Skip to content
All posts

Specialty Clinics

HIPAA Compliant Text Messaging: What Clinics Can Text Patients

7 min read

HIPAA compliant text messaging means texting patients in a way that protects their health information: using a vendor that signs a business associate agreement, applying reasonable safeguards, limiting what goes in the message, and honoring how each patient wants to be contacted. HIPAA does not ban texting patients. It bans careless texting.

This guide is for owners and managers of med spas, hormone and TRT clinics, wellness practices, and other private-pay clinics that want to text leads and patients without creating a privacy problem. You will learn what HHS actually says, what is safe to text, what to keep out of a message, how to choose a texting platform, and where marketing texts fit.

Key takeaways

  • HHS allows providers to communicate electronically with patients if they apply reasonable safeguards, such as limiting the information in unencrypted messages.
  • Appointment reminders are part of treatment and do not need a separate HIPAA authorization.
  • Any texting platform that stores or transmits patient information on your behalf is a business associate and must sign a BAA.
  • Patients can ask to be contacted a different way, and patients who prefer plain texts after being told the risks can generally be accommodated.
  • Marketing texts are a separate question: they need TCPA consent, and some uses of patient information for marketing need HIPAA authorization.

Is texting patients HIPAA compliant?

It can be. HHS guidance on electronic communication says the Privacy Rule allows covered health care providers to communicate electronically with patients, provided they apply reasonable safeguards. HHS adds that the rule does not prohibit unencrypted messages for treatment-related communications, but other safeguards should apply, such as limiting the amount or type of information disclosed. That FAQ is written about email, and the same principles are widely applied to texting.

Two other points from the same guidance matter for texting:

  • A patient can request communication by alternative means, and reasonable requests must be accommodated.
  • If a patient starts the conversation by a channel, the provider can generally assume that channel is acceptable unless the patient says otherwise, and can alert the patient to the risks and let them decide.

What clinics can safely text

Usually fine (with safeguards) Keep out of plain texts
Appointment date, time, location Diagnoses, conditions, lab results
Clinic name and a callback number Medication names and dosages
"Reply to confirm or reschedule" Treatment names that reveal a condition
Links to a secure portal to view details Insurance and payment details tied to care
General office updates (hours, closures) Photos of patients or before and after images
Replies to a patient's own question, kept minimal Anything the patient asked you not to text

Appointment reminders are a good example. HHS says appointment reminders are considered part of treatment and can be made without an authorization. The safe practice is to send date, time, and location, and leave out the reason for the visit. Our guide to text appointment reminders includes a discreet clinic template.

For sensitive services like hormones, weight loss, sexual health, or mental health, assume someone else might see the patient's lock screen. "Your appointment at [Clinic] is Thursday at 3 PM" is fine. "Your testosterone follow-up is Thursday" is not.

When does a texting tool need a BAA?

If a texting platform creates, receives, stores, or transmits protected health information on your behalf, it is a business associate, and HIPAA requires a business associate agreement before you use it for patient communication. That includes most CRMs, texting platforms, and AI assistants that will see patient names tied to appointments or treatments.

Ask every vendor:

  • Will you sign a BAA? (If not, do not use it for patient messages.)
  • Is message data encrypted in transit and at rest?
  • Can we control which staff see which conversations, with unique logins?
  • Are message logs and access logs kept and exportable?
  • Can we set retention and delete data when required?
  • Does it support two-factor authentication?
  • Can we send a secure link to a portal for anything sensitive?

Consumer apps and personal phones fail most of these checks. When staff text patients from their own phones, the messages live on devices the clinic does not control, cannot audit, and cannot wipe when someone leaves.

Secure messaging vs regular SMS

Regular SMS is not encrypted end to end, so treat it like a postcard: fine for logistics, not for clinical detail. A secure messaging setup sends the patient a text with a link, and the details live behind a login in a portal or app.

A practical clinic setup uses both:

  • Plain SMS for reminders, scheduling, and simple replies, with minimal content.
  • Secure links for results, treatment plans, intake forms, and anything clinical.
  • One shared inbox in a HIPAA eligible platform, so conversations are not stuck on personal phones.

Marketing texts are a separate issue

HIPAA and the Telephone Consumer Protection Act are different laws, and marketing texts have to satisfy both:

  • TCPA: promotional texts sent with automated systems need prior express written consent. See our SMS opt-in guide for language.
  • HIPAA: using patient information to market third-party products, or receiving payment for marketing communications, generally requires the patient's authorization. Communications about your own services have more room, but the details matter.
  • Carriers: your texting must be registered (see A2P 10DLC registration), and some content is restricted. Major platforms such as Twilio forbid promotional texts for prescription drugs, even from licensed providers, so hormone and weight loss clinics should promote consults and services, not medications. The same logic applies to ads; see our guide to LegitScript certification. Our guide to SHAFT texting rules covers the restricted categories.

Keep promotional texts generic ("New spring openings for consults") rather than targeted by condition ("Since you're on TRT..."), and keep patients who only consented to reminders out of promotional lists.

A HIPAA compliant text messaging checklist for clinics

  1. Move patient texting off personal phones into one platform that signs a BAA.
  2. Turn on unique logins, two-factor authentication, and role-based access.
  3. Write templates for reminders, confirmations, and replies with minimal content.
  4. Use secure links for anything clinical.
  5. Update your notice of privacy practices and intake forms to describe texting.
  6. Capture texting preferences and consent at intake, and record requests for other channels.
  7. Train staff on what never goes in a text, and review a sample of conversations monthly.
  8. Separate reminder consent from marketing consent in the CRM.

We set up texting this way as part of the clinic follow-up and sales systems we build, connected to the EMR and CRM through our platforms and integrations work. For Innovation Health, a multi-location wellness clinic, lead-to-consult held at 40% for a full year. See how we work with specialty and hormone clinics.

This is general information, not legal advice. HIPAA, state privacy laws, and texting rules can all apply; have your compliance advisor review your setup.

Frequently asked questions

Is it a HIPAA violation to text patients?

Not by itself. HHS allows electronic communication with patients if you apply reasonable safeguards, such as limiting the information in unencrypted messages and using vendors that sign a business associate agreement. Texting diagnoses or treatment details in plain SMS, or texting from personal phones, creates risk.

What makes a texting app HIPAA compliant?

The vendor signs a BAA, encrypts data in transit and at rest, supports unique logins and access controls, keeps audit logs, and lets you manage retention. No app makes you compliant on its own; how your team uses it matters too.

Can I send appointment reminders by text under HIPAA?

Yes. HHS considers appointment reminders part of treatment, so they do not require a separate authorization. Keep them to date, time, location, and your clinic name, and leave out the reason for the visit.

What if a patient wants plain text messages?

Patients can request how they are contacted, and HHS guidance indicates that a patient who prefers unencrypted messages after being told of the risks can generally be accommodated. Document the request and still keep sensitive details to a minimum.

Do marketing texts to patients need extra consent?

Yes. Promotional texts need TCPA written consent, and some uses of patient information for marketing need HIPAA authorization. Keep marketing lists separate from reminder-only patients.

If you want patient texting moved off personal phones into a system that is fast, discreet, and connected to your EMR, book a call.

Where is your funnel breaking?

One call. We will find the stage that is holding you back and tell you honestly what we would do about it.