Healthcare organizations face unique challenges when using SMS for patient and staff communication. HIPAA (Health Insurance Portability and Accountability Act) imposes strict requirements on how Protected Health Information (PHI) is handled — and standard SMS text messaging does not inherently meet those requirements. Understanding what HIPAA says about SMS is essential for any healthcare organization using text messaging.
Is Standard SMS HIPAA Compliant?
Standard SMS text messaging is generally not considered HIPAA compliant for transmitting PHI. The reasons include: SMS messages are not encrypted in transit, messages are stored on carrier servers without access controls, and there is no mechanism to verify that messages were received only by the intended recipient. HIPAA's Security Rule requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI) — safeguards that standard carrier SMS does not provide.
What PHI Cannot Be Sent via Standard SMS
Healthcare organizations should avoid sending any of the following via standard SMS:
- Specific diagnoses, test results, or treatment information
- Prescription details linked to an individual patient
- Mental health, substance abuse, or HIV/AIDS information
- Insurance or billing information connected to specific health conditions
- Any combination of identifiers + health information that would constitute PHI
What Healthcare Organizations CAN Send via SMS
Not all healthcare SMS is subject to the same restrictions. The following types of messages are generally low-risk when properly implemented:
- Appointment reminders that include only the date, time, and provider name (no diagnosis or treatment information)
- General wellness reminders that aren't linked to specific health conditions
- Office notifications about hours, closures, or general practice information
- Staff operational communications that don't include patient PHI
Patient-Initiated Communication Exception
HIPAA recognizes that patients have the right to choose how they receive their own information. If a patient requests to receive their health information via SMS and is informed of the risks of unencrypted communication, the healthcare provider may comply with that request without violating HIPAA. Document the patient's informed consent.
HIPAA-Compliant SMS Solutions
For healthcare organizations that need to send PHI via SMS, encrypted secure messaging platforms that include Business Associate Agreements (BAAs) with the provider are required. These platforms encrypt messages and provide the audit trails and access controls HIPAA demands.
For appointment reminders and operational notifications that don't include PHI, standard SMS platforms like PageGate can be used effectively and appropriately in healthcare settings.
Note: This article provides general information and is not legal or compliance advice. Consult your organization's HIPAA compliance officer or legal counsel for guidance specific to your situation.
