Skip to main content
Compliance

HIPAA-Compliant Texting: Rules, Risks & Best Practices

Learn what HIPAA-compliant texting actually requires, why standard SMS and consumer apps fall short, and how to evaluate a compliant messaging platform.

Text messaging has become one of the fastest and most convenient ways for healthcare professionals to communicate, and that speed is exactly why it creates compliance risk. Most consumer apps are not HIPAA-compliant, and texting through those apps creates risks for your organization.

But that doesn’t mean you have to skip texting entirely.

HIPAA-compliant texting refers to the safeguards, agreements, and processes that let healthcare organizations use text messaging without exposing Protected Health Information (PHI) to unauthorized access. In this guide, you’ll discover:

  • What HIPAA actually requires for text-based communication
  • Why standard SMS and consumer apps create risk
  • The penalties tied to non-compliant texting
  • How to evaluate a platform that meets the HIPAA bar.

We’ll also cover a distinction most vendors skip entirely: patient texting and internal staff communication carry the same PHI exposure, but they call for different safeguards. By the end, you’ll have all the necessary information required to equip your team for safe HIPAA-compliant messaging.

Key takeaways

  • HIPAA-compliant chat depends on who sent the message, what it contains, which service carried it, and what safeguards surround it. It's not entirely dependent on any single feature or app.

  • Standard SMS, iMessage, and consumer chat apps lack the Business Associate Agreements, audit trails, and access controls HIPAA requires, which is why they create compliance risk even for well-intentioned messages.

  • The HIPAA Security Rule organizes requirements into technical, administrative, and physical safeguards, and a compliant texting program needs all three working together.

  • Wire supports HIPAA-eligible internal communication for clinical and administrative teams through always-on end-to-end encryption, admin-blind access controls, and flexible deployment.

What Is HIPAA-Compliant Texting?

HIPAA-compliant texting is a secure messaging method that protects patient medical data during electronic communication. It ensures protected health information PHI remains confidential according to applicable HIPAA Privacy and Security Rule requirements. HIPAA messaging compliance depends on several factors working together:

  • Who sent it: Only covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates are bound by HIPAA. A text from someone outside that relationship can’t violate HIPAA, even if it discusses health information.

  • What it contains: A message with only a name, date, and time carries far less regulatory weight than one referencing a diagnosis, treatment, or payment detail. HIPAA protects PHI specifically, not every mention of a patient.

  • Which service carries it: The platform must be covered by a signed Business Associate Agreement (BAA) and configured with technical safeguards that satisfy the Security Rule.

To be compliant, you need a combination of the platform's technical architecture and your organization's own processes around consent, training, and minimum necessary use. A HIPAA-eligible platform gives an organization the tools it needs to be compliant, but the organization still has to use those tools correctly for any given message to actually meet the bar.

This distinction also plays out differently depending on who's receiving the text. Patient-facing texting (appointment reminders, billing notices, results updates) and internal staff communication (handoffs, care coordination, executive updates) both fall under this framework, but they call for different tools and different safeguards. Let’s understand this in more detail below.

Is Standard Messaging HIPAA-Compliant?

No, most standard messages and consumer apps like iMessage or WhatsApp are not HIPAA-compliant. That’s because they lack end-to-end encryption, do not maintain audit logs, and the app administrator can access and store messages indefinitely.

None of the major consumer platforms offer a signed BAA, which HIPAA requires before PHI can pass through a vendor's service. Without that agreement in place, a covered entity has no contractual assurance that the vendor will safeguard the data, and the Office for Civil Rights (OCR) treats that absence as a foundational violation regardless of how the message itself was worded.

Beyond the missing BAA, consumer messaging carries a few structural gaps:

  • No audit trail: Standard SMS doesn't log who accessed a message, when, or from what device, which makes it difficult to demonstrate compliance during an OCR investigation.

  • Lacks access controls: Anyone who unlocks the phone can read the message thread, with no role-based permissions or authentication layer in front of it.

  • Data retained outside the organization's control: iMessage backs conversations up to iCloud by default, and unless a user disables that setting, PHI sent through the app can sit on Apple's servers indefinitely.

At the same time, saying that HIPAA universally prohibits every SMS message would be inaccurate. HIPAA Journal explains that the requirements for SMS, instant messaging, and email can vary depending on the organization, the healthcare services it provides, and how PHI is communicated. This is why healthcare organizations need to assess the safeguards around each communication channel rather than assuming that every form of texting is either automatically compliant or prohibited.

Wire Pro Tip
Learn what end-to-end encryption actually means for secure team messaging software and how Wire’s secure messaging encrypts every message by default, which is essential for HIPAA compliance.

What HIPAA Requires for Text-Based Communication

HIPAA does not explicitly ban text messaging, but standard SMS text messages and regular apps like iMessage or WhatsApp are not secure enough for patient data. To text safely, HIPAA's Security Rule organizes its requirements into three categories of safeguards.

Technical Safeguards

Technical safeguards govern the technology used to protect electronic protected health information (ePHI) and control access to it. That includes:

    • Encryption for data in transit and at rest, so intercepted messages remain unreadable.

    • Access controls that limit who can open a conversation, typically enforced through unique user credentials and authentication.

    • Audit controls that log activity on systems containing PHI, including message access and any administrative changes.

    • Transmission security measures that guard against unauthorized access while a message moves between sender and recipient.
Also read: Learn more about how encrypted messaging apps work and the technical safeguards they provide here.

Administrative Safeguards

Once you’ve selected a HIPAA-compliant messaging platform, it's also important to train your medical staff to use it in a way that meets the compliance requirements in day-to-day use. This includes conducting a risk assessment specific to text-based communication, writing a documented texting policy that mentions what can and can't be sent, training the workforce on that policy, and securing a signed BAA with any vendor that will handle PHI.

Physical Safeguards

Physical safeguards protect the devices themselves. Relevant controls include mobile device management (MDM) for company-issued phones, restrictions on sending or receiving PHI over public Wi-Fi, and procedures for locking, wiping, or recovering a lost or stolen device before it becomes an exposure point.

Wire Pro Tip

None of these three categories works well on its own. A platform with strong encryption still creates risk if staff isn't trained on what to send, and a well-written policy doesn't help if the underlying app has no access controls to enforce it. Compliant texting requires all three working together.

Learn how Wire helps implement all three security controls

Common HIPAA Texting Violations and Penalties

Some of the most common HIPAA texting violations include:

  • Sending PHI over standard SMS or a consumer app without a BAA in place, even when the intent was harmless, such as confirming a diagnosis with a colleague.

  • Skipping the Business Associate Agreement with a texting vendor, which leaves your organization without contractual protection even if the platform itself is technically secure.

  • Sharing more than the minimum necessary information, like a full diagnosis and treatment history in a message that only needed to confirm an appointment time.

  • Staff using personal devices without safeguards, particularly when a phone lacks a passcode, encryption, or the ability to be remotely wiped if lost.

  • Failing to document patient consent for texting, especially when a patient has requested an alternative communication method under their HIPAA privacy rights.

Each of these can trigger a violation independent of whether any harm actually occurred, and here’s what you’d be expected to pay as a fine if you face a violation, based on how much your organization knew and how you responded:

Penalty Tier

Level of Culpability

Min. Penalty per Violation

Max. Penalty per Violation

Annual Penalty Limit

Tier 1

Lack of Knowledge

The entity did not know and, through reasonable diligence, would not have known about the violation.

$141

$35,581

$35,581

Tier 2

Reasonable Cause

The violation resulted from reasonable cause and did not involve willful neglect.

$1,424

$71,162

$142,355

Tier 3

The violation involved willful neglect and was corrected within the applicable 30-day period.

$14,232

$71,162

$355,808

Tier 4

The violation involved willful neglect and was not corrected within the applicable 30-day period.

$71,162

$2,134,831

$2,134,831

Penalties correct as of December 6, 2025. Confirm current figures directly with U.S. Department of Health and Human Services (HHS) before using them in an internal risk assessment.

Beyond the civil penalties, OCR can also refer cases involving deliberate misuse of PHI for criminal investigation, and state Attorneys General have independent authority to pursue additional fines, particularly in states with their own opt-in requirements for patient texting.

Did you know?
In October 2018, health insurer Anthem Inc. paid a $16 million settlement to the HHS to resolve violations tied to a massive 2015 cyberattack that exposed 78.8 million personal and medical records, making it the largest HIPAA penalty in history. Learn more about how you can manage security and compliance risk with a secure enterprise collaboration platform like Wire.

Key Features of HIPAA-Compliant Texting Software

A HIPAA-compliant messaging platform must ensure that PHI can’t be accessed, altered, or exposed at any point, from the moment it is sent, through transmission and storage, to its eventual retrieval by an authorized user. Here are some specific features that help achieve this.

Strong End-to-End Encryption

Start by understanding what the vendor means when it says messages are "encrypted” because different encryption models protect data at different points in the communication.

  • Transport encryption protects data while it moves between a user's device and the provider's servers, typically using protocols such as TLS. The provider may still be able to decrypt and process the content on its infrastructure.

  • Encryption at rest protects messages and other data while they are stored on servers or devices. It reduces the risk of someone obtaining readable information directly from storage, but it does not by itself determine who can access content while the service is running.

  • End-to-end encryption (E2EE) encrypts content on the sender's device and decrypts it only on authorized recipients' devices. The provider does not hold the keys needed to read the conversation.

E2EE provides the strongest protection for sensitive healthcare communication because PHI remains encrypted throughout its journey and even the service provider can’t access the decrypted content. It also reduces the number of systems and privileged parties that healthcare organizations need to include within the trust boundary.

Wire Pro Tip

Even if a platform offers encryption, take time to understand what kind of encryption it is. For instance, Microsoft Teams’ optional E2EE lacks full coverage and uses outdated protocols, making it risky for compliance-driven and security-first sectors.

Identity and Access Controls

Access controls determine who can open a conversation and what they can do once inside it. Strong implementations include multi-factor authentication (MFA), role-based access that limits visibility based on job function, device verification that confirms a login is coming from a trusted device, and secure provisioning and revocation so access can be granted or removed the moment someone joins or leaves the organization.

Auditability and Administrative Controls

Audit trails give administrators and OCR investigators a record of who accessed what, when, and from where. This is important in case of an investigation and is nonetheless a requirement for a HIPAA-compliant messaging app. An enterprise messaging platform should log message activity, security events like failed login attempts, and any changes to user permissions, and should make that history exportable for review during a risk assessment.

Message and device protection

We mentioned earlier how HIPAA-compliant text messaging requires physical safeguards that protect the devices themselves because healthcare communication increasingly happens across phones, laptops, tablets, and remote environments. The secure team messaging software should give IT teams a clear way to manage access when one of those endpoints can no longer be trusted.

For example, if a clinician loses a smartphone containing access to clinical conversations, the security team should have a defined process for removing that device's trust and preventing continued access without waiting for every individual conversation owner to respond.

Also read: Discover practical steps to establish secure internal communication, govern access, and build a resilient communication environment across teams and devices.

BAA and Vendor Security Practices

A signed BAA between the vendor and your healthcare organization is non-negotiable for HIPAA-compliant texting for medical professionals. The agreement should specify exactly how the vendor handles PHI internally, including whether its own employees or systems can access message content, how long data is retained, and what happens to that data if the contract ends.

Even if a vendor claims they can’t see your messages (which is only possible through E2EE), a BAA is still legally required if data passes through their systems.

Flexible Deployment Options

The right deployment model depends on your healthcare organization’s infrastructure, security requirements, and broader risk management strategy. Some organizations prefer a managed cloud deployment for easier maintenance and scalability, while others require private cloud or on-premises infrastructure for greater control over where sensitive communication data is hosted.

Deployment choice itself does not determine HIPAA compliance. However, having the flexibility to choose where your communication platform runs can help align it with your organization’s security policies.

Wire supports cloud, private cloud, and on-premises deployments, allowing healthcare organizations to select the model that fits their security and infrastructure requirements.

Patient Texting vs. Internal Care Team Communication: Two Different Risk Profiles

Text messaging in healthcare generally covers two types of communication, and each has different security and operational requirements.

Patient-facing texting covers outbound communication like appointment reminders, billing notices, prescription refill alerts, and results notifications. This category has its own specific requirements for HIPAA:

  • Documented patient consent: Compliance requires written authorization before texting a patient PHI, and that consent has to be tracked and revocable.

  • Opt-in and opt-out workflows: This respects a patient's stated communication preferences.

  • EHR or practice management integration: Helps messages stay tied to the right patient record instead of creating a parallel, unmanaged data source.

  • Carrier-based SMS delivery: In many cases, patients expect to receive texts on their native messaging app rather than downloading a separate one.

On the other hand, internal enterprise communication covers a different set of conversations. For example, a nurse handing off a patient at shift change, a care team coordinating treatment across departments, compliance and legal discussing a sensitive matter, or leadership communicating during an incident. These conversations carry the same PHI exposure as patient texting, but the risk profile looks different:

  • Always-on encryption: Matters more here because staff communication happens constantly and informally. This applies to text, calls, HIPAA-compliant live chat, and even video conferencing.

  • Deployment flexibility: Crucial for organizations with strict data-residency requirements, or for organizations that want an internal communication channel that stays reachable even if their primary infrastructure is compromised during an incident.

  • Shadow IT risk: A major risk here because clinical staff default to whatever app is already on their phone when the sanctioned tool feels slow, and that default is usually a consumer app with none of the safeguards above.

Most healthcare organizations need both categories covered to ensure true HIPAA compliance.

If you’re looking for a secure internal team communication platform, get in touch with our team to see how Wire can help you meet HIPAA communication compliance.

Best Practices for HIPAA-Compliant Text Messaging

Some of the best practices for HIPAA-compliant messaging (even when using a secure collaboration platform) include limiting PHI to the minimum, training staff to reduce shadow IT, and building an out-of-band incident communication plan in case the primary platform goes down.

  • Limit the information your team shares: Only include the patient information needed for the conversation. For example, if a clinician only needs a room number and procedure update to coordinate a handoff, ask your team not to add unrelated medical history or other patient details.

  • Use Zero Trust and role-based access: Follow a Zero Trust model, where no user, device, or account is automatically trusted simply because it is already inside the organization’s network. Verify and limit access based on what each person needs for their role. Without role-based controls, employees can retain access to sensitive conversations and PHI they don’t need. Former employees whose accounts or devices remain active create another serious access risk because compromised or misused credentials can give attackers a direct route into company systems.

  • Train staff on real communication scenarios: Training should cover approved tools, PHI handling, lost devices, suspicious access, accidental disclosures, and shadow IT for HIPAA-compliant chat.

  • Prepare an out-of-band communication channel. Have a secure communication channel ready before a cyberattack or outage happens. Your security, compliance, clinical operations, legal, and leadership teams should still be able to coordinate if email or your primary collaboration platform is unavailable or compromised. Learn more about how you can build an effective business continuity plan in case that happens.
Wire Pro Tip
Following these best practices can also strengthen your healthcare organization’s cyber resilience. Strong access controls, secure communication, regular employee training, and proper account management can reduce opportunities for cyberattacks, while an out-of-band communication channel helps your teams respond and recover if an attack succeeds.

How to Choose a HIPAA-Compliant Texting Solution

To choose HIPAA-compliant texting software, look for BAA availability & compliance, ask what encryption it offers, consider access control & admin visibility, and make sure the platform is easy for your team to use.

  • BAA availability and compliance: Confirm the vendor offers a BAA by default and read the agreement closely. Ask specifically how the vendor documents its own compliance posture and whether it can produce audit records if your organization needs them for an OCR investigation or internal review.
  • Access control and admin visibility: Look for role-based permissions, multi-factor authentication, and clear documentation of what administrators can and can't see. This overlaps with encryption architecture but deserves separate attention, since a platform can offer strong encryption in transit while still giving broad content access to anyone holding admin credentials.
  • Deployment flexibility: Confirm whether the platform supports cloud, private cloud, or on-premises deployment, and think through which option fits your organization's data-residency requirements and existing infrastructure.

  • Fit for use case: Match the platform to the problem you're actually solving. A software built around patient engagement and appointment reminders is unlikely to be the right fit for secure internal, staff-to-staff clinical communication, and the reverse is true too. Most healthcare organizations need both, which usually means evaluating two categories of vendors rather than looking for one platform to cover everything.

  • Usability and adoption: Finally, even the most secure HIPAA-compliant messaging platform available doesn't help if clinicians route around it. Consider how quickly staff can send a message during a busy shift, how intuitive the interface is, and whether the HIPAA-compliant messaging software offers a desktop and mobile app for easy communication.

Read on to see how Wire provides secure text messaging for healthcare professionals.

How Wire Supports Secure Healthcare Communication

Wire is a secure internal communication and collaboration platform for organizations that need strong controls around sensitive information. For healthcare organizations, Wire can support HIPAA-compliant internal, staff-to-staff clinical and administrative communication under an appropriate BAA.

Here’s how:

  • Always-on E2EE protects every conversation by default, across messaging, calling, video, and file sharing, built on Messaging Layer Security (MLS), the IETF-standard protocol. Encryption applies automatically to every conversation, rather than depending on a busy care team remembering to turn on a setting.

  • Even Wire's own administrators can’t access message content, ensuring the conversation is only seen by people it is meant for.

  • ID Shield verifies staff devices through the organization's existing identity provider, letting administrators certify, renew, or revoke trusted devices without relying on manual processes.

  • SSO and SCIM: Wire integrates with enterprise identity systems through Single Sign-On (SSO) and System for Cross-domain Identity Management (SCIM). Healthcare IT teams can centrally manage user access and automate provisioning and deprovisioning as employees join, leave, or change roles. This helps prevent old accounts or unnecessary permissions from leaving PHI accessible to people who no longer need it.

  • Flexible deployment across cloud, private cloud, on-premises, and air-gapped environments lets you keep this communication layer aligned with your own data-residency and infrastructure requirements.

  • Secure file sharing through Wire Drive keeps attachments, images, and documents inside the same end-to-end encrypted environment as the conversation itself, rather than routing them through a separate, less secure tool.

1,800+ organizations, including health systems and other regulated enterprises, already rely on Wire for secure, sovereign internal communication.

Request a demo to see how Wire can support your organization's internal clinical and administrative communication strategy too.

Frequently Asked Questions

What is PHI?

PHI in healthcare stands for Protected Health Information, which is any data about a patient's medical history, health condition, treatment, or payment that can be linked to a specific individual. It is legally defined and protected under the Health Insurance Portability and Accountability Act (HIPAA) in the United States.

Is iMessage HIPAA-compliant?

iMessage is not HIPAA-compliant and should not be used to communicate PHI because iMessage's default iCloud backup can store PHI on Apple's servers, which is outside an organization's control.

Is SMS HIPAA-compliant?

Standard SMS is not HIPAA-compliant by default because carriers don't sign BAAs, messages aren't encrypted end-to-end, and the network has no audit trail or access-control layer.

Is Telegram HIPAA-compliant?

Telegram is not HIPAA-compliant for healthcare communication. Its default chats aren't end-to-end encrypted (only the optional "Secret Chat" feature offers that), it doesn't offer a BAA, and it lacks the administrative controls, audit logging, and access management that regulated healthcare communication requires.

Is WhatsApp HIPAA-compliant?

WhatsApp is not HIPAA-compliant for healthcare use. It offers end-to-end encryption for some messages, but Meta does not sign Business Associate Agreements, and the platform lacks the audit trails, role-based access controls, and administrative oversight that HIPAA requires.

Is email HIPAA-compliant?

Standard email is not automatically HIPAA-compliant, but it can be made compliant with the right safeguards in place. That typically means encryption in transit and at rest, a signed BAA with the email provider, access controls, and audit logging. Many healthcare organizations use dedicated HIPAA-compliant email services to meet these requirements before sending PHI by email.

What is secure messaging in healthcare?

Secure messaging in healthcare refers to communication platforms built with the encryption, access controls, audit trails, and Business Associate Agreements needed to transmit Protected Health Information safely. It covers both patient-facing texting for appointments and results, and internal staff communication for care coordination, and the safeguards required differ somewhat between the two use cases.

Can healthcare staff text each other about patients?

Yes, but only through a platform that meets HIPAA's technical, administrative, and physical safeguards, backed by a signed BAA. Staff texting through personal SMS or consumer apps about a specific patient's condition creates HIPAA violation risk, even when the intent is purely clinical coordination.

 

Wire

As a leader in secure communication, we empower businesses and government agencies with expert-driven content that helps protect what matters. Stay ahead with industry trends, compliance updates, and best practices for secure digital exchanges.

Similar posts

See Wire in action 

product_shot_mobile_and_desktop_calling_1200px-min

Discover in a quick call how Wire enables secure, compliant, and seamless collaboration for your organization, without compromising on usability or control.

  • Messaging, calling, conferencing, and file sharing — all in one app.
  • The only full implementation of Messaging Layer Security (MLS).
  • Invisible security that’s easy to use and built for enterprise scale.
  • Government-approved for VS-NfD, GDPR, and NIS2, trusted by 1,800+ customers.