.
  • Built-in consent capture and opt-out handling with time-stamped records, rather than a spreadsheet your team maintains by hand.
  • 10DLC-registered sending numbers and TCPA-aware sending workflows, so carrier filtering and telemarketing rules are handled at the platform level.
  • Two-way messaging with human escalation, so patient replies reach a person instead of dead-ending in a broadcast tool.
  • Configurable retention windows aligned to your record-keeping policies.
  • Flat, predictable pricing so compliance is not undermined by pressure to cut message volume mid-program. See our pricing overview for how FRANSiS structures this.

For hospitals and health systems

Prioritize granular role-based permissions, department-level audit segmentation, and the vendor's willingness to work through your security review. At health-system scale, the BAA's subcontractor coverage matters as much as the platform features.

For private practices and clinics

Smaller teams need compliance built into the default workflow: consent capture, opt-out handling, and reminder sequences that work correctly out of the box without a compliance officer configuring them. Our healthcare solutions overview shows how FRANSiS handles this for lean clinical teams.

For behavioral health and community providers

Sensitivity is higher here: an appointment reminder that reveals the type of provider can itself disclose PHI. Look for message templates designed around the minimum-necessary standard and staff controls that keep clinical detail out of the channel entirely.

For public health programs and campus clinics

Government and university health programs often layer additional requirements on top of HIPAA, such as records retention rules and accessibility standards. Confirm the platform supports the strictest framework you operate under, not just HIPAA alone.

How FRANSiS supports HIPAA-compliant text messaging

FRANSiS is built for mission-driven organizations that cannot afford compliance shortcuts. The platform supports HIPAA compliance through:

  • A signed BAA issued before onboarding
  • Encryption in transit (TLS 1.3) and at rest (256-bit AES) across all message storage
  • Role-based access controls with audit logs on all user actions
  • Documented consent capture and storage built into the workflow
  • 10DLC-registered sending numbers with TCPA opt-out handling
  • An AI Powered Helper that drafts, routes, and escalates messages, keeping human staff in control of every clinical decision

Pricing is flat, predictable, unlimited messaging, so your team can run high-volume patient communication programs without watching a per-message meter. For a full breakdown of what a compliant setup looks like, visit our HIPAA-compliant text messaging overview.

Book a 15-min walkthrough

Frequently asked questions

Is regular SMS HIPAA-compliant?

Standard SMS is not HIPAA-compliant on its own. Messages travel across carrier networks unencrypted, no audit logging exists, and the access controls HIPAA requires are not supported. To send PHI via text message, you must use a purpose-built platform that signs a BAA and provides the required technical safeguards.

Is it a HIPAA violation to text patients?

Texting patients is not a violation by itself; HIPAA regulates how PHI is protected, not which channel you use. Texting becomes a violation when PHI moves over a channel without the required safeguards: a signed BAA, encryption, access controls, audit logs, and documented consent. With a compliant platform and the right workflow, texting patients is permitted and widely used.

What is a Business Associate Agreement and why do I need one?

A Business Associate Agreement (BAA) is a legally required contract between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on its behalf. It obligates the vendor to protect that PHI under HIPAA standards and to report breaches within the required timeframe. Transmitting PHI through any platform without a signed BAA in place is a HIPAA violation regardless of the platform's technical configuration.

Do patients need to consent before receiving HIPAA-compliant text messages?

Yes. Before sending messages that contain PHI, covered entities must obtain and document written patient consent to receive communications via that channel. Consent records should include the patient's name, the date consent was given, and the specific channel authorized. Undocumented consent is not auditable and creates compliance risk if your organization is reviewed.

Can appointment reminders be sent by regular text message?

Reminders occupy a gray area: regulators have acknowledged that limited-content reminders may be sent when the patient has been informed of the risks and has agreed to the channel. In practice, most organizations avoid the ambiguity by sending reminders through a compliant platform, which also adds confirmation handling, opt-out logging, and an audit trail that plain SMS cannot provide. The safest reminder contains only the date, time, and a way to confirm or reschedule.

Are WhatsApp, iMessage, or other consumer apps HIPAA-compliant?

Consumer messaging apps generally do not offer BAAs to healthcare organizations, and without a BAA they cannot be used for PHI regardless of how strong their encryption is. They also lack organizational access controls, centralized audit logs, and consent management. Encryption alone does not make a channel HIPAA-compliant; the full set of safeguards and the signed agreement do.

Does HIPAA allow staff to text each other about patients?

Staff-to-staff messages that reference patients are PHI and fall under the same rules as patient-facing texts. Care team coordination over personal phones or consumer apps creates the same unlogged, unencrypted exposure as texting a patient directly. Internal clinical communication should run through a covered channel with access controls and audit logging.

What if a patient texts us PHI first?

A patient sending PHI unprompted does not violate HIPAA, and it does not authorize your organization to continue the conversation over an unprotected channel. Acknowledge the message, move the exchange to your compliant platform or another secure channel, and document the interaction. Many organizations also use the moment to capture formal consent for future texting.

What encryption is required for HIPAA-compliant texting?

HIPAA does not mandate a specific encryption standard, but current best practice, and what regulators expect to see during a breach investigation, is TLS 1.3 protecting messages as they travel and 256-bit AES protecting stored data. A platform that meets both requirements, combined with the other required safeguards and a signed BAA, demonstrates a reasonable and appropriate approach to PHI protection.

Related guides: HIPAA Compliant Forms: How to Collect Patient Information by Text · Text Message Marketing Laws by State: What Changes the Rules

Join The Troop

Sign up for our mailing list for insights, perks, and more!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.