HIPAA Security Rule: What Healthcare Practices Must Do About Patient Calls and Texts in 2026

Patient calls and texts can expose electronic protected health information (ePHI) long before it enters an electronic health record. 

A message may name a medication, reveal a diagnosis, attach a lab result, or identify a patient through an appointment reminder.

Thus, healthcare practices must control how clinicians send, receive, store, and review mobile communications. 

That said, personal numbers, standard SMS, shared logins, and unmanaged voicemail can expose patient information to risks outside the practice's approved safeguards.

An HHS update confirms that the current HIPAA Security Rule remains in effect during review of proposed changes. 

The discussion below explains which requirements apply now, what the proposal could change, and how a secure business communication service such as iPlum can put those requirements into daily use.

Table of Contents

1. What did HHS confirm about the HIPAA Security Rule?

2. How does the HIPAA Security Rule apply to patient calls and texts?

3. What must healthcare practices do about patient calls and texts now?

4. How iPlum turns HIPAA call and text policies into daily controls

5. Frequently asked questions

6. Prepare patient communication for 2026 and beyond

What did HHS confirm about the HIPAA Security Rule?

HHS updated its Summary of the HIPAA Security Rule on August 7, 2026. The page states that its summary addresses the rule currently in effect and points readers to the separate Notice of Proposed Rulemaking (NPRM).

Therefore, healthcare practices cannot pause their HIPAA work until HHS issues a final rule. Existing administrative, physical, and technical safeguard requirements apply today.

HHS proposed major changes in December 2024. 

The proposal would require encryption of ePHI at rest and in transit, multi-factor authentication in most cases, annual audits, technology inventories, network maps, and tighter access-termination deadlines.

However, proposed provisions are not final. HHS states that the current Security Rule remains in effect during rulemaking. Practices should separate current duties from preparations for possible obligations.

How does the HIPAA Security Rule apply to patient calls and texts?

The Security Rule applies to ePHI that a regulated entity creates, receives, maintains, or transmits. A text about a prescription, an image of a wound, a voicemail transcription, and a saved call recording can all contain ePHI.

Live speech requires a distinction. 

The Security Rule does not govern PHI maintained or transmitted verbally, although the Privacy Rule still governs call disclosures. Recordings, voicemails, transcriptions, and other electronically stored call data may fall within the Security Rule’s scope.

Call logs, contact names, timestamps, attachments, notification previews, and archived threads can reveal a patient relationship or treatment context. Therefore, an assessment limited to the EHR misses much of the mobile communication environment.

A practice should examine every location where call or text data could appear, such as:

  • Personal smartphones, native SMS, and consumer messaging apps
  • Voicemail, call recording, and transcription systems
  • Desktop or browser portals, cloud backups, and device backups
  • Shared business numbers, forwarding destinations, archives, and attachments


What must healthcare practices do about patient calls and texts now?

HIPAA does not name a required phone brand or messaging app. Even so, safeguards must reflect the practice’s environment and ePHI exposure.

1. Map every communication channel that contains ePHI

Start with an accurate inventory of how patient communication enters and leaves the practice. Record the numbers clinicians use, apps that store messages, voicemail destinations, call forwarding, and backups.

Next, include remote workers, contractors, answering services, and former accounts. An approved app may still forward voicemail to an unmanaged email inbox. A shared password can also make it impossible to attribute user activity.

The current rule requires an accurate and thorough risk analysis. Therefore, the analysis must include mobile communication if calls, texts, recordings, or voicemail contain ePHI. Document identified vulnerabilities, selected safeguards, responsible owners, and review dates.

2. Set rules for ordinary SMS and secure messaging

Standard SMS does not give full command over encryption, recipient devices, backups, screenshots, forwarding, or carrier storage. Consequently, ordinary texting should not serve as the default channel for detailed clinical information.

Define which messages can use standard SMS and which must use an encrypted channel. A limited appointment reminder differs from a test result, a diagnosis, a treatment instruction, an image, or an insurance document.

Patient preference also deserves attention. A request to use text does not erase the practice’s Security Rule duties. Verify the number, explain the method, limit the content, and document the decision.

3. Give every user an individual account

Shared credentials make it difficult to prove who opened a message, changed a setting, downloaded an attachment, or contacted a patient. Accordingly, each authorized user should receive a unique account.

Access should match the user’s role. 

A receptionist may need appointment and routing information but not detailed clinical threads. Administrators should review permissions when duties change and disable access promptly after departure.

The current rule permits only authorized users to reach ePHI and requires identity verification. Unique accounts, secure passwords, device passcodes, session controls, and, where appropriate, multi-factor authentication can meet those requirements.

4. Protect ePHI during transmission and storage

Transmission security requires technical measures that guard ePHI sent through an electronic network. Encryption is an addressable implementation specification under the current rule. However, “addressable” does not mean optional.

A regulated entity must assess whether encryption is reasonable and appropriate. If it is not, the entity must document why and adopt an equivalent alternative when reasonable and appropriate. Patient messages on mobile devices generally warrant encryption.

The proposed rule would make encryption of ePHI at rest and in transit mandatory, subject to limited exceptions. 

Therefore, choosing encrypted communication now can meet the current assessment outcome and reduce the need for remediation later if HHS finalizes a similar requirement.

5. Review messaging and phone vendors

A vendor that creates, receives, maintains, or transmits PHI on behalf of a healthcare practice generally acts as a business associate. Before granting such access, the practice must obtain a compliant Business Associate Agreement (BAA).

The agreement should define permitted uses, safeguards, incident reporting, subcontractor obligations, and PHI disposition after termination. However, a “HIPAA compliant” claim does not replace vendor review or a signed BAA.

Ask how the vendor encrypts communication, assigns accounts, records activity, manages lost devices, archives messages, deletes data, and reports incidents. Also verify which plan activates the HIPAA features.

6. Record and examine system activity

The Security Rule requires mechanisms to record and examine activity in systems that contain or use ePHI. 

For mobile communication, relevant records may include login activity, call and text logs, account changes, message exports, and administrative actions.

Set a review schedule based on the communication assessment. Investigate unfamiliar logins, failed access attempts, forwarding changes, bulk exports, or activity from a former worker's account.

Meanwhile, distinguish audit data from medical record documentation. 

A messaging archive can preserve the communication history, but clinicians should still enter diagnoses, care decisions, medication changes, and follow-up actions in the designated clinical record.

7. Secure smartphones used for patient communication

Personal ownership does not exempt a smartphone from HIPAA safeguards. Bring-your-own-device rules should address approved apps, passcodes, automatic lock, updates, notifications, downloads, backups, public Wi-Fi, loss reporting, and account removal.

Moreover, limit local attachments and message previews where possible. A locked app offers little protection if a full test result appears in a notification or personal photo library.

HHS advised regulated entities in January to secure smartphones and other systems by patching, configuring appropriately, removing unnecessary software, securing account settings, and conducting periodic evaluations.

Remote logout or account deactivation also allows an administrator to respond when a phone goes missing.

8. Establish call and text incident procedures

Communication incidents require a written response process. Examples include a text sent to the wrong number, a lost phone, unauthorized account access, an exposed voicemail transcription, or a recording shared outside its approved purpose.

Define reporting, investigation, mitigation, breach assessment, and documentation duties. Depending on the facts, the Breach Notification Rule may require notices to the affected patient, HHS, and sometimes the media.

Finally, test the process. A policy has little value if workers do not know whom to contact after sending PHI to the wrong recipient.

9. Train workers on real call and text situations

Annual HIPAA training should use real examples, including reminders, test results, caregiver requests, voicemails, shared phones, screenshots, misdirected texts, and lost devices.

Training should explain the difference between ordinary SMS and the approved secure channel. Workers need to know when to verify a recipient, what to leave in voicemail, where to document decisions, and how to report mistakes.

Revisit training after adopting a new phone system, changing a workflow, or finding a recurring problem during log review.


How iPlum turns HIPAA call and text policies into daily controls

Written policies establish what workers should do. However, the communication service determines which safeguards they can apply during an ordinary patient call or message.

iPlum’s HIPAA-compliant calling and texting service adds a separate business number to an existing smartphone. Clinicians can use a dedicated work identity for calls, secure texts, and voicemail rather than giving patients a personal number.

With iPlum, you can:

Move clinical messages into an encrypted channel

iPlum offers secure texting through its mobile app. A practice can invite patients to communicate through a free iPlum account or an app-less online portal. AES-256 encryption and PKI cryptography protect communication in the iPlum environment.

Therefore, clinicians can reserve ordinary SMS for limited administrative content and use secure messaging when a conversation contains a diagnosis, treatment detail, image, or other ePHI.

Add account and device safeguards

The iPlum secure second line provides password protection, remote logout, calling and texting logs, and a cloud account console. Administrators can create subaccounts for authorized users rather than sharing one login.

Those features can reinforce role-based access, workforce changes, lost-device procedures, and activity review. A separate business number also prevents patient communication from mixing with personal calls and texts in the native phone history.

Execute a BAA and retain approved records

iPlum provides a BAA with its Professional and Enterprise phone plans. The Professional plan also provides secure, encrypted texting, web calling and texting, voicemail transcription, and one year of text archiving.

For organizations with longer retention policies, the iPlum Enterprise plan adds call recording, a recording consent announcement, and 10 years of call recording and text archiving. 

State call-recording laws can require consent, so practices should configure announcements and recording rules with legal review.

That said, iPlum does not replace the practice’s full HIPAA program or EHR. 

Administrators still need an assessment, written policies, appropriate configuration, user training, clinical documentation, vendor review, and incident procedures. Yet iPlum gives the practice communication controls that ordinary personal calling and SMS do not provide.


Frequently asked questions

Is standard SMS prohibited by HIPAA?

HIPAA does not name SMS as prohibited. However, a practice must apply reasonable safeguards, assess transmission security, limit disclosures, verify recipients, and document its communication decisions.

Does patient consent make personal texting HIPAA compliant?

Patient preference can inform the communication method, but consent alone does not satisfy Security Rule duties. The practice must still manage access, security, vendors, devices, and incidents.

Are patient phone calls subject to the Security Rule?

The Privacy Rule governs verbal disclosures. When a practice stores voicemail, recordings, transcriptions, or related call information electronically, the resulting ePHI also enters the Security Rule’s scope.

Does the current HIPAA Security Rule require encryption?

Encryption remains addressable under the current rule, not optional. A regulated entity must assess it, implement it when appropriate, or document an equivalent alternative and the reasoning for it.

Does a BAA make phone service HIPAA-compliant?

A BAA is essential when a vendor acts as a business associate, but the practice must also properly configure the service, restrict access, train users, and monitor activity.


Prepare patient communication for 2026 and beyond

Healthcare practices must comply with the current HIPAA Security Rule. 

To remain compliant, begin with every number, app, voicemail box, recording system, user account, and vendor that touches patient information. 

Then apply encryption, access restrictions, audit reviews, device safeguards, training, and incident procedures based on the documented findings.

iPlum can move patient calls, secure texts, and voicemail to a dedicated business number backed by encryption, account administration, archiving, and a BAA. 

As a result, the practice can implement its HIPAA communication policy and prepare for stricter federal requirements if HHS finalizes them.

Sign up for iPlum to get started

Tags
No items found.
Download Our APP Now!