HIPAA Compliant Texting

HIPAA compliant texting is the use of text messaging systems and workflows that protect electronic protected health information and restrict uses and disclosures in accordance with the HIPAA Privacy Rule, the HIPAA Security Rule, the HIPAA Breach Notification Rule, and the HIPAA Minimum Necessary Rule.

HIPAA compliant texting requires a platform and governance model that support access controls, unique user identification, authentication, and role-based permissions for workforce members who send or receive protected health information. It also requires transmission security and storage security so messages, attachments, and metadata containing protected health information are protected when sent, received, and retained. Audit controls and monitoring procedures are needed to record message access and support investigations of unauthorized activity.

Operational controls determine whether texting remains within permitted purposes and minimum necessary limits. Workforce policies should define permitted message content, identity verification requirements, patient consent practices when applicable, and restrictions on personal devices and consumer texting applications. Configuration and retention settings should support message expiration or archiving rules, remote wipe and device management where used, and incident response procedures that support breach assessment and notification decisions under the HIPAA Breach Notification Rule.

Business Associate governance applies when a vendor creates, receives, maintains, or transmits protected health information through the texting service. A Business Associate Agreement should cover the specific texting services in use and require safeguards, reporting duties, and limits on use and disclosure consistent with HIPAA.

Daniel Lopez

Daniel Lopez is the HIPAA expert behind HIPAA Coach. Daniel has over 10 years experience as a HIPAA trainer and has developed deep experience in teaching HIPAA to healthcare professionals. Daniel has contributed to numerous publications including expert articles on The HIPAA Guide. Daniel is currently a staff writer on HIPAA at the Healthcare IT Journal. Daniel was a subject matter expert for ComplianceJunction's online HIPAA training. Daniel's academic background in Health Information Management is the foundation of his HIPAA expertise. Daniel's primary professional interest is protecting patient privacy, which he believes is the core of the HIPAA regulations and the best route to HIPAA compliance. You can reach Daniel on the contact page of HIPAA Coach and follow him on Twitter https://twitter.com/DanielLHIPAA