9 min read
HIPAA Texting Governance for athenahealth Networks
Mira Gwehn Revilla
:
September 16, 2026
- Curogram holds SOC 2 Type 2 certification, audited by Thoropass. Every client gets a signed BAA.
- Message history is never deleted, so any site or date range can be exported.
- Permissions are scoped by location, department, and role, and every access is logged.
- Standard SMS carries non-PHI notices only, such as a reminder that asks for a YES reply.
- PHI goes by encrypted message, opened with a secure link and an ID check, with no portal login.
A medical assistant at your Riverside site texts a patient pre-op instructions from her own phone. The portal version of that message would have waited for a login. Her patient was already driving to work, so she used the tool that works.
That text helped the patient. It also put PHI on a device your network doesn't manage and can't search.
Now multiply her by 40 locations. Every site has someone doing the same favor this week, usually more than one.
HIPAA-compliant texting governance for athenahealth enterprise networks starts from a plain claim: a rule loses to a faster channel. Staff aren't skipping policy out of spite. They pick the path that gets a patient answered before the schedule swallows the day.
Money makes the stakes real. IBM's Cost of a Data Breach Report 2026 put the average healthcare breach at $6.64 million. That's the costliest of any sector for a 13th straight year, and US organizations averaged $11.5 million.
Retention adds a second problem. HIPAA asks for six years of compliance documentation under 45 CFR 164.316(b)(2). A thread sitting on someone's iPhone can't be kept, searched, or handed to counsel.
Your compliance officer already suspects this. Ask any regional director which sites text patients from personal numbers, and you get names rather than denials.
Our position: attestation measures the wrong thing. Signature counts prove your staff read a policy. An export of every patient thread proves what they did, and that export is what an investigator asks for.
Shadow Texting
Athenahealth routes patient messages through the Patient Portal. A patient needs an account, a password, and the right care team showing in the messaging drop-down. Springfield Clinic's portal help page tells patients to fill out a provider connection form when their provider isn't listed.
Count the steps between a question and an answer. Form, wait, login, reply.
Your front desk already did that math years ago. Texts get read in minutes. Portal messages get read whenever someone digs up the password, which for a same-day instruction is too late to matter.
The Policy Covers Every Channel But The Busiest One
Your enterprise patient texting compliance policy almost certainly names the portal, email, fax, and the phone system. Personal devices sit outside all of it. Device management can't reach a phone your network doesn't own, and nothing generates a log you could pull later.
Shadow IT healthcare communication rarely starts with a bad actor. It starts with a scheduler who needed one patient to know the office moved to the second floor.
Annual attestation misses every bit of this. Staff sign that they understand the rules, and they do understand them. They also have a patient waiting and a phone in their pocket.
The Volume Nobody Counts
Say each of your 40 sites sends 25 patient texts a week from personal numbers. That works out to 1,000 messages a week and roughly 52,000 a year, none of them logged. Treat those figures as illustrative math, then run your own guess past a site manager and watch the number go up.
Opt-out is the quieter casualty. Athenahealth honors standard SMS opt-out keywords on its side, and your texting platform should behave the same way. A patient who replies STOP to a staff member's personal number has told nobody, so your consent record still shows them as reachable.
TCPA raises the floor further. Informational messages need prior express consent, and marketing messages need it in writing. Neither standard survives a channel with no record of what the patient agreed to.
What Patients Do with a Staff Cell Number
A personal number never goes back in the box. Patients save it, and they use it. Hand out a number in January and you're still fielding that patient's refill questions in August.
Sunday night is the part that should worry you. A patient texts that cell about chest pain, the assistant is at her kid's game, and nobody else can see the message. No queue picks it up. No after-hours line gets triggered.
Clinical risk and compliance risk arrive together here. The same message that never reached a nurse also never reached a log, so you learn about it from a complaint rather than a report.
Small Channels Draw Real Penalties
OCR settled with Manasa Health Center over PHI that turned up in replies to Google reviews. The penalty was $30,000 for a handful of public posts. Regulators don't grade channels on how official they look.
A single pre-op text carries a name, a procedure, and a date. That's more sensitive than most of what ends up in a review reply.
When The Request Lands On Your Desk
Counsel asks for every communication with one patient over the past 18 months. Your team pulls the chart, the claims, and the portal thread by lunch. Then somebody has to decide whether to email 40 site managers and ask them to poll their staff about personal phones.
Turnover makes it worse. The assistant who sent those texts left in March, and her phone went with her. You can't subpoena a former employee's messages app on a deadline.

The Compliance Backbone
Three things decide whether a sanctioned channel gets used at scale. It has to move faster than a personal text. It has to reach patients who will never log in. And it has to sit where the work already happens, next to the schedule and the record.
Two Channels Inside One Thread
Curogram's client agreement draws a hard line on PHI. Standard SMS carries general notices only, like a reminder asking a patient to reply YES to confirm a visit. Anything with a condition, a result, or a medication name goes through encrypted messaging.
Patients get a text pointing to a secure link, verify who they are, and read the message. No portal password. No app to download.
|
Message content |
Correct channel |
|
Visit date and time, reply YES to confirm |
Standard SMS |
|
Lab values, diagnosis, medication name |
Encrypted message, secure link |
|
Prescription is ready for pickup |
Standard SMS |
|
Balance due with a secure payment link |
Standard SMS |
|
Pre-op instructions tied to a named procedure |
Encrypted message, secure link |
Role-Based Access for Clinic Messaging
Role-based access in clinic messaging keeps each person inside their own work. A scheduler at Riverside sees Riverside scheduling threads.
A billing lead covering three sites sees those three sites. Permissions get set centrally, so a regional change doesn't require 40 local admins to agree.
Float staff are where most networks get sloppy. A per diem assistant working two sites should be scoped to both, rather than handed a shared login that hides who sent what.
Offboarding gets easier too. Cutting one login ends message access everywhere, and the threads that person handled stay put.
Audit Trail for Patient Texts Across Multi-Location Networks
Curogram doesn't delete message history, so the record stays whole. Pull threads by patient, by location, or by date range. Six-year documentation duties finally point at something you can retrieve on a Tuesday afternoon.
Reconstructing the same 18 months from 40 sites means emails, phone polls, and screenshots of uneven quality. Some sites answer in a day. A few never answer at all, and your response to counsel says so.
What Security Review Will Ask For
Enterprise security review runs on documents, and the questionnaire lands before any pilot starts. Curogram is SOC 2 Type 2 certified through an outside audit by Thoropass. PHI is encrypted in transit and at rest, and staff complete required HIPAA training.
A SOC 2 patient messaging network still needs the contract behind it. Your BAA with a texting vendor at enterprise scale makes those duties enforceable under HIPAA, which is why review teams ask for both papers in the same packet.
One thing a certification can't tell you is whether your own people will use the tool. Pair the paperwork review with a two-site pilot and watch the message counts.
Bring four questions to that review. Who ran the audit, how long is message retention, who can see which threads, and how fast can one patient's full history be exported.
Speed is a Compliance Control
Most security programs treat speed as a product question and compliance as a policy question. At 40 sites they're the same question. A sanctioned channel that takes four steps manufactures the shadow system your policy then has to chase.
So measure the sanctioned path like a product. Time how long it takes to answer one scheduling question from a site's queue, then time the same reply on a personal phone. If the governed version loses, staff will keep voting with their thumbs, and no amount of training changes the count.
Templates, queues, and record context are what close that gap. They're also what an auditor sees as controls, which is a rare case of the operations win and the compliance win being the same build.
The athenaOne Boundary
athenaText handles provider-to-provider secure messaging inside athenaOne, with a set retention period and documented instructions for pulling message logs. Patient-facing conversation needs its own governed home.
Tie those conversations back to the patient record and the compliant version becomes the clinically complete one.
Compliant Because Convenient
Take the Riverside pre-op text again and send it through the sanctioned channel.
- The assistant opens the patient's thread from the schedule, with record context already loaded.
- Visit confirmation goes out as standard SMS, no PHI attached.
- Pre-op instructions go as an encrypted message. The patient taps a secure link and verifies identity.
- The reply lands in the Riverside queue, so a covering scheduler can answer at 4:45 while the assistant is rooming a patient.
- Every step stays in message history, exportable by patient or by site.
Consent gets captured along the way. The patient's opt-in status, and any later STOP reply, lands in the same record as the conversation.
Nothing in that sequence takes longer than typing a text on a personal phone. Step 4 is quicker, because a queue has more than one pair of hands.
|
What matters |
Personal phone |
Governed channel |
|
Patient reads it |
Minutes |
Minutes |
|
Who can cover the reply |
One person |
Anyone scoped to that site |
|
Where it's stored |
A staff phone |
Message history |
|
Visible with the record |
No |
Yes |
|
Available in an audit export |
No |
Yes |
Curogram Highlight: Role-Based Access And Audit Trails
Role-Based Access & Audit Trails is the piece your security team will care about most. Every user gets scoped to their own locations and departments.
A scheduler in Riverside doesn't see Brentwood's threads, and a regional billing lead sees only the sites she covers. Admins manage all of it centrally, so a new hire at site 37 gets the right view without a ticket to IT.
Message history is never deleted. The audit trail behind a patient conversation stays complete years after the visit, which is what six-year documentation duties assume. When counsel asks for 18 months of communication with one patient, your answer is a filtered export.
Access itself gets logged. You can show who opened a thread, along with who sent each message. That detail matters when a complaint names one staff member.
Central policy templates handle the parts most networks let drift. Consent language, opt-out handling, and after-hours auto-replies stay identical at every site.
Athenahealth already honors standard SMS opt-out keywords. Match that behavior in your texting platform, and patients get one answer instead of two.
For a 40-location group, the practical win is boring and useful. Onboarding site 41 means assigning roles from a template, not writing a local process nobody audits.
Conclusion: Close the Last Gap in the Program
You can't attest your way out of convenient communication. Staff keep choosing whatever answers a patient fastest, and an honest program starts from that fact.
athenaOne protects your clinical record. Everyday conversation with patients deserves the same standard, in a place you control and can search.
Ask your compliance officer one question this week: could we produce every patient communication from last quarter? Act on the pause that follows. Then ask how many of your 40 sites have a staff member texting from a personal number. That count is never zero.
Schedule a demo and bring your security questionnaire. SOC 2 Type 2 paperwork and BAA terms are ready for your review team.
Frequently Asked Questions
By winning on speed. Staff switch when the sanctioned path takes fewer taps than opening their own messages app. Templated replies, location queues, and patient context pulled from the schedule beat typing a name into a personal phone. Adoption drives compliance here, which is why rules alone rarely close the gap across 40 sites.
Portals assume the patient logs in. Athenahealth's Patient Portal needs an account, a password, and the right care team in the messaging drop-down. Patients missing that listing have to request provider access first. For a same-day instruction, each step is a place the message stops moving. Staff notice that long before compliance does.
Access is scoped by location, department, and role. A scheduler at one site sees that site's scheduling threads rather than the whole network. Administrators set it centrally and adjust it as staff move between sites. Every access event is logged, which gives you a real answer when a complaint names one employee.
athenaText is built for provider-to-provider secure messaging inside athenaOne, with its own retention period and documented log requests. Patient-facing conversation runs on different rules: consent standards, opt-out handling, and front desk queues. Those needs call for a channel designed around patients, not around clinicians messaging each other between visits.
Ask for the SOC 2 Type 2 report and the auditor's name. Then the signed BAA, encryption in transit and at rest, and message retention limits. Close with the operational one. Can you export every message for one patient across all sites, and how many minutes does it take?
