Emailing and texting patients: consent, encryption, and configuration
Summary
Yes. HIPAA does not ban emailing or texting patients; the Privacy Rule permits patient communication and the Security Rule sets scalable safeguards for electronic PHI. Encryption is strongly preferred but treated as addressable, so a patient may choose to receive unencrypted messages after you explain the risk and document it. Use a vendor that will sign a business associate agreement, send only the minimum necessary, and keep promotional messages behind a signed authorization.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
Is emailing or texting patients allowed under HIPAA?
Yes. HIPAA does not prohibit communicating with patients by email or text — the Privacy Rule permits a covered entity to communicate with patients about their care, including electronically 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule permits communicating with patients, applies minimum necessary, and grants the right to request confidential communications by alternative means.. What governs the how is the Security Rule, which requires administrative, physical, and technical safeguards for electronic PHI and is explicitly scaled to the size and resources of the practice 2Ref 2HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to the practice, and anchored in a risk analysis.. A solo clinician is not held to a hospital's controls; you are held to what is reasonable for a one-person office.
The question is never whether, but how safely. Email and SMS both carry PHI across networks you do not control, so the rule asks you to assess the risk and apply safeguards proportionate to it. That assessment — not a blanket ban — is the actual legal obligation, and it is the same analysis whether you use a dedicated practice email or a texting tool.
Encryption: required, addressable, or the patient's choice?
Encryption of ePHI is what the Security Rule calls addressable, not optional-to-ignore: you either implement it, or document why an equivalent safeguard is reasonable in your setting 3Ref 3Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The operative Security Rule text treating encryption as an addressable implementation specification.. In practice, that means encrypted transmission is the strongly preferred default. But the Privacy Rule also lets a patient decide to receive communications by less secure means — a patient can ask you to email them in ordinary text after you have explained the risk that others might read it 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule permits communicating with patients, applies minimum necessary, and grants the right to request confidential communications by alternative means..
Warn, then honor the request, then write it down. If a patient wants plain email or standard SMS, the compliant path is: explain that the channel is not secure, confirm they still want it, and document that conversation. You have met your obligation by warning and recording the choice; you are not required to refuse. Your risk analysis is where you decide which channels you offer at all 2Ref 2HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to the practice, and anchored in a risk analysis..
Getting and documenting the patient's preference
Capture communication preferences in writing at intake, because the Privacy Rule gives patients a right to request confidential communications by alternative means or at alternative locations, and you must accommodate reasonable requests 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule permits communicating with patients, applies minimum necessary, and grants the right to request confidential communications by alternative means.. A one-page form that lists email, text, phone, and portal, asks which the patient authorizes, and notes any address they do not want used, resolves most of this before the first message goes out.
Build the record so a later dispute is easy to answer. Note the date, the channels the patient approved, the risk warning you gave for any unsecured channel, and the patient's signature. When a family member later asks why you texted a certain number, or a patient questions a message, the intake form answers it. Revisit the preferences if a patient changes numbers or asks you to stop using a channel.
Which tools need a business associate agreement
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and requires a signed BAA before it touches patient data 4Ref 4HHS Office for Civil Rights (2026).Business Associates.That a vendor transmitting or storing PHI on the practice's behalf is a business associate requiring a signed BAA.. That reaches your email host, a secure-messaging or texting platform, and a telehealth tool — but not the patient's own phone or email account, because the patient is not your business associate. The practical filter: if the company's servers hold or route your patients' messages, you need the agreement.
Consumer apps usually will not sign one. A standard personal email account or a free consumer chat app generally does not offer a BAA, which is why a dedicated practice email on a platform that will sign is the cleaner foundation. For telehealth specifically, the COVID-era enforcement discretion has ended, so the video and messaging tools you use must run on HIPAA-compliant arrangements with a BAA in place 5Ref 5HHS Office for Civil Rights (2026).HIPAA and Telehealth.That the COVID-era enforcement discretion has ended and telehealth messaging and video tools must run on HIPAA-compliant arrangements with a BAA.. Do not assume a tool is covered because it is popular; confirm the signed agreement.
Texting carries risks email does not
Standard SMS travels through carrier infrastructure unencrypted, lands on a lock screen anyone nearby can read, and often backs up to a cloud account you do not control — so texting deserves tighter limits than email. Apply the minimum-necessary principle hard: a text can confirm an appointment time without naming the condition, the medication, or anything a glance at a locked phone would expose 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule permits communicating with patients, applies minimum necessary, and grants the right to request confidential communications by alternative means.. The safest texts carry no clinical content at all.
Keep clinical substance off SMS. Appointment reminders, a request to call the office, or a portal notification are low-risk; a discussion of symptoms, results, or diagnosis belongs in a secure channel or the portal. The same discipline that governs voicemail and answering services applies here — say only what a stranger reading it could see without harm. If you would not leave it on a voicemail a roommate might hear, do not send it as a text.
Marketing texts, and the short policy that ties it together
Appointment reminders and care-related messages are treatment communications and need no separate authorization, but a promotional message — a newsletter, a service you are selling, a wellness offer — is marketing and generally requires the patient's signed authorization first 7Ref 7HHS Office for Civil Rights (2026).Marketing.That promotional messages to patients are marketing and generally require a signed authorization, distinct from permitted treatment communications.. The line is purpose: reminding a patient about their own care is permitted; using their contact information to sell them something is not, absent authorization.
Write it down once, in a page. Solo practices meet this obligation with a short written policy backed by a real risk analysis, and the free Security Risk Assessment tool that ONC and OCR publish is sized for exactly a one- or two-person office 6Ref 6Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC and OCR publish a free Security Risk Assessment tool sized for small practices to run the required risk analysis.. Run the security risk analysis, solo edition, name the channels you offer and their safeguards, record how you capture patient consent, and keep the file. That document — plus a signed intake preference and a BAA per vendor — is what an investigator would ask to see, and what a lost phone or the contingency plan you keep for device loss would rely on.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule permits communicating with patients, applies minimum necessary, and grants the right to request confidential communications by alternative means.
- 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to the practice, and anchored in a risk analysis.
- 3.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The operative Security Rule text treating encryption as an addressable implementation specification.
- 4.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor transmitting or storing PHI on the practice's behalf is a business associate requiring a signed BAA.
- 5.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat the COVID-era enforcement discretion has ended and telehealth messaging and video tools must run on HIPAA-compliant arrangements with a BAA.
- 6.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC and OCR publish a free Security Risk Assessment tool sized for small practices to run the required risk analysis.
- 7.HHS Office for Civil Rights (2026). Marketing. U.S. Department of Health and Human Services. linkThat promotional messages to patients are marketing and generally require a signed authorization, distinct from permitted treatment communications.
https://www.gale.care/for-providers/hip-email-texting-patients · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.