Why Texting Isn’t HIPAA Compliant: Safe Guidelines | VentureTel

Why Texting is Not HIPAA Compliant and Guidelines for Safe Texting

Overview

Texting (SMS) is a convenient way to communicate, but it is not inherently HIPAA compliant when handling Protected Health Information (PHI) in healthcare settings. This article explains why standard texting poses risks under the Health Insurance Portability and Accountability Act (HIPAA), outlines what is safe to text and what isn’t, and provides recommendations for secure communication alternatives.

Why Texting is Not HIPAA Compliant

Standard SMS texting does not meet HIPAA’s Privacy, Security, and Breach Notification Rules for protecting PHI. Here are the key reasons why:

Lack of Encryption

- Standard SMS messages are not encrypted in transit. They travel over cellular networks and can be intercepted by third parties, violating HIPAA’s requirement to protect PHI during transmission.

Unsecured Storage on Devices

- SMS messages are stored on the sender’s and recipient’s devices, often in unencrypted form. If a device is lost, stolen, or accessed by an unauthorized person, PHI can be exposed, leading to a HIPAA breach.

No Access Controls

- SMS platforms lack robust access controls, such as role-based access or multi-factor authentication (MFA), making it difficult to ensure only authorized individuals can view PHI.

No Audit Trails

- Standard texting does not provide audit logs to track who accessed PHI, when, or how, which is a HIPAA requirement for monitoring and accountability.

Risk of Misdirection

- Texting increases the risk of sending PHI to the wrong recipient (e.g., due to a typo in the phone number), leading to unauthorized disclosure.

Carrier Storage Risks

- Cellular carriers may store SMS messages on their servers, and these messages may not be encrypted or protected under a Business Associate Agreement (BAA), creating a compliance gap.

What is Okay to Text and What Isn’t

Texting can be used in healthcare settings, but you must avoid including PHI to stay compliant with HIPAA. Here’s a breakdown of what is safe and what isn’t:

What is Okay to Text

- General Reminders Without PHI: You can send appointment reminders or general notifications that do not include PHI. For example: “You have an appointment tomorrow at 10 AM with Dr. Smith.”
- Links to Secure Portals: You can send a link to a secure portal (e.g., a Microsoft Teams channel or patient portal) where PHI can be accessed securely. For example: “View your lab results here: [secure link].”
- Non-Sensitive Communication: Text messages about general office updates, such as “Our office will be closed tomorrow,” are safe as they do not involve PHI.

What Isn’t Okay to Text

- Any Message Containing PHI: PHI includes any individually identifiable health information, such as patient names, medical record numbers, diagnoses, treatment details, or test results. For example, texting “John Doe’s lab results show high cholesterol, schedule a follow-up” is not HIPAA compliant.
- Messages with Sensitive Details: Avoid texting details like medication lists, appointment reasons (e.g., “Your chemotherapy session is at 2 PM”), or billing information tied to a patient’s identity.
- Group Texts with PHI: Never include PHI in group texts, as all recipients can see the message, increasing the risk of unauthorized disclosure.

Recommendations for Secure Communication

Since standard texting is not HIPAA compliant for PHI, consider these alternatives and best practices:

Use Microsoft Teams Chat

- Instead of SMS, use Microsoft Teams’ chat feature for internal communication of PHI. Teams chat is encrypted, access-controlled, and logged, making it more secure than SMS when configured for HIPAA compliance (see our KB article on securing Microsoft 365 for HIPAA compliance).

Limit SMS Use

- Reserve SMS for non-sensitive notifications, such as appointment reminders without PHI, or to send links to secure portals where patients can access PHI.

Implement a HIPAA-Compliant Texting Solution

- If texting PHI is necessary, use a dedicated HIPAA-compliant texting platform that offers encryption, access controls, audit logs, and a BAA. VentureTel can help explore options for secure texting solutions.

Train Staff on Safe Texting Practices

- Train your staff to avoid texting PHI and to double-check recipient phone numbers to prevent misdirection. Ensure they understand the risks of standard SMS and the importance of using secure alternatives.

- If texting non-sensitive information (e.g., appointment reminders), obtain patient consent for SMS communication and inform them that standard SMS is not secure for PHI.

Additional Notes

  • Risk Assessments: Regularly assess your communication workflows to identify risks, such as texting PHI, and address them promptly.
  • Device Security: Ensure all devices used for texting are secure, with features like automatic logoff, updated antivirus software, and encryption enabled.
  • Consult a Professional: HIPAA compliance can be complex. We recommend consulting with a HIPAA compliance expert or legal counsel to ensure your communication practices meet all requirements.

Conclusion

Texting is not HIPAA compliant when it involves PHI due to the lack of encryption, access controls, and audit trails in standard SMS. To stay compliant, avoid texting PHI and use secure alternatives like Microsoft Teams chat for sensitive communication. By following the guidelines above, you can use texting safely for non-sensitive notifications while protecting patient data.

For further assistance, contact VentureTel.


    • Related Articles

    • How VentureTel’s eFax Integration with Microsoft Teams is HIPAA Compliant

      Overview VentureTel’s eFax integration with Microsoft Teams allows healthcare organizations to send and receive faxes securely within Teams, but ensuring HIPAA compliance is critical when handling Protected Health Information (PHI). This article ...
    • Securing Microsoft 365 for HIPAA Compliance

      Overview Microsoft 365 (M365), including Microsoft Teams, is a powerful platform for collaboration, but using it in healthcare settings requires ensuring it meets the Health Insurance Portability and Accountability Act (HIPAA) standards for ...
    • Initiating a call from the SMS Texting App

      We've added the ability to initiate a call through your cell phone (without using a soft phone or LTE service) from your office number, we call this a "Quick Call".   What's a Quick Call? A quick call can be made to any of your devices not just your ...
    • VentureTel SMS on Mobile

      VentureTel.app our business texting and end user app for managing your phone settings is available in the Apple App Store for iOS and on Google Play for Android.  Start by downloading the app for your device then login with your user to start sending ...
    • How Long Will It Take To Port My Number to VentureTel?

      In most cases, we can transfer your number within ten business days from when you submit the number transfer request, provided that all the correct information and documentation is submitted, including a correctly filled out Letter of Authorization ...