
If you're a healthcare provider, you send text messages for appointment reminders, prescription updates, billing questions, and follow-up instructions.
However, a short message can disclose more than expected.
A patient's name next to a clinic name, medication, diagnosis, or appointment time may constitute protected health information.
So, is SMS HIPAA compliant?
Standard SMS doesn't meet HIPAA compliance standards for routine messages containing PHI.
Ordinary SMS lacks the encryption, access controls, user authentication, audit logs, and administrative oversight expected when healthcare organizations send electronic protected health information.
While HIPAA doesn't explicitly ban text messaging, it requires healthcare practices to apply appropriate administrative, physical, and technical safeguards to patient data.
That said, a healthcare provider can use text messaging when it adopts a secure messaging platform, signs the necessary vendor agreements, documents its policies, trains healthcare professionals, and limits messages to the minimum necessary information.
Read on as we explore SMS, HIPAA compliance, and how iPlum allows you to send secure patient messages.
Table of Contents
2. What information in a text message counts as PHI?
3. Why standard SMS doesn't meet HIPAA compliance standards
4. Does patient consent make standard SMS HIPAA-compliant?
5. Are WhatsApp and other consumer messaging apps HIPAA compliant?
6. What does HIPAA-compliant text messaging require?
7. What can happen after a texting-related HIPAA violation?
8. How iPlum replaces standard SMS with HIPAA-compliant texting
9. How to move from standard SMS to iPlum
11. Get a secure SMS alternative for HIPAA-compliant texting
Is SMS HIPAA compliant?
No, standard SMS isn't HIPAA compliant for routine communication involving PHI.
Ordinary SMS messages are sent through cellular carrier networks.
As a result, the data doesn't receive end-to-end encryption throughout its journey. Copies can remain on personal phones, carrier systems, cloud backups, and notification screens.
The sender also loses authority over the message after transmission. A patient could change numbers. Moreover, another person could gain access to the phone. In addition, an employee could leave the practice with patient conversations stored on a personal device.
There are several missing safeguards that make standard SMS unsuitable for PHI, including:
- End-to-end encryption
- Unique user authentication
- Role-based access controls
- Administrator-managed accounts
- Detailed audit logs
- Automatic access removal
- Secure message retention
- Remote device protections
- A signed Business Associate Agreement
- Organizational oversight of business conversations
The point is, delivery confirmation alone doesn't make SMS HIPAA compliant. Healthcare organizations must also examine how a service transmits, stores, and protects patient information, as well as who can access it.
And, the HHS summary of the HIPAA Security Rule explains why.
Regulated entities must protect the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit.
Standard SMS lacks the guardrails needed to meet those requirements.
What information in a text message counts as PHI?
Protected health information, or PHI, refers to individually identifiable health information held or transmitted by a HIPAA covered entity or its business associates.
Protected health information PHI can appear in an ordinary-looking text. Examples include:
- “Your cardiology appointment is at 2 p.m.”
- “Your blood test results are available.”
- “Your prescription for metformin is ready.”
- “Please send a photo of the surgical area.”
- “Your therapy session has moved to Friday.”
- “Your insurance denied the requested procedure.”
- “Please call the oncology department.”
- “Your outstanding treatment balance is $250."
A name, phone number, or appointment time isn’t automatically PHI in all circumstances. However, it can become PHI when it connects an identifiable patient to treatment, payment, diagnosis, or another healthcare service.
Messages containing PHI can involve:
- Diagnoses and symptoms
- Medical histories
- Test results
- Treatment instructions
- Prescription information
- Insurance details
- Billing information
- Referrals
- Clinical photographs
- Appointment reminders revealing a medical specialty
Text messages that don’t contain PHI aren't subject to the HIPAA Security Rule restrictions applied to ePHI. For example, a generic office-closure notice sent to a public subscriber list generally doesn’t reveal patient information.
However, healthcare practices should still review the recipient list, the message's purpose, and the surrounding context before deciding whether a text contains no PHI.
Why standard SMS doesn't meet HIPAA compliance standards
HIPAA-compliant texting requires several protections that ordinary carrier SMS doesn't provide.
Let's unpack that:
Standard SMS lacks adequate encryption
The best HIPAA-compliant apps must encrypt protected health information during transmission and storage.
Encryption converts readable patient data into an unreadable format. If an unauthorized person intercepts properly encrypted information, the data remains unreadable unless they have the required decryption credentials.
Standard SMS doesn't provide end-to-end encryption. A message can pass through multiple systems in readable form before reaching the recipient.
Transmission security becomes especially important when healthcare professionals send:
- Medical images
- Test results
- Medication information
- Clinical instructions
- Insurance documents
- Payment details
Secure texting for physicians uses encryption for messages in transit and at rest.
Personal devices can expose patient data
A clinician who uses standard SMS can mix personal and patient conversations in the same messaging app.
Message previews can appear on a lock screen. Family members can access a shared phone. Cloud backups can copy conversations into an unmanaged account. A lost device can expose years of patient communication.
Personal devices used for ePHI need suitable security measures, such as:
- Device encryption
- Password or biometric protection
- Automatic screen locks
- Multi-factor authentication
- Remote access removal
- Remote wipe capabilities
- Approved backup settings
- Regular software updates
A personal phone number also creates problems when an employee leaves. The organization might lose access to the communication history, yet the former user could retain messages containing sensitive data.
A HIPAA-compliant phone service helps reduce this exposure.
Standard SMS lacks access controls
Access controls determine who can view, send, edit, or manage electronic protected health information.
HIPAA-compliant messaging apps give authorized users unique credentials. In addition, administrators can assign permissions based on job responsibilities.
Meanwhile, role-based access controls can prevent a scheduler, billing user, contractor, or clinician from accessing patient information outside an approved role.
Ordinary SMS doesn’t give a healthcare organization comparable account administration. Anyone who unlocks the device can potentially read the message history.
Only authorized users should access messages containing PHI. Therefore, a compliant texting service should provide:
- Individual user accounts
- Secure login credentials
- Multi-factor authentication
- Permission settings
- Automatic session expiration
- Administrator-managed access
- Prompt access removal after role changes
Because after all is said and done, that's what healthcare secure text messaging is about.
Standard SMS doesn't create adequate audit trails
Audit trails record account and message activity.
A secure messaging solution should record who accessed patient data, what actions were taken, and when they occurred. Those records allow administrators to investigate unusual activity, verify compliance, and respond to a suspected disclosure.
Basic SMS timestamps don't provide a complete audit trail. A user can delete a message, lose a device, or leave the organization with the conversation history.
HIPAA-compliant messaging platforms should provide audit logs for:
- User logins
- Message activity
- Administrative changes
- Permission changes
- Account access
- Security events
- Retained communication records
Healthcare organizations should review those logs according to documented policies. Merely collecting them isn’t enough.
Standard SMS vendors generally don't sign a BAA
A Business Associate Agreement defines how a vendor will protect PHI and meet its HIPAA obligations.
Healthcare organizations need a BAA when a vendor creates, receives, maintains, or transmits PHI as a business associate, unless a narrow exception applies.
The agreement should address permitted data use, required security measures, breach reporting, subcontractor use, access to records, and what happens to PHI at the end of the contract.
A consumer mobile carrier might act only as a conduit for transient data transmission in certain circumstances. However, a messaging vendor that stores or processes PHI usually performs a broader role.
A HIPAA-compliant texting platform should offer a signed Business Associate Agreement before the healthcare organization sends PHI through the service.
Does patient consent make standard SMS HIPAA-compliant?
No. Patient consent doesn't convert an unsecured service into a HIPAA-compliant texting solution.
Healthcare providers should document patient communication preferences. They should also warn patients about the privacy and data security concerns associated with standard SMS before sending PHI via an unencrypted channel.
However, HIPAA doesn't impose a universal written-consent requirement for every treatment-related text. The exact requirement depends on the communication’s purpose, the information involved, applicable state law, and the organization's policies.
The HIPAA Privacy Rule allows treatment communications when providers apply reasonable safeguards. HHS also says a provider can discuss treatment information via electronic communication after implementing appropriate safeguards.
If a patient initiates contact via standard SMS, the provider can acknowledge the message and explain how to continue using an approved secure channel.
Limited communication via the patient's requested method may be reasonable after the provider explains the privacy concerns.
Still, a patient's request doesn't erase the provider's responsibilities under the Security Rule.
Healthcare practices should:
- Verify the patient’s identity and phone number
- Explain the concerns linked to standard SMS
- Document the patient’s communication preference
- Send only the minimum necessary PHI
- Avoid detailed diagnoses or treatment records
- Move sensitive conversations to secure messaging
- Apply organizational policies consistently
- Review relevant state consent and privacy laws
A signed form cannot fix missing encryption, absent access controls, poor authentication, or a vendor’s refusal to sign a BAA.
Are WhatsApp and other consumer messaging apps HIPAA compliant?
Consumer WhatsApp shouldn't serve as a healthcare organization's HIPAA-compliant messaging app.
WhatsApp offers end-to-end encryption. However, encryption alone doesn't establish HIPAA compliance.
The standard consumer service doesn't give healthcare organizations the full administrative controls, audit capabilities, account ownership, and signed BAA they need for regulated patient communication.
So, is WhatsApp HIPAA compliant? Not as a standard consumer app used for routine PHI communication.
The same concern applies to consumer iMessage, Facebook Messenger, Telegram, and personal email accounts. A service can encrypt content, yet still lack the organizational safeguards required under HIPAA regulations.
In fact, iPlum's analysis of whether iMessage is HIPAA compliant explains why encryption doesn’t answer the entire compliance question. The comparison of email security and text security also examines similar concerns.
What does HIPAA-compliant text messaging require?
A HIPAA-compliant messaging platform should combine technology, account administration, vendor commitments, and written organizational policies.
Encryption
The service should encrypt PHI in transit and at rest. Proper encryption protects patient data if an unauthorized party intercepts a transmission or accesses stored records.
User authentication
Users should prove their identity before opening patient conversations. Passwords, biometrics, secure PINs, and multi-factor authentication add protective layers around patient information.
Access management
Administrators should create accounts, assign permissions, review access, and revoke credentials when a user changes roles or leaves the practice.
Audit logs
Detailed records should show who accessed data and when. Logs can also document message activity, account changes, and administrative actions.
Secure retention
Healthcare organizations should establish retention policies based on federal rules, state requirements, clinical needs, contracts, and litigation obligations.
Minimum necessary disclosures
Healthcare communications should minimize the amount of sensitive data shared. Text messages should contain only the minimum necessary PHI for their purpose.
A Business Associate Agreement
A compliant service that acts as a business associate should sign a BAA before receiving protected health information.
Documented policies
Organizations using texting should establish written policies governing:
- Permitted and prohibited message content
- Patient identity verification
- Consent and communication preferences
- Device security
- User access
- Message retention
- Incident reporting
- Lost or stolen devices
- Employee departure
- Emergency communication
Security assessment
Healthcare organizations must assess their SMS practices involving PHI. The assessment should examine devices, vendors, message content, storage, access, backups, user roles, and possible unauthorized access.
Software alone doesn’t complete HIPAA compliance. Healthcare professionals also need training and recurring policy reviews.
What can happen after a texting-related HIPAA violation?
Texting PHI via a non-compliant service may constitute a HIPAA violation if the organization fails to implement reasonable safeguards.
Possible consequences include:
- An HHS Office for Civil Rights investigation
- Corrective action requirements
- Mandatory policy revisions
- Security assessments
- Employee retraining
- Patient notification
- Civil monetary penalties
- State regulatory action
- Legal costs
- Loss of patient trust
HIPAA violations can trigger substantial civil monetary penalties.
HHS assigns penalties based on the organization’s level of culpability, the number and duration of violations, corrective actions, and other statutory factors.
Penalties can exceed $50,000 per violation, and annual caps can exceed $1.9 million for repeated violations of the same HIPAA requirement.
HHS also adjusts these amounts for inflation. Therefore, the applicable penalty depends on when the violation occurred and which enforcement tier applies.
How iPlum replaces standard SMS with HIPAA-compliant texting
iPlum gives healthcare providers a separate business number for secure calls, texts, and voicemail on an existing smartphone.
The service brings patient communication under a business account instead of leaving conversations in personal SMS inboxes. iPlum allows you to:
Separate personal and patient communication
Clinicians can use an iPlum second phone number on their current mobile device.
The business number creates a separate identity for:
- Patient phone calls
- Secure texting
- Voicemail
- Appointment reminders
- Follow-up messages
- Billing communication
With iPlum, organizations retain ownership of business numbers, and administrators can assign users and withdraw access after an employee leaves.
And, healthcare professionals don’t have to give patients their personal numbers. Patients also receive a consistent business identity when the clinician calls or sends an approved message.
Send encrypted patient messages
iPlum’s secure texting uses an encrypted channel for PHI communication.
Secure messaging protects information during transmission and storage. Authenticated access means only authorized users can open the protected conversation.
Healthcare practices can use it for:
- Treatment follow-ups
- Prescription questions
- Care instructions
- Secure photographs
- Referral information
- Appointment communication
- Billing questions
Healthcare providers can use standard SMS to tell a patient that a secure message is ready. However, they should exclude PHI from the notification and place sensitive details within the encrypted messaging environment.
The same principle applies to therapy conversations, where even a short message can reveal sensitive information.
Apply business account administration
iPlum administrators can manage users, business numbers, permissions, and account access.
Administrative controls give a healthcare practice authority over its communication accounts. Access doesn’t depend on a clinician retaining a personal phone number or personal messaging history.
Account administration also makes it easier to apply documented rules for texting patients and maintaining HIPAA compliance.
Receive a signed BAA
iPlum offers a HIPAA Business Associate Agreement for eligible healthcare accounts.
The BAA addresses iPlum’s responsibilities when its service creates, receives, maintains, or transmits PHI for a covered entity.
Healthcare organizations should complete the agreement and activate the appropriate HIPAA settings before users send patient data.
Protect calls and voicemail
Patient communication extends beyond text messages.
iPlum provides HIPAA-compliant phone calls and secure voicemail through the same business number. Organizations can also configure business hours, call routing, extensions, and an auto attendant.
Therefore, a patient can call the practice, leave a protected voicemail, and continue through secure messaging under the business account.
Text patients using a secure channel
iPlum lets healthcare providers create encrypted, bidirectional text channels for PHI-containing conversations.
Clinicians can send messages, receive patient replies, share protected information, and continue the conversation inside the secure iPlum environment.
Patients don’t need a paid iPlum plan. The practice sends an invitation, and the patient creates a free account to access the secure conversation. Both parties can then send and receive encrypted messages instead of placing PHI in standard SMS or MMS.
Learn how to invite patients and begin secure bidirectional texting with a free patient account.
How to move from standard SMS to iPlum
Begin by identifying clinicians who use personal numbers, SMS, iMessage, WhatsApp, or other consumer apps for patient communication.
Then complete the following actions:
- Document where users send or receive protected health information.
- Review devices, cloud backups, shared accounts, and stored conversations.
- Create an iPlum business account.
- Select the appropriate healthcare plan.
- Assign business numbers and individual user accounts.
- Configure permissions, secure texting, voicemail, and business hours.
- Establish policies for messages containing PHI.
- Explain the secure messaging process to patients.
- Train users on identity verification and minimum-necessary disclosures.
- Test account removal, device protections, and incident procedures.
- Review audit information and communication policies regularly.
- Document the organization’s security assessment.
iPlum provides encryption, access controls, secure storage, audit records, and BAA.
Standard SMS vs. iPlum
The table below compares standard SMS and iPlum based on the communication and compliance criteria healthcare practices should consider before using either service for daily patient calls and text messages.

Get a secure SMS alternative for HIPAA-compliant texting
Standard SMS doesn't meet HIPAA compliance standards for routine communication involving PHI.
It lacks the encryption, authentication, audit trails, business account administration, and vendor commitments expected from a HIPAA-compliant texting service.
Patient consent doesn’t correct the absence of security controls. Encryption alone doesn’t make a consumer app compliant either.
iPlum provides healthcare providers with a dedicated business number, encrypted secure texting, HIPAA-compliant calling, protected voicemail, administrator-managed accounts, and a signed BAA for eligible healthcare accounts.
Click the link below to get started with iPlum and move patient calls and messages to a HIPAA-compliant communication service.

%20(1).avif)
.avif)