HIPAA and texting patients: what practices need to know

A plain-English overview of texting patients under HIPAA — what counts as PHI, business associate agreements, patient consent, and how to word messages safely.

·7 min read

Practices often hear that HIPAA forbids texting patients. It does not. What it does is set conditions on what you send, who handles it, and what the patient agreed to.

This is a general overview, not legal advice — every practice should run its specific setup past its own compliance counsel. But the shape of the rules is consistent enough to plan around.

What actually counts as protected information

Protected health information is anything that identifies a patient and relates to their health, care, or payment for care. The name and phone number alone can be enough when combined with context that reveals treatment.

This is why the safest reminder text names the practice, the date, and the time, and nothing else. "Your appointment with [Practice] is Tuesday at 2pm" carries far less exposure than a message naming a specific procedure or specialty clinic.

  • Keep diagnoses, procedures, and test results out of SMS
  • Avoid naming specialty practices in a way that reveals a condition
  • Send logistics, and let the patient call for clinical detail
  • Never include account numbers or full dates of birth

Vendors, agreements, and patient consent

Any vendor that transmits or stores patient information on your behalf is a business associate and needs a signed business associate agreement. If a texting platform will not sign one, it is not an option for patient communication.

Separately, document that the patient agreed to be contacted at that number by text, note the discussion in the record, and honor any request to stop or to be contacted another way. Patients are allowed to accept the risks of unencrypted texting once those risks are explained to them.

Marketing is a different standard

Reminders and care-related messages are treatment communications. Promotional messages — a cosmetic service special, a new product line — are marketing, which brings both HIPAA marketing rules and the TCPA consent requirements that govern every business text.

Keep the two streams separate. Mixing a promotion into a clinical reminder muddies the consent basis for both, and it is the kind of detail that looks bad in hindsight.

Key takeaways

  • HIPAA permits texting patients; it constrains content, vendors, and consent.
  • Send logistics only — no diagnoses, procedures, or results by SMS.
  • Your messaging vendor must sign a business associate agreement.
  • Keep clinical reminders and marketing messages in separate streams.

Put this into practice with Text2Sale

Upload your leads, automate fast first-touch texts and follow-ups, stay 10DLC and TCPA compliant, and manage every conversation in one inbox.

Frequently asked questions

Can medical practices text patients under HIPAA?

Yes, provided the practice limits what it sends, uses a vendor that has signed a business associate agreement, documents that the patient agreed to be texted at that number, and honors requests to stop. Practices should confirm their specific setup with their own compliance counsel.

What should you never put in a patient text message?

Diagnoses, test results, procedure names, medication details, account numbers, and anything that reveals a condition by naming a specialty clinic. Reminders should carry practice name, date, time, and location only.

Do patients have to consent to receive texts from a doctor?

Practices should document that the patient provided the number for contact and agreed to text communication, and note that the patient was informed unencrypted texting carries some risk. Marketing texts require separate express written consent under telemarketing rules.

Keep reading