TL;DR

Standard SMS has zero encryption, no audit trails, and no access controls, which means every text containing a patient’s name plus health information is a potential HIPAA violation. The fix isn’t encrypting SMS. It’s moving all clinical communication into a HIPAA-compliant in-app messaging platform and using SMS only for neutral, non-PHI notifications. This glossary defines the key terms rehab providers need to understand and gives you concrete steps to close the gap before the 2026 HIPAA Security Rule update makes compliance even stricter.


You texted a patient their updated rotator cuff program last night. Name, diagnosis, sets and reps, all in one iMessage. This morning, you sent a progress photo reminder via SMS. Both messages are sitting on your phone, your patient’s phone, your carrier’s servers, and probably a cloud backup somewhere.

That’s PHI leaking through SMS. And roughly 80% of healthcare professionals use personal mobile devices for exactly this kind of communication, often without realizing they’re violating HIPAA every time they hit send.

This isn’t a theoretical risk. In 2024 alone, PHI for over 276 million individuals was exposed or stolen. At least 85% of those breaches trace back to individual mistakes, not sophisticated hackers. The therapist texting exercise videos from a personal phone after hours is the breach vector.

Whether you’re a physical therapist, chiropractor, occupational therapist, or speech-language pathologist, this glossary defines every term you need to understand the risk and stop PHI from leaking through SMS for good.

See plan options and pricing →


PHI (Protected Health Information)

Definition: Any information in a medical record that can identify an individual and was created, used, or disclosed while providing a healthcare service like diagnosis or treatment.

Here’s the formula that matters: identifier + health information = PHI. Health information by itself, without any of the 18 HIPAA identifiers, is not PHI. A dataset of vital signs alone doesn’t qualify. But add a patient’s name or medical record number to those vital signs, and the entire dataset becomes protected.

The 18 identifiers most relevant to texting include names, dates (except year), telephone numbers, email addresses, Social Security numbers, medical record numbers, biometric identifiers, and full-face photographs or comparable images.

Rehab example: If you text a patient “Hi Sarah, here’s your updated rotator cuff program, 3×15 external rotations,” that message contains PHI. You’ve combined an identifier (Sarah’s name, sent to her phone number) with health information (a prescribed exercise for an implied shoulder condition). The same applies to texting a video of a patient performing exercises with their name visible on screen, or sending HEP set and rep changes via iMessage.

Understanding what qualifies as PHI in a text is the first step in learning how to stop PHI leaking through SMS in your practice.


ePHI (Electronic Protected Health Information)

Definition: PHI that is created, stored, transmitted, or received in electronic form.

The moment you type a patient’s health information into a text message, it becomes ePHI. This distinction matters because ePHI triggers the HIPAA Security Rule, which has specific technical requirements that standard SMS cannot meet.

An SMS text, an iMessage, a WhatsApp message, a Facebook Messenger chat: all of these create ePHI if they contain identifiable health data. And here’s the part that surprises many providers: even “deleted” messages may still reside on a carrier’s server or be backed up to cloud services. You can’t truly delete ePHI from SMS.

The 2026 HIPAA Security Rule update will make encryption of ePHI mandatory, both at rest and in transit. The old “addressable” loophole, where organizations could document why they chose not to encrypt, is disappearing. For rehab providers who haven’t moved to secure clinical video tools, the window is closing.


HIPAA Security Rule

Definition: The federal regulation establishing standards for protecting ePHI through administrative, physical, and technical safeguards.

The Security Rule requires five categories of technical safeguards for any system handling ePHI: access controls, audit trails, encryption, integrity controls, and person or entity authentication.

Standard SMS fails every single one of these:

  • Access controls: Anyone who picks up an unlocked phone can read texts. There’s no role-based access.
  • Audit trails: SMS provides no log of who sent what, when, or whether it was read.
  • Encryption: SMS messages travel in plaintext across carrier networks with no end-to-end encryption.
  • Integrity controls: There’s no way to verify a text wasn’t altered in transit.
  • Authentication: SMS doesn’t verify that the person reading the message is the intended recipient.

Apps like iMessage, SMS, WhatsApp, and Facebook Messenger are not HIPAA compliant, even if your patient agrees to use them. Patient consent doesn’t override your obligation to use compliant tools.

The 2026 Update

The 2026 HIPAA Security Rule update represents the most substantial change since the original rule. Key changes include mandatory encryption of ePHI at rest and in transit (using standards like AES-256 and TLS 1.2+), required multi-factor authentication for all systems accessing ePHI, and 72-hour incident reporting requirements. The “addressable” designation for safeguards is being eliminated entirely.

One significant concern: HHS itself projected approximately $9 billion in year-one compliance costs, and critics argue small and mid-sized providers cannot absorb that expense. Regardless, the direction is clear. Understanding these requirements is essential for any provider figuring out how to stop PHI leaking through SMS before enforcement tightens.


Minimum Necessary Standard

Definition: The principle that covered entities must limit PHI disclosures to the minimum amount necessary to accomplish the intended purpose.

This standard is your best friend when it comes to texting. The practical application is simple: use SMS only for non-PHI notifications, and route everything clinical through a secure channel.

Compliant text: “You have a new message in your app. Tap to view.”

Non-compliant text: “I changed your squat from 3×10 to 3×15 because of your knee pain.”

The first message contains zero PHI. It’s a neutral pointer that drives the patient to a secure platform where they can access their updated home exercise program, activity logs, and other clinical resources. The second message contains an identifier (sent to the patient’s phone number), a specific exercise prescription, and a diagnosis reference.

This “notification then app” pattern is the single most practical step to stop PHI from leaking through SMS in daily practice. Practitioners on Reddit frequently discuss the challenge of breaking the habit of quick clinical texts, and the consensus is that having a fast, easy secure alternative is the only thing that actually changes behavior. If the secure option takes three extra clicks, staff will revert to SMS.

For strategies on keeping patients engaged through compliant channels, see this guide on increasing patient engagement.


Business Associate Agreement (BAA)

Definition: A legally binding contract between a covered entity and any third-party vendor that creates, receives, maintains, or transmits PHI on the entity’s behalf.

If your texting platform vendor won’t sign a BAA, they’re not HIPAA compliant. Period. This is the simplest litmus test you can apply. Apple won’t sign a BAA for iMessage. Google won’t sign one for standard SMS. Neither will Meta for WhatsApp or Messenger.

A BAA must specify how the vendor protects PHI, what happens in a breach, and the vendor’s obligations under HIPAA. Under the 2026 rules, a signed BAA alone won’t be sufficient. Covered entities will need to obtain written verification of their vendors’ technical safeguards on an annual basis.

When evaluating platforms, look for vendors that proactively offer BAAs and can document their encryption, access controls, and audit capabilities. Clinics with multiple locations need to verify that the BAA covers all sites and all users, not just the primary account holder.


End-to-End Encryption

Definition: A method of securing communication so that only the sender and recipient can read the message content, making it unreadable to carriers, servers, and third parties.

Standard SMS has no encryption whatsoever. Messages travel as plaintext across carrier networks, can be intercepted, and are stored on carrier servers in readable form. This is the core technical reason SMS fails HIPAA requirements.

The 2026 Security Rule will require AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit. These aren’t optional suggestions. They’ll be mandatory for every system that touches ePHI.

For rehab providers who share exercise videos and progress photos, encryption needs to cover not just text but also media files. Sending an MMS with a patient performing exercises is sending unencrypted ePHI through an unencrypted channel. A HIPAA-compliant platform handles video sharing within the app, so the content never touches SMS or MMS.


Audit Trail

Definition: A chronological record documenting who sent a message, to whom, when, and whether it was accessed or read.

SMS has no audit trail. You cannot prove who read a message, when it was opened, or whether it was forwarded. If a regulator asks you to demonstrate that PHI was handled properly in a text conversation, you have nothing to show them.

HIPAA-compliant messaging platforms generate audit trails automatically. Every message, every file share, every login is logged. This documentation is also critical for Remote Therapeutic Monitoring, where you need to demonstrate patient interaction and engagement for billing purposes.


Remote Wipe

Definition: The ability to erase all data, including PHI, from a device remotely after it’s been lost or stolen.

This capability is critical for any practice that allows staff to use personal devices (a BYOD, or bring-your-own-device, policy). If a therapist’s phone is lost at the gym or stolen from a car, every patient text on that device is exposed. Standard SMS messages on a lost phone are fully readable to anyone who picks it up.

Secure messaging apps with remote wipe let administrators erase all protected content from the device without needing physical access. When paired with auto-timeout (which logs users out after inactivity), remote wipe creates a meaningful safety net. Without it, a single lost phone can become a reportable breach affecting hundreds of patients.


Patient Consent for Electronic Communication

Definition: Documented, informed permission from a patient to receive health-related communications through electronic channels, including an explanation of risks and the option to opt out.

Under §164.522(b) of the HIPAA Privacy Rule, patients can request to receive communications via alternative means, including text. If the request is reasonable, providers must accommodate it, even if the method introduces risk. In those cases, the patient must be warned of the risks, offered a compliant alternative, and the warning should be documented.

Here’s the critical nuance that trips up many providers: consent does not make SMS compliant. Even if a patient signs a form saying they want to receive texts, you’re still obligated to use tools that meet the Security Rule. Consent addresses the Privacy Rule. It doesn’t override the Security Rule’s technical safeguards.

Understanding this distinction is fundamental to patient health literacy and communication in a compliant practice.


Data Breach Notification Rule

Definition: The HIPAA requirement that covered entities must notify affected individuals, the Department of Health and Human Services, and (for breaches affecting 500+ individuals) the media when unsecured PHI is compromised.

If PHI leaks through an SMS, the Breach Notification Rule applies. You must notify every affected patient without unreasonable delay (and no later than 60 days after discovery). Breaches affecting 500 or more individuals in a single state require media notification as well.

Here’s the compounding problem with SMS: breach detection is nearly impossible without an audit trail. If a staff member sends PHI via text to the wrong number, you might never know it happened. The absence of logging means the breach clock may never start ticking, but the violation still exists, and the liability remains.

More than 935 million individuals have had PHI exposed or impermissibly disclosed over time, roughly 2.6 times the entire U.S. population. Many of those exposures came from exactly the kind of casual, well-intentioned texting that happens in rehab clinics every day.


HIPAA Violation Penalty Tiers

Penalties for PHI violations are structured in four tiers based on the level of culpability. Understanding these tiers is a key motivator for providers learning how to stop PHI leaking through SMS.

TierCulpability LevelFine Per ViolationAnnual Maximum
1Lack of knowledge (didn’t know and couldn’t have known)$137 to $34,464$34,464
2Reasonable cause (knew or should have known, but not willful neglect)$1,379 to $68,928$137,886
3Willful neglect, corrected within 30 days$13,785 to $68,928$344,638
4Willful neglect, not corrected$68,928+ per violation$2,067,813

Criminal penalties apply when violations involve malicious intent. These can include fines up to $250,000 and prison sentences ranging from 1 to 10 years.

The “lack of knowledge” defense in Tier 1 is getting harder to claim. When the entire industry knows SMS isn’t compliant, and this information is freely available, arguing ignorance becomes a tough sell to an auditor.


The Fix: Move PHI Inside the App

The real solution to stopping PHI leaks through SMS isn’t encrypting text messages. It’s eliminating SMS as a PHI channel entirely.

The pattern works like this:

  1. Use SMS for neutral notifications only. “You have a new message. Open your app to view it.” No names, no diagnoses, no treatment details.
  2. Route all clinical content through a HIPAA-compliant in-app messaging platform. Exercise videos, HEP updates, progress photo requests, scheduling details that reference conditions: all of it stays inside the secure channel.

A compliant platform must include encryption (both in transit and at rest), user authentication, access controls, audit logs, auto-timeout after inactivity, remote wipe capability, and a signed BAA.

For rehab providers specifically, the platform needs to handle video and photo sharing inside the secure channel. One-tap custom video prescriptions mean clinicians never need to text exercise videos via SMS or MMS. Personalized reminders go through the secure app, not through unprotected SMS. When the platform tracks patient activity and generates reports within the compliant environment, there’s no need to text patients for status updates at all.

Practitioners on YouTube walkthroughs have noted that the biggest compliance gains come not from adding encryption to existing workflows, but from switching to a platform where the compliant path is also the easiest path. If sending a secure in-app message is faster than opening iMessage, staff will actually use it.

Explore AC Health’s pricing and plans →

This approach also supports practices looking to adopt physical therapy technology that integrates HEP delivery, messaging, and monitoring in one place.


Action Checklist: How to Stop PHI Leaking Through SMS

  1. Audit current texting habits. Have every staff member honestly document what patient information they’ve sent via SMS in the past 30 days.
  2. Draft a texting policy. Define what can and cannot be sent via standard SMS. The short version: nothing containing PHI.
  3. Get patient consent for electronic communications. Document it properly, including risk warnings and opt-out options.
  4. Adopt a HIPAA-compliant messaging platform. Look for encryption, audit trails, remote wipe, auto-timeout, and a signed BAA.
  5. Train every staff member. Not once. Annually. Include real scenarios they’ll recognize, like texting a patient their exercise video from a personal phone after hours.
  6. Run annual risk assessments. The 2026 rules will make this even more critical, with 72-hour incident reporting and mandatory documentation of safeguards.

The sooner you stop treating SMS as a clinical communication tool, the sooner you eliminate the biggest PHI leak vector in your practice.

Schedule a free demo with AC Health →


Frequently Asked Questions

Can I text patients if they give me written consent?

Patient consent allows you to communicate electronically under the Privacy Rule, but it does not make standard SMS compliant with the Security Rule. You still need to use a platform with encryption, audit trails, and access controls. Consent plus a compliant tool equals compliance. Consent plus SMS does not.

Is iMessage HIPAA compliant because it has encryption?

No. While iMessage uses end-to-end encryption between Apple devices, Apple will not sign a Business Associate Agreement. Without a BAA, the platform cannot be used for PHI regardless of its encryption. The same applies to WhatsApp, Signal, and Facebook Messenger.

What if I only text appointment reminders without mentioning a diagnosis?

A simple “Your appointment is tomorrow at 3pm” generally does not contain PHI if it doesn’t reference a condition or provider specialty that implies one. However, if the message says “Your physical therapy appointment for your back injury is at 3pm,” that’s PHI. When in doubt, keep SMS messages completely free of health-related details.

How does the 2026 HIPAA Security Rule change affect small clinics?

The 2026 update makes encryption mandatory (no more “addressable” workaround), requires multi-factor authentication, and introduces 72-hour breach reporting. Small clinics will need compliant platforms and documented security policies. HHS projected about $9 billion in first-year industry costs, but affordable platforms with free or low-cost tiers exist to help smaller practices comply without breaking the budget.

What counts as a breach if I text the wrong patient?

Sending PHI to the wrong phone number is an impermissible disclosure and qualifies as a breach under the Breach Notification Rule. You’d need to conduct a risk assessment, notify the affected patient, and potentially report to HHS. If it involves fewer than 500 individuals, you log it and report annually. For 500 or more, notification to media outlets is also required.

Can my staff use personal phones for patient communication?

Only if you have a formal BYOD policy that includes a HIPAA-compliant messaging app with remote wipe, auto-timeout, and proper access controls. Using the phone’s native SMS or messaging apps for PHI is a violation regardless of whether the phone is personal or practice-owned.

What’s the safest way to send exercise videos to patients?

Use a HIPAA-compliant platform that supports in-app video sharing. Record the exercise during the visit, assign it within the app, and let the patient access it through their secure login. Never send exercise videos via SMS, MMS, or consumer cloud links like Google Drive or Dropbox (unless those services are configured with a BAA and proper access controls, which most practices don’t do).

How often should I train staff on HIPAA texting policies?

At minimum, annually. But effective training happens more frequently through brief refreshers, especially when new staff join or when regulations change. The 2026 update is a natural trigger for a comprehensive retraining. Include scenario-based examples specific to your practice, because abstract compliance rules don’t change behavior the way “here’s exactly what you did wrong” stories do.

{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “@id”: “#faq”, “mainEntity”: [ { “@type”: “Question”, “@id”: “#faq-question-1”, “name”: “Can I text patients if they give me written consent?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Patient consent allows you to communicate electronically under the Privacy Rule, but it does not make standard SMS compliant with the Security Rule. You still need to use a platform with encryption, audit trails, and access controls. Consent plus a compliant tool equals compliance. Consent plus SMS does not.” } }, { “@type”: “Question”, “@id”: “#faq-question-2”, “name”: “Is iMessage HIPAA compliant because it has encryption?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “No. While iMessage uses end-to-end encryption between Apple devices, Apple will not sign a Business Associate Agreement. Without a BAA, the platform cannot be used for PHI regardless of its encryption. The same applies to WhatsApp, Signal, and Facebook Messenger.” } }, { “@type”: “Question”, “@id”: “#faq-question-3”, “name”: “What if I only text appointment reminders without mentioning a diagnosis?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “A simple \”Your appointment is tomorrow at 3pm\” generally does not contain PHI if it doesn’t reference a condition or provider specialty that implies one. However, if the message says \”Your physical therapy appointment for your back injury is at 3pm,\” that’s PHI. When in doubt, keep SMS messages completely free of health-related details.” } }, { “@type”: “Question”, “@id”: “#faq-question-4”, “name”: “How does the 2026 HIPAA Security Rule change affect small clinics?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “The 2026 update makes encryption mandatory (no more \”addressable\” workaround), requires multi-factor authentication, and introduces 72-hour breach reporting. Small clinics will need compliant platforms and documented security policies. HHS projected about $9 billion in first-year industry costs, but affordable platforms with free or low-cost tiers exist to help smaller practices comply without breaking the budget.” } }, { “@type”: “Question”, “@id”: “#faq-question-5”, “name”: “What counts as a breach if I text the wrong patient?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Sending PHI to the wrong phone number is an impermissible disclosure and qualifies as a breach under the Breach Notification Rule. You’d need to conduct a risk assessment, notify the affected patient, and potentially report to HHS. If it involves fewer than 500 individuals, you log it and report annually. For 500 or more, notification to media outlets is also required.” } }, { “@type”: “Question”, “@id”: “#faq-question-6”, “name”: “Can my staff use personal phones for patient communication?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Only if you have a formal BYOD policy that includes a HIPAA-compliant messaging app with remote wipe, auto-timeout, and proper access controls. Using the phone’s native SMS or messaging apps for PHI is a violation regardless of whether the phone is personal or practice-owned.” } }, { “@type”: “Question”, “@id”: “#faq-question-7”, “name”: “What’s the safest way to send exercise videos to patients?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Use a HIPAA-compliant platform that supports in-app video sharing. Record the exercise during the visit, assign it within the app, and let the patient access it through their secure login. Never send exercise videos via SMS, MMS, or consumer cloud links like Google Drive or Dropbox (unless those services are configured with a BAA and proper access controls, which most practices don’t do).” } }, { “@type”: “Question”, “@id”: “#faq-question-8”, “name”: “How often should I train staff on HIPAA texting policies?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “At minimum, annually. But effective training happens more frequently through brief refreshers, especially when new staff join or when regulations change. The 2026 update is a natural trigger for a comprehensive retraining. Include scenario-based examples specific to your practice, because abstract compliance rules don’t change behavior the way \”here’s exactly what you did wrong\” stories do.” } } ] }