← Back to Compliance Insights

September 5, 2026  ·  Jonah Gobah

Is It HIPAA Compliant to Text or Email Patients?

Short answer: Standard SMS text messaging and regular email are generally not secure enough on their own for sending PHI, because they typically aren't encrypted and you can't control the security of the patient's own device or inbox. However, HIPAA does allow electronic communication with patients, including standard text or email, if the patient is informed of the risks and still requests or consents to that method — or if you use a secure, encrypted patient communication platform designed for this purpose instead.

Why plain texting and email are risky, not automatically prohibited

A common misconception is that HIPAA flatly bans texting or emailing patients. It doesn't. What it actually requires is that PHI be protected appropriately based on the method of transmission, and standard SMS and consumer email generally don't meet that bar on their own — messages typically aren't encrypted in transit, can be stored unencrypted on multiple devices and servers, and you have no control over the recipient's own device security.

The patient consent pathway

HIPAA does allow for the possibility that a patient, after being informed of the risks, chooses to communicate via unencrypted text or email anyway. If a patient explicitly requests this method and you've documented that they were informed of the security limitations, that communication can be permissible. This isn't a loophole to rely on broadly, though — it needs genuine, documented patient consent, not an assumption that texting is fine because "most patients probably don't mind."

What a secure alternative actually looks like

Patient portals. Most EHR systems include a secure patient portal for messaging, which handles encryption and access control appropriately, without relying on the patient's personal device security.

HIPAA-compliant texting platforms. Purpose-built secure messaging platforms exist specifically for healthcare communication, using encryption and access controls that standard SMS doesn't have, while still giving patients a text-like experience.

Encrypted email services. Some email platforms offer HIPAA-compliant encrypted email specifically designed for healthcare use, distinct from a standard consumer email account.

What definitely shouldn't happen

  • Staff texting patient information from personal cell phones using standard SMS, without documented patient consent for that specific method
  • Emailing lab results or diagnoses to a patient's personal email account as a matter of routine, without using a secure or consented channel
  • Group texts or emails that could expose one patient's information to another recipient by mistake

What to check for your practice

If your practice currently communicates with patients by standard text or email, the questions worth answering are: do you have documented patient consent for that specific method, have patients actually been informed of the risks, and would a secure patient portal or compliant messaging platform be a better long-term solution than relying on individual patient consent for every interaction.

Building this into your broader compliance program

Patient communication methods should be addressed specifically in your written policies, not left as an informal practice each staff member handles their own way. This is exactly the kind of practical, everyday gap that a general "we're HIPAA compliant" assumption tends to miss.

Run the free HIPAA risk assessment →

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles