HIPAA-Compliant Texting in 2026: A Real Guide (Not Marketing Copy)
HIPAA-compliant texting is real and doable in 2026, but most of what is online is out of date. The actual rules: BAA with the platform, Security Rule safeguards, documented patient consent, state-specific overlays (CMIA, HB 300, SHIELD, MHMDA). Plus OCR enforcement context and the practical implementation.
Demo User
The Texter team is dedicated to helping businesses improve their communication through SMS messaging.
Short version: HIPAA-compliant texting is real and doable in 2026 — but most of what you'll read about it online is either out of date, marketing-flavored, or both. The actual rules are: you need a Business Associate Agreement (BAA) with the texting platform, you need administrative/physical/technical safeguards under the HIPAA Security Rule, you need documented patient consent if you're going to put any PHI in an SMS, and you need to know which states (California, Texas, New York, Washington, others) layer additional rules on top. Below: the regulatory mechanics, what can and can't go in an SMS, the BAA must-haves, state-specific overlays, real OCR enforcement context, and what's changed for 2026.
Disclaimer: this article is informational, not legal advice. Always consult a HIPAA-qualified attorney or compliance officer before implementing patient SMS workflows. Specifics differ by entity type, state, and clinical context.
HIPAA basics — what the rules actually require
HIPAA isn't one rule; it's a framework with two pieces that matter most for SMS:
The Privacy Rule (45 CFR § 164.500-534)
The Privacy Rule governs who can use or disclose Protected Health Information (PHI) and under what circumstances. For SMS:
- Covered Entities (health plans, healthcare clearinghouses, healthcare providers who transmit health info electronically) are the primary obligation-holders.
- Business Associates — vendors that handle PHI on behalf of a Covered Entity — are bound by HIPAA via contract (the BAA). A texting platform that touches PHI is a Business Associate.
- Communications for "treatment, payment, and healthcare operations" (TPO) are generally permitted without separate patient authorization. Appointment reminders fall under TPO.
- "Minimum necessary" applies: even when communication is permitted, you should disclose only the PHI needed for the purpose. "You have an appointment at 2 PM" satisfies minimum necessary; "You have a 2 PM appointment for your colonoscopy follow-up" does not.
The Security Rule (45 CFR § 164.302-318)
The Security Rule governs how electronic PHI (ePHI) is protected. SMS is ePHI when it contains PHI. Required safeguards:
- Administrative safeguards: written policies, workforce training, designated security officer, regular risk assessments.
- Physical safeguards: control over devices that access ePHI, secure workstation use, device disposal procedures.
- Technical safeguards: access controls (unique user IDs, automatic logoff), audit controls (logging access to ePHI), integrity controls (preventing improper alteration of PHI), transmission security (encryption in transit).
SMS itself is technically not encrypted at the carrier level — it traverses signaling protocols (SS7) that can be intercepted. The HIPAA Security Rule allows "addressable" encryption rather than mandatory, meaning you can use SMS for ePHI if you've documented a risk analysis concluding it's reasonable for your context, OR if you've obtained patient consent acknowledging the risk. Most modern healthcare practices choose the second path: explicit patient opt-in to SMS communication with documented acknowledgment that SMS isn't end-to-end encrypted.
The BAA: what it actually contains, and what to look for
The Business Associate Agreement is a contract — not a certification — between a Covered Entity (your practice) and a Business Associate (the texting platform). HIPAA requires it; without it, the Business Associate can't lawfully handle your PHI. A valid BAA must include:
- Permitted and required uses/disclosures of PHI. Specifies what the Business Associate can do with PHI — only what's necessary to provide the contracted service, and only for purposes specified.
- Requirement to safeguard PHI. The Business Associate must implement Administrative, Physical, and Technical safeguards equivalent to what a Covered Entity would.
- Reporting of breaches. Must notify the Covered Entity of any breach within a specified timeframe (typically 24–72 hours for actual breaches, longer for suspected).
- Subcontractor flow-down. If the Business Associate uses subcontractors that touch PHI, those subcontractors also need BAAs.
- Return or destruction of PHI on termination. When the BAA ends, the Business Associate must return PHI to the Covered Entity or destroy it (with documentation).
- Specifics on permitted versus disallowed disclosures. Texter's BAA, for example, prohibits using PHI for advertising, marketing, or aggregated analysis without explicit Covered Entity authorization.
Things to verify before signing a BAA:
- The platform's underlying carriers (Twilio, Bandwidth, etc.) are also BAA-eligible or aren't touching PHI directly. Most platforms route through carriers that have their own enterprise BAA programs; verify yours does.
- Where the data is stored geographically. Some practices need US-only storage; some need specific region constraints.
- Retention and deletion policies. HIPAA doesn't mandate a specific retention period for SMS, but the state, the type of PHI, and the practice's own policies do.
- Logging and audit-export capability. You'll need this for risk assessments and any incident response.
- Termination assistance. If you offboard, the platform should return PHI in a usable format and destroy its copies within a specified window.
Many SMS platforms don't sign BAAs at all — SimpleTexting and EZTexting are explicit that they're not HIPAA-compliant. That's not a defect on their part; they're built for use cases where PHI isn't in scope. But it does mean those platforms can't be used for any healthcare workflow where PHI might appear in an SMS. Our SimpleTexting comparison covers this gap specifically.
What can and cannot go in an SMS to a patient
This is where most practices get tripped up. The rule of thumb: anything that, on its own or in combination with other information, could identify the patient and reveal something about their health is PHI and triggers the full Security Rule analysis.
Generally safe (TPO, minimum-necessary scope)
- Appointment confirmations with date, time, and provider name (e.g. "Reminder: Tuesday 3/19 at 2 PM with Dr. Patel — reply C to confirm")
- Prescription-ready notifications (without medication name) — "Your prescription is ready for pickup"
- Office-hours, location, and contact information
- Generic post-visit instructions ("Please complete the survey we'll email you")
- Billing-due notifications without diagnosis or treatment details
Borderline (allowed only with documented patient consent for PHI-via-SMS)
- Appointment reminders that imply the reason for visit ("Annual physical with Dr. Patel" — this discloses that the patient is seeing a primary-care provider, which is borderline PHI)
- Medication-refill reminders that name the medication
- Lab-result notifications that say "Your results are ready" but not what they are
- Specialty-clinic appointment reminders ("Cardiology appointment Tuesday 2 PM") — discloses the specialty, which can imply a condition
Not allowed in SMS without strong, specific PHI consent (and arguably not even then)
- Diagnoses ("Your test results indicate diabetes")
- Specific treatment recommendations
- Mental health information (especially regulated under 42 CFR Part 2 for substance abuse)
- Substance use treatment information (42 CFR Part 2)
- Test results (especially abnormal results — these should always be communicated through a secure channel)
- Genetic information (GINA-protected)
- HIV status, abortion services, gender-affirming care (state-specific protected categories — see below)
The practical default most HIPAA-aware healthcare practices land on: keep PHI out of SMS entirely. Use SMS for "you have an appointment" and "your prescription is ready" — direct patients to a secure patient portal for anything substantive. This is far more defensible than trying to navigate the PHI-via-SMS consent path.
State-specific rules layered on top of HIPAA
HIPAA is the federal floor. States can — and many do — impose stricter rules. Practices serving patients across state lines have to comply with the strictest applicable rule. The major state overlays:
California: CMIA (Confidentiality of Medical Information Act)
CMIA predates HIPAA and applies to a broader class of entities (including health-related apps that wouldn't be Covered Entities under HIPAA). Key differences from HIPAA:
- Patient authorization requirements are stricter — the form and content of authorization is prescribed.
- Penalties are statutory ($1,000-$25,000 per violation for negligent disclosure, up to $250,000 for knowing/willful disclosure for financial gain) and individuals can sue directly (no need to wait for OCR).
- Reproductive health, gender-affirming care, and HIV/AIDS information have additional protected status.
- The 2023 amendment further restricted disclosure of reproductive-health information to out-of-state requesters.
Texas: HB 300 (Texas Medical Records Privacy Act)
Texas HB 300 applies more broadly than HIPAA — it covers anyone who "comes into possession" of PHI, not just Covered Entities and Business Associates. Notable:
- Mandatory employee training on HIPAA and Texas-specific rules.
- Stricter consumer access and amendment rights.
- Texas Health and Human Services Commission can audit any business handling PHI.
- Civil penalties up to $1.5M per year for compliance failures.
New York: SHIELD Act + reproductive-health protections
New York SHIELD applies to any business with NY residents' private information, broader than just healthcare. The 2022 reproductive-health amendments added strong restrictions on disclosure of pregnancy-termination-related information to out-of-state authorities.
Washington: My Health My Data Act (2024)
Washington's My Health My Data Act covers consumer health data far beyond what HIPAA does — fitness trackers, period-tracking apps, mental wellness apps, anything "linked to identifiable health status." Required notice and consent before processing; private right of action up to $7,500 per violation. If your practice has Washington patients, this applies.
Other states with reproductive-health protections
Connecticut, Illinois, Massachusetts, Oregon, and several others have passed protective laws around reproductive and gender-affirming healthcare data since 2022. The general pattern: out-of-state subpoenas for these data categories may not be honored, and disclosure to out-of-state law-enforcement can create state-law liability.
OCR enforcement context — what gets practices fined
The HHS Office for Civil Rights (OCR) enforces HIPAA. Settlements are public; recent patterns informing what to avoid:
- Missing BAAs. Multiple settlements in 2023-2024 involved Covered Entities that had vendors handling PHI without a BAA in place. The fines run $10,000-$150,000 per missing BAA situation, plus corrective action plans.
- Inadequate risk analyses. The Security Rule requires periodic risk analyses; failing to perform or document them is the #1 most-cited deficiency in OCR audits.
- Phishing and credential-theft breaches. Most ransomware and email-compromise incidents trace back to a missing technical control (MFA, encrypted backups, network segmentation). Fines correlate with breach size and pre-breach control gaps.
- Right of access violations. OCR's "Right of Access Initiative" has produced 40+ settlements where practices failed to provide patients their records within HIPAA's required 30 days. Fines typically $20,000-$70,000.
- Unsecured PHI disclosure. Practices that emailed or texted PHI without appropriate safeguards or consent. Fines depend on the volume and sensitivity.
For SMS-specific practices: the structural defenses are (1) get a BAA with your platform, (2) document patient consent including the "SMS is not end-to-end encrypted" acknowledgment, (3) keep PHI out of message content as much as possible, (4) audit logs on the platform side, (5) workforce training on what can and can't go in a text.
Patient consent for SMS: what valid consent actually looks like
Most HIPAA disputes about SMS center on consent. Valid SMS consent in a healthcare context should include:
- Clear statement of what will be communicated. "Appointment reminders, prescription-ready notifications, billing reminders" is specific. "Communications about your care" is too vague.
- Acknowledgment that SMS is not encrypted end-to-end. The patient is opting into a known-imperfect channel.
- Right to opt out at any time. Documented opt-out procedure.
- Patient's specific phone number. Cross-referenced against the phone number in the EHR.
- Timestamp and method of consent capture. Web form, paper signature, verbal-with-witness, etc. Audit trail.
The classic gap: practices get verbal "yes, you can text me" at check-in but never document it. This is roughly equivalent to having no consent at all from an OCR-audit standpoint. Texter's intake flow records consent capture as a structured event with timestamp, IP, and exact consent language — which is the kind of documentation OCR actually wants to see.
Audit trails: what to log, how long to keep it
The Security Rule requires audit controls — "hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information." For SMS this means:
- Every message sent (sender, recipient, timestamp, content, delivery status)
- Every message received (sender, recipient, timestamp, content)
- Every user access to the platform (login, viewed conversations, sent messages, exports)
- Every consent capture and opt-out event
- Every administrative change (workforce-member added, permissions changed, BAA acknowledged)
HIPAA doesn't specify a retention period for audit logs; OCR guidance and most state laws settle in the 6-year range for HIPAA-relevant documentation. Some states (Texas, California for minors) require longer. The platform you use should support audit-log export in a format you can archive independently — Texter's exports are CSV/JSON.
What's changed for 2026
Three updates worth tracking:
The 2024 HIPAA Privacy Rule reproductive-health amendments. Effective late 2024 and being enforced through 2026, the rule prohibits using or disclosing PHI to investigate or prosecute lawful reproductive healthcare. Practices need to update their BAAs, NPPs (Notice of Privacy Practices), and workforce training accordingly.
State My Health My Data Act expansion. Washington's 2024 law is being copied by Nevada (effective 2024) and is under consideration in several other states. The trajectory is toward broader "consumer health information" definitions that capture more SaaS and app vendors than HIPAA traditionally has.
OCR's focus on right-of-access and risk analyses. Both have been the most-cited deficiency categories in OCR enforcement for several years running. Expect continued enforcement focus through 2026 — risk analyses in particular should be done annually with documentation.
Implementing HIPAA-aware SMS with Texter
Concrete steps for a healthcare practice setting this up:
- Request the BAA. Texter signs BAAs as part of the Professional and Enterprise tier onboarding. The Basic tier is not BAA-eligible because BAA-required workflows have additional infrastructure requirements.
- Configure HIPAA-aware templates. Our healthcare playbook ships with templates pre-stripped of PHI — appointment reminders without diagnosis, prescription-ready notifications without medication name, etc.
- Set up patient consent capture. Webform integration with structured consent recording, or paper intake forms that map to Texter's consent records via your EHR integration.
- Connect your EHR / practice-management system. Native integrations for Practice Fusion, eClinicalWorks, Athenahealth, NextGen, and Epic (Enterprise). Smaller practices can use Zapier or webhooks.
- Configure audit log retention. Default is 6 years; configurable up to 10 for state-law-driven needs.
- Train your workforce. Texter ships with a workforce-training module that covers SMS-specific HIPAA considerations.
- Annual risk analysis. Texter provides a risk-analysis template populated with platform-specific controls (encryption in transit, access controls, audit logging, breach notification timelines).
Common HIPAA-SMS violations to avoid
- Using personal phones for patient communication. Personal devices aren't under your safeguards; PHI on them is exposed in case of loss, theft, or family member access. Texts must go through a managed platform.
- Group texts including patients. Disclosing patient identity to other patients via group SMS is a Privacy Rule violation.
- Auto-forwarding work texts to personal numbers. Common when staff use their cell phones — the auto-forward extends the surface area of where PHI lives.
- Inadequate consent documentation. Verbal-only consent without timestamped recording.
- Including PHI in group marketing SMS. A "we miss you" message that mentions the last visit type discloses PHI to whoever else might see the recipient's phone.
- Failing to honor opt-outs. HIPAA + TCPA require honoring opt-out requests; 30-day cure window is the federal minimum, faster is better.
- Not updating BAAs after platform changes. If your texting platform's subcontractors change, your BAA should be re-issued.
The compliance checklist
- ☐ BAA signed with the texting platform
- ☐ BAA covers permitted uses, breach notification, subcontractor flow-down, termination
- ☐ Patient consent for SMS captured with timestamp, channel, and exact language
- ☐ Consent includes acknowledgment that SMS is not end-to-end encrypted
- ☐ Templates and workflows minimize PHI in message content
- ☐ Encrypted-in-transit transmission verified
- ☐ Access controls: unique user IDs, automatic logoff, MFA enforced
- ☐ Audit logs retained for at least 6 years
- ☐ Workforce training completed on SMS-specific HIPAA considerations
- ☐ Annual risk analysis documented
- ☐ Breach notification procedures defined (your obligations + the platform's)
- ☐ State-specific overlays identified (CMIA, HB 300, SHIELD, MHMDA, etc.) and addressed
- ☐ Personal devices excluded from patient SMS workflows
- ☐ Opt-out handling tested and documented
Bottom line
HIPAA-compliant SMS is a solved problem in 2026, but only for practices that take it seriously — BAA in place, consent properly documented, PHI kept out of message content, audit trails maintained, state-specific rules considered. Most violations don't come from technology failures; they come from process gaps: a missed BAA, an undocumented verbal consent, a staff member texting from a personal phone, a forgotten state rule. Texter ships the technology layer (BAA, encrypted transmission, audit logs, HIPAA-aware templates) so the process layer is what your practice actually has to operate.
If you want to run patient SMS on a platform that signs BAAs and ships HIPAA-aware workflows out of the box, Texter's healthcare playbook is the place to start. Pricing for the BAA-eligible Professional and Enterprise tiers. Compare against SimpleTexting (not HIPAA-compliant) or Twilio (BAA-eligible but you build everything else yourself).
Ready to Transform Your Business Communication?
Start your free trial of Texter and experience the power of professional SMS messaging.