HIPAA-compliant texting and encrypted messaging: what the rules actually require
Standard SMS is not encrypted and has no audit trail. What the HIPAA Security Rule, Privacy Rule, and proposed Security Rule NPRM require before you text patient information.
By Kristen Sherrill, MCSP, SCA, PMP, CSPO — Stag Compliance
20-minute read
Clinicians and staff text constantly. A nurse confirms a medication change with the attending physician. A hospice social worker sends the case manager an update from a patient's home. A dental office manager texts the treatment coordinator about a patient's insurance issue. These are normal, useful communications, but in some practices they happen over standard SMS, which is not encrypted and has no audit trail.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) never names text messaging in its regulations, and that silence is deliberate. The Security Rule was written to be technology neutral, so its safeguards apply to every electronic system that creates, receives, maintains, or transmits electronic protected health information (ePHI), including channels that did not exist when the rule was finalized. Courts, the Office for Civil Rights (OCR), and the Centers for Medicare and Medicaid Services (CMS) have consistently applied that standard to text messages containing patient data. Texting is not a gap in the rule. It is squarely inside it.
This article explains what the rules require, what standard SMS lacks, what a defensible messaging setup looks like, and what the proposed Security Rule update would change.
Why HIPAA applies to text messages
HIPAA imposes requirements through three main rules. Those are the Privacy Rule, the Security Rule, and the Breach Notification Rule. All three can apply when a practice uses text messaging.
The Security Rule (45 CFR Part 164, Subpart C) requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect ePHI. The technical safeguards standard at 45 CFR § 164.312 explicitly governs transmission security, which is the requirement to guard against unauthorized access to ePHI transmitted over an electronic communications network. A text message transmitted over a cellular or wireless network falls within this requirement.
The Privacy Rule (45 CFR Part 164, Subpart E) governs how protected health information (PHI) may be used and disclosed. PHI is the broader category that covers records in any form, electronic or not. Sending a patient's diagnosis, treatment, or appointment information to an unauthorized recipient via any channel, including SMS, is an impermissible disclosure under 45 CFR § 164.502.
The Breach Notification Rule (45 CFR Part 164, Subpart D) requires covered entities to notify affected individuals, OCR, and in some cases the media when unsecured PHI is breached. A misdirected text message containing PHI, whether it went to the wrong number, sat exposed on a lost phone, or was intercepted in transit, may trigger breach notification obligations.
What makes standard SMS unfit for ePHI
Standard SMS, the native text messaging protocol that carriers use to deliver "green bubble" messages, was designed for convenience rather than security. It fails the Security Rule's technical safeguard requirements in several distinct ways.
No encryption in transit. Standard SMS travels over cellular networks using the Signaling System No. 7 (SS7) protocol. SS7 was designed in 1975 and has known vulnerabilities that allow interception. The transmission security standard at 45 CFR § 164.312(e)(1) requires technical security measures to guard against unauthorized access to ePHI transmitted over electronic networks. Encryption is currently listed as an "addressable" specification, meaning a covered entity can document why it chose an alternative approach. For many practices in 2026, though, no documented alternative to encryption is defensible for messaging ePHI over a public network.
No encryption at rest. SMS messages stored on a device are accessible to anyone who picks up the phone. The encryption and decryption specification at 45 CFR § 164.312(a)(2)(iv), which is also currently addressable, calls for a mechanism to encrypt and decrypt ePHI. Messages stored in a phone's native SMS app are not encrypted at rest and are available to anyone with physical access to the device.
No access controls or unique user identification. Under 45 CFR § 164.312(a)(1), covered entities must implement technical policies and procedures that allow access to ePHI only to authorized persons. SMS does not require authentication to read a received message. Anyone with access to the device can read every thread, and there is no concept of role based access or individual user identification.
No audit logs. The audit controls standard at 45 CFR § 164.312(b) requires mechanisms that record and examine activity involving ePHI. Standard SMS carriers do not maintain logs of who read a message, when it was accessed, or whether it was forwarded.
No automatic logoff. The automatic logoff specification at 45 CFR § 164.312(a)(2)(iii) calls for electronic procedures that terminate a session after a predetermined period of inactivity. The native SMS app has no concept of session timeout.
No business associate agreement. Any vendor that handles ePHI on behalf of a covered entity must sign a business associate agreement (BAA) under 45 CFR § 164.308(b). Mobile carriers do not sign BAAs for standard SMS, and they are not required to, because entities that merely transport data qualify as conduits rather than business associates. That is precisely the problem. No BAA governs the transmission, so none of the contractual safeguards HIPAA relies on, such as breach reporting, use restrictions, and security obligations, apply to a standard text message. A purpose-built messaging vendor, by contrast, is a business associate and must sign one.
What a compliant secure messaging platform must provide
A secure messaging platform built for healthcare addresses each gap above. When evaluating a platform, the Security Rule's technical safeguard standards provide the checklist.
Encryption in transit and at rest. The platform must encrypt messages while they travel across the network and while they are stored on servers and devices. Transport Layer Security (TLS) 1.2 or higher is the current minimum in transit, TLS 1.3 is preferred, and Advanced Encryption Standard (AES) 256 is the current standard at rest. This addresses both the transmission security standard at § 164.312(e)(1) and the encryption specification at § 164.312(a)(2)(iv).
Unique user identification and access controls. Every person who uses the platform must have a unique username and credential that ties every message to an identified individual. Role based access controls should restrict which staff can see which patient conversations. This addresses the access control standard at § 164.312(a)(1) and the unique user identification specification at § 164.312(a)(2)(i).
Automatic session logoff. The platform must lock or terminate a session after a configurable period of inactivity on the device. This addresses § 164.312(a)(2)(iii).
Audit logging. The platform must log who sent each message, when it was sent, when it was delivered, and when it was read. Those logs must be retained and accessible for review. Security Rule documentation must be retained for six years under 45 CFR § 164.316(b)(2)(i), and applying the same retention standard to audit logs is the defensible practice. This addresses the audit controls standard at § 164.312(b).
A signed business associate agreement. Before using any platform to transmit ePHI, the covered entity must execute a BAA with the vendor. The BAA must specify the vendor's obligations to safeguard PHI, report breaches, and restrict use of the data. Without a BAA, using a platform to transmit ePHI is itself a violation under § 164.308(b)(1).
Device security. Many compliant platforms include mobile device management (MDM) features or require device level encryption as a condition of use. This addresses the physical safeguards for device and media controls at 45 CFR § 164.310.
Administrative requirements that accompany any messaging workflow
Technical controls are only part of the picture. The administrative safeguard requirements at 45 CFR § 164.308 apply whenever a practice adopts a new messaging workflow.
Conduct a risk analysis. Under § 164.308(a)(1)(ii)(A), covered entities must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI in their environment. A secure messaging platform is a new technology that processes ePHI, which means it must be evaluated in the risk analysis before deployment rather than after. CMS reinforced this in its February 2024 guidance memorandum on secure texting platforms (CMS QSO-24-05), stating explicitly that risk assessment should precede adoption.
Train your workforce. The workforce training requirement at § 164.308(a)(5) requires covered entities to implement procedures for authorizing access to ePHI and train every member of the workforce who handles it. Training must cover what may and may not be sent, what platform must be used, and what to do if a message is sent to the wrong recipient.
Apply the minimum necessary standard. The Privacy Rule's minimum necessary standard at 45 CFR § 164.502(b) requires that PHI disclosed for any purpose be limited to the minimum necessary to accomplish that purpose. Applied to messaging, an appointment reminder should not include a diagnosis, and a message that a patient in room 4 needs attention should not include the patient's full name or condition if those details are not needed for the recipient to act. This standard applies to both the platform and the habits of the person composing the message.
Document your policies and procedures. Under § 164.316(b)(1), covered entities must maintain written policies and procedures for their HIPAA safeguards and retain documentation for six years. A messaging policy that specifies which platform is approved, what types of information may be sent, and what happens when staff violate the policy must exist in writing.
The patient communication exception and when unencrypted SMS may be permissible
The rules described above govern messaging between staff and messaging to patients that the practice initiates. A separate, narrower set of rules governs communication from patients and patient requests for a particular channel.
Under 45 CFR § 164.522(b), every covered health care provider must accommodate reasonable requests by patients to receive communications by alternative means or at alternative locations. That includes a patient's request to receive health information by standard SMS, even though SMS is not encrypted. The framework for accommodating such a request has three parts.
-
Inform the patient of the risks. Before complying with a request for unencrypted communication, the covered entity should advise the patient that standard SMS is not secure and that the message could be intercepted or accessed by unauthorized parties. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights has confirmed this in its guidance on email and text communication with patients.
-
Document the patient's informed choice. The patient's acknowledgment that they understand the risks and still prefer SMS should be documented in the medical record. The Omnibus Rule commentary (78 Fed. Reg. 5634) confirms that a covered entity may communicate with patients via unencrypted channels when the patient has been warned and elected to proceed.
-
Offer a compliant alternative. The patient should always be offered a secure alternative. If they decline and accept the risk, proceeding with their preferred channel is permissible. If they later object, the practice must switch.
Messages the patient initiates are treated differently. When a patient sends a text message to the practice first, OCR guidance indicates the provider may assume the patient accepts the risks of that channel unless the patient has explicitly stated otherwise. The ePHI received from the patient's message becomes the practice's responsibility to protect from that point forward, since 45 CFR Part 164, Subpart C applies once the practice possesses it, but the channel itself was the patient's choice.
One important limitation. The patient communication exception applies only to messages between the provider and the patient and to messages the patient initiates. It does not authorize staff to message each other over unencrypted channels, even when the subject matter involves a specific patient. Coordination between clinicians requires a compliant platform.
Encrypted SMS versus a secure messaging platform
Search results for encrypted SMS often describe two different things, and the distinction matters for HIPAA.
Encrypted SMS in the consumer sense most often refers to messaging apps that provide end to end encryption over an internet connection rather than the cellular SS7 protocol. These apps encrypt content in transit, but consumer versions typically do not sign BAAs, do not maintain compliant audit logs, do not enforce access controls or automatic logoff, and do not meet the full set of Security Rule requirements. Encrypted by default does not equal HIPAA ready.
A HIPAA compliant secure messaging platform is a purpose built tool that addresses all five technical safeguard standards at § 164.312, not just encryption in transit. The full stack of encryption, access controls, audit logging, session timeout, and a signed BAA must be present and documented.
When evaluating a vendor, confirm in writing that the vendor will sign a BAA, and ask for documentation that the platform addresses each of the five § 164.312 standards. General marketing claims about encryption or security are not a substitute for a signed agreement and a reviewed architecture. The BAA is the contractual evidence that matters.
What the proposed Security Rule update would change
The Security Rule Notice of Proposed Rulemaking (NPRM), published January 6, 2025 (90 Fed. Reg. 898), proposes two changes directly relevant to messaging.
Encryption would become mandatory. Under the current Security Rule, encryption is an "addressable" specification, and a covered entity can document why it chose an alternative safeguard instead. The NPRM proposes removing the distinction between addressable and required specifications entirely. Encryption of ePHI at rest and in transit would become a mandatory standard with only one narrow exception. An individual patient may request to receive their own ePHI in unencrypted form. That exception does not create permission for a covered entity to operate messaging infrastructure without encryption by default.
Multifactor authentication would become mandatory. The proposed rule would also reclassify multifactor authentication (MFA) from addressable to required for every system that touches ePHI. For messaging platforms, this means the login step for the platform, not just the message itself, must require a second factor.
The rule is not yet final. The comment period closed March 7, 2025, with approximately 4,700 submissions. A final rule has not been published as of the date this article was last verified, and the current Security Rule remains in effect. Practices making technology investments in messaging infrastructure should build toward the proposed standard given the direction of enforcement, but should consult with compliance counsel about timelines once a final rule is published.
Where messaging gaps concentrate in mobile and field based care
The HIPAA requirements for encrypted messaging apply uniformly to every covered entity. But the risk of an informal texting gap is highest where clinical staff routinely work away from a fixed workstation, whether in patient homes, across multiple sites, or in the community. The settings below share a common structural pressure. The work demands real time coordination, staff typically have a phone in their pocket, and a purpose built secure platform can feel like friction compared to the native SMS app.
Home health agencies
Home health nurses, physical therapists, occupational therapists, and speech therapists spend their days moving between patient homes. They coordinate with supervising physicians, intake coordinators, and each other throughout the day, often from a personal phone. Under the CMS Conditions of Participation for home health agencies (42 CFR Part 484), agencies must maintain clinical records that are accurately written, promptly completed, properly filed, and accessible (42 CFR § 484.110). Any clinical communication that constitutes a record must be captured rather than left to disappear when a staff member's phone is replaced.
Home health agencies face the bring your own device (BYOD) pressures common to all care delivered in the field. Clinicians often use personal smartphones, and agencies with lean budgets cannot always provide dedicated devices. The Security Rule obligations are unchanged by who owns the hardware. The approved messaging platform must be the channel for ePHI whether the device is issued by the agency or owned by the clinician, and mobile device management (MDM) policies must address the personal device scenario explicitly.
Hospice
A hospice interdisciplinary group (IDG) of nurses, physicians, social workers, chaplains, home health aides, and often volunteer coordinators coordinates care across private homes, assisted living facilities, and inpatient units. The pace is genuine. A nurse at a patient's home at 2 a.m. needs to reach the physician on call immediately, and the default is whatever communication tool is already on the phone.
Under 42 CFR Part 418, the hospice Conditions of Participation, patients have an explicit right to a confidential clinical record. 42 CFR § 418.52(c)(5) states that access to or release of patient information and clinical records is permitted in accordance with 45 CFR parts 160 and 164, meaning the full HIPAA Privacy and Security Rules apply. Hospice agencies are covered entities under HIPAA.
Hospice care also involves a layer of communication that home health does not always share. Family caregivers are often the primary day to day contact, and a family member managing a patient's last weeks may expect to receive nursing updates by text. Two questions arise. First, who is the authorized recipient? A family caregiver involved in the patient's care may receive PHI under the Privacy Rule's personal representative and treatment provisions, but the hospice must confirm the patient has authorized that disclosure and verify the caregiver's identity before sharing clinical details. Second, what channel is permissible? The patient communication exception under 45 CFR § 164.522(b) described earlier applies. If the patient or their authorized representative has requested updates by text and been informed of the risks, the agency may accommodate that preference, and the documentation of that informed choice belongs in the clinical record.
Behavioral health mobile teams
Assertive Community Treatment (ACT) teams, mobile crisis response units, and community mental health outreach workers operate almost entirely in the field. An ACT team member may contact a psychiatric nurse practitioner, a peer support specialist, and a case manager in sequence during a single home visit. Because behavioral health information carries heightened sensitivity, and because many behavioral health patients have complicated relationships with formal institutions, the informal SMS habit can seem harmless. It is not.
Behavioral health providers who handle substance use disorder records face an additional layer. 42 CFR Part 2 governs those records with stricter consent requirements than standard HIPAA, and a 2024 Final Rule that aligned Part 2 more closely with HIPAA changed but did not eliminate those additional protections. Any mobile communication workflow involving substance use disorder records must be reviewed against both HIPAA and the applicable Part 2 requirements.
PACE programs
PACE programs, which provide comprehensive Medicare and Medicaid care for frail elderly participants, coordinate care across three settings simultaneously. Those are the participant's home, the PACE adult day health center, and inpatient or specialist facilities. The PACE interdisciplinary team (IDT) is required under 42 CFR Part 460 to meet regularly and communicate continuously about each participant's plan of care (42 CFR § 460.98). That level of coordination among staff who rotate across all three settings creates persistent pressure to communicate quickly by phone. The same HIPAA requirements apply.
The shared pattern across all these settings
Each of these care models shares the same risk profile. The clinical need for immediate communication is real and urgent, the workforce is mobile, personal phones are at hand, and the administrative infrastructure to enforce a secure channel is harder to maintain than in a fixed location clinic. The answer is the same in every case. Use a purpose built secure messaging platform covered by a BAA, include it in the risk analysis, and enforce it through written policy and training. The urgency of the clinical setting does not create a HIPAA exception. It creates a greater obligation to make the compliant tool easy enough to use that staff actually reach for it first.
Personal device policies for all mobile settings
Where BYOD is in use, the practice must ensure the following.
- The approved messaging platform is installed on the personal device and is the only channel used for ePHI.
- MDM policies can remotely wipe the approved app, or the device itself, in the event of loss or termination of employment.
- Device encryption and screen lock are required as a condition of participation.
- BYOD expectations are documented in the workforce policy and covered in training.
CMS guidance on texting patient orders
On February 8, 2024, CMS issued memorandum QSO-24-05, reversing a 2018 prohibition and clarifying that hospitals and critical access hospitals may transmit patient information and orders by text, provided the platform meets HIPAA Security Rule requirements and the Conditions of Participation at 42 CFR § 482.24 for hospitals and 42 CFR § 485.638 for critical access hospitals. Those conditions require that orders be dated, timed, authenticated, and promptly placed in the medical record. This guidance applies specifically to hospitals and critical access hospitals. Home health, hospice, PACE, and behavioral health agencies should assess whether their own Conditions of Participation impose comparable documentation requirements on clinical communications.
Where to start if your practice has no messaging policy
The gap between "we text patients on our personal phones" and "we have a documented, BAA covered secure messaging workflow" is a gap your risk analysis must capture before it appears in an OCR investigation.
First, include messaging in your risk analysis. The Security Rule requires a risk analysis that covers all ePHI in your environment (§ 164.308(a)(1)(ii)(A)). If you have not specifically evaluated how clinical information is communicated by text, meaning what channels are in use, who sends what, on which devices, to which recipients, that is a gap in your risk analysis regardless of what platform you eventually choose.
Second, identify what is actually happening. Before writing a policy, document current practice. Interview staff. Ask whether they text clinical information, which apps they use, and whether they use personal or practice issued devices. Enforcement investigations often reveal that official policy said to use secure messaging while actual practice was that everyone texts from a personal phone. The risk analysis must reflect actual behavior, not aspirational policy.
Third, evaluate platforms against the Security Rule requirements. When reviewing vendors, use the five § 164.312 standards as your checklist. Those standards are access controls, audit controls, integrity controls, authentication, and transmission security. Require the vendor to sign a BAA before deployment, not after.
Fourth, document and train. Write a messaging policy that specifies which channel is approved, which types of information may be transmitted, and what staff should do if they send a message to the wrong recipient. Train every member of the workforce who communicates clinical information. Retain training records.
Fifth, include the platform in ongoing risk management. The Security Rule requires not just a one time risk analysis but ongoing risk management (§ 164.308(a)(1)(ii)(B)). Periodically review whether the platform's security posture has changed, whether the BAA is current, and whether actual use matches policy.
The steps are clear. The execution, which means documenting current state, identifying gaps, selecting and configuring a compliant platform, writing policy, and completing workforce training, takes focused work and carries consequences if done incompletely.
Sources and citations
-
45 CFR Part 164 — HIPAA Security, Privacy, and Breach Notification Rules: ecfr.gov
-
45 CFR § 164.312 — Security Rule technical safeguards: ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
-
45 CFR § 164.522(b) — Patient right to confidential communications by alternative means: ecfr.gov
-
HHS Office for Civil Rights FAQ, "Does the HIPAA Privacy Rule permit health care providers to use e-mail to discuss health issues and treatment with their patients?": hhs.gov/hipaa/for-professionals/faq/570
-
Omnibus Rule (2013), commentary on unencrypted communication with patient consent: 78 Fed. Reg. 5634 (Jan. 25, 2013)
-
CMS Memorandum QSO-24-05-Hospital/CAH, "Texting of Patient Information and Orders for Hospitals and CAHs" (Feb. 8, 2024): cms.gov/files/document/qso-24-05-hospital-cah.pdf
-
HIPAA Security Rule NPRM: 90 Fed. Reg. 898 (Jan. 6, 2025): federalregister.gov/d/2024-30983
-
42 CFR § 418.52(c)(5) — Hospice patient right to confidential clinical record: law.cornell.edu/cfr/text/42/418.52
-
42 CFR Part 484 — Home Health Agencies Conditions of Participation, including clinical record requirements at § 484.110: ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-484
-
42 CFR Part 460 — PACE Programs Conditions of Participation, including IDT coordination requirements at § 460.98: ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-460
-
42 CFR Part 2 — Confidentiality of Substance Use Disorder Patient Records: ecfr.gov/current/title-42/chapter-I/subchapter-A/part-2
-
HIPAA civil monetary penalty tiers, 2025 inflation-adjusted schedule: 45 CFR § 102.3