SMS / Text Messages
Unencrypted, stored on carrier servers, no access controls, no audit trail. Interceptable and subpoena-eligible.
Used by 73% of healthcare staff for patient communication (Spok, 2023).
HIPAA compliant messaging
If your staff texts patients from personal phones, your practice has an open HIPAA violation right now. SMS, iMessage, and WhatsApp are not compliant — and the penalties compound with every message sent.
The problem
Unencrypted, stored on carrier servers, no access controls, no audit trail. Interceptable and subpoena-eligible.
Used by 73% of healthcare staff for patient communication (Spok, 2023).
End-to-end encryption exists, but no BAA available, no audit logging, no access management, and messages persist on personal devices.
The most commonly reported shadow communication channel in independent practices.
Standard email is unencrypted in transit. Attachments with ePHI sit in Gmail, Yahoo, or Outlook inboxes indefinitely. No retention controls.
Staff routinely forward patient information to personal accounts for 'convenience.'
Facebook Messenger, Instagram DMs, and similar platforms have zero HIPAA controls. No encryption guarantees, no audit trail, no BAA.
More common than practices admit — especially for appointment scheduling and follow-up.
What compliance requires
The Patient Protect solution
All patient communication flows through Patient Protect's encrypted messaging system. No SMS. No personal email. No shadow channels.
Every message is logged with sender, recipient, timestamp, and content hash. Evidence is available when auditors or attorneys arrive.
Eight defined roles control who can send messages, view patient information, and access communication history.
The platform works through the browser — staff do not need to install apps on personal phones or use personal accounts.
Consumer platforms
Consumer messaging apps are the most common source of HIPAA-messaging confusion. All three of the platforms below have been repeatedly asked about by clinicians and practice staff. The answers are unambiguous.
Not HIPAA compliant
Meta does not sign a Business Associate Agreement for WhatsApp on any tier — including WhatsApp Business. End-to-end encryption does not equal HIPAA compliance. Without a BAA, sharing PHI through WhatsApp is a HIPAA violation regardless of encryption.
Common gap: clinicians using WhatsApp for on-call handoffs assume encryption means compliance. It does not.
Not HIPAA compliant
Apple does not sign a BAA for iMessage, and Apple's terms of service do not cover PHI transmission. Even though iMessage uses end-to-end encryption between Apple devices, texting patient data via iMessage is a HIPAA violation. When iMessage falls back to SMS (green bubbles), it is even less compliant — SMS is unencrypted.
Common gap: "just texting" from a work iPhone to a patient's iPhone. The convenience is why the violation happens.
Not HIPAA compliant
Meta does not sign a BAA for Facebook Messenger. Messages are stored on Meta infrastructure and used for advertising and machine-learning purposes covered by Meta's consumer terms. PHI in Facebook Messenger is a violation and often triggers OCR investigation when discovered.
Common gap: practice social media accounts responding to patient DMs with any clinical context.
The rule is consistent across all consumer messaging platforms: no BAA, no PHI.Encryption, security features, and marketing claims do not substitute for the contractual relationship HIPAA requires. Even Signal — often considered the gold standard for private messaging — is not HIPAA-eligible because Signal does not sign BAAs.
Common scenarios
Real-world texting questions get asked faster than policies can anticipate them. Here are direct answers to the scenarios that come up most often.
Yes, if it is over unencrypted SMS or a non-BAA-covered app. A patient's name plus the fact that they are receiving care from your practice is PHI. Over a compliant messaging platform with the practice's BAA in place, it is not a violation.
Yes, over standard SMS or consumer messaging apps. Any protected health information transmitted through a channel without encryption, access controls, and a BAA is a HIPAA violation regardless of the specific content.
Not on standard SMS or consumer apps. Staff-to-staff messaging about patients is subject to the same requirements as patient communication. Use a HIPAA-compliant secure messaging platform or an approved workplace platform (Microsoft Teams with a signed BAA, for example) — not personal iMessage or WhatsApp threads.
Generic reminders (date, time, "please call to confirm") are generally acceptable under treatment operations. Clinical detail in the reminder ("your dermatology follow-up") converts it into PHI transmission and requires a BAA-covered channel.
Patient-initiated communication does not waive the practice's obligation to use a compliant channel. Best practice: acknowledge briefly with no PHI, then move the conversation to a HIPAA-compliant patient portal or secure messaging platform.
Only over a HIPAA-compliant channel. Provider-to-provider messaging (clinician to pharmacist, PCP to specialist) is subject to the same rules. Even minimal information — "patient Mrs. Smith needs a refill" — is PHI in transit.
Retention
Messaging retention is one of the most-overlooked HIPAA requirements. Practices focus on transmission security and never think about how long the message needs to exist afterward.
HIPAA requires six years of retention for documentation of compliance activities. Patient communications that are part of the medical record or that reflect a decision affecting care are subject to state medical-records retention requirements, which typically range from 6 to 10 years for adults and until age 21+ for minors.
If a text is documentation of a clinical decision, it is part of the designated record set and must be retained under the same policy as clinical records.
Consumer messaging apps do not support HIPAA-compliant retention. Messages sync across the user's devices, live in the Meta/Apple/Google backup cloud, and delete based on user action — not on retention policy. Even if the app were HIPAA-eligible (which none of the consumer apps are), the retention model would not comply.
HIPAA-compliant secure messaging platforms (including Patient Protect Secure Messaging, Klara, Spruce, and enterprise Slack Grid) provide configurable retention policies, audit trails, and export tools. Practices set the retention window according to their state's medical-records retention law.
FAQ
Yes, if the text contains protected health information (PHI) and is sent via standard SMS, iMessage, WhatsApp, or other non-compliant channels. HIPAA requires encryption, access controls, and audit logging for all electronic communication containing ePHI.
No. WhatsApp does not offer a Business Associate Agreement (BAA), does not provide audit logging, and does not meet HIPAA access control requirements. Even though it offers end-to-end encryption, it is not HIPAA compliant.
HIPAA compliant messaging requires: end-to-end encryption, unique user authentication, role-based access controls, audit logging, message retention controls, automatic session timeout, and a signed BAA with the messaging platform.
Next step
If the answer involves personal phones, standard email, or messaging apps — you have an open violation. The risk assessment shows you exactly where.