1 min read
What is HIPAA-Compliant Two-Way Texting?
💡 EHIPAA-compliant two-way texting is secure, consented messaging between a practice and patients that meets HIPAA's privacy and security rules....
18 min read
Mira Gwehn Revilla
:
July 28, 2026
Ask five practice managers what makes texting HIPAA compliant and you'll hear five answers. The vendor handles it. We only send reminders, so it doesn't apply. We signed a contract, so we're fine. Each answer holds a piece of the truth, which is why the topic stays muddy.
Compliance sits with your clinic. Your vendor carries part of the load. The audit letter still arrives at your address.
And the load is smaller than most owners fear. Eight items, checked once and reviewed each year, cover what a clinic needs to text patients legally. No compliance officer required.
Timing matters this year. HHS put out a proposed Security Rule update on January 6, 2025. It would make encryption and multi-factor login mandatory rather than optional.
As of July 2026, OCR hasn't issued a final rule, and the federal agenda now points toward July 2027. So the current Security Rule stays in force. The checklist below reflects the rules you answer to today, and we flag what shifts if the proposal lands.
We wrote this as an operations document. Each item covers three things: what it is, why HIPAA asks for it, and the question that gets a straight answer out of a vendor. Work through it with your texting platform open in another tab.
Bring the front desk lead, since they'll know which rules already get bent on a busy Monday. Most clinics find two or three gaps. Most of those close with a settings change and one staff huddle.
A business associate agreement (BAA) is a contract between your clinic and any company that handles patient data for you. Your texting vendor qualifies. So does the cloud host storing those threads, which is why the agreement has to reach subcontractors too.
The BAA binds your vendor to the same safeguards you follow. It names what data they may use and what they may never do with it. Breach notice timing goes in there too, along with the deadline for telling you.
A good agreement also states what happens to your data when the contract ends. Most run a few pages and read plainly.
Read the termination clause first. Your message history should come back to you in a usable format. The vendor should destroy their copy on a stated schedule. Clinics discover this clause is missing at the worst possible moment, three days into switching platforms.
Check whether the vendor names its own subcontractors. Text delivery usually runs through a carrier aggregator. HIPAA requires that chain to be covered. A vendor who can't explain their chain hasn't thought about it.
Under the Privacy Rule, you may share protected health information with a business associate only after getting written assurances. Those assurances say the data stays protected. Without a BAA, the vendor has no lawful basis to hold your data at all.
OCR treats the missing paperwork as its own violation, separate from any breach. A clinic can have tight security and never lose a record. It can still be cited because a signed agreement wasn't on file. That's an unforced error, and it's the cheapest item on this list to fix.
Note the direction of liability. A BAA adds a second party who shares responsibility with you. Your own duty stays exactly where it was.
Most BAA texting vendor requirements collapse into four questions. A sales rep should answer all four without checking with legal:
Two patterns show up again and again:
A practice signs with a texting tool during a busy quarter. The BAA gets emailed over and nobody countersigns it. That file then sits in a shared drive, unsigned, for two years. Every message sent in the meantime moved PHI without a lawful basis.
Scope drift is the second pattern. Say you signed a BAA covering appointment reminders. Later the same vendor adds intake forms and payment links. Now they're holding a different category of data. Ask whether your existing agreement covers the new module before you switch it on.
Curogram's client agreement spells out the split directly. The platform provides the secure tools. The clinic agrees to limit access to approved staff and keep PHI out of unsecured channels.
That kind of written division of duties is what you want from any vendor. It tells you which half of the job stays yours.
One more habit worth building. Store every signed BAA in a single folder, with the vendor name and signature date in the filename. During an audit you'll be asked for them together, on short notice.
Count the vendors while you're in there. A five-provider clinic often has six or seven business associates: the EHR, the texting platform, the billing service, the answering service, the shredding company, and the IT contractor with remote access.
Each one needs an agreement. Missing BAAs cluster around the small vendors nobody thinks of as software.
Encryption scrambles data so anyone who intercepts it sees noise. HIPAA cares about two states. Data moving between systems, and data sitting on a server. Both need coverage, and the second one gets forgotten more often.
In transit means the connection between your browser and the vendor's server is protected, usually with TLS. At rest means the stored message database is scrambled on disk. Ask your vendor to state both in writing.
Standard SMS is the gap. Once a message leaves the platform, it travels the carrier network to a patient's phone as plain text. It sits in view on the lock screen. Nothing your vendor does changes that, because the carrier network was never built for health data.
Secure platforms work around it. Patients receive a plain text carrying a link. Sensitive content lives behind that link, on an encrypted page.
Before the page opens, the patient confirms who they are. Only routine wording travels over SMS itself.
Under the current Security Rule, encryption is an addressable specification. You either put it in place, or you document a reasonable alternative and explain why. In practice, most auditors expect encryption and treat the alternative path with suspicion.
The January 2025 proposal would remove that flexibility. Encryption of ePHI would become required at rest and in transit. Multi-factor login would be required for any system holding patient data.
It remains a proposal. The comment period closed in March 2025 and no final rule has been published. If the rule is finalized, it takes effect 60 days after publication. Compliance follows 180 days after that. BAAs get updated within a year.
Practical read for a small clinic: encrypt now anyway. Every vendor worth using already does, so choosing an encrypted platform costs you nothing and removes the paperwork.
This line trips up more clinics than any other item on the checklist. Generic logistics are fine over SMS. Clinical detail attached to a name is not.
|
Safe over plain SMS |
Needs a secure link |
|
"You have an appointment on Jan 25 at 2 PM. Reply YES to confirm." |
"Your cardiology appointment to address your coronary artery disease is Jan 25 at 2 PM." |
|
"Your prescription is ready for pickup at your pharmacy." |
"Your prescription for Lisinopril 10 mg is ready for pickup." |
|
"You have a balance due of $50. Tap to pay: [secure link]" |
"Your bill for your recent diabetes treatment is $200." |
|
"You have a secure message from XYZ Family Practice: [secure link]" |
"Your blood sugar result is 140 mg/dL." |
Examples adapted from Curogram's client PHI acknowledgment, which draws the same line for its own users. Notice the pattern on the right. A full name plus a condition, a drug, or a number turns a routine message into PHI.
Ask three things:
Do you encrypt in transit and at rest, and will you say so in the BAA?
What happens when staff type clinical detail into a plain SMS field, and does anything warn them?
Can we send a secure link from the same thread, without the patient downloading an app?
That last question separates real platforms from repackaged marketing tools. If the patient has to install something, adoption dies at the front desk. Older patients call to ask what the link is, and now you're back on the phone.
Ask about attachments too. Photo replies from patients are common in dermatology and wound care. Those images need the same encrypted storage as any other record, and some platforms keep them on a separate system with different rules.
Clinics that solve texting often leave email untouched. The rule is identical. A message reading "your records are ready, click the secure link to verify your identity" is fine. The same message with a chart PDF attached is not.
Set both channels up the same week. Staff who learn one line for texting and a different line for email will mix them up, usually on a busy afternoon when a patient is waiting on the phone.
This question comes up in every compliance review, and the answer is reassuring. If your sensitive content lives behind a verified link, a stolen phone shows an old notification and nothing else. The link expires. Whoever holds the device can't open the record without passing identity verification.
Compare that to a thread where results were typed straight into SMS. Those messages sit on the device until someone deletes them, and you have no way to reach in and remove them. That difference is the entire argument for secure-link delivery, and it's worth walking your providers through once.
Consent is where texting patients HIPAA rules meet a second law entirely. HIPAA covers the privacy of what you send. The TCPA, enforced by the FCC, covers whether you were allowed to send an automated text to that number at all. You need both, and they get documented differently.
For appointment reminders and other treatment messages, the bar is prior express consent.
The patient gave you the mobile number and understood you'd use it to reach them. A patient writing their cell number on an intake form, under a line about text reminders, clears that bar.
Billing reminders and payment links sit in the same treatment-and-payment lane. Marketing is stricter and needs written consent that says so in plain words.
Keep the two lists apart inside your platform. A recall message and a review request belong in different categories.
Verbal consent counts if you record it. A chart note reading "pt verbally OK'd text reminders, 3/14/26, LM at front desk" is a real record.
The capture works like this when it's built into the workflow instead of bolted on:
Step five is the one clinics skip. During an OCR inquiry or a TCPA demand letter, you'll be asked to produce the record within days. Existence and retrievability get treated as the same thing.
Four fields need to travel together:
Store the wording, rather than a bare yes. Two years from now, "the patient agreed" carries far less weight than the sentence they actually read.
Clean consent records pay for themselves in throughput. Based on our internal data in the Curogram Case Studies, clients average above a 75% appointment confirmation rate. Atlas Medical Center cut no-shows from 14.20% to 4.91% within three months of turning on automated reminders.
An opt-out is a compliance event with a clock on it. Treat it as a system function rather than a favor the front desk does when someone complains twice.
The FCC's 2024 consent order named replies that count as a valid opt-out. Stop, quit, end, cancel, unsubscribe, revoke, and opt out all qualify. Any reasonable phrasing that clearly asks you to stop also counts, including a sentence that never uses one of those words.
That's broader than most platforms handle by default. A reply reading "please stop texting me, I've asked twice already" won't match a keyword filter. Someone has to read it and act on it.
Once a valid opt-out arrives, automated calls and texts to that number must stop within 10 business days. Your confirmation text may confirm the opt-out. It may not try to talk the patient out of leaving.
One nuance worth knowing this year. The FCC's broadest provision would make a single opt-out apply to every unrelated message type from the same sender. That piece has been pushed back twice.
A January 6, 2026 order moved the effective date to January 31, 2027 while the agency reviews comments on whether to change the rule. Healthcare messages that don't require prior consent sit in a narrower carve-out. None of that changes your duty to honor a clear stop request today.
Three settings do most of the work:
Add a fourth if your platform supports it. Flag opted-out numbers inside the EHR view your front desk actually uses, rather than only inside the texting tool. Staff work where the schedule lives.
Ask the rep to opt out a test number in front of you. Then send a message from a different module. Reminders, recalls, and payment requests often run on separate rails inside the same product. A suppression that covers one rail is a gap you'll find the hard way.
Then ask where the opt-out log lives and whether you can export it. A patient complaint six months from now gets answered by a timestamp, not by anyone's memory of the call.
-mid.png?width=1080&height=1350&name=HIPAA-Compliant%20Texting%20Checklist%20for%20Small%20Clinics%20(2026)-mid.png)
Shared logins are the most common gap we hear about from small clinics, and the easiest to close. A password taped under the front desk monitor is a HIPAA finding waiting for a reason to surface.
The Security Rule requires a unique user ID for anyone reaching systems that hold patient data. One shared front-desk account breaks that rule outright. The log can no longer say who did anything.
Role-based access follows from there. A biller needs payment threads. A part-time medical assistant probably doesn't need the full message archive for every patient in the practice.
Most platforms ship with two or three roles. Use them, and review the assignments when someone changes jobs internally.
Termination procedures are a written requirement, and they're where small practices drift. A per-diem MA leaves in March. Their login still works in September because nobody owned the offboarding step.
Put it on the same checklist as the badge and the key. One line: disable platform login, same day. Then verify monthly by exporting the active user list and reading the names out loud in a staff meeting. It takes four minutes.
Contractors deserve a second look. Billing services, answering services, and locum providers all get accounts and rarely get removed.
Multi-factor login is addressable under the current rule and required under the January 2025 proposal. Turn it on regardless. A texting inbox holding two years of patient threads deserves the same protection as your email.
Automatic logoff matters more in a clinic than in a back office. Front desk screens face the waiting room. Set the session timeout short enough that a walk-away doesn't expose a thread.
Keep it long enough that staff don't start propping sessions open with a mouse jiggler. Fifteen minutes is a common landing spot.
Ask for a look at the user management screen during the demo. You want individual accounts, assignable roles, an active/inactive toggle, an MFA setting, and a session timeout field. If roles cost extra, price that now, because you'll need them by your second hire.
An audit log records who did what inside the system, and when. HIPAA calls for the capability and for reviewing it. Both halves matter, and clinics usually have the first without the second.
At minimum, the log should hold messages sent and received, the staff account that sent each one, the patient record it attached to, and timestamps.
Add logins and failed login attempts. Add any change to consent or opt-out status. Exports should open in a spreadsheet without special software.
Volume is why usability isn't a luxury here. Covina Arthritic Clinic confirms more than 1,100 appointments a month through automated texting, based on our internal data in the Curogram Case Studies.
A log covering that volume only helps if you can filter it by user, by patient, and by date range in a few clicks.
Four things, and the whole pass takes about 20 minutes:
Ask for a sample export before you sign. You want an anonymized CSV pulled from a demo account. A feature description won't tell you whether the export works. Two things commonly go wrong.
The log exists but can't be exported without a support request. Or the log records sends without recording who opened a thread.
Ask how long logs are kept, too. Six years is the HIPAA documentation standard. A vendor keeping 90 days has made a decision on your behalf that you're the one who answers for.
A written policy is a Security Rule requirement and a practical one. Staff make judgment calls at speed. A two-page document beats a hallway rule that changes depending on who's asking.
Keep the HIPAA text messaging policy clinic staff receive short enough that a new hire reads it on day one. Name the approved platform.
Draw the line between plain SMS and a secure link. Say who may text patients, how consent gets captured, how opt-outs are handled, and who to tell when something goes sideways.
Add one section people will actually reach for: sample wording. Three approved reminder templates, one payment message, one secure-link message. Templates prevent improvisation, and improvisation is where PHI ends up in plain text.
Say it plainly in writing. Patient texting happens on the approved platform, from clinic accounts. No personal phones, and no exception for the on-call rotation.
On-call is where policies bend. A physician texts a patient from a personal cell at 8 PM because it's faster than logging in. That thread now sits outside your audit log, outside your BAA, and inside a device nobody controls. Give on-call staff platform access on their phones so the fast option is also the compliant one.
The same rule covers photos. A wound picture saved to a personal camera roll is PHI on an unmanaged device.
Train at hire and once a year. Keep the sign-in sheet or the completion export, because unrecorded training gets treated as training that didn't happen.
Fifteen minutes covers it for most staff. Walk through the plain-SMS line, the consent step, the opt-out step, and who to call. Run a short refresher after any real incident, including a near miss.
Name one person. A practice manager or office lead works fine, and the name belongs on the policy itself. Set a review date each year, note the version, and keep old versions. If a question comes up about a message sent in 2024, you'll want the policy that was in force then.
Read the policy against what staff actually do, rather than against the last version. Four questions do the job:
Rewrite the sections that fail. Leave the rest alone, since a policy that changes every year stops being memorable, and memorable is the whole point of keeping it to two pages.
-inline.png?width=2000&height=1125&name=HIPAA-Compliant%20Texting%20Checklist%20for%20Small%20Clinics%20(2026)-inline.png)
The last item is the one nobody thinks about until they need it. Three decisions, made once, written down where a new manager can find them.
Patient texts belong to the record when they carry clinical content. Retention follows your state's medical record law, which commonly runs six to ten years for adults and longer for minors.
HIPAA separately requires six years of retention for compliance records, including policies, training logs, and BAAs.
Set the platform retention window to match your state rule. Then confirm that "deleted" means deleted on the vendor's side. Some platforms hide messages from your view while keeping them in a backup for years.
Watch the other direction too. A platform that purges at 12 months by default will delete threads your state requires you to keep, without warning anyone. Check that default setting before your first year is up.
Your clinic does, and the contract should say so. Ask for the export format, the delivery timeline, and whether there's a fee. CSV or JSON with timestamps and patient identifiers is the answer you want.
Clinics that skip this question lose years of documented consent when they switch vendors. You won't notice the loss until a TCPA letter arrives asking about a message sent two years ago.
Under the Breach Notification Rule, you notify affected patients without unreasonable delay, and no later than 60 days after discovery.
Breaches affecting 500 or more people also require notice to HHS and to prominent media in the state, inside that same window. Smaller breaches get logged and reported to HHS once a year.
Write the plan on one page before you need it:
During a real incident, staff follow the page in front of them. Nobody reads a manual at 4 PM on the day a laptop goes missing.
Put all three in a single document with an owner and a review date:
|
Decision |
What to write down |
Review |
|
Retention window |
State rule, platform setting, backup behavior |
Yearly |
|
Data ownership |
Export format, timeline, fee, who requests it |
At renewal |
|
Breach response |
Four named roles, notice templates, HHS portal link |
Yearly |
Keep it with the BAAs. During an audit, a reviewer asks for all of it in the same conversation.
Assign the review to a real date, not a season. "First Monday in March" survives staff turnover. "Annually" does not, and a decision nobody revisits turns into a setting nobody remembers choosing.
Every item above maps to a failure we've watched play out in small practices. These five account for most of them, and none of the fixes takes more than a week.
|
What happens |
Why it's a problem |
The fix |
|
Staff text patients from personal cell phones |
No BAA, no audit log, no way to retrieve the thread |
Give staff platform access on mobile; state the rule in the policy |
|
Test results or diagnoses sent over plain SMS |
Unencrypted PHI on a carrier network and a lock screen |
Send a secure link; lock templates so free text can't carry results |
|
No consent record for the number being texted |
TCPA exposure with nothing to produce on request |
Capture consent at intake with a timestamp and store the wording |
|
Shared front desk login |
The audit log can't attribute anything to a person |
One account per staff member, roles assigned, monthly user review |
|
A patient texts PHI first and staff reply in kind |
The reply creates the exposure, even when the patient started it |
Train the pivot: acknowledge, move to a secure link, note the chart |
Every platform in this category claims to meet HIPAA texting requirements for clinics. A grid makes them prove it.
Use the same eight rows for every product you look at. Fill it in during the demo, while the rep is still on the call and can answer.
|
Checklist item |
What to ask for |
Curogram |
|
Signed BAA |
Signed before onboarding, no fee, subcontractors named |
Yes, plus a written client PHI agreement |
|
Encryption |
In transit and at rest, stated in the BAA |
Yes, with secure-link delivery for PHI |
|
Consent capture |
Timestamped, tied to the number, stored wording |
Yes, through digital intake forms |
|
Opt-out handling |
Auto-suppress across all message types, exportable log |
Yes |
|
Unique logins |
Individual accounts, roles, MFA, session timeout |
Yes |
|
Audit logs |
Exportable CSV, filterable, retention stated |
Yes |
|
Policy support |
Template library, locked templates |
Yes |
|
Data ownership |
Export format, timeline, cost on exit |
Yes, defined in the client agreement |
Score honestly. A platform failing two rows still deserves a look if the gaps are cheap to close. A platform passing all eight can still be wrong for a four-provider clinic on price alone.
Small clinics get held to the same texting rules as health systems with a full compliance department. That's the unfair part. It's also why an eight-item list beats a 40-page manual nobody opens.
Start with the two items carrying the most risk for the least effort. Confirm the BAA is countersigned and on file. Then find out whether anyone on staff has texted a patient from a personal phone this month.
Those two conversations surface most of what's wrong. Work the rest over a few weeks. Consent capture and opt-out handling usually need a settings change.
Logins and audit review need a habit. The policy needs one afternoon and a template.
None of this is meant to slow down texting. Practices with the foundation in place end up texting more, because staff stop hesitating over what's allowed. Confirmation rates climb and the schedule holds.
If you'd like to see the eight items inside a working platform, book a demo with our team. We'll pull up the audit log, the consent record, and the secure-link flow on a live account.
Reminders run on prior express consent, usually the number given at intake. Marketing needs separate written consent naming that purpose. Keep both lists apart in your platform so a review request never rides on reminder consent.
Neither vendor signs a BAA for standard consumer accounts, which ends the analysis. Both also lack per-user audit logs, role controls, and opt-out suppression. Threads live on personal devices you can't wipe or export.
Reply without repeating any clinical detail. Acknowledge the message, send a secure link, and continue there. Note the exchange in the chart. The patient broke no rule; a matching reply from your account creates the exposure.
Pull the record showing the number, capture date, method, and the exact wording the patient saw. Store it inside the platform rather than a paper file. Anything requiring a vendor support ticket won't arrive fast enough.
Once a year, on your go-live anniversary, plus any time you add a module, change EHRs, or open a location. Each of those events can move data outside what your current BAA and retention settings cover.
1 min read
💡 EHIPAA-compliant two-way texting is secure, consented messaging between a practice and patients that meets HIPAA's privacy and security rules....
💡 Physician groups replace phone calls by moving scheduling, reminders, confirmations, intake, and billing follow-up onto secure two-way texting...
💡 Medical SMS messages are text messages sent between a healthcare practice and its patients through a secure, HIPAA-compliant platform. They are...