Most owners assume the liability follows the person who sent the text. It doesn't.
Under 45 CFR §160.402, the practice is the covered entity, and violations by workforce members are attributed to it. When a medical assistant at your Elm Street office texts a patient from her own phone, OCR's letter arrives addressed to the group. She made the choice. The group owns the consequence.
Now look at what OCR has actually been penalizing. All seven settlements in its Risk Analysis Initiative cited the same failure — no accurate, thorough assessment of risk under 45 CFR §164.308(a)(1)(ii)(A). Not a hacker. Not a headline breach. A missing document.
That's our claim for this article: for a group practice, the exposure is documentary before it's technical. You're far more likely to be penalized for being unable to describe and produce your patient communication than for anything that happens inside it.
Which is a problem, because right now you can't describe it. Patient texting is running at all five offices on hardware nobody bought. A patient texting compliance policy for a small group gets announced at a Tuesday staff meeting and lasts about nine days.
Practice Fusion locks down the chart. The conversations happening around the chart — the dosage question, the rescheduling, the "is this normal" at 8 pm — sit outside it entirely.
Nobody approved this. It grew because the alternative was slow. A patient calls Riverside asking whether to keep taking an antibiotic.
The medical assistant can't reach the provider by portal message. She texts the answer from her own phone in the parking lot.
Personal phone PHI risk for staff is easy to describe and hard to see. The device isn't managed, isn't wiped, isn't backed up anywhere the practice controls, and it leaves with her.
|
Entity |
Settlement |
Cited failure |
|---|---|---|
|
Michigan surgical group |
$10,000 |
No thorough risk analysis |
|
Guam public hospital |
$25,000 |
Risk analysis; unauthorized employee access |
|
Oklahoma EMS provider |
$90,000 |
No thorough risk analysis |
Seven actions, $872,816 total, October 2024 to April 2025. The $10,000 figure is the one worth sitting with. A surgical group's settlement was small because the group was small, which means size doesn't exempt you from the process — it just changes the number on the check.
Penalty tiers reset every January. As of January 28, 2026, a single violation runs from $145 at the lowest tier to $73,011 at willful neglect, with the uncorrected tier capping at $2,190,294 a year.
Tiers turn on what you knew and whether you fixed it. A group that can't produce its patient communications can't demonstrate either one.
Curogram works as the compliance backbone by winning the speed argument outright. Templated replies, a shared queue per office, and chart context beat thumb-typing into a personal contact list. Adoption follows on its own, which matters when there's no one on payroll to enforce it.
Role-Based Access & Audit Trails scopes each user to their office and duties, then records everything they do with the thread. A scheduler at Fairground opens Fairground scheduling threads. The billing person sees billing across all five offices and no clinical threads anywhere.
Every send, view, and permission change is written down, which gives you one audit trail of patient texts across offices instead of five phone bills and a guess.
That satisfies the Information Access Management standard at 45 CFR §164.308(a)(4) through the tool rather than a binder. NIST describes the same model in SP 800-66 Rev. 2. Our deeper piece on right-sized access control walks through how the permissions get built.
Ask any BAA texting vendor for three things during evaluation. The signed agreement, the SOC 2 Type II report, and a plain description of how access is scoped.
A serious SOC 2 patient messaging platform hands all three over before the pilot. Consent language and opt-out handling then run from one template at every office, so the smallest office isn't improvising its own version.
100% of patient text communication on governed infrastructure. That sentence is the whole point, and it's currently unavailable to you at any price, because the thing it describes doesn't exist yet.
Staff stops reaching for personal phones when the office channel is quicker, and they keep the speed that made them improvise. No warnings, no signed acknowledgment forms, no quarterly reminder that gets ignored by March.
Breaches affecting fewer than 500 people get reported to HHS within 60 days after the calendar year ends (45 CFR §164.408(c)). Most group practices meet that late-February deadline by hoping there's nothing to report.
A logged channel lets you answer from a filter instead of from memory. Rolling the same setup across every office is covered in our guide to multi-site rollout.
You can't ban convenient communication. You can make the compliant version the fastest thing in the building and let the habit do the enforcement for you.
Your clinical record is Practice Fusion's job. The everyday conversations around it are Curogram's, held to the same standard, with the transcript filed back onto the chart.
One question is worth asking yourself this week. If OCR wanted last quarter's patient communications, could you hand them over? However long you hesitate is the finding.
Book a demo. SOC 2 Type II documentation and BAA terms are ready for review, and reading them doesn't require a security team.