HIPAA-Compliant SMS for Therapists, Doctors & Small Healthcare Practices

What HIPAA-compliant SMS actually means for solo and small healthcare practices, what to text vs. not text, and how to set up appointment reminders without a compliance headache.

HIPAA-Compliant SMS for Therapists, Doctors & Small Healthcare Practices
Textndial Team6 min read

Healthcare practices come up surprisingly often in our SMS conversations, and almost every time the question is some version of: "is texting my patients about their appointment going to get me in trouble with HIPAA?"

The honest answer is more nuanced than the marketing copy from texting platforms suggests. SMS itself is not HIPAA-compliant; it's an unencrypted protocol. What makes a workflow compliant is a combination of what you choose to send, how you got the patient's permission, and the agreements you have with the platform you're using. Get those three right and you can use SMS confidently for the things it's good at — appointment reminders, intake confirmations, simple time-sensitive updates — without exposing your practice to a violation.

This is general guidance, not legal advice. Compliance content like this gets reviewed by our founder before publishing.

The thing nobody tells you upfront

There's no such thing as "HIPAA-compliant SMS" as a product feature. SMS is plaintext. Each carrier handles the message in transit and stores logs of it. The protocol predates HIPAA by a couple of decades, and the fix isn't really at the protocol level — the fix is at the workflow level.

What HIPAA actually requires:

  1. A business associate agreement (BAA) with any vendor that creates, receives, maintains, or transmits Protected Health Information on your behalf. Your messaging provider stores phone numbers and message contents, which can be PHI in context. You need a BAA.
  2. Reasonable safeguards appropriate to the channel and what you're sending through it. SMS's reasonable safeguard is mostly what you don't send.
  3. Patient consent — and an option to opt out — for ongoing communications, particularly for marketing. Treatment-related communications are more permissive but still need to give patients an opt-out.
  4. Documentation — records that you got consent, that you respect opt-outs, and that your minimum-necessary practice is documented somewhere.

Get those four boxes checked and SMS is fine for the things SMS is fine for.

What's safe to send (and what isn't)

A useful distinction: identifying that there is an appointment is generally OK; describing what the appointment is for is risky. The minimum-necessary rule means you should send the smallest amount of identifying detail required to accomplish the legitimate purpose.

Generally safe:

Avoid in plaintext SMS:

The reframing: "would I be comfortable if this exact message were forwarded to a third party by accident?" If yes, it's fine for SMS. If not, send it through your patient portal.

What you actually need to set up

For a small practice (solo therapist, single-provider clinic, small dental or chiropractic office), the practical setup is more straightforward than the compliance literature makes it sound:

  1. Choose a messaging vendor that signs BAAs. Not every platform will. Ask before signing up. Get the BAA in writing before you send your first PHI-adjacent message.
  2. Document patient consent. A line in your intake paperwork — "You agree to receive appointment reminders, communications about your care, and practice notifications via SMS to the number provided. Standard message and data rates may apply. Reply STOP at any time to opt out." — does the work for treatment-related messaging. Keep the signed intake forms.
  3. Set up your appointment-reminder content carefully. Use templates that include only the minimum necessary information. Configure your scheduling system or messaging platform to populate templates from data; don't rely on staff typing PHI into a chat tool.
  4. Honor STOP requests immediately and log them. Most platforms automate this. Verify yours does, and check the opt-out list periodically.
  5. Train any staff who use the messaging tool. Don't let well-meaning office staff "explain" via text what's better explained on the phone or in the portal. The most common HIPAA SMS missteps are well-intentioned over-sharing.

Marketing messages are different

If you're sending healthcare-related marketing messages — promoting a new service, sharing wellness content, soliciting reviews — the rules tighten:

The cleanest separation: register two campaigns — one for transactional/treatment communications (appointment reminders, confirmations, telehealth links) and one for marketing (newsletters, promotions, review requests). Send each from a clearly-labeled flow. Don't blur them.

A note on patient-initiated communications

HHS has been increasingly clear that patients have a right to communicate with their providers via the channel they choose, including SMS, even if SMS is unencrypted. If a patient texts you first asking about their care, you can respond — provided you've made them aware (usually via a one-time disclosure) that SMS isn't a secure channel.

Practical implementation: when a new patient first texts your practice, send a one-time response: "Thanks for reaching out. SMS isn't encrypted — for sensitive details, please use our patient portal at [link] or call us at [number]. Otherwise, we're happy to help with quick questions here. Reply STOP to opt out." Save that as a template; it covers the disclosure requirement and the opt-out language in one go.

What about voice?

Worth a mention because healthcare practices often forget: voice has its own HIPAA implications. Voicemails left for patients should follow the same minimum-necessary rule (don't leave a message that says "please call us about your test results" — say "please call us back at [number]"). Recorded calls (if you record any) are PHI and need to be retained and protected accordingly.

We have more on small-practice phone setup in our guide to small-business phone systems — many of the same considerations apply, just to voice rather than text.

The shortest version

If you only remember three things:

  1. Don't put PHI in the body of SMS messages. Send identifying details (date, time, who) but not clinical content.
  2. Have a BAA with your messaging provider.
  3. Document consent and respect opt-outs.

That's most of HIPAA SMS compliance for a small practice. The rest is about being thoughtful when content gets close to the line, and using your patient portal for anything that doesn't need to be in a text.

Textndial Team

Telecom operators & product team at Vibratel.

Text N Dial is built and operated by people running real carrier infrastructure. We write what we’ve actually shipped, broken, and fixed — not what a stock-photo content marketer thinks “sounds good.”

Reviewed by Joey Capo, Founder

Frequently asked questions

Is text messaging HIPAA-compliant by default?

No. Standard SMS travels in plaintext across mobile carriers and is not encrypted at rest or in transit. By itself, SMS is not HIPAA-compliant for sending Protected Health Information. What makes a healthcare SMS workflow compliant is what you choose to send (and not send), the platform you use (with a signed BAA), and your patient-consent process.

Can I text appointment reminders to patients?

Yes, with care. HHS guidance has long permitted appointment reminders as part of treatment operations, including via SMS, provided the patient has been given the opportunity to opt out and the message contains the minimum information necessary. Don't include diagnostic information or sensitive details in the reminder itself.

Do I need a Business Associate Agreement (BAA) with my SMS provider?

If your provider stores or transmits any PHI on your behalf, yes. Even when you intend to send only minimal information, the provider has access to your patient phone numbers and message history, which can constitute PHI in context. Use a vendor that will sign a BAA. We sign BAAs on request for healthcare customers.

What about WhatsApp, iMessage, or Signal?

Encrypted messaging apps (Signal, WhatsApp end-to-end mode, encrypted iMessage) are technically more secure than SMS, but they don't automatically make a workflow HIPAA-compliant. You still need a BAA with the provider where applicable, patient consent, and policies covering retention, access, and breach response. Encryption is one piece, not the whole picture.

Can I send a patient their lab results via SMS if they ask me to?

HHS guidance permits unencrypted email and SMS communication of PHI when the patient explicitly requests it and has been advised of the security risks. Document the request in the chart. But making it your default channel for results is not advisable — encrypted patient portals are the safer baseline.

Still have questions? Talk to sales →

Keep reading

SMS Compliance

Everything a small business actually needs to know about texting customers in 2026 — 10DLC, TCPA, the recent rule changes, real costs, and why messages still get blocked even when you do everything right.

12 min read
SMS Delivery

Texts marked delivered but never received? Texts that just disappear? Here's a small-operator's guide to diagnosing why business SMS fails and fixing each cause.

8 min read
TCPA Update

The Fifth Circuit ruled the FCC's 'prior express written consent' rule exceeds the TCPA statute. What that means for business texting in 2026, and what hasn't changed.

7 min read
← Back to all postsTags: #hipaa, #healthcare, #sms-compliance