HIPAA-Compliant Texting for Medical and Dental Practices: What Actually Matters

Short answer: HIPAA does not ban texting patients — it bans careless handling of PHI. You need a signed BAA with your communications vendor, individual staff logins, audit logging and encryption in transit. Keep texts to logistics like appointment times, confirmations and form links, and move diagnoses, results and medications to a secure link or a call.
Patients overwhelmingly prefer texting their healthcare providers — and most front desks are terrified to do it. The fear is understandable but mostly misplaced: HIPAA does not ban texting. It bans being careless with protected health information (PHI). With the right platform configuration and a signed BAA, texting is not just legal — it's become standard of care for patient communication.
(This post is the texting deep dive, part of our complete HIPAA-compliant communications guide — which covers every channel: calls, voicemail, video, fax, and after-hours answering. If your question is specifically about appointment reminders — what they may contain, and the three different consents people confuse — that has its own guide: HIPAA appointment reminders.)
What HIPAA actually requires
- ▸A Business Associate Agreement (BAA) with any vendor that transmits or stores PHI on your behalf — including your communications platform
- ▸Access controls: only authorized staff can view patient conversations, with unique logins (no shared 'frontdesk' account)
- ▸Audit logging: a record of who accessed what, when
- ▸Encryption in transit for messages moving through the platform
- ▸Reasonable safeguards against misdirected messages (verified numbers, contact matching)
Reminders vs. PHI: the line that matters
Appointment reminders with limited information — name, date, time, provider — are broadly permissible under HIPAA's treatment-communication provisions, and patients can consent to more. The danger zone is clinical detail: diagnoses, test results, medications in an unencrypted SMS body. The practical pattern: use texts for logistics (confirmations, reschedules, balance notices, form links) and pull anything clinical behind a secure link or a phone call.
And for the clinical conversations that don't belong in a text thread? More practices now route those calls through AI voice agents built for medical front desks — same BAA discipline, but the phone gets answered at 2 a.m.
Patient consent, simply
Get texting consent at intake (a checkbox on your digital forms), honor opt-outs automatically, and document both. Standard SMS is technically unencrypted on the carrier leg — which is why consent plus minimum-necessary content is the compliant pattern the industry has settled on, and why regulators have focused enforcement on breaches and carelessness, not on reminder texts.
Your compliance checklist
- ▸Signed BAA with your communications vendor (Talk Is Cheap includes one on Real Talk and above)
- ▸Individual staff logins with role-based access to conversations and recordings
- ▸Texting consent captured at intake and stored
- ▸Templates reviewed so automated messages carry logistics, not clinical detail
- ▸Audit logs enabled; a named person reviews access quarterly
- ▸Staff trained: clinical content goes to secure channels, not SMS bodies
The bottom line
If your current vendor waves at 'HIPAA-friendly' but won't sign a BAA, that's your answer about them. Compliance is a configuration and a contract, not a premium SKU — and refusing to text patients in 2026 doesn't protect them, it just sends them to a practice that will.
Frequently asked questions
What does HIPAA actually require for texting patients?
Five things, all of them configuration rather than a product tier: a signed BAA with any vendor that transmits or stores PHI for you, access controls with individual staff logins rather than a shared front-desk account, audit logging of who accessed what and when, encryption in transit, and reasonable safeguards against misdirected messages such as verified numbers and contact matching.
Is standard SMS encrypted enough for HIPAA?
No — standard SMS is technically unencrypted on the carrier leg, which is exactly why the compliant pattern is consent plus minimum-necessary content rather than encryption alone. Keep the message to logistics and put anything clinical behind a secure link or a phone call. Enforcement attention has gone to breaches and carelessness, not to reminder texts.
How do I get and record patient consent to text?
Capture it at intake, typically as a checkbox on your digital forms, honor opt-outs automatically, and document both. Consent is what makes richer messages permissible, and the documented record is what you rely on later — so the storing matters as much as the asking.
What if my communications vendor won't sign a BAA?
Then they are not a HIPAA-compliant option for your practice, whatever the marketing says. A vendor that describes itself as "HIPAA-friendly" but declines to sign a Business Associate Agreement has answered the question. Talk Is Cheap includes a BAA on Real Talk and above.