← Back to blog

Hospitals: How CMS QSO-24-05 Changes HIPAA Texting Rules

September 13, 2026
Hospitals: How CMS QSO-24-05 Changes HIPAA Texting Rules

Yes, healthcare providers can text patients and staff in a HIPAA-compliant way, but only when four things line up: a secure texting platform built for PHI, a signed Business Associate Agreement with that vendor, adherence to the minimum necessary standard, and documented patient consent or an honored request for confidential communications. The CMS QSO-24-05 memorandum confirms hospitals and critical access hospitals can use secure texting platforms for patient information and orders once their Conditions of Participation are met. Standard SMS on a personal phone rarely clears that bar.


TL;DR:

  • Using HIPAA-compliant texting requires a secure platform, signed Business Associate Agreements, proper documentation of patient consent, and adherence to minimum necessary standards.
  • Sending diagnoses, lab results, or multiple identifiers over unencrypted SMS or consumer chat apps automatically violates HIPAA rules.
  • Vendors must prove technical safeguards like encryption, audit logs, multi-factor authentication, and device controls before handling PHI securely.
  • Patient consent must be an ongoing, documented process with clear opt-in, scope, and revocation options, especially when patients initiate contact.
  • Secure texting platforms can support accurate order reconciliation and follow CMS conditions of participation, but workflows must be explicitly documented and regularly audited.

Signalengine
Find Your Revenue Leaks
Signalengine helps businesses identify customer behavior changes, retention risks, competitor openings, and next actions automatically.
Explore Signalengine

Table of Contents

When Texting Becomes a HIPAA Violation

The distinction that trips up most staff isn't whether texting is allowed. It's who initiated the message, what it contains, and where it lands afterward. A patient who texts their provider first, using their own device and number, isn't creating a HIPAA problem on its own. The exposure starts when a provider or staff member replies with protected health information over a channel that wasn't vetted for security.

Privacy Rule §164.522(b) matters here because patients have a right to request confidential communications by alternative means, including text. If a patient asks for text updates and the practice documents that request, texting becomes part of an authorized communication plan. Skip the documentation step, and the same message looks like an unapproved disclosure the moment an auditor asks why PHI went out over unencrypted SMS.

Certain content turns an ordinary text into a violation almost automatically:

  • Sending a diagnosis, treatment plan, or mental health detail over standard SMS
  • Texting lab values, imaging results, or medication orders outside a secure platform
  • Including two or more identifiers (name plus date of birth, name plus medical record number) in a plain text message
  • Forwarding a screenshot of an EHR screen to a personal messaging app
  • Group-texting a care team about a specific patient using consumer chat apps

Roles matter too. A hospital or physician group is the covered entity. A vendor that stores or transmits messages on the entity's behalf is a business associate. If that vendor uses subcontractors, like a cloud hosting provider or SMS gateway, those subcontractors inherit business associate obligations through flow-down provisions. Miss that chain, and the covered entity is still on the hook.

Technical Safeguards Vendors Must Prove, Not Just Promise

The HIPAA Security Rule doesn't name "texting" specifically, but its technical safeguard requirements apply directly to any tool that creates, stores, or moves electronic PHI. Evaluating a texting vendor means checking for five categories of control, not taking a sales deck at face value.

  1. Encryption in transit and at rest. Messages need to be encrypted while moving between devices and while sitting in storage. TLS handles the transport layer well, but true end-to-end encryption is stronger because even the vendor can't read message content. Standard SMS fails both tests: carriers can access message content, and it isn't encrypted at rest on most devices.
  2. Authentication and access control. Every user needs a unique login, and multi-factor authentication should be non-negotiable for anyone touching PHI. Role-based access limits who can see which patient threads, which matters most in larger practices where front-desk staff shouldn't see the same detail as attending physicians.
  3. Audit logging and message integrity. The platform should log who sent what, when, and to whom, with timestamps that can't be altered after the fact. This is what makes reconciliation with the EHR possible later, and it's the piece regulators check first during an incident review.
  4. Device-level controls. Mobile device management (MDM) should be able to remotely wipe a lost phone, disable automatic cloud backups of message content, and enforce screen locks. A texting platform with airtight server-side encryption still fails if a lost, unlocked phone dumps message history into an unsecured backup.
  5. Transmission security. PHI shouldn't traverse a path where it could be intercepted or fall back to standard SMS when signal drops. Some platforms silently downgrade to carrier SMS during connectivity issues, which quietly defeats the entire point of the secure app.

Pro Tip: Ask any vendor to show you their audit log output, not just describe it. A platform that can't produce a clean, timestamped record of a single conversation on request probably can't produce one during a breach investigation either.

The codified version of these obligations lives in 45 CFR §164.308 for administrative safeguards, which pairs with the technical requirements to form the full compliance picture. A texting platform that satisfies technical safeguards but sits on top of an organization with no documented risk analysis is still exposed.

Consent for texting isn't a single signature. It's an ongoing record of what the patient asked for, when they asked, and how the practice responded. Under §164.522(b), patients can request confidential communications by alternative means, and providers must accommodate reasonable requests.

A compliant opt-in process typically includes:

  • A written or electronic disclosure explaining that standard SMS carries some risk, even through a secure platform, and outlining what type of information will and won't be sent by text
  • A clear method for the patient to say yes, specifying phone number and preferred hours
  • A note in the medical record documenting the date of consent and the scope agreed to (appointment reminders only, versus broader clinical updates)
  • A visible, simple way to revoke consent at any time, with that revocation also logged

Patient-initiated texts deserve their own protocol. If a patient texts a question to a provider's secure line first, most compliance teams treat that as an implicit invitation to reply through the same channel for that specific exchange, though it's safer to follow up with a formal opt-in for anything beyond a one-off reply. When a patient asks to stop receiving texts, that request needs to be honored immediately and reflected in the record, not just filed away informally by whichever staff member took the call.

Minimum Necessary: What Belongs in a Text and What Doesn't

The minimum necessary standard asks a simple question before every message goes out: does this text need every detail it contains to accomplish its purpose? Appointment reminders and administrative notices almost always pass. Clinical detail almost never does.

Safe, low-risk templates look like this:

  • "Reminder: You have an appointment with Dr. Lee on Thursday at 2:00 PM. Reply C to confirm."
  • "Your prescription refill is ready for pickup at the front desk."
  • "Please call our office at [number] to discuss your recent visit."

What to leave out: diagnoses, specific lab or imaging results, medication names tied to a condition, and any combination of identifiers beyond what's needed to confirm the right patient. The moment a message needs to convey a result, a change in treatment, or anything a patient would consider sensitive, escalate to a secure patient portal message or a phone call instead of stretching a text to cover it. Texting works well for logistics. It works poorly as a substitute for a real clinical conversation.

What Belongs in the BAA With Your Texting Vendor

Any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf must sign a Business Associate Agreement. That includes texting platforms, the cloud infrastructure they run on, and any subcontractor in that chain. If a vendor won't sign one, that's the end of the conversation, regardless of how polished their product demo looks.

A solid BAA should spell out:

  • Specific encryption commitments for data in transit and at rest, not vague language about "industry standard security"
  • Breach notification timelines and responsibilities, including how quickly the vendor must inform the covered entity
  • Subcontractor flow-down provisions requiring any downstream vendor to meet the same obligations
  • Audit cooperation clauses that give the covered entity the right to review security practices
  • Data retention and destruction terms consistent with the organization's own retention policy

Signed paperwork alone isn't proof of anything. Ask for a current SOC 2 report, a recent penetration test summary, and a documented vulnerability disclosure process before trusting a vendor with PHI. A telecom compliance guide on HIPAA-ready VoIP makes a similar point about voice systems: contractual language and technical configuration have to match, or the paperwork is decorative.

What CMS QSO-24-05 Actually Changed for Hospitals

The CMS memo issued in February 2024 confirmed that hospitals and critical access hospitals can use a secure texting platform to send patient information and orders among care team members, provided the platform meets the applicable Conditions of Participation. This clarified prior uncertainty where some facilities had avoided texting orders outright due to caution.

CPOE, computerized provider order entry, remains the preferred method for entering orders directly into the EHR, though texting may be used as an alternative when compliant. CMS considers secure texting as an accepted alternative, not a replacement, expecting "prompt, authenticated" entry into the medical record once an order is texted. In practice, that means a workflow where a texted order gets logged into the EHR by an authorized user within a defined window, with a timestamp tying the two records together.

Secure order reconciliation workflow illustration

Joint Commission guidance echoes this: surveyors will look for evidence that texted orders reconcile cleanly with the official record, and gaps here are one of the most common findings during accreditation reviews. Hospitals are advised to document their reconciliation workflow explicitly rather than treat it as an informal practice.

Rolling Out Secure Texting Without Breaking Anything

A compliant texting rollout follows a sequence, and skipping steps to move faster almost always creates the gaps that show up in an audit six months later.

  1. Run a focused risk analysis on messaging workflows specifically, separate from your general Security Rule risk analysis. Identify exactly where PHI could travel by text, who sends it, and where it's stored.
  2. Define approved use cases before deployment. Decide which templates staff can use, restrict any freeform clinical detail, and set a retention period for message history that matches your broader records policy.
  3. Validate the secure texting platform's controls directly. Request the SOC 2 report and recent penetration test summary rather than accepting a vendor's compliance checklist at face value.
  4. Sign the BAA before a single test message contains real PHI. No exceptions, even for a pilot group.
  5. Build the EHR reconciliation process before go-live, not after. Decide who logs texted orders into the record, on what timeline, and how that gets audited weekly.
  6. Deploy MDM across every device in the pilot, enable multi-factor authentication, and train staff on what can and can't go in a text before they get access.
  7. Set a recurring audit cadence. Monthly log reviews catch drift (staff texting outside approved templates) long before it becomes a pattern serious enough to trigger a complaint.

Pro Tip: Start your pilot with one department and one use case, like appointment reminders or discharge follow ups, before expanding to clinical orders. It's far easier to catch a broken reconciliation workflow when only ten patients are affected instead of ten thousand.

How Signalengine Fits Into the Bigger Communication Picture

Security policy only means something if it's backed by real operational transparency. Signalengine publishes its own security, privacy, and compliance practices so healthcare-adjacent businesses can see exactly how data is handled before they commit to a platform, which is the same standard any texting vendor should be held to.

Managed text campaigns also show what's possible when messaging is done well. Contractors using Missed Call Text Back see a 32.7% reply rate on automated follow-up texts, a useful benchmark for how engaged patients or customers can be with SMS when the message is relevant and timely. That number is about engagement, not clinical safety. It doesn't substitute for the encryption, access control, and audit logging a healthcare texting platform needs. It just shows that when texting is done right, people respond.

Why the Safest Answer Is Rarely the Fastest One

Every hospital compliance team I'd trust on this topic eventually lands on the same tension: speed and record integrity pull in opposite directions. Texting an order feels faster than logging into the EHR, which is exactly why CMS built in the expectation of "prompt" reconciliation instead of pretending texting replaces CPOE outright.

The practical move isn't picking one extreme. Pilot a single narrow use case, audit it weekly for the first two months, and only expand once the reconciliation workflow runs without manual chasing. Policy edge cases, like what counts as a reasonable confidential communication request, or how long to retain texted images, deserve a conversation with compliance counsel rather than a guess based on what another hospital does. The Joint Commission's stance on secure texting makes clear that surveyors care about documented process, not good intentions.

— Bernard

Ready to Stop the Revenue Leak.

Signal Engine gives small and local businesses 31 AI-powered tools to score leads by buying intent, predict churn before it happens, auto-generate email and SMS campaigns, and and recover missed calls automatically — all in one dashboard starting at $49/month.

Start your free 7-day trial — no credit card required and Setup takes 5 minutes.

For healthcare practices juggling patient texting policy alongside everyday customer communication, a platform built for revenue intelligence and SMS automation can handle the non-clinical side, like appointment follow-ups and missed call recovery, while your secure texting platform stays dedicated to PHI. See how the dashboard works with a live demo before deciding where each tool fits your workflow.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

FAQ

What Is the New HIPAA Rule for Texting in 2026?

There is no standalone texting rule for the future. The governing framework remains the existing HIPAA Security and Privacy Rules combined with CMS QSO-24-05, which formally confirmed hospitals can text patient orders through a secure platform when Conditions of Participation are met.

Are iPhone Text Messages HIPAA Compliant?

Standard iPhone Messages (SMS or unencrypted iMessage to non-Apple devices) generally aren't HIPAA-compliant on their own because carriers can access content and there's no audit logging or BAA in place. A secure texting platform with a signed BAA is required for any message containing PHI.

Is It a HIPAA Violation to Text a Patient's Name?

A name alone typically isn't a violation, but pairing it with another identifier, like a diagnosis, appointment reason, or medical record number, over an unsecured channel usually is. The safest approach uses a secure platform and limits identifiers to the minimum necessary.

Are Text Messages Covered by the HIPAA Security Rule?

Yes. Any text message containing electronic PHI falls under the Security Rule's requirements for encryption, access control, audit logging, and transmission security, regardless of which app or carrier sends it.

Do Providers Need a BAA With Their Texting App Vendor?

Yes, whenever the vendor creates, receives, maintains, or transmits PHI on the provider's behalf. This applies to secure texting platforms, their cloud hosts, and any subcontractor in that chain.