Guide

Emailing and texting patients: consent, encryption, and configuration

Summary

Yes. HIPAA does not ban emailing or texting patients; the Privacy Rule permits patient communication and the Security Rule sets scalable safeguards for electronic PHI. Encryption is strongly preferred but treated as addressable, so a patient may choose to receive unencrypted messages after you explain the risk and document it. Use a vendor that will sign a business associate agreement, send only the minimum necessary, and keep promotional messages behind a signed authorization.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

Is emailing or texting patients allowed under HIPAA?

Yes. HIPAA does not prohibit communicating with patients by email or text — the Privacy Rule permits a covered entity to communicate with patients about their care, including electronically 1. What governs the how is the Security Rule, which requires administrative, physical, and technical safeguards for electronic PHI and is explicitly scaled to the size and resources of the practice 2. A solo clinician is not held to a hospital's controls; you are held to what is reasonable for a one-person office.

The question is never whether, but how safely. Email and SMS both carry PHI across networks you do not control, so the rule asks you to assess the risk and apply safeguards proportionate to it. That assessment — not a blanket ban — is the actual legal obligation, and it is the same analysis whether you use a dedicated practice email or a texting tool.

Encryption: required, addressable, or the patient's choice?

Encryption of ePHI is what the Security Rule calls addressable, not optional-to-ignore: you either implement it, or document why an equivalent safeguard is reasonable in your setting 3. In practice, that means encrypted transmission is the strongly preferred default. But the Privacy Rule also lets a patient decide to receive communications by less secure means — a patient can ask you to email them in ordinary text after you have explained the risk that others might read it 1.

Warn, then honor the request, then write it down. If a patient wants plain email or standard SMS, the compliant path is: explain that the channel is not secure, confirm they still want it, and document that conversation. You have met your obligation by warning and recording the choice; you are not required to refuse. Your risk analysis is where you decide which channels you offer at all 2.

Getting and documenting the patient's preference

Capture communication preferences in writing at intake, because the Privacy Rule gives patients a right to request confidential communications by alternative means or at alternative locations, and you must accommodate reasonable requests 1. A one-page form that lists email, text, phone, and portal, asks which the patient authorizes, and notes any address they do not want used, resolves most of this before the first message goes out.

Build the record so a later dispute is easy to answer. Note the date, the channels the patient approved, the risk warning you gave for any unsecured channel, and the patient's signature. When a family member later asks why you texted a certain number, or a patient questions a message, the intake form answers it. Revisit the preferences if a patient changes numbers or asks you to stop using a channel.

Which tools need a business associate agreement

Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and requires a signed BAA before it touches patient data 4. That reaches your email host, a secure-messaging or texting platform, and a telehealth tool — but not the patient's own phone or email account, because the patient is not your business associate. The practical filter: if the company's servers hold or route your patients' messages, you need the agreement.

Consumer apps usually will not sign one. A standard personal email account or a free consumer chat app generally does not offer a BAA, which is why a dedicated practice email on a platform that will sign is the cleaner foundation. For telehealth specifically, the COVID-era enforcement discretion has ended, so the video and messaging tools you use must run on HIPAA-compliant arrangements with a BAA in place 5. Do not assume a tool is covered because it is popular; confirm the signed agreement.

Texting carries risks email does not

Standard SMS travels through carrier infrastructure unencrypted, lands on a lock screen anyone nearby can read, and often backs up to a cloud account you do not control — so texting deserves tighter limits than email. Apply the minimum-necessary principle hard: a text can confirm an appointment time without naming the condition, the medication, or anything a glance at a locked phone would expose 1. The safest texts carry no clinical content at all.

Keep clinical substance off SMS. Appointment reminders, a request to call the office, or a portal notification are low-risk; a discussion of symptoms, results, or diagnosis belongs in a secure channel or the portal. The same discipline that governs voicemail and answering services applies here — say only what a stranger reading it could see without harm. If you would not leave it on a voicemail a roommate might hear, do not send it as a text.

Marketing texts, and the short policy that ties it together

Appointment reminders and care-related messages are treatment communications and need no separate authorization, but a promotional message — a newsletter, a service you are selling, a wellness offer — is marketing and generally requires the patient's signed authorization first 7. The line is purpose: reminding a patient about their own care is permitted; using their contact information to sell them something is not, absent authorization.

Write it down once, in a page. Solo practices meet this obligation with a short written policy backed by a real risk analysis, and the free Security Risk Assessment tool that ONC and OCR publish is sized for exactly a one- or two-person office 6. Run the security risk analysis, solo edition, name the channels you offer and their safeguards, record how you capture patient consent, and keep the file. That document — plus a signed intake preference and a BAA per vendor — is what an investigator would ask to see, and what a lost phone or the contingency plan you keep for device loss would rely on.

Common questions

Not in every case. Encryption is an addressable specification, meaning you implement it or document an equally reasonable alternative for your setting. Encrypted transmission is the safe default, but a patient may choose to receive plain email after you explain the risk. The compliant move is to warn them, honor the choice, and document it — not to refuse all unencrypted contact.

A reminder that carries no clinical detail is low-risk, but a personal phone raises questions about backups, lock-screen exposure, and whether the number is a practice line. Keep the content to the minimum necessary — a time and a request to call — and consider a dedicated practice number or a secure messaging tool. Document the patient's consent to be texted at that number.

If the provider stores or transmits your patients' PHI, yes — it is a business associate and needs a signed agreement before it handles patient data. Consumer email accounts generally will not sign one, which is why a practice email on a platform that offers a BAA is the cleaner setup. The patient's own email account, by contrast, is not your business associate.

A patient may initiate contact by any channel they choose, and responding in kind is permitted once you have made them aware of the risk. Good practice is to note the risk in your reply or intake materials and to record their preference. You are not responsible for the security of the patient's own account, only for reasonable safeguards on your side.

It depends on content. A care-related notice is a permitted communication, but a promotional newsletter is marketing and generally requires each recipient's signed authorization. Sending to visible recipients also exposes the patient list itself. If you send any bulk message, use blind fields, keep the content non-promotional or authorized, and honor opt-outs.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule permits communicating with patients, applies minimum necessary, and grants the right to request confidential communications by alternative means.
  2. 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scalable to the practice, and anchored in a risk analysis.
  3. 3.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe operative Security Rule text treating encryption as an addressable implementation specification.
  4. 4.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor transmitting or storing PHI on the practice's behalf is a business associate requiring a signed BAA.
  5. 5.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat the COVID-era enforcement discretion has ended and telehealth messaging and video tools must run on HIPAA-compliant arrangements with a BAA.
  6. 6.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat ONC and OCR publish a free Security Risk Assessment tool sized for small practices to run the required risk analysis.
  7. 7.HHS Office for Civil Rights (2026). Marketing. U.S. Department of Health and Human Services. linkThat promotional messages to patients are marketing and generally require a signed authorization, distinct from permitted treatment communications.

https://www.gale.care/for-providers/hip-email-texting-patients · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)