Skip to content

HIPAA and texting patients: the practical rules for a small practice

What a dental, medical or therapy practice can text, what it should keep out of texts, what the patient's own preference changes, and what to ask a messaging vendor. Not legal advice.

Frontiva · · 4 min read

A practice covered by HIPAA can text patients about appointments and general logistics, and can reply to a patient who texted first, as long as it keeps protected health information out of the message where it can and honours the patient's preferences. Reminders that say the time and place, not the reason for the visit, are the standard. Anything clinical goes through a secure channel. Vendors that handle patient messages on your behalf sign a business associate agreement. This post describes common practice, not legal advice; your compliance officer or counsel decides for your practice.

What is fine to text

An appointment reminder with date, time, location and provider name. A confirmation. A reschedule conversation. "Your forms are ready to complete at this link." "We are running 15 minutes behind." A reply to a patient's logistical question. The rule most practices follow: nothing in the message that reveals why the patient is being seen or what they are being treated for.

What to keep out of texts

Diagnoses, test results, medication names, treatment details, and anything that would tell a reader what the patient's condition is. "Your cleaning is tomorrow at 10" is a scheduling message; "your root canal follow-up is tomorrow" is arguably clinical. "Your lab results are in, please call" is fine; the results themselves are not. Patient-initiated questions about symptoms get a reply that moves the conversation to the phone or the portal.

The patient's preference

Patients can ask to be contacted by text, and can ask to be contacted in a particular way (only reminders, no messages about a specific matter). Honour what they ask, record it, and let them change it. A patient who texts you first has chosen the channel for that conversation; that does not mean they want clinical detail in it.

Minimum necessary

Every message carries the least information needed to do its job. This is a HIPAA principle and also just good practice for text: shorter messages, less exposure if a phone is shared or lost. A reminder does not need the provider's specialty, the service name if it reveals a condition, or the account balance.

The vendor question

If a messaging platform stores, sends or processes patient messages for you, it is a business associate and should sign a business associate agreement (BAA). Ask before you sign up. Ask also where data is stored, who at the vendor can see it, how it is encrypted, how long it is kept, and how you get it back. A vendor that will not sign a BAA is not a vendor for a covered practice.

The AI receptionist and patient messages

An AI that replies to patients needs the same rules a receptionist follows: scheduling and logistics yes, clinical detail no, symptoms to a person, and no discussion of any patient other than the one texting. It should be set to move any clinical question off text ("Dr Lee will call you about that") and to never confirm or deny a family member's appointment. The vendor's BAA should cover the AI's processing of messages.

Records and retention

Messages with patients are part of the record, in most practices' policies. Keep them where they can be found, export them when needed, and apply your retention policy to them. A platform that keeps every conversation on the patient's record and exports it does this for you.

Frequently asked questions

Can we text a patient their appointment reason if they asked us to?

Some practices do with documented patient preference; many keep the rule simple and leave it out regardless. Follow your compliance officer's guidance.

What about a patient who sends clinical details by text unprompted?

Reply to move the conversation to a secure channel, do not discuss the details by text, and keep the message on the record. The patient's own choice to send it does not change what you should send back.

Do reminders need patient consent under HIPAA?

Reminders are generally treated as part of treatment communications. Texting rules (the TCPA) still want consent to text, and asking at intake covers both.

What Frontiva does here

In Frontiva, SMS reminders go only to patients who ticked the consent box and are held out of quiet hours, and questions about diagnoses, prescriptions or results are caught by a guardrail and handed to a person. Frontiva is not HIPAA certified, as the security page says; ask us directly before patient messages go through any tool, ours included. See the dental and medical pages for the workflows.

Practically, the safest system is one that cannot say the wrong thing. In Frontiva the AI answers only from your approved knowledge, and anything resembling a clinical question is caught by the sensitive-domain guardrail and handed to a person instead of answered. See what an AI receptionist should refuse to answer.

Start free. Be live this week.

Built for dental, med spa, home services, and the businesses that live on the phone.