Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA compliant messaging

Texting patients is one of the most common HIPAA violations.

If your staff texts patients from personal phones, your practice has an open HIPAA violation right now. SMS, iMessage, and WhatsApp are not compliant — and the penalties compound with every message sent.

The problem

Every non-compliant message is a separate potential violation.

SMS / Text Messages

Unencrypted, stored on carrier servers, no access controls, no audit trail. Interceptable and subpoena-eligible.

Used by 73% of healthcare staff for patient communication (Spok, 2023).

iMessage / WhatsApp

End-to-end encryption exists, but no BAA available, no audit logging, no access management, and messages persist on personal devices.

The most commonly reported shadow communication channel in independent practices.

Personal Email

Standard email is unencrypted in transit. Attachments with ePHI sit in Gmail, Yahoo, or Outlook inboxes indefinitely. No retention controls.

Staff routinely forward patient information to personal accounts for 'convenience.'

Social Media DMs

Facebook Messenger, Instagram DMs, and similar platforms have zero HIPAA controls. No encryption guarantees, no audit trail, no BAA.

More common than practices admit — especially for appointment scheduling and follow-up.

What compliance requires

HIPAA compliant messaging is a regulatory requirement. Here is what it takes.

  • End-to-end encryption for all messages containing ePHI
  • Access controls — only authorized users can send and receive
  • Audit logging — who sent what, when, and to whom
  • Message retention and disposal policies
  • Business Associate Agreement with the messaging platform
  • Unique user identification — no shared accounts
  • Automatic session timeout and device management
  • Breach notification capability if a message is compromised

The Patient Protect solution

Replace personal phone communication with compliant, auditable workflows.

Encrypted secure messaging

All patient communication flows through Patient Protect's encrypted messaging system. No SMS. No personal email. No shadow channels.

Audit-ready by default

Every message is logged with sender, recipient, timestamp, and content hash. Evidence is available when auditors or attorneys arrive.

Role-based access

Eight defined roles control who can send messages, view patient information, and access communication history.

No personal devices required

The platform works through the browser — staff do not need to install apps on personal phones or use personal accounts.

Consumer platforms

Is WhatsApp, iMessage, or Facebook Messenger HIPAA compliant?

Consumer messaging apps are the most common source of HIPAA-messaging confusion. All three of the platforms below have been repeatedly asked about by clinicians and practice staff. The answers are unambiguous.

WhatsApp

Not HIPAA compliant

Meta does not sign a Business Associate Agreement for WhatsApp on any tier — including WhatsApp Business. End-to-end encryption does not equal HIPAA compliance. Without a BAA, sharing PHI through WhatsApp is a HIPAA violation regardless of encryption.

Common gap: clinicians using WhatsApp for on-call handoffs assume encryption means compliance. It does not.

Apple iMessage

Not HIPAA compliant

Apple does not sign a BAA for iMessage, and Apple's terms of service do not cover PHI transmission. Even though iMessage uses end-to-end encryption between Apple devices, texting patient data via iMessage is a HIPAA violation. When iMessage falls back to SMS (green bubbles), it is even less compliant — SMS is unencrypted.

Common gap: "just texting" from a work iPhone to a patient's iPhone. The convenience is why the violation happens.

Facebook Messenger

Not HIPAA compliant

Meta does not sign a BAA for Facebook Messenger. Messages are stored on Meta infrastructure and used for advertising and machine-learning purposes covered by Meta's consumer terms. PHI in Facebook Messenger is a violation and often triggers OCR investigation when discovered.

Common gap: practice social media accounts responding to patient DMs with any clinical context.

The rule is consistent across all consumer messaging platforms: no BAA, no PHI.Encryption, security features, and marketing claims do not substitute for the contractual relationship HIPAA requires. Even Signal — often considered the gold standard for private messaging — is not HIPAA-eligible because Signal does not sign BAAs.

Common scenarios

Is texting patients a HIPAA violation?

Real-world texting questions get asked faster than policies can anticipate them. Here are direct answers to the scenarios that come up most often.

  • Is texting a patient's name a HIPAA violation?

    Yes, if it is over unencrypted SMS or a non-BAA-covered app. A patient's name plus the fact that they are receiving care from your practice is PHI. Over a compliant messaging platform with the practice's BAA in place, it is not a violation.

  • Is texting patient information a HIPAA violation?

    Yes, over standard SMS or consumer messaging apps. Any protected health information transmitted through a channel without encryption, access controls, and a BAA is a HIPAA violation regardless of the specific content.

  • Can staff text each other about patients on personal phones?

    Not on standard SMS or consumer apps. Staff-to-staff messaging about patients is subject to the same requirements as patient communication. Use a HIPAA-compliant secure messaging platform or an approved workplace platform (Microsoft Teams with a signed BAA, for example) — not personal iMessage or WhatsApp threads.

  • Does an appointment reminder text violate HIPAA?

    Generic reminders (date, time, "please call to confirm") are generally acceptable under treatment operations. Clinical detail in the reminder ("your dermatology follow-up") converts it into PHI transmission and requires a BAA-covered channel.

  • If the patient texts us first, is it OK to respond?

    Patient-initiated communication does not waive the practice's obligation to use a compliant channel. Best practice: acknowledge briefly with no PHI, then move the conversation to a HIPAA-compliant patient portal or secure messaging platform.

  • Can I text my colleague at the pharmacy about a patient?

    Only over a HIPAA-compliant channel. Provider-to-provider messaging (clinician to pharmacist, PCP to specialist) is subject to the same rules. Even minimal information — "patient Mrs. Smith needs a refill" — is PHI in transit.

Retention

HIPAA message retention: how long must messages be kept?

Messaging retention is one of the most-overlooked HIPAA requirements. Practices focus on transmission security and never think about how long the message needs to exist afterward.

The minimum retention requirement

HIPAA requires six years of retention for documentation of compliance activities. Patient communications that are part of the medical record or that reflect a decision affecting care are subject to state medical-records retention requirements, which typically range from 6 to 10 years for adults and until age 21+ for minors.

If a text is documentation of a clinical decision, it is part of the designated record set and must be retained under the same policy as clinical records.

What retention actually requires

  • Messages stored in a location where they can be produced during an OCR audit or subpoena
  • Audit logs of who sent and received each message, with timestamps
  • Backup and disaster recovery for the message store
  • Ability to search and export messages related to a specific patient (for patient access requests under §164.524)
  • Deletion or anonymization when retention period expires

Retention on consumer messaging apps

Consumer messaging apps do not support HIPAA-compliant retention. Messages sync across the user's devices, live in the Meta/Apple/Google backup cloud, and delete based on user action — not on retention policy. Even if the app were HIPAA-eligible (which none of the consumer apps are), the retention model would not comply.

Retention on compliant platforms

HIPAA-compliant secure messaging platforms (including Patient Protect Secure Messaging, Klara, Spruce, and enterprise Slack Grid) provide configurable retention policies, audit trails, and export tools. Practices set the retention window according to their state's medical-records retention law.

FAQ

Common questions about HIPAA compliant messaging.

Is texting patients a HIPAA violation?

Yes, if the text contains protected health information (PHI) and is sent via standard SMS, iMessage, WhatsApp, or other non-compliant channels. HIPAA requires encryption, access controls, and audit logging for all electronic communication containing ePHI.

Can I use WhatsApp to communicate with patients?

No. WhatsApp does not offer a Business Associate Agreement (BAA), does not provide audit logging, and does not meet HIPAA access control requirements. Even though it offers end-to-end encryption, it is not HIPAA compliant.

What makes messaging HIPAA compliant?

HIPAA compliant messaging requires: end-to-end encryption, unique user authentication, role-based access controls, audit logging, message retention controls, automatic session timeout, and a signed BAA with the messaging platform.

Next step

How is your staff communicating with patients today?

If the answer involves personal phones, standard email, or messaging apps — you have an open violation. The risk assessment shows you exactly where.