A patient at the front desk says, "Don't call me at work — just text me when the biopsy result is back." Your medical assistant hesitates, looks at you, and asks whether that's allowed. The answer is yes, with conditions — and the conditions are almost entirely about documentation. This is a practical walkthrough of HIPAA texting patients: who authorizes it, what warning you must give, which vendor agreement you need, and what a surveyor or OCR investigator would expect to find in your file six months later. No clinical advice, no vendor pitch — just the obligations and the evidence.

HIPAA does not ban SMS. It bans undocumented SMS.

There is no provision in the Privacy Rule or Security Rule that says "do not text protected health information to patients." What exists instead is a set of requirements: reasonable safeguards, minimum necessary, a documented risk analysis covering every system that transmits ePHI, and — critically — the individual's right to receive their information by the method they choose.

Two provisions do most of the work. Under 45 CFR 164.522(b), you must accommodate reasonable requests for confidential communications by alternative means or at alternative locations. Under the right of access rules at 45 CFR 164.524, if an individual requests their ePHI be sent unencrypted, you generally must honor that request after warning them of the risk. HHS states this plainly in its right of access guidance: the covered entity is not responsible for unauthorized access that occurs in transit after a light-warned individual insists on unsecured transmission.

That last clause is the entire game. "After warning them" is a documentation obligation, and it is the first thing an investigator will ask you to produce.

Is texting patients a HIPAA violation? The short answer

No — texting patients is not a HIPAA violation when four conditions are met:

  • The patient requested or agreed to text messaging, and that preference is recorded in the chart with a date and the staff member who captured it.
  • You warned the patient of the risks of unencrypted SMS — interception, a shared or lost phone, a reassigned number — and documented the warning.
  • Any vendor that stores, routes, or logs the message content is under a signed Business Associate Agreement.
  • Your risk analysis and policies name texting as a transmission channel and record the safeguards you chose, including any decision not to encrypt.

Miss the fourth condition and you have a Security Rule problem even if no message ever went astray. Miss the third and you have an impermissible disclosure to the vendor itself.

The warning script and where it lives

Write one paragraph and use it everywhere. It should say that standard text messages are not encrypted, that anyone with access to the phone can read them, that carriers and phone backups may retain copies, and that the practice cannot control the message once it leaves your system. Then it should say the patient may withdraw the preference at any time by calling the office.

Capture the acknowledgment in one of three places, in order of durability:

1. A communication preferences form

Signed at intake or at the moment of the request, scanned into the record. This is the cleanest evidence. Include fields for the mobile number, the categories the patient is opting into, and the date.

2. A structured field in the chart

Many practice management systems have a contact-preference flag. Use it, but pair it with a dated note that references your warning language by name — for example, "Reviewed Text Messaging Risk Notice v2 with patient; patient elects SMS for appointment reminders and result notifications."

3. A telephone note

Acceptable when the request comes in by phone. Weakest of the three, because it depends on the staff member's wording. Give your front desk a copy-paste template so the note is consistent.

Do not rely on the fact that the patient texted you first. An inbound text tells you they are willing to use SMS; it does not document that you warned them or that they consented to receive clinical content.

Scope the content, not just the channel

The minimum necessary standard does not apply to disclosures to the individual, so you are not legally barred from texting a result to the patient who asked for it. Operationally, though, most practices set tiers, and tiers are easier to train:

  • Tier 1 — logistics. Appointment reminders, arrival instructions, forms links, balance-due notices with no clinical detail.
  • Tier 2 — status. "Your results are available in the portal" or "Dr. Reyes has a message for you; please call." No findings in the body of the message.
  • Tier 3 — clinical content. Actual results, medication changes, instructions. Requires the documented Tier 3 preference, not just a general opt-in.

Assign the tiers in writing and tie them to roles. Front desk sends Tier 1 and Tier 2. Only clinical staff send Tier 3, and only when the chart flag says the patient elected it.

One category deserves a hard stop: records subject to 42 CFR Part 2 (substance use disorder treatment from a Part 2 program) carry consent requirements that are stricter than HIPAA. Reproductive health information also warrants extra care given the 2024 Privacy Rule changes and the litigation surrounding them. If your practice touches either category, route those messages through the portal and keep them out of SMS entirely.

Your texting platform is a business associate. Get the BAA signed first.

Here is the distinction that trips up practice owners. A mobile carrier that merely transports a message may fall within the narrow conduit exception HHS describes for entities like the postal service and telecommunications providers. A messaging platform that queues, stores, logs, templates, or analyzes your messages is doing far more than transporting — it is creating, receiving, maintaining, and transmitting PHI on your behalf. That is a business associate, full stop.

So is the appointment-reminder module bolted onto your scheduling system, the two-way chat widget your marketing person installed, the answering service that texts callbacks, and the automated recall vendor that pulls your patient list every Monday. Each one needs an executed agreement on file before the first message goes out. If you are staring at a vendor that will not sign, that is your answer about the vendor.

If your BAA folder has gaps — and after a year of adding communication tools, most do — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX for countersignature. It is a one-time purchase, no subscription, which matters when you need three agreements this week and none next month.

Two housekeeping items your privacy officer owns: a vendor inventory that lists every system capable of sending a patient message, and a review date on each agreement. An expired or superseded BAA is functionally the same as no BAA when someone asks for it.

The Security Rule side: your risk analysis must name SMS

Encryption is an addressable implementation specification under 45 CFR 164.312(a)(2)(iv) and (e)(2)(ii) — not optional, but flexible. Addressable means you assess whether it is reasonable and appropriate, implement it if so, and if not, document why and what you did instead. "The patient asked for unencrypted texts after being warned" is a legitimate, documentable rationale for that specific channel. "We never thought about it" is not.

Your risk analysis should therefore include a row for patient SMS covering the threat (interception, wrong recipient, device loss), the likelihood, the impact, the safeguards in place, and the residual risk you accepted. NIST's SP 800-66r2 gives you a usable structure for that analysis if you are building it from scratch, and practices that want the underlying risk analysis and policy set generated for them can start there rather than with a blank spreadsheet.

Keep an eye on the proposed Security Rule overhaul HHS published in January 2025. As of today it remains a proposed rule, not law, but it would tighten several addressable specifications — including encryption — into requirements with narrow exceptions, and it would formalize asset inventories and network mapping. If it finalizes in something close to its proposed form, an undocumented SMS channel becomes a much harder finding to explain. Build the documentation now; it costs you a spreadsheet row today and a corrective action plan later.

Wrong number, wrong patient: the clock that starts immediately

Two texts a year go to the wrong person in a busy practice. A digit gets transposed, a number gets reassigned, an adult child's number is still on file for a parent who moved out.

When it happens, run the four-factor risk assessment under 45 CFR 164.402: the nature and extent of the PHI involved, who received it, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated. Document the analysis whether or not you conclude a breach occurred — the absence of a written assessment is itself the finding.

If it is a reportable breach, individual notice goes out without unreasonable delay and no later than 60 calendar days from discovery. Breaches affecting fewer than 500 individuals go on your internal log and are reported to HHS no later than 60 days after the end of the calendar year in which they were discovered — so incidents discovered during 2025 are due by the deadline in early 2026. HHS's breach notification page is the authority; the submission portal is the only accepted route.

Mitigation for a wrong-number text is straightforward and worth scripting: attempt contact with the recipient, request deletion, document the attempt and the outcome, correct the number in the chart, and note who verified the correction.

TCPA and state law sit on top of HIPAA

HIPAA compliance does not resolve your telemarketing exposure. The Telephone Consumer Protection Act governs autodialed and prerecorded messages and carries private rights of action with statutory damages per message — a materially different risk profile from an OCR investigation. Healthcare treatment messages have historically received distinct treatment under FCC rules, but the boundary between a treatment reminder and a marketing message is where the litigation lives. "We're now offering aesthetic injectables" is not an appointment reminder.

Practical rule for your operations: honor STOP immediately and log it, keep marketing consent separate from clinical communication consent, and have counsel review any campaign that goes to a list rather than to a scheduled patient. Several states also impose consent or content restrictions beyond HIPAA — check yours rather than assuming the federal floor is the ceiling.

The workflow to hand your front desk

  1. Ask at every registration and annual update: "What's the best way to reach you, and is it okay to text this number?"
  2. Read the risk notice verbatim if the answer is yes. Do not paraphrase.
  3. Record the preference in the designated chart field and scan the signed form.
  4. Verify the number aloud, digit by digit, at the moment of capture.
  5. Send only from the approved platform. No personal phones, ever — a text from a staff member's own device puts ePHI on an unmanaged endpoint with no audit log.
  6. Check the tier flag before including any clinical content.
  7. Report a misdirected message to the privacy officer the same day. No exceptions, no informal fixes.

What your evidence file should contain

If OCR opened an inquiry tomorrow about your patient texting program, you would be asked to produce roughly this:

  • A written patient communication policy naming SMS, with a version number and effective date
  • The risk notice language and a sample of completed patient acknowledgments
  • Executed BAAs for every messaging, reminder, and answering-service vendor
  • A risk analysis entry for the SMS channel plus the documented encryption decision
  • Training records showing which staff were trained on the texting workflow and when
  • Message send logs retained for your stated retention period
  • Your breach log, including four-factor assessments for misdirected messages that you concluded were not breachable

Retain all of it for six years from creation or last effective date, per 45 CFR 164.316(b)(2).

Start with the vendor gap

Most practices already text patients; what they lack is the paper. Pull your vendor list this week, mark every system that can send a patient message, and check each one against your signed agreements. For the gaps, build the BAA in six steps and send it out for signature before the next reminder batch goes out. The policy and the risk analysis row take an afternoon after that — and together they turn a routine convenience into a defensible program.