What we do · 03 · HIPAA-Compliant

HIPAA-compliant texting your team will actually use.

Your patients want to text you. So does the law of every modern care setting. FRANSiS delivers BAA-backed, two-way SMS that handles routine patient questions automatically — at 11pm, after Saturday clinic, between visits. The way text actually works.

✓ HIPAA COMPLIANT BAA INCLUDED 4-WEEK IMPLEMENTATION
VH
Valley Health
VIA FRANSiS™ · SMS
Tues · 11:04 PM
Hey — what time does the Henderson clinic open tomorrow? Also do I need a referral for my son's asthma follow-up?
Hi Maria — Henderson opens 7 AM. For an asthma follow-up with Dr. Patel no referral is needed. Want me to hold a 7:30 slot?
Yes please 🙏
Done. Confirmation #H7821. We'll text a reminder at 6 AM. Rest well.
Trusted by mission-based healthcare organizations
COMPASS HEALTH · TOURO UNIVERSITY · FAITH LUTHERAN · COMMUNITY SERVICES
99.9%
platform uptime. SOC 2 Type II.
24/7
conversations handled. Never panicked.
4 wk
implementation, not 4 quarters.
messages. No per-message billing.
06 · The Checklist

What actually makes texting HIPAA-compliant.

HIPAA doesn't ban text messaging. It requires that any tool handling Protected Health Information meet six baseline safeguards. Miss one — even encryption — and you're not compliant.

Business Associate Agreement

A signed contract acknowledging the vendor processes PHI on your behalf. A missing BAA is among the most-cited HIPAA violations — and most carriers won't sign one.

Encryption in transit

All messages encrypted with TLS 1.2 or higher while moving between servers and devices. Prevents interception of PHI on the network layer.

Encryption at rest

Stored messages and contact data encrypted on vendor servers using AES-256 or equivalent. Protects PHI even if storage is ever compromised.

Access controls

Role-based permissions so only authorized staff can send, view, or export messages. The HIPAA "minimum necessary" standard, enforced.

Audit logs

Immutable, exportable logs of every message sent, received, read, and deleted — with user identity and timestamp. Required for compliance audits and breach investigations.

Retention policy

Configurable rules for how long messages are stored and when they are automatically deleted. Meets HIPAA retention requirements without manual cleanup.

07 · The Gap

Standard SMS isn't HIPAA-compliant. It can't be.

Every text your staff sends from a phone, iMessage, or WhatsApp about a patient is operating outside HIPAA. Most teams don't realize until an audit.

Standard SMS / consumer apps
  • No BAA — AT&T, Verizon, T-Mobile, iMessage, WhatsApp don't sign one
  • Plaintext transmission, no end-to-end encryption
  • No access controls — any app on the device can read messages
  • No audit trail for sent, received, or deleted messages
  • No remote deletion or retention policy enforcement
  • Phone numbers + timestamps are themselves PHI under HIPAA
FRANSiS™
  • BAA included on day one, before any PHI moves through
  • 256-bit AES at rest, TLS 1.2+ in transit
  • Role-based access — clinical, admin, compliance views separated
  • Immutable audit log of every message event, exportable on demand
  • Configurable retention with automatic deletion
  • Phone numbers, contact data, and metadata fully encrypted
08 · Platform

Purpose-built for mission-driven healthcare.

Not a marketing SMS tool with a compliance veneer. Every layer reflects the realities of care delivery — sensitive patient data, lean staffing, and the need for AI that gets out of the way.

BAA on day one

Every healthcare customer gets a standard BAA at onboarding — not as an add-on, not "available on request". Executed before the first message.

256-bit AES + TLS 1.2+

End-to-end encryption that meets and exceeds the HIPAA Security Rule's technical safeguard standards.

AI two-way conversations

Patient asks a routine question, FRANSiS™ answers within a HIPAA-safe envelope. Your team only sees the conversations that need human judgment.

Compliance dashboard

Real-time view of delivery rates, response rates, and opt-out activity. Compliance officers can audit any message event and export records on demand.

SOC 2 + TCPA aligned

SOC 2 Type II controls, TCPA opt-in management, consent logging, and opt-out processing — built in, not bolted on.

Managed 10DLC

FRANSiS™ handles 10DLC brand and campaign registration on your behalf — full carrier throughput, no compliance gaps. See the full 10DLC guide →

09 · Use Cases

Built for the way care actually happens.

FQHCs

Appointment reminders, care plan check-ins, screening outreach, transportation coordination — all BAA-backed, in patient-preferred languages. The high-need populations FQHCs serve have the most to gain from text.

Behavioral health

Sensitive, private communication for medication adherence, crisis-line referrals, and group check-ins — with encryption and audit logging your compliance officer can sign off on.

Hospital systems

Discharge follow-up, post-surgical care, preventive screening campaigns, patient experience surveys — at scale, without overloading clinical staff.

Correctional healthcare

Compliant SMS workflows for facilities where phone access is constrained — medication management, appointment coordination, and re-entry healthcare continuity.

Telehealth providers

Session links, reschedule reminders, intake form requests, follow-up care instructions — the SMS layer that video alone can't deliver.

Independent practices

The same compliance posture as a hospital system, configured for a 4-person front office. BAA, audit log, AI — all of it, in a 4-week implementation.

10 · Comparison

Honest comparison.

Across the criteria that matter for healthcare — not the surface features.

PlatformBAA includedAI two-wayNonprofit/FQHC pricing10DLC managedAudit trail
FRANSiS™Yes (standard)Yes — AI conversational layerYes — mission-driven pricingYes — fully managedYes — full log
TextlineYesNo — manual replies onlyStandard SaaSPartialYes
TigerConnectYesNo — provider-to-provider focusEnterpriseNot listedYes
CurogramYesLimited — template-basedStandard SaaSPartialYes
Standard SMS (carrier)NoNoN/AN/ANo
11 · Launch

Live in under 14 days.

Most healthcare organizations move from decision to first live campaign in under two weeks.

  1. 01

    Intake

    Share your communication workflows, EHR system, and compliance requirements in a 30-min call.

  2. 02

    BAA

    Your legal or compliance team reviews and signs the BAA. No PHI moves until it's in place.

  3. 03

    Import

    Upload your patient list via secure CSV or EHR integration. Consent metadata recorded for every contact.

  4. 04

    Configure

    Build appointment reminder sequences, follow-up workflows, and AI response handling for common questions.

  5. 05

    Launch

    Go live. Compliance dashboard shows delivery, response, and opt-out activity in real time.

"

The first product in my 33 years of working in behavioral health that I could see us using and implementing organization-wide.

Tom Sebastian · CEO, Compass Health Staff returned to clinical work instead of answering "where's your office?" for the 800th time.
12 · FAQ

HIPAA-compliant texting, answered.

What makes a text messaging platform HIPAA-compliant?
A HIPAA-compliant text messaging platform must include a signed BAA, end-to-end encryption in transit and at rest, role-based access controls, immutable audit logs, configurable retention policies, and proper consent management. Encryption alone is not enough — a BAA is the legal foundation.
Can standard SMS apps like iMessage or WhatsApp be HIPAA-compliant?
No. Standard consumer SMS apps do not offer BAAs and do not provide the encryption, access control, and audit logging required by HIPAA. Using them for PHI is a compliance violation, regardless of how careful the staff member is.
Does FRANSiS™ sign a Business Associate Agreement?
Yes. FRANSiS™ provides a standard BAA to all healthcare customers as part of onboarding. The BAA is executed before any PHI moves through the platform.
What is the difference between HIPAA-compliant SMS and regular SMS?
Regular SMS transmits data in plaintext with no encryption, no access controls, and no audit trail. HIPAA-compliant SMS uses encrypted infrastructure, role-based permissions, comprehensive audit logging, and operates under a BAA between the healthcare organization and the platform vendor.
What types of healthcare organizations use HIPAA-compliant SMS?
FQHCs, behavioral health clinics, hospital systems, correctional healthcare facilities, telehealth providers, and independent practices all use HIPAA-compliant SMS for appointment reminders, care follow-up, screening outreach, and patient engagement.
How does HIPAA-compliant SMS help reduce patient no-shows?
SMS appointment reminders delivered at optimized intervals allow patients to confirm, reschedule, or ask questions via text — leading to meaningful reductions in no-show rates while staying within HIPAA's PHI handling rules.
What is a BAA and why does it matter for text messaging?
A BAA is a legally required HIPAA contract between your healthcare organization and any vendor handling PHI on your behalf. Without it, even a fully encrypted SMS platform cannot lawfully process PHI for your organization.
Is two-way SMS allowed under HIPAA?
Yes. Two-way SMS is permitted when the platform maintains a BAA, encrypts messages in transit and at rest, implements access controls, and maintains a complete audit trail. FRANSiS™ adds an AI layer that handles routine patient questions within these guardrails.
How quickly can a healthcare organization get started with FRANSiS™?
Most organizations complete onboarding in under two weeks including BAA execution, contact import, compliance configuration, and AI workflow design. Implementation timelines vary by EHR integration complexity.
Stop treating your team like a call center

Give your team back 15–20 hours a week — this quarter.

Predictable pricing, unlimited messages, four-week implementation. No per-message anxiety. Most organizations see full ROI in the first quarter.

4 wk
Implementation, not 4 quarters.
Messages. No per-msg billing.