Skip to main content
Best Practices

Is SMS Texting HIPAA Compliant?

Over the last 4 months I have given close to 200 demos of our secure messaging application, qliqConnect, to a variety of organizations, ranging from solo practices to large health systems... and just about everything in between. While our primary objective is to help healthcare professionals communicate securely and efficiently, there is no denying that the “SMS problem” is at the forefront of the compliance consciousness.

2 min read
sms hipaa compliance|is sms hipaa compliant

Over the last 4 months I have given close to 200 demos of our secure messaging application, qliqConnect, to a variety of organizations, ranging from solo practices to large health systems... and just about everything in between. While our primary objective is to help healthcare professionals communicate securely and efficiently, there is no denying that the “SMS problem” is at the forefront of the compliance consciousness.

SMS Texting by Healthcare Professionals

is sms hipaa compliant

The “SMS problem” is, of course, the widespread use of SMS-based texting by healthcare professionals to communicate sensitive protected health information (PHI). While this is not exactly a new problem, it is becoming clear that the heightening enforcement of HIPAA and HITECH privacy and security regulations by both the Office of Civil Rights (OCR) and state attorney general offices is forcing covered entities to take a much closer look at previously ignored gaps.

“Why isn’t SMS Texting HIPAA-compliant?”

Despite the explosive growth in organizations seeking a secure alternative to SMS, the question I am most frequently asked is, “Why isn’t SMS HIPAA-compliant?” On one level, it’s a good thing that so many organizations are getting the word and are beginning to explore alternative solutions. On another level, however, I think the general lack of understanding of SMS’ inherent limitations helps to perpetuate the belief by end users that it’s not as bad as people make it out to be. As one CIO lamented, “it’s pretty hard to convince the docs to stop texting when I can’t draw a clear picture for them why they shouldn’t.”

HIPAA Compliant SMS Texting

We couldn’t agree more, so we created this infographic in the hopes that users can understand why SMS - while great for exchanging recipes with your new BFF - might just not be the best way to exchange PHI.

Frequently Asked Questions

Find answers to common questions about this topic.

SMS messages are transmitted unencrypted, stored on multiple servers, and can be easily intercepted or accessed by unauthorized parties. This creates significant privacy vulnerabilities when sharing protected health information (PHI) that violate HIPAA security requirements.

Yes, healthcare providers can face HIPAA violations and penalties from the Office of Civil Rights (OCR) and state attorney general offices for transmitting PHI via unsecured SMS. Enforcement of HIPAA and HITECH regulations has increased significantly in recent years.

Healthcare organizations should implement HIPAA-compliant secure messaging applications that encrypt communications and provide proper access controls. These solutions are specifically designed to protect PHI while maintaining efficient communication between healthcare professionals.

SMS may be acceptable for general communications that don't contain PHI, such as appointment reminders with minimal patient identifiers or internal administrative messages. However, any communication containing specific patient health information requires HIPAA-compliant secure messaging platforms.

Leaders should clearly explain the security vulnerabilities of SMS and provide easy-to-use, HIPAA-compliant alternatives. Education about potential legal consequences and demonstrating secure messaging solutions can help staff understand the importance of compliance.

Krishna Kurapati

Written by

Krishna Kurapati

Founder & CEO

Founder & CEO of QliqSOFT with 20+ years of healthcare technology experience.

View all posts

Related Articles

wellpoint hipaa breach alert|wellpoint hipaa breach settlement
Best Practices

HIPAA Breach Alert: WellPoint fined $1.7M

In what is believed to be one of the larger HIPAA breach settlements in recent memory, health insurer WellPoint has agreed to settle with HHS for $1.7M stemming from a 2009 and 2010 incident where WellPoint impermissibly disclosed the ePHI of over 600,000 individuals through an unsecured online application. During its investigation, OCR found that WellPoint had not enacted the appropriate administrative, technical, and physical safeguards mandated under HIPAA.

Krishna KurapatiKrishna Kurapati
1 min read
2m left