TL;DR
Standard SMS is not HIPAA-compliant, and texting patients without a written policy puts your license and practice at risk. This guide defines every key HIPAA term therapists need to understand, then provides a sample HIPAA-compliant texting policy framework you can adapt for your practice. You need three separate documents: an internal texting policy, a patient consent form, and a Business Associate Agreement with your messaging vendor. Building all three correctly is what actual compliance looks like.
Why Every Therapist Needs a Written Texting Policy
Here’s a fact that should worry you: approximately 80% of medical professionals use personal mobile devices for work, creating serious risks of PHI being disclosed to unauthorized individuals. For therapists, the risk is compounded by the clinical sensitivity of what you discuss with patients.
A written texting policy isn’t a nice-to-have. It’s an administrative safeguard required under HIPAA. Most therapy practices, especially solo and small ones, don’t have one. That’s the single most common compliance gap the Office for Civil Rights investigates.
This guide walks through a sample HIPAA-compliant texting policy for therapists, starting with every term you need to know and ending with a section-by-section framework you can adopt today. Whether you’re a physical therapist, occupational therapist, speech-language pathologist, or mental health clinician, the same rules apply.
See AC Health’s HIPAA-native messaging features →
What Is a HIPAA-Compliant Texting Policy?
A HIPAA-compliant texting policy is the written internal document governing how, when, and through which channels therapists may text patients or colleagues about Protected Health Information. It is not the same thing as a patient consent form (which is patient-facing) or a Business Associate Agreement (which is vendor-facing).
You need all three documents. The policy is your internal rulebook. The consent form gets the patient’s informed permission. The BAA binds your texting platform vendor to HIPAA obligations. Competitors and generic guides frequently blur these distinctions, but getting them wrong can mean the difference between compliance and a six-figure fine.
A strong policy doesn’t just say “use encrypted texting.” It specifies which platforms are approved, what types of messages are allowed, who can send them, how devices must be secured, and what happens when something goes wrong.
Core HIPAA Terms Every Therapist Must Know
Each term below includes a plain-language definition and a “Policy Implication” note showing exactly how that concept should appear in your texting policy.
Protected Health Information (PHI)
PHI is any individually identifiable health information held or transmitted by a covered entity or its business associate. In a therapy context, this includes a patient’s name combined with their diagnosis, treatment plan details, appointment dates, insurance information, or session notes.
If a text message contains a patient’s name and anything about their health, treatment, or payment, it’s PHI.
Policy implication: Your texting policy must define PHI explicitly and give staff concrete examples. “You have an appointment at 3pm” directed to a known patient is borderline. “Your rotator cuff exercises have been updated” paired with a name is clearly PHI.
Electronic PHI (ePHI)
ePHI is the subset of PHI that is transmitted or stored electronically. Every text message about a patient’s health qualifies as ePHI, whether sent via SMS, iMessage, WhatsApp, or a secure messaging platform.
Policy implication: Your policy should state that all ePHI transmitted via text must use an approved, encrypted platform. No exceptions.
Covered Entity
A covered entity is a healthcare provider who transmits any health information electronically in connection with a HIPAA-covered transaction. If you bill insurance electronically (which nearly every therapist does), you are a covered entity. This applies to PTs, OTs, SLPs, psychologists, psychiatrists, and chiropractors alike.
Policy implication: Your policy’s scope section should confirm that the practice is a covered entity and that all staff who handle patient communications are bound by the policy.
Business Associate and Business Associate Agreement (BAA)
A business associate is any person or organization that performs functions involving the use or disclosure of PHI on behalf of a covered entity. Your texting platform vendor is a business associate. A Business Associate Agreement is the legally binding document that outlines the responsibilities of both parties, including how the vendor safeguards PHI and supports breach reporting.
Policy implication: Your policy must name approved messaging platforms and confirm that a signed BAA is on file for each one. If the vendor won’t sign a BAA, you cannot use them for patient texting.
Minimum Necessary Standard
Under §164.502(b), covered entities must limit PHI use and disclosure to the minimum amount necessary to accomplish the intended purpose. For texting, this means sending only the information required, nothing more.
Good example: “Your appointment is confirmed for Thursday at 2pm.”
Bad example: “Your anxiety medication has been adjusted to 20mg Lexapro, and we’re also watching your blood pressure following last week’s panic episode.”
Policy implication: Include a minimum necessary standard section with examples specific to your practice type. A PT sending a home exercise program link looks different from a psychologist confirming a session time.
Psychotherapy Notes
This is the term that generic healthcare texting guides almost universally miss. HIPAA places special protections on psychotherapy notes that go beyond standard medical record safeguards. These notes contain a therapist’s personal impressions, analysis, and observations about a patient’s mental health, and they are kept separate from the rest of the medical record.
Disclosing psychotherapy notes requires a separate, specific written authorization from the patient. General HIPAA consent is not enough.
Policy implication: Your texting policy must explicitly prohibit sending psychotherapy note content via text, even on a HIPAA-compliant platform, unless you hold a separate written authorization for that specific disclosure. This is non-negotiable for mental health professionals.
Administrative Safeguards
Administrative safeguards are the policies, procedures, and training that govern how your practice handles ePHI. They include your written texting policy itself, staff training programs, risk assessments, and ongoing monitoring. These are the organizational controls, not the technical ones.
Policy implication: Document your training schedule (at minimum annually), who is responsible for policy enforcement, and how you conduct risk assessments.
Physical Safeguards
Physical safeguards protect the devices and environments where ePHI is accessed. For texting, this means device encryption, mandatory screen locks, restrictions on who can access clinic devices, and remote wipe capabilities for lost or stolen phones.
Mobile devices can be easily lost or stolen, making remote wipe essential. If a clinic phone disappears, you need the ability to erase all PHI from it immediately.
Policy implication: Your policy should specify minimum device security requirements: passcode length, auto-lock timing, encryption status, and remote wipe enrollment. It should also address whether personal devices are allowed and under what conditions.
Technical Safeguards
Technical safeguards are the technology controls that protect ePHI. The three pillars are end-to-end encryption (making messages unreadable to anyone except sender and recipient), access controls (ensuring only authorized users can view messages), and audit logs (recording who accessed what and when).
Policy implication: Specify that your approved messaging platform must provide all three. If it doesn’t, it’s not compliant.
Audit Trail / Audit Log
An audit trail is a chronological record of all messaging activity, including who sent messages, who read them, when they were accessed, and any changes made. HIPAA-compliant platforms automatically document these events, including administrator actions, authentication events, and message read receipts.
HIPAA authorization forms must be stored for a minimum of six years. Your audit logs should follow the same retention standard.
Policy implication: Your policy should state the retention period for messaging audit logs and identify who reviews them and how often.
Risk Analysis / Security Risk Assessment
A risk analysis is a systematic evaluation of potential threats to ePHI. It’s not a one-time exercise; OCR expects covered entities to conduct risk assessments regularly, and it has been actively enforcing this requirement. Texting introduces specific risks (device theft, carrier interception, screen previews) that your risk analysis should address.
Policy implication: Reference your risk assessment schedule in the texting policy and note that texting-related risks must be included in the scope.
Breach Notification Rule
If unsecured PHI is accessed, used, or disclosed in a way not permitted by HIPAA, it’s a breach. The Breach Notification Rule requires covered entities to notify affected individuals within 60 days, notify HHS, and in some cases notify the media.
Policy implication: Your texting policy should include an incident response section that specifies who to contact, what to document, and the timeline for reporting.
TCPA Consent vs. HIPAA Authorization
This distinction trips up a lot of therapists. The Telephone Consumer Protection Act (TCPA) and HIPAA are separate federal laws with separate consent requirements. A patient signing a HIPAA authorization does not satisfy the TCPA’s express written consent requirement for automated or pre-recorded messages. You need both.
Policy implication: Your consent workflow must capture HIPAA authorization and TCPA consent as separate acknowledgments. Using a single form that covers both is fine, but both elements must be present and clearly identified.
Standard SMS vs. HIPAA-Compliant In-App Messaging
Standard SMS, iMessage, WhatsApp, and similar consumer messaging apps lack the security controls required for HIPAA compliance. They don’t offer access controls, compliant data storage, BAAs, or proper audit trails. Messages traverse carrier networks with no encryption or access controls.
In-app secure messaging (like a HIPAA-compliant patient communication portal) keeps PHI inside a protected environment. Messages never leave the encrypted platform, access is controlled, and every interaction is logged.
Policy implication: Your policy should explicitly name which platforms are approved and which are prohibited. List common prohibited platforms by name (SMS, iMessage, WhatsApp, Facebook Messenger) so there’s no ambiguity.
Message Auto-Expiration and Data Minimization
Security experts recommend implementing policies that ensure messages containing PHI automatically expire and are deleted after a specified period. This minimizes the risk of unauthorized access to outdated information and aligns with the principle of data minimization.
Policy implication: If your platform supports auto-expiration, enable it and document the retention window. If it doesn’t, include manual review and deletion procedures.
Sample HIPAA-Compliant Texting Policy Framework for Therapists
Below is a section-by-section policy framework you can adapt for your practice. Fill in the bracketed fields with your practice-specific details. This is the core of the sample HIPAA-compliant texting policy for therapists that most searchers are looking for, and that no other guide actually provides.
Disclaimer: This is an educational framework, not legal advice. Consult a HIPAA attorney to finalize your policy for your specific jurisdiction and practice type.
Section 1: Purpose and Scope
[Practice Name] establishes this policy to govern all text-based communication involving Protected Health Information (PHI). This policy applies to all staff, contractors, and affiliated providers who send or receive text messages related to patient care, scheduling, or administrative functions at [Practice Name].
This policy covers communication with patients and between staff members. It applies to all devices, including practice-owned and personal devices used for practice communications.
Section 2: Approved Platforms and BAA Status
The only approved platform(s) for text-based patient communication at [Practice Name] are:
– [Platform Name] (BAA signed on [Date], filed at [Location])
– [Additional Platform if applicable]
Standard SMS, iMessage, WhatsApp, Facebook Messenger, and any consumer messaging application are prohibited for any communication containing PHI.
Section 3: Permitted Message Types
The following message types are approved for text-based communication through approved platforms:
– Appointment reminders and confirmations (using compliant reminder tools reduces no-shows while protecting PHI)
– Care plan links and home exercise program notifications
– General wellness check-ins (without specific clinical details)
– Billing and payment reminders (without detailed treatment information)
– Requests for the patient to call the office
Section 4: Prohibited Message Types
The following content must never be sent via text, regardless of platform:
– Psychotherapy notes or content from psychotherapy notes (requires separate written authorization)
– Social Security numbers, full insurance ID numbers, or financial account details
– Detailed diagnoses, medication names, or dosage adjustments
– Complete medical records or treatment summaries
– Any PHI via standard SMS or non-approved platforms
– Photos or videos containing identifiable patient information sent outside approved platforms
Section 5: Patient Consent Procedures
Before initiating text communication, [Practice Name] must obtain:
1. HIPAA authorization: Written acknowledgment that the patient understands PHI may be transmitted via text, the risks involved, and their right to revoke consent at any time.
2. TCPA consent: Separate express written consent for any automated or pre-recorded messages, including the type and frequency of messages they will receive.
Consent forms must inform patients of: what messages they will receive, risks of texting, how to revoke consent, and [Practice Name]’s texting policy. All consent forms must be retained for a minimum of six years.
Section 6: Minimum Necessary Standard Application
All text messages must contain only the minimum information necessary to accomplish the communication’s purpose. Staff should default to less information rather than more. When in doubt, use text to request a phone call or in-person conversation rather than transmitting clinical details.
Section 7: Device Security Requirements
All devices used to access approved messaging platforms must meet these requirements:
– Full-disk encryption enabled
– Passcode of at least [6 digits/alphanumeric]
– Auto-lock after [60 seconds/2 minutes] of inactivity
– Lock-screen message previews disabled
– Remote wipe capability enrolled and verified
– Automatic cloud backup of messages to personal accounts (iCloud, Google) disabled for approved messaging apps
– [For personal devices: Mobile Device Management (MDM) software installed]
Section 8: Staff Training Requirements
All staff with access to patient messaging must complete HIPAA texting compliance training:
– Upon hire or role assignment
– Annually thereafter
– Within 30 days of any policy update
Training must cover: this policy, PHI identification, platform usage, device security, incident reporting, and the minimum necessary standard. Training completion must be documented and retained for six years. Practices looking to reduce time wasted on admin can integrate training into existing onboarding workflows.
Section 9: Audit and Monitoring Procedures
[Practice Name] will:
– Review messaging audit logs [monthly/quarterly]
– Verify BAA status with all messaging vendors annually
– Conduct a texting-specific risk assessment as part of the annual security risk analysis
– Document all audit activities and retain records for a minimum of six years
Section 10: Incident Response and Breach Notification
In the event of a suspected or confirmed breach involving text-based PHI:
1. The staff member must immediately notify [Designated Privacy Officer/Practice Owner]
2. The Privacy Officer will document the incident and assess scope within 24 hours
3. If a breach is confirmed, notification to affected individuals must occur within 60 days
4. HHS must be notified per breach notification requirements
5. All incident documentation must be retained for six years
Section 11: Policy Review Schedule
This policy will be reviewed and updated:
– At minimum, annually
– Following any HIPAA regulatory change
– After any breach or near-miss incident
– When adopting a new messaging platform
Last reviewed: [Date]
Next review due: [Date]
Policy owner: [Name/Title]
Common Mistakes Therapists Make With Texting
Even well-intentioned therapists fall into these traps. A proper sample HIPAA-compliant texting policy for therapists should prevent each one.
Using iMessage, WhatsApp, or personal SMS for patient communication. These platforms don’t offer BAAs, compliant storage, or access controls. Convenience doesn’t equal compliance. Standard texting platforms lack the security, compliance, and control necessary to text patients compliantly.
Failing to get separate TCPA consent alongside HIPAA authorization. These are two different legal frameworks. A HIPAA consent form does not cover the TCPA’s express written consent requirement for automated messages.
Not disabling lock-screen message previews. A patient’s name and message content visible on a locked phone in a clinic hallway is a potential breach. It takes 30 seconds to fix in device settings.
Storing text conversations in personal iCloud or Google backups. If your approved messaging app syncs to a personal cloud account, those messages are now sitting in an environment you don’t control and that has no BAA.
Having no written policy at all. This is the most common and most dangerous gap. Practitioners on Reddit and compliance forums consistently report that solo therapists and small practices assume compliance is about the app they use. It’s not. The app is one piece. Without a written policy, you have no administrative safeguard, and that alone can trigger a violation.
Blurring the line between administrative and clinical texting. As one practitioner-oriented therapy guide puts it, therapists should make it part of their practice to explain when and how texting is okay, and when a video call or in-person visit is the better route. Boundary-setting matters as much as encryption.
What to Look For in a HIPAA-Compliant Messaging Platform
Your texting policy is only as strong as the platform supporting it. Here’s what to evaluate.
Must-haves:
- Willingness to sign a BAA
- End-to-end encryption for messages in transit and at rest
- Role-based access controls
- Complete audit logs with retention capabilities
- Remote wipe support
- Patient consent workflow integration
Nice-to-haves:
- Message templates for common communications
- Auto-expiration for messages containing PHI
- Read receipts logged in audit trail
- EHR or practice management integration
- Customizable reporting
The key distinction is between platforms that bolt security onto consumer messaging and platforms built from the ground up with HIPAA compliance as a core feature. In-app messaging within a HIPAA-compliant platform keeps PHI inside a protected environment, while SMS traverses carrier networks with no encryption.
For rehab therapists specifically, look for platforms that combine HIPAA-secure messaging with clinical functionality like care plan delivery and exercise video sharing. A tool that handles both reduces fragmented tooling and keeps all patient interactions in one compliant workspace.
Explore AC Health’s plans and features →
HIPAA Violation Penalties: What’s Actually at Stake
The financial consequences of non-compliance are severe, and they apply to small practices just as much as large health systems. In 2025, OCR levied more than $6.6 million in HIPAA fines.
The penalty structure has four tiers:
- Tier 1 (didn’t know, couldn’t have avoided): $141 to $35,581 per incident
- Tier 2 (should have known): $1,424 to $71,162 per incident
- Tier 3 (willful neglect, corrected): $14,232 to $71,162 per violation
- Tier 4 (willful neglect, uncorrected within 30 days): $71,162 to $2,134,831 per incident
A therapist texting a patient’s diagnosis via standard SMS without a written policy, consent, or BAA could face Tier 2 penalties at minimum. Even a single violation at that level could devastate a small practice financially and reputationally.
Proposed 2026 HIPAA Security Rule: What Therapists Should Know Now
The proposed HIPAA Security Rule update, published as a Notice of Proposed Rulemaking on January 6, 2025, signals where enforcement is heading even though it’s not yet final law.
Key proposed changes relevant to your texting policy:
- Encryption becomes mandatory, removing the current “addressable” designation that allows practices to justify not encrypting
- Multi-factor authentication (MFA) required for all systems accessing ePHI
- 72-hour incident reporting requirements (much tighter than the current framework)
- Annual penetration testing mandated
- Enhanced business associate oversight obligations
Even though the final rule hasn’t been issued, OCR’s enforcement priorities have already shifted toward the controls the proposal would require. Many of the proposed measures reflect what reasonable security looks like in 2026 regardless of any rulemaking outcome.
The practical takeaway: build MFA and mandatory encryption into your texting policy now. Don’t wait for the final rule to catch up with what regulators already expect.
Putting Your Texting Policy Into Practice
Writing a sample HIPAA-compliant texting policy for therapists is the critical first step, but a policy document sitting in a drawer protects nobody. Here’s how to make it operational:
- Draft your policy using the framework above, customized to your practice type and state requirements.
- Select a compliant platform and execute a BAA before sending a single patient message.
- Create your patient consent form as a separate document covering both HIPAA authorization and TCPA consent.
- Train all staff and document that training.
- Configure devices to meet the physical safeguard requirements in your policy.
- Schedule your first audit log review within 90 days.
- Set a calendar reminder for your annual policy review.
For practices already using a HIPAA-compliant platform for care plan delivery, expanding its use to cover all patient messaging is often the simplest path to full compliance.
Schedule a demo to see how AC Health handles HIPAA-secure messaging →
Frequently Asked Questions
Can a therapist legally text a patient?
Yes, but only under specific conditions. You need a HIPAA-compliant platform with a signed BAA, written patient consent acknowledging the risks, and an internal texting policy governing how messages are sent. The APA acknowledges that HIPAA allows patients to text providers with unencrypted messages if the patient is warned and consents, but for therapy specifically, the clinical sensitivity demands more than the bare legal minimum. Standard SMS alone is never compliant for PHI.
Is it HIPAA-compliant to text appointment reminders?
Appointment reminders are generally considered one of the safest types of text communication, but they still require compliance measures. Keep messages minimal (“You have an appointment Thursday at 2pm”), use an approved platform, and ensure consent is documented. Even appointment reminders via automated systems require TCPA consent.
Do I need a BAA with my texting app?
Absolutely. If your messaging platform handles any PHI on your behalf, the vendor is a business associate and must sign a BAA. Major consumer apps like iMessage, WhatsApp, and standard SMS carriers do not sign BAAs. If your vendor won’t sign one, find a different vendor.
How long do I need to keep consent forms and audit logs?
HIPAA authorization forms must be stored for a minimum of six years. Apply the same standard to your messaging audit logs, training records, and policy documentation. Many practices default to a seven-year retention window to provide a buffer.
What’s the difference between secure in-app messaging and SMS?
SMS travels across carrier networks with no encryption, no access controls, and no audit trail. Anyone who intercepts the message can read it. In-app secure messaging within a HIPAA-compliant platform keeps all data encrypted, within a controlled environment, with full logging. It’s the difference between sending a postcard and sending a sealed, tracked package.
What are the fines for texting HIPAA violations?
Penalties range from $141 per incident for unknowing violations up to $2,134,831 per incident for willful neglect that goes uncorrected. OCR enforcement affects small practices and solo therapists, not just large hospital systems. A single violation at the higher tiers can be financially devastating.
Can I use my personal phone for patient texting?
Only if your practice’s texting policy permits it and the device meets all physical safeguard requirements: encryption, passcode, auto-lock, remote wipe enrollment, disabled lock-screen previews, and (ideally) Mobile Device Management software. Many practices find it simpler to prohibit personal device use for patient communication entirely.
Does this policy apply to texts between therapists and other staff?
Yes. If staff members text each other about patients using PHI, those messages are subject to the same HIPAA requirements. Internal communication containing PHI must use approved platforms and follow the minimum necessary standard. Your policy should cover staff-to-staff messaging explicitly.
{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “@id”: “#faq”, “mainEntity”: [ { “@type”: “Question”, “@id”: “#faq-question-1”, “name”: “Can a therapist legally text a patient?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes, but only under specific conditions. You need a HIPAA-compliant platform with a signed BAA, written patient consent acknowledging the risks, and an internal texting policy governing how messages are sent. The APA acknowledges that HIPAA allows patients to text providers with unencrypted messages if the patient is warned and consents, but for therapy specifically, the clinical sensitivity demands more than the bare legal minimum. Standard SMS alone is never compliant for PHI.” } }, { “@type”: “Question”, “@id”: “#faq-question-2”, “name”: “Is it HIPAA-compliant to text appointment reminders?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Appointment reminders are generally considered one of the safest types of text communication, but they still require compliance measures. Keep messages minimal (\”You have an appointment Thursday at 2pm\”), use an approved platform, and ensure consent is documented. Even appointment reminders via automated systems require TCPA consent.” } }, { “@type”: “Question”, “@id”: “#faq-question-3”, “name”: “Do I need a BAA with my texting app?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Absolutely. If your messaging platform handles any PHI on your behalf, the vendor is a business associate and must sign a BAA. Major consumer apps like iMessage, WhatsApp, and standard SMS carriers do not sign BAAs. If your vendor won’t sign one, find a different vendor.” } }, { “@type”: “Question”, “@id”: “#faq-question-4”, “name”: “How long do I need to keep consent forms and audit logs?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “HIPAA authorization forms must be stored for a minimum of six years. Apply the same standard to your messaging audit logs, training records, and policy documentation. Many practices default to a seven-year retention window to provide a buffer.” } }, { “@type”: “Question”, “@id”: “#faq-question-5”, “name”: “What’s the difference between secure in-app messaging and SMS?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “SMS travels across carrier networks with no encryption, no access controls, and no audit trail. Anyone who intercepts the message can read it. In-app secure messaging within a HIPAA-compliant platform keeps all data encrypted, within a controlled environment, with full logging. It’s the difference between sending a postcard and sending a sealed, tracked package.” } }, { “@type”: “Question”, “@id”: “#faq-question-6”, “name”: “What are the fines for texting HIPAA violations?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Penalties range from $141 per incident for unknowing violations up to $2,134,831 per incident for willful neglect that goes uncorrected. OCR enforcement affects small practices and solo therapists, not just large hospital systems. A single violation at the higher tiers can be financially devastating.” } }, { “@type”: “Question”, “@id”: “#faq-question-7”, “name”: “Can I use my personal phone for patient texting?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Only if your practice’s texting policy permits it and the device meets all physical safeguard requirements: encryption, passcode, auto-lock, remote wipe enrollment, disabled lock-screen previews, and (ideally) Mobile Device Management software. Many practices find it simpler to prohibit personal device use for patient communication entirely.” } }, { “@type”: “Question”, “@id”: “#faq-question-8”, “name”: “Does this policy apply to texts between therapists and other staff?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes. If staff members text each other about patients using PHI, those messages are subject to the same HIPAA requirements. Internal communication containing PHI must use approved platforms and follow the minimum necessary standard. Your policy should cover staff-to-staff messaging explicitly.” } } ] }


