What You Can Text a Patient — and What Needs a Secure Channel
Where the line sits between a text message and a secure channel in a therapy practice: the HIPAA framework, the consent language, and a message-by-message map.
4 notes left
Close-the-day system
Capture
Objective data at point of care
Interpret
One clinical decision
Close
Sign, route, and clear exceptions
A finish line for every clinical day
At a glance
What you’ll leave with
- HIPAA does not prohibit texting patients. HHS guidance permits unencrypted electronic communication with patients when the practice applies reasonable safeguards — and the safeguard that does most of the work is limiting what the message contains.
- The dividing line is logistics versus care: date, time, practice name, and a way to respond can ride in a plain text a patient has agreed to; anything that pairs the patient’s identity with a diagnosis, result, or treatment detail needs a secure channel.
- Patients choose the channel, not the practice. Under 45 CFR 164.522(b) a provider must accommodate reasonable requests to be contacted by alternative means — and may not demand an explanation for the request.
- The TCPA is a separate federal law with its own consent rules for automated texts, enforced by the FCC, with conditions HIPAA never mentions — including message caps and an opt-out in the message body for exempted healthcare texts.
A parent texts the practice number at 7:40 a.m.: “Running late, be there by 8:15 — also, did the feeding eval show anything?” The first half of that message deserves a fast, friendly text back. The second half, answered in kind, would put a child’s name next to an evaluation finding in an unencrypted channel that lives on in two phones, two carrier systems, and whatever cloud backups either phone feeds. Same thread, same thumb, two completely different compliance situations — and the front desk has about thirty seconds to tell them apart.
Most practices resolve this tension in one of two bad ways. Some ban texting entirely and lose the one channel patients reliably answer, bleeding attendance to protect against a risk HIPAA never actually demanded they eliminate. Others drift the opposite direction: texting starts with reminders, and six months later test scores and home-program changes are riding in SMS because nobody ever drew the line. This article draws it — what federal privacy law actually says about texting patients, which messages can ride in a plain text, which need a secure channel, and the consent footing to put under all of it.
The framework
What HIPAA actually says about texting patients
Start with what the law does not say: HIPAA contains no rule against texting patients, and no requirement that every patient-facing message be encrypted. The Department of Health and Human Services (HHS) addresses the question directly in its guidance on emailing patients, and the logic transfers to any unencrypted electronic channel: the Privacy Rule permits providers to communicate electronically with patients, provided they apply reasonable safeguards when doing so. HHS is explicit that unencrypted email is not prohibited for treatment-related communication with a patient — but that other safeguards, like limiting the amount of information in the message and confirming the address before sending, should carry the protective load instead.
The second principle is that the patient, not the practice, picks the channel. HHS says that when a provider is concerned a patient may not understand the risks of an unencrypted channel, the move is to warn the patient and let them decide — and if an unencrypted channel is unacceptable to a patient who asks for confidential communications, the practice should offer and accommodate something more secure, or fall back to mail or phone. That patient right has regulatory teeth: under 45 CFR 164.522(b), a covered health care provider must accommodate reasonable requests to receive communications by alternative means or at alternative locations, may require the request in writing, and may not demand an explanation as a condition of honoring it.
The third principle comes from the Security Rule, and it is where “texting is fine” meets its limit. Electronic protected health information (ePHI) — any health information that identifies a patient, and a first name next to a diagnosis is enough — triggers 45 CFR 164.312(e): technical safeguards against unauthorized access to ePHI transmitted over a network. Encryption there is an “addressable” specification, which does not mean optional; it means your practice must assess whether it is reasonable and appropriate, implement it or an equivalent, and document the decision in its risk analysis. Standard SMS is unencrypted and outside your control once it leaves the phone. A practice can defensibly conclude SMS is acceptable for low-content logistics a patient has agreed to — what it cannot do is skip the analysis and let the channel decide for itself.
Consent
The patient agreed to this channel
Warn about the risk of unencrypted messaging once, let the patient choose, and record the choice. HHS guidance protects the practice that honors an informed preference.
Content
The message carries the minimum the task needs
HHS’s own example for reminders: name, number, and the information needed to confirm — or a request to call back. Nothing clinical rides along.
Channel
Anything clinical moves to a secure channel
Results, diagnoses, and treatment detail belong in an encrypted, access-controlled channel your practice controls — usually the portal or a messaging tool under a BAA.
Those three questions — consent, content, channel — are the entire test. Every row of the map below is just the three applied to one message type.
The centerpiece
The message map: what rides in a plain text
Print this, tape it where the front desk can see it, and the thirty-second decision becomes a lookup. The dividing line running through every row is logistics versus care: a plain text may establish that an appointment exists; it may not say what the appointment is for, how it went, or what comes next clinically.
Plain SMS or secure channel, message by message
Comparison| Message | Plain SMS? | Why |
|---|---|---|
| Appointment reminder: practice name, date, time, a way to confirm or reschedule | Yes, with texting consent on file | HHS treats reminders as part of treatment — no authorization needed. Its own content guidance: name, number, and what is needed to confirm, or a request to call back. |
| Schedule logistics: running late, therapist out sick, rebooking offers, weather closure | Yes | Same footing as a reminder — it confirms logistics and names nothing clinical. Keep it to the practice name and the scheduling fact. |
| A link to your portal or intake forms | Yes, if the link reveals nothing | The text should say “forms are ready” — not which questionnaire, screener, or specialty clinic sits behind the link. The clinical content lives behind the login, not in the message. |
| A balance reminder with no detail: “you have a statement ready, call us or check the portal” | Caution | HIPAA permits payment communication with safeguards, but the FCC’s exemption for automated healthcare texts excludes billing — so automated balance texts need their own consent footing. Keep the amount and the services off the message. |
| Answers to clinical questions, home-program changes, “how did the session go” | No — secure channel | This pairs identity with treatment detail: ePHI in transit, exactly what the Security Rule’s transmission-security standard exists for. Route to the portal or a messaging tool under a BAA, or pick up the phone. |
| Evaluation results, test scores, diagnoses, referral reasons | No — secure channel or a call | The highest-content messages in the practice. Even a patient’s general consent to texting is not a request to receive results by SMS — that takes a specific, informed, documented ask. |
| Photos or video of a patient | No — secure channel, if at all | Media is ePHI with the identity built in, and SMS threads sync to personal cloud backups the practice does not control. If media must move, it moves inside a channel the practice controls. |
The paperwork
Put the consent and the warning in the intake packet
The consent conversation happens once, at intake, or it happens badly in fragments forever. One paragraph in the intake packet does three jobs at the same time: it delivers the risk warning HHS expects, it records the patient’s channel choice, and it sets the scope of what texting will be used for — which is what keeps the channel from drifting into clinical content later. It also collects the one fact the TCPA cares most about: that the patient gave you this number and agreed to receive these messages at it.
Copy-ready
Texting consent language for your intake packet
A starting point for your intake forms — have your counsel review and adapt it to your state and your tools before use.
Text message communication. With your permission, we send text messages for scheduling purposes only: appointment reminders, schedule changes, and requests to confirm or rebook. We will not send clinical information — such as evaluation results, diagnoses, or treatment recommendations — by standard text message.
Please be aware that standard text messages (SMS) are not encrypted. A message could potentially be read by a third party while in transit or on a lost or shared phone. Messages may also be stored by your phone carrier and in your phone’s backups.
You may withdraw this permission, or ask us to use a different contact method (such as phone, mail, or our secure patient portal), at any time and without giving a reason. Reply STOP to any message, or tell any member of our staff.
[ ] I consent to receive scheduling text messages at the mobile number I have provided: ______________________
[ ] I prefer not to receive text messages. Please contact me by: [ ] phone [ ] email [ ] patient portal [ ] mail
Signature: ______________________ Date: ____________
Two details in that language earn their place. “Scheduling purposes only” is the scope limit — it is what makes the later “no” easy when a parent asks for results by text, because the practice is honoring its own stated policy rather than improvising a refusal. And the no-reason-needed withdrawal line is not generosity; it mirrors 45 CFR 164.522(b), which forbids conditioning a confidential-communication accommodation on an explanation.
The other statute
The TCPA is a separate law with its own rules
HIPAA is not the only federal law in the thread. The Telephone Consumer Protection Act (TCPA), enforced by the Federal Communications Commission (FCC), governs automated calls and texts to mobile numbers — which is exactly what a reminder platform sends. Its baseline is prior express consent, and the FCC has long held that a patient who voluntarily provides a mobile number has consented to be contacted at it for purposes closely related to why the number was given. That is the practical reason the intake form above captures the number and the purpose together.
In its July 2015 declaratory ruling (FCC 15-72), the Commission also exempted certain time-sensitive healthcare treatment messages — appointment reminders among them — from the prior-express-consent requirement, but under strict conditions: messages must be free to the recipient, sent only to the number the patient provided, identify the provider, stay concise, offer an opt-out that is honored immediately, and stay within one message per day and three per week per provider. Billing and collection messages are expressly outside the exemption. You do not need to memorize the conditions — you need a texting platform that enforces them and a policy that does not lean on the exemption for anything but genuine treatment logistics.
The alternative
What “secure channel” actually means
“Use a secure channel” is useless advice until you can say what qualifies. Three properties separate a secure channel from a consumer app with an encryption badge. First, encryption in transit — the property SMS lacks. Second, practice control: access that ends when an employee leaves, messages that live behind authentication rather than on a lost phone’s lock screen, and an audit trail of who saw what. Third — the one most often missed — a business associate agreement. Under 45 CFR 164.308(b), a vendor that creates, receives, maintains, or transmits ePHI on your behalf is a business associate, and you need their written assurances before the first message moves. Your reminder platform and your secure-messaging tool are business associates; the phone carrier delivering an SMS is a mere conduit and is not.
That third property is why a consumer messaging app with end-to-end encryption still fails the test. The transmission may be encrypted, but the practice controls nothing: no BAA, no access management, no audit trail, and the thread lives in employees’ personal accounts. For most therapy practices the secure channel is not exotic — it is the patient portal attached to the EHR, or a messaging feature inside a platform that already signs a BAA. The text message then has one honest job: “you have a message waiting in the portal.” The notification travels unencrypted and reveals nothing; the content sits behind a login.
The gray zone
When the patient texts first
Patients do not read your communication policy before texting you a question, and HHS has addressed the equivalent situation for email: when a patient initiates the exchange, the provider can assume that channel is acceptable to them unless they have said otherwise — and if the provider suspects the patient does not grasp the risk, the move is to warn once and let the patient decide. What the patient’s opening text does not do is license the practice to answer anything in kind. The parent who texts “did the feeding eval show anything?” has consented to texting; they have not asked for results by SMS, and they are probably not picturing where that answer will be stored.
The workable reply answers the logistics and moves the clinical: “Happy to go over the eval — I’ve sent the summary to your portal, and we can talk at Thursday’s session or by phone today after 3.” It takes ten seconds, honors the patient’s channel, discloses nothing, and quietly teaches every family where clinical answers live. If a patient then explicitly says “just text it to me, I understand it’s not secure,” that is a confidential-communications preference the practice may honor — warn once, get it in writing, note it in the chart, and still keep the content to what the patient actually asked for.
Implementation
Set it up once, in an afternoon
- 01
Write the one-sentence policy
Decide what texting is for — “scheduling logistics only” is the version that survives contact with a busy front desk — and put it in your policies and the intake packet. The scope line is what makes every later channel decision a lookup instead of a judgment call.
- 02
Add the consent paragraph to intake
Risk warning, scope, opt-out, and the number in the patient’s own hand. Run existing patients through it at their next visit rather than retrofitting all at once.
- 03
Stand up the secure channel before you need it
Confirm the portal or messaging tool has a signed BAA, and build the reflex reply — “sent to your portal, happy to discuss by phone” — into front-desk scripts so the secure route is the easy route.
- 04
Wire opt-outs and preferences into the schedule
A STOP reply must halt automated messages immediately, and a patient’s request for a different channel — or a different number, when a patient asks you not to use the home phone — gets recorded where scheduling actually looks, not in a note nobody reopens.
- 05
Document the decision and train to the map
Record the SMS-for-logistics decision in your security risk analysis, post the message map at the front desk, and make the waiting-room test part of onboarding. The policy that lives only in a binder is the one that drifts.
Is texting patients a HIPAA violation?
Not by itself. HHS guidance permits unencrypted electronic communication with patients when the practice applies reasonable safeguards — limiting what the message contains, confirming the number, and honoring patient preferences. The violation risk comes from the content, not the channel: pairing a patient’s identity with clinical detail in an unencrypted message, or ignoring a patient’s request to be contacted differently.
Do I need a signed authorization to send text appointment reminders?
No. HHS treats appointment reminders as part of treatment, so they do not require a HIPAA authorization. You still want documented texting consent — partly as the risk warning HHS expects for unencrypted channels, and partly because the TCPA, a separate law, governs automated texts to mobile numbers and consent is your clean footing under it.
A patient asked me to text their results. Can I?
You may accommodate it — HHS is explicit that a patient who understands the risk of an unencrypted channel can choose it, and 45 CFR 164.522(b) makes reasonable channel preferences the patient’s call. Warn once, get the request in writing, record it in the chart, and send only what was asked for. Many practices still route results to the portal and text “your results are posted” — which honors the preference for texting without putting the content itself in SMS.
Does my texting or reminder platform need a business associate agreement?
If it creates, receives, maintains, or transmits PHI on your behalf — and a reminder platform holding your patient list and appointment times does — it is a business associate under HIPAA, and you need a written BAA before it handles live data. The phone carrier that delivers the SMS is a conduit and does not need one.
Can I text patients about unpaid balances?
Carefully. HIPAA permits payment-related communication with safeguards, so a minimal “you have a statement ready” text is defensible content-wise. But the FCC’s exemption for automated healthcare texts covers treatment messages, not billing — so automated balance texts need the patient’s own consent to rely on, and the amount, the services, and anything clinical should stay off the message.
Is an encrypted app like iMessage or WhatsApp HIPAA-compliant for patient messaging?
Encryption in transit is one property of a secure channel, not the whole test. Consumer apps give the practice no business associate agreement, no access management, no audit trail, and threads that live in personal accounts beyond the practice’s control. Use a channel the practice controls under a BAA — typically the patient portal or the messaging tool inside your practice platform.
Primary sources
Bibliography / 8- 01FAQ: Does the HIPAA Privacy Rule permit health care providers to use e-mail to discuss health issues with their patients?U.S. Department of Health and Human Services
- 02FAQ: Are appointment reminders allowed under HIPAA without authorization?U.S. Department of Health and Human Services
- 03FAQ: Does the Security Rule allow for sending electronic PHI in an email or over the Internet?U.S. Department of Health and Human Services
- 0445 CFR § 164.522 — Rights to request privacy protection for protected health informationElectronic Code of Federal Regulations
- 0545 CFR § 164.502 — Uses and disclosures of protected health information: general rules (minimum necessary)Electronic Code of Federal Regulations
- 0645 CFR § 164.312 — Technical safeguards (transmission security)Electronic Code of Federal Regulations
- 0745 CFR § 164.308 — Administrative safeguards (business associate contracts)Electronic Code of Federal Regulations
- 08TCPA Omnibus Declaratory Ruling and Order, FCC 15-72 (July 10, 2015)Federal Communications Commission
Written by Callie Editorial
Published October 7, 2026
Educational content, not legal, billing, or patient-specific clinical advice.