Yes, you can text patients — but only when you use a HIPAA-compliant secure texting platform, execute a Business Associate Agreement with your vendor, and document patient preferences. Plain SMS to a patient's cell phone carrying protected health information is a violation unless the patient has expressly accepted the risk in writing. Here is what to do first:
- Stop any PHI transmission over unmanaged SMS immediately. Appointment times without names or identifiers carry lower risk; lab results, diagnoses, or clinical orders sent through a standard carrier text are not acceptable without documented patient consent to the risk.
- Map your texting use cases. Appointment reminders, clinical result notifications, internal staff orders, and telehealth links each carry different risk profiles and require different controls.
- Choose a compliant workflow. That means a secure texting platform (STP) with a signed BAA, documented patient communication preferences, and staff trained on message content limits.
The governing authorities are HHS's Privacy Rule and Security Rule, the Security Rule's general requirements at 45 CFR §164.306, administrative safeguards at 45 CFR §164.308, patient confidential communications rights at 45 CFR §164.522(b), and the CMS February 2024 memo confirming that texting orders is permissible through a compliant STP.
Key Takeaways
HIPAA texting compliance requires a compliant platform, a signed BAA, documented patient preferences, trained staff, and an annual risk analysis covering all messaging channels.
| Point | Details |
|---|---|
| Secure platform plus BAA first | No PHI should move through any texting channel until a BAA is signed and the platform meets Security Rule encryption and audit requirements. |
| Document patient preferences at intake | Capture communication preference and TCPA opt-in on the same intake form; store in the EHR and honor opt-outs immediately. |
| Minimum necessary content in every message | Strip messages to the minimum data needed; route clinical details to a secure portal and use text as a notification trigger only. |
| Train staff and audit regularly | Annual training plus quarterly audit log review catches the workflow drift that turns a compliant platform into a liability. |
| Cannatract automates the workflow | Cannatract connects your STP, EHR, and intake system into an auditable flow, built in 2–4 weeks with a fixed quote. |
Table of Contents
- When are HIPAA texting rules violated versus when is texting permitted?
- Which HIPAA rules apply to texting PHI?
- What technical and administrative safeguards does texting PHI require?
- What should a BAA with a texting vendor include?
- How do you document patient consent and communication preferences for texting?
- Is standard SMS or iMessage actually HIPAA compliant?
- How do TCPA and FCC rules intersect with HIPAA for automated texting?
- What policies and workflows does compliant texting require?
- What are the breach notification rules and penalties for texting violations?
- Quick answers to common real-world texting scenarios
- Compliance checklist: what your practice needs before texting PHI
- The real compliance gap most practices miss
- Cannatract builds compliant texting workflows healthcare teams actually use
- Sources
- FAQ
When are HIPAA texting rules violated versus when is texting permitted?
The answer turns on five factors: who is sending, what the message contains, which platform carries it, what the patient has requested or accepted, and whether your workforce has the controls in place to enforce those decisions consistently.
Factors that determine permissibility:
- Sender status. Only covered entities and their business associates are bound by HIPAA. A patient texting you is not a covered entity, so a patient-initiated text does not create a HIPAA obligation on the sender's side — though your response may.
- Message content. A text that says "Your 2 PM appointment is confirmed" contains no PHI if it carries no name, date of birth, condition, or account number. The moment a message ties an individual to a health condition, treatment, or payment record, it is PHI and the full Security Rule applies.
- Platform. Unencrypted carrier SMS is not a HIPAA-compliant transmission channel for PHI. A secure texting platform with encryption in transit and at rest, audit logging, and a signed BAA changes the analysis entirely.
- Documented patient preference. Under 45 CFR §164.522(b), patients have the right to request confidential communications by alternative means. If a patient requests text as their preferred channel and you document that request, you have a legal basis to text — even if the channel carries some risk, provided you have warned them.
- Workforce controls. A practice with no texting policy, no training, and no sanctions framework is exposed even when the platform is technically compliant.
Common scenarios:
- Appointment time only, no name or condition: Generally low risk; still confirm your platform and policy cover it.
- Lab results sent via carrier SMS: A violation unless the patient has signed a documented risk acknowledgment and you have warned them in writing per HHS guidance.
- Clinical orders texted staff-to-staff via an STP: Permissible per the CMS February 2024 memo, provided the platform meets Security Rule and Conditions of Participation requirements and CPOE remains the preferred entry method.
- Patient texts a photo of a wound: Patient-initiated, so the patient bears the transmission risk — but your reply and how you store that image must comply with HIPAA.
When a patient expressly requests text communication, document the request in the medical record, provide a written warning that unencrypted SMS is not fully secure, and record their acceptance. That documentation is your defense if OCR ever investigates.
Which HIPAA rules apply to texting PHI?
Three distinct HIPAA obligations converge on every text message that touches patient data.
The Privacy Rule and confidential communications
The Privacy Rule governs who may receive PHI and under what conditions. Its most directly relevant provision for texting is 45 CFR §164.522(b), which gives patients the right to request that you communicate with them by a specific means or at a specific location. A patient who asks you to text rather than call is exercising this right. You must accommodate reasonable requests, and you cannot require the patient to explain why they prefer that channel.
The HHS Privacy Rule resources also impose the minimum necessary standard: every disclosure of PHI must be limited to the information needed to accomplish the purpose. For texting, that means your message templates should be stripped of unnecessary identifiers, diagnosis codes, or clinical detail that is not required for the communication's purpose.
The Security Rule: general requirements and technical safeguards
45 CFR §164.306 sets the baseline: covered entities must protect the confidentiality, integrity, and availability of ePHI and guard against reasonably anticipated threats. A text message sent over an unencrypted channel to an unverified device is a reasonably anticipated threat. That is not a judgment call — it is the regulatory standard.
45 CFR §164.308 then specifies the administrative safeguards: risk analysis, workforce training, sanction policies, and oversight of business associates. Any messaging system that creates, receives, uses, or maintains ePHI falls under this framework. The HHS Security Rule resources map these requirements to specific implementation specifications, some required and some addressable.
Minimum necessary in practice
The minimum necessary standard is often where texting policies break down. A nurse who texts a patient's full name, date of birth, diagnosis, and medication list in a single message has almost certainly exceeded what the purpose required. Build your message templates around the minimum data set needed — typically a reference number, a callback number, or a generic prompt to log into a secure portal for details.
What technical and administrative safeguards does texting PHI require?
The Security Rule's technical safeguard requirements are not optional for any system that handles ePHI. Here is how they map to a texting environment:
Technical safeguards:
- Transmission encryption. Messages must be encrypted in transit. Standard SMS is not encrypted end-to-end under provider control. A compliant STP uses TLS or equivalent protocols.
- Encryption at rest. Messages stored on servers or devices must be encrypted at rest. This includes message archives and any attachments.
- Unique user authentication. Each staff member must log in with individual credentials. Shared logins are a Security Rule violation regardless of platform.
- Audit controls. The system must generate logs showing who sent what, to whom, and when. Audit trails are required under 45 CFR §164.308 and are your primary evidence in an OCR investigation.
- Automatic log-off. Devices and sessions must time out after a defined period of inactivity.
- Remote wipe capability. If a device carrying PHI is lost or stolen, you must be able to wipe it remotely.
Administrative and physical controls:
- Documented risk analysis covering messaging systems specifically
- Written texting policy with permitted content types and prohibited uses
- Workforce training on the policy, with records of completion
- Sanctions policy for misuse, applied consistently
- Device inventory tracking every device authorized to send or receive PHI via text
- Physical controls preventing unauthorized access to devices
| Control | Security Rule objective | Practical implementation |
|---|---|---|
| Transmission encryption | Protect ePHI against interception in transit (§164.306) | Deploy an STP using TLS or equivalent protocols; disable plain SMS for PHI |
| Encryption at rest | Protect stored ePHI from unauthorized access | Require AES-256 or equivalent on servers and mobile devices |
| Unique user authentication | Ensure accountability and access control (§164.308) | Enforce individual logins; prohibit shared credentials |
| Audit logging | Detect and investigate unauthorized access | Enable platform-level logs; retain per your retention policy |
| Remote wipe | Limit breach impact from lost/stolen devices | Enroll all devices in MDM (e.g., Microsoft Intune, Jamf) |
| Risk analysis | Identify and address vulnerabilities (§164.308) | Conduct annual risk assessment covering all messaging channels |
| Staff training | Reduce human-error incidents | Annual HIPAA training plus role-specific texting policy training |
Pro Tip: Integrate your secure texting platform with your EHR so that patient messages are automatically captured in the medical record. This solves two problems at once: it satisfies audit trail requirements and eliminates the manual step where staff forget to document a text exchange.
What should a BAA with a texting vendor include?
Any vendor that transmits, stores, or accesses PHI on your behalf is a business associate. That includes every secure texting platform you use. A signed BAA is not optional — it is a legal prerequisite before the vendor touches a single patient record.
HHS sample BAA provisions give you a starting framework. Build on it with these specific requirements for a texting vendor:
BAA checklist:
- Explicit description of permitted uses and disclosures of PHI through the platform
- Requirement that the vendor implement Security Rule-compliant technical safeguards (encryption, access control, audit logging)
- Breach notification timeline: the vendor must notify you within a defined period, short enough that you can meet your own 60-day OCR notification deadline
- Subcontractor rules: the vendor must require its own subcontractors (data centers, infrastructure providers) to sign equivalent BAAs
- Your right to audit the vendor's security controls or review third-party audit reports (SOC 2 Type II is a reasonable baseline)
- Liability allocation: clear language on which party bears responsibility for a breach caused by vendor negligence versus your misconfiguration
- Data return or destruction provisions at contract termination
Vendor selection checklist:
- Does the platform integrate with your EHR or practice management system?
- Does it provide exportable audit logs in a format your compliance team can review?
- What authentication modes does it support (SSO, MFA, biometric)?
- Does it support remote wipe via MDM integration?
- Can it scale to your message volume without degrading audit trail completeness?
- Does the vendor have a documented incident response plan and a named security contact?
The Joint Commission confirms that hospitals may use secure texting platforms for patient information and orders, provided the system meets HIPAA requirements and ensures record integrity and author identification. Verify that your vendor can demonstrate both.
How do you document patient consent and communication preferences for texting?
Patient consent for texting operates on two levels that are easy to conflate: HIPAA authorization and TCPA opt-in. They are not the same, and you need both when sending automated messages.
HIPAA consent and documented preferences:
Under HIPAA, you do not need a separate signed authorization to text a patient about their own care — the treatment, payment, and operations exception covers most clinical communications. What you do need is documentation of the patient's communication preference and, when using an unencrypted channel, a documented risk warning and acceptance.
A practical intake form entry might read: "I prefer to receive health-related communications by: [ ] phone call [ ] text message [ ] patient portal message [ ] email. I understand that text messages and email may not be fully secure and that I am accepting this risk by selecting these options."
That language, signed at intake and stored in the patient record, satisfies the HHS guidance requirement to warn patients and document their choice.
Under 45 CFR §164.522(b), if a patient requests a specific communication channel, you must accommodate it. Document the request, the date, and any warnings provided. If the patient later changes their preference, update the record and confirm the change in writing.
TCPA opt-in for automated messages:
The Telephone Consumer Protection Act adds a separate consent layer for automated or prerecorded messages sent to wireless numbers. HIPAA does not preempt TCPA. If you send automated appointment reminders via an autodialer or bulk messaging system, you need prior express written consent from the patient for that specific type of automated contact.
Best practice: capture TCPA opt-in at intake alongside your HIPAA preference documentation, using language that specifically identifies automated text messages as a contact method. Keep records of opt-in timestamps and the specific consent language the patient agreed to.
Opt-out handling:
Any patient who texts STOP must be removed from automated messaging immediately. Failure to honor opt-outs is a TCPA violation carrying civil liability independent of any HIPAA exposure.
Is standard SMS or iMessage actually HIPAA compliant?
The short answer: standard SMS is not a compliant channel for PHI without documented patient consent to the risk. iMessage is more nuanced but still falls short of full HIPAA compliance for most clinical use cases.
Why plain SMS falls short:
- Messages are transmitted through carrier infrastructure without end-to-end encryption under your control.
- No audit trail exists that you can access or export.
- Messages are cached on carrier servers and backed up to device cloud accounts (iCloud, Google Drive) outside your control.
- There is no mechanism for remote wipe of a specific message thread.
- No BAA is available from major carriers for standard SMS service.
The iMessage question:
Apple's iMessage encrypts messages end-to-end between Apple devices when both parties use iMessage. That encryption is real. But it does not solve the HIPAA problem because Apple does not sign BAAs for consumer iMessage, there are no audit logs accessible to your organization, and messages back up to iCloud under the patient's account settings. A staff member using their personal iPhone to send a patient's lab result via iMessage is still a violation.
When SMS is acceptable:
A non-PHI appointment reminder — "You have an appointment tomorrow. Call 555-0100 to reschedule" — sent via standard SMS carries minimal risk if it contains no name, condition, or account information. When a patient has signed a documented risk acknowledgment per HHS guidance, you have a defensible basis to use SMS for PHI — but a secure platform is still the better choice.
| Message type | Standard SMS | Secure texting platform |
|---|---|---|
| Appointment reminder (no PHI) | Acceptable with policy | Preferred |
| Lab result or diagnosis | Not acceptable without documented patient risk consent | Required |
| Clinical order (staff-to-staff) | Not acceptable | Required per CMS memo |
| Telehealth link (no PHI in link) | Generally acceptable | Preferred |
| Medication instructions | Not acceptable without documented patient risk consent | Required |
How do TCPA and FCC rules intersect with HIPAA for automated texting?
TCPA compliance is a parallel obligation that your HIPAA texting policy cannot ignore. The two frameworks overlap most visibly in appointment reminders and bulk outreach campaigns.
The TCPA baseline:
The TCPA requires prior express consent before sending autodialed or prerecorded messages to wireless numbers. The Supreme Court's 2021 decision in Facebook v. Duguid narrowed the definition of an autodialer, requiring that the system use a random or sequential number generator to produce or dial numbers. Many modern healthcare messaging platforms may not meet that narrowed definition. But the practical advice from compliance professionals remains: treat any bulk or automated messaging system as subject to TCPA and obtain express written consent regardless.
Where HIPAA and TCPA overlap:
Appointment reminders are the most common intersection. You may have HIPAA authority to send a reminder as a treatment-related communication, but if you send it via an automated system to a wireless number, TCPA consent is also required. The FCC has issued guidance confirming that healthcare-related calls and texts can qualify for certain TCPA exemptions, but those exemptions are narrow and condition-specific. Do not rely on them without legal review.
Professional organizations note that TCPA requirements add a second compliance layer for automated or bulk texting, and that appointment reminders sent via automated systems can trigger TCPA opt-in obligations even when also subject to HIPAA.
Practical alignment:
- Capture HIPAA communication preferences and TCPA opt-in on the same intake form, using separate consent language for each.
- Involve your legal and compliance teams when deploying any automated messaging system.
- Document opt-in timestamps, the consent language shown, and the patient's affirmative action.
- Build opt-out handling into the system so STOP responses are processed automatically and immediately.
What policies and workflows does compliant texting require?
A compliant texting workflow has five stages: preference capture, authentication, message creation, sending, and EHR documentation. Each stage has a responsible role and a control point.
Recommended workflow:
- Intake (front desk or patient portal): Capture communication preference and TCPA opt-in. Record in EHR. Flag patients who have accepted SMS risk with a documented warning.
- Authentication (staff): Log into the secure texting platform with individual credentials. No shared logins.
- Message creation (clinical or admin staff): Select a pre-approved template or compose a message using minimum necessary content. No diagnosis codes, full medication names, or account numbers unless the message type specifically requires them.
- Sending (platform): Message routes through the encrypted STP. Platform logs sender, recipient, timestamp, and content.
- EHR documentation (staff or automated integration): Message thread or summary is captured in the patient record within the same session or via automated EHR sync.
Policy elements your written texting policy must include:
- Permitted message types and pre-approved templates for each
- Prohibited content (full SSN, financial account numbers, detailed diagnoses in low-security channels)
- Device authorization list and MDM enrollment requirement
- Incident reporting procedure: staff must report a misdirected text within one business day
- Training frequency: initial training at hire, annual refresher, and ad hoc training after any incident
- Sanctions for policy violations, applied consistently regardless of seniority
Message template guidance:
For low-risk messages: "Reminder: your appointment is scheduled. Call [number] with questions."
For higher-risk communications (results, instructions): route through the secure portal with a text prompt: "You have a secure message from [Practice Name]. Log in at [portal URL] to view." This keeps PHI off the text channel entirely while still using text as a notification trigger.
When a patient calls back asking for details, escalate to a phone call or portal message rather than expanding the text thread.
What are the breach notification rules and penalties for texting violations?
A texting incident becomes a reportable breach when it involves an impermissible disclosure of unsecured PHI and the disclosure cannot be demonstrated to carry a low probability of compromise. The four-factor risk assessment OCR uses covers: the nature and extent of the PHI involved, who accessed it, whether PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.
Notification timelines:
- Breaches affecting 500 or more individuals in a state or jurisdiction: notify HHS and prominent media outlets within 60 days of discovering the breach.
- Breaches affecting fewer than 500 individuals: notify HHS annually (within 60 days of the end of the calendar year) and notify affected individuals without unreasonable delay and within 60 days of discovery.
- Individual notification is required in all cases, regardless of breach size.
OCR enforcement approach:
OCR investigates complaints and conducts audits. Penalties are tiered by culpability: unknowing violations carry lower penalties than willful neglect. Willful neglect that is not corrected carries the highest penalty tier. A practice that had no texting policy, no BAA with its messaging vendor, and no staff training is in the worst possible position if a texting breach triggers an investigation.
Hypothetical enforcement scenarios:
A small clinic sends appointment reminders via a staff member's personal iPhone, including patient names and appointment types. A phone is lost. The clinic has no MDM, no remote wipe capability, and no BAA with any messaging vendor. OCR opens an investigation, finds systemic noncompliance, and issues a corrective action plan requiring a full risk analysis, written policies, staff training, and a BAA with a compliant vendor — plus a monetary penalty.
A hospital uses a compliant STP but has not trained staff on minimum necessary content. A nurse texts a patient's full medication list to a colleague's personal cell phone. The hospital self-reports, demonstrates it has a written policy and BAA, and shows the incident was an isolated training failure. OCR accepts a corrective action plan without a monetary penalty.
The difference between those two outcomes is documentation, policy, and a BAA.
Quick answers to common real-world texting scenarios
Can I text lab results to a patient? Yes, but only through a secure texting platform with a BAA, or if the patient has signed a documented risk acknowledgment for unencrypted SMS. Plain SMS without that documentation is a violation.
Can staff text clinical orders to other staff? Yes, through a compliant STP that meets Security Rule requirements and integrates with your EHR. The CMS February 2024 memo confirms this, with the caveat that CPOE remains the preferred order-entry method.
Can a patient text a photo of a wound to their provider? The patient initiates the transmission, so the patient bears the risk of that transmission. Your obligation is to store and handle the received image in compliance with HIPAA — which means it must be documented in the medical record and not left sitting in a personal email inbox or SMS thread.
Is texting a patient's name a HIPAA violation? A name alone is not PHI. A name combined with a health condition, appointment type, medication, or any other health-related identifier is PHI. "John, your prescription is ready" is PHI. "Your appointment is confirmed" with no name is not.
Red flags that should trigger escalation to a secure portal or phone call:
- The message requires including a diagnosis, medication name, or test result
- The patient has not opted in to text communication
- The message is going to a number you cannot verify belongs to the patient
- The content requires the patient to take a clinical action (e.g., adjust a medication dose)
Compliance checklist: what your practice needs before texting PHI
Use this checklist to verify readiness. Assign each item to a responsible person and set a completion date.
Governance and policy:
- Written HIPAA texting policy approved by compliance officer or legal counsel
- Policy covers permitted message types, prohibited content, device rules, and sanctions
- Incident reporting procedure documented and communicated to staff
Vendor and BAA:
- Secure texting platform selected and evaluated against Security Rule requirements
- BAA signed with the STP vendor before any PHI is transmitted
- BAA reviewed for breach notification timelines, subcontractor rules, and audit access
Patient preferences:
- Intake form captures communication preference and TCPA opt-in with separate consent language
- Risk warning language included for patients selecting SMS or email
- Preference records stored in EHR and accessible to scheduling and clinical staff
Technical controls:
- All devices authorized for texting enrolled in MDM with remote wipe enabled
- Unique user credentials enforced; shared logins eliminated
- Audit logging enabled and retention period defined
- EHR integration or manual documentation process in place for message threads
Training and monitoring:
- All staff who send or receive patient texts have completed HIPAA texting policy training
- Training records maintained with completion dates
- Audit log review scheduled (quarterly at minimum)
- Annual risk analysis updated to include messaging systems
Risk analysis:
- Risk analysis conducted covering all messaging channels (SMS, STP, email, portal)
- Identified risks documented with mitigation plans and responsible owners
- Risk analysis reviewed and updated after any incident or system change
The real compliance gap most practices miss
Most HIPAA texting guidance focuses on platform selection. Pick the right STP, sign the BAA, and you are done — that is the conventional framing. It is incomplete, and the gap it leaves is where most real-world violations actually happen.
The harder problem is workflow consistency. A practice can deploy a compliant STP on Monday and have a nurse texting lab results from her personal iPhone by Friday because the STP "takes too long to log into." The platform was right. The workflow was not designed for the way staff actually work.
Small practices should prioritize three things above all else: a secure texting platform with a simple, fast login (friction kills compliance), a one-page intake consent form that captures both HIPAA preference and TCPA opt-in in under two minutes, and a written policy that staff have actually read and signed. Sophisticated audit workflows matter less when you are a two-provider clinic. What matters is that the right channel is the easiest channel.
Hospitals face a different problem. The STP must integrate with the EHR and the CPOE system, or staff will route around it. The Joint Commission and CMS both require that texted orders be captured in the medical record with author identification. If your STP does not write back to the EHR automatically, you have a documentation gap that will surface in a survey. Enterprise implementations need formal vendor validation, integration testing, and audit log review built into the compliance calendar — not as a one-time project but as an ongoing operational control.
The pitfall both settings share: treating the BAA as the finish line. The BAA is the starting line. What happens after you sign it — training, monitoring, incident response, and annual risk analysis updates — is where compliance is actually maintained or lost.
Cannatract builds compliant texting workflows healthcare teams actually use
Healthcare providers running on manual intake forms, disconnected messaging tools, and staff who route around the STP because it is clunky are not just exposed to OCR — they are losing time on every patient interaction. Cannatract designs and deploys workflow automation systems that connect your secure texting platform, EHR, and intake processes into a single, auditable flow.

A typical engagement covers: automated patient preference capture at intake, TCPA opt-in documentation, EHR sync for message threads, and staff-facing templates that enforce minimum necessary content by default. For practices that need a compliant patient portal or consent capture tool, Cannatract builds those too. The build timeline is 2–4 weeks for a defined automation scope, with a fixed quote before any work begins — no open-ended retainers and no surprise invoices.
If you want to see exactly where your current texting workflow breaks down before committing to a build, book a free automation audit at Cannatract. You will leave with a clear picture of your gaps and a prioritized list of what to fix first. Check Cannatract's pricing page for current engagement options.
Sources
Primary authorities to bookmark for ongoing compliance reference:
- Texting of Patient Information and Orders for Hospitals and CAHs | CMS
- Ecfr
- Hhs
- Texting - Use of Secure Text Messaging for Patient Information and Orders | Joint Commission
- Is Texting in Violation of HIPAA? 2026 Update
Tip: Bookmark the OCR enforcement page and the CMS policy memos index. Both are updated when new guidance or corrective action resolutions are published, and both are the first place to check when a new enforcement trend emerges.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
What is the new HIPAA rule for texting in 2026?
There is no new standalone HIPAA texting statute. The governing framework remains the Privacy Rule and Security Rule, supplemented by the CMS February 2024 memo confirming that texting patient information and orders is permissible through a compliant secure texting platform with a BAA.
Are iPhone text messages HIPAA compliant?
Standard SMS and consumer iMessage are not HIPAA compliant for PHI. Apple does not sign BAAs for consumer iMessage, there are no accessible audit logs, and messages back up to iCloud outside your organization's control. A compliant secure texting platform is required for clinical PHI.
Is texting a patient's name a HIPAA violation?
A name alone is not PHI. A name combined with any health-related information — a condition, appointment type, medication, or test result — is PHI and must be handled accordingly. "Your appointment is confirmed" is not a violation; "John, your lab results are ready" is.
Are text messages covered by the HIPAA Security Rule?
Yes. The Security Rule applies to all electronic PHI, which includes any text message that contains or references a patient's health information. 45 CFR §164.306 requires covered entities to protect ePHI against reasonably anticipated threats, and unencrypted SMS is a reasonably anticipated threat.
When does a misdirected text become a reportable breach?
A misdirected text containing PHI is a reportable breach unless a four-factor risk assessment demonstrates a low probability that the PHI was compromised. In practice, a message containing a patient's name and a health identifier sent to an unknown third party is very difficult to clear through that assessment, and individual notification plus HHS reporting is typically required within 60 days of discovery.
