Skip to main content
Best Practices

Why Risk HIPAA Violation for Texting, When Compliance is Free?

HIPAA violations, the bane of Healthcare IT specialists around the country, are a large problem for many doctors, nurses, and healthcare administrators. Physicians find it easy to communicate with texting, but the vulnerability of these platforms and the sensitive nature of the data they are communicating, make it a bad solution.

3 min read
hipaa violations in small healthcare practices|

HIPAA violations, the bane of Healthcare IT specialists around the country, are a large problem for many doctors, nurses, and healthcare administrators. Physicians find it easy to communicate with texting, but the vulnerability of these platforms and the sensitive nature of the data they are communicating, make it a bad solution. Balancing security and the importance of physician-to-physician communication is no easy task and the consequences are very high. HIPAA violations have cost large hospitals, as well as small practices, large sums of money and made collaborating with their colleagues very difficult. ( As seen in this Infographic ) One major example of a large organization that has fallen victim to bad privacy policies in their operations is the Alaska Department of Health and Social Services (DHSS). They were forced to pay $1.7 million to settle the dispute. This kind of fine is expected when a hospital has a large breach. In actuality, a flash drive suspected of containing ePHI was stolen along with a vehicle. There was no concrete evidence that the USB even contained ePHI. As this example shows, even small infractions can be quite costly.HIPAA Violations on Small Healthcare PracticesSmall practices are also affected by HIPAA violations. In 2008, a nurse accidentally revealed patient information to her husband through text messaging and he later used them in a suit against the patient. This nurse was terminated and the private practice was fined $250,000 for HIPAA violations. Fines like these not only affect hospitals and medical practices financially but also affect reputation among peer groups. With the increased use of smart devices in the healthcare, the risk is only going to rise. qliqSOFT and several others have developed applications to help ease the implementation of HIPAA compliance. For example, qliqSOFT’s qliqConnect can be used by everyone within the medical field. It allows for texting, sending patient files, images, lab results and more in an encrypted and safe format.

QliqSoft Makes HIPAA Violations Obsolete with Secure Texting App

As always implementing any new IT solution has hidden costs of training and support even if the such solution is free. However, QliqSOFT has made it as easy as setting up a linkedIn group and built the application to mimic familiar SMS on iphone & Android and instant messaging on desktop computers.

HIPAA compliance healthcare it

With encryption of data on the device, end-to- end encryption of messages between sender and receiver and advanced security features such as idle lockout, remote lock, and remote wipe of data in the event of lost or misplaced device, the risk of HIPAA violation is reduced significantly for texting.

Frequently Asked Questions

Find answers to common questions about this topic.

HIPAA violation fines can range from hundreds of thousands to millions of dollars. Large organizations like Alaska DHSS paid $1.7 million, while small practices can face fines of $250,000 or more for violations involving patient data breaches.

No, regular text messaging should not be used for patient information as it lacks proper encryption and security measures required by HIPAA. Standard SMS platforms are vulnerable and can lead to costly violations and compromised patient privacy.

HIPAA-compliant messaging apps should include end-to-end encryption, device-level data encryption, idle lockout features, and remote lock/wipe capabilities. These security measures protect patient information if devices are lost or stolen.

Yes, there are free HIPAA-compliant messaging solutions available, such as qliqConnect, that allow secure texting and sharing of patient files, images, and lab results. These platforms are designed to be user-friendly while maintaining required security standards.

Healthcare staff who cause HIPAA violations can face termination and their organizations may be subject to significant fines. For example, a nurse was fired after accidentally sharing patient information via text, resulting in a $250,000 fine for the practice.

Krishna Kurapati

Written by

Krishna Kurapati

Founder & CEO

Founder & CEO of QliqSOFT with 20+ years of healthcare technology experience.

View all posts

Related Articles

wellpoint hipaa breach alert|wellpoint hipaa breach settlement
Best Practices

HIPAA Breach Alert: WellPoint fined $1.7M

In what is believed to be one of the larger HIPAA breach settlements in recent memory, health insurer WellPoint has agreed to settle with HHS for $1.7M stemming from a 2009 and 2010 incident where WellPoint impermissibly disclosed the ePHI of over 600,000 individuals through an unsecured online application. During its investigation, OCR found that WellPoint had not enacted the appropriate administrative, technical, and physical safeguards mandated under HIPAA.

Krishna KurapatiKrishna Kurapati
1 min read
hipaa data breaches|securing your healthcare organization from HIPAA data breaches
Best Practices

HIPAA Data Breaches: Bad Technology or Bad Training?

As regular readers of the qliqSOFT blog are now aware, the HIPAA Omnibus changes have been in effect for just over two weeks. In the wake of the September 23 compliance deadline, HIPAA compliance should be on the minds of most covered entities even more than usual, and rightfully so – HIPAA data breaches not only sacrifice the trust you’ve established with your patients, but also they’re extraordinarily expensive.

Krishna KurapatiKrishna Kurapati
3 min read
hipaa omnibus changes|hipaa omnibus changes for healthcare security
Best Practices

HIPAA Omnibus Changes – Just One Week Left

One week. That’s all that remains between now and September 23rd, the date at which the HIPAA Omnibus regulations go into effect. Covered entities under the law should have already completed most of the long-term compliance work under regulations – e.g., updating their Business Associate Agreements, revising their Notices of Privacy. Practices, completing a detailed risk assessment – but the biggest change that goes into effect in seven days is the shift in a presumption in what constitutes a breach.

Krishna KurapatiKrishna Kurapati
2 min read
3m left