THE MOXCARES FIELD GUIDE / Security & Compliance

HIPAA-Compliant Patient Messaging: A Clinic Checklist

Make it easy to reach the clinic without scattering clinical conversations across personal devices. This is a workflow checklist, not legal advice or a guarantee of compliance.

01 — Choose a protected workflow

Do not rely on a disclaimer

A disclaimer does not authenticate a recipient or protect the contents of a message. Evaluate the actual safeguards and how staff use them.

HIPAA does not impose a blanket ban on email. HHS explains that providers may use electronic communication with reasonable safeguards and appropriate Security Rule protections. Moxcares uses a notification-and-private-link design: clinical messages stay in the authenticated conversation, rather than the notification.

02 — Patient access

Separate the notification from the conversation

A patient receives a private link, authenticates and opens the conversation. Staff should verify contact details and use the practice's approved process for identity questions, caregiver access and wrong-recipient concerns.

Test the real patient experience before rollout. Check what a notification reveals, what happens when a link is forwarded and how access is restricted. Ask the vendor to demonstrate those behaviors; a lock icon is not evidence on its own.

03 — Preferences and expectations

Be clear about what the patient is agreeing to

Record communication preferences and any consent required for your message types. Distinguish care-related communication from marketing, honor opt-outs and have counsel confirm the applicable telecommunications and state requirements.

Tell patients when staff monitor the inbox and how to seek urgent help. A routine message channel should not imply immediate clinical attention. Assign a staff owner for unanswered conversations and exceptions.

04 — Clinical context

Keep attachments with the exchange

Moxcares supports two-way messages and attachments inside the secure conversation. Staff can review the patient's information with the relevant context instead of forwarding it through personal accounts.

Decide which team members need access, how the exchange informs the chart and when a clinician must review it. Sharing a document with the clinic is not the same as approving its contents as a clinical record.

05 — Evidence and retention

Check the control, then the policy

Review encryption, role-based access, attributable activity and the relevant BAA. Ask which vendors handle PHI and which do not. Review security documentation and incident-response responsibilities with your practice's privacy lead.

Do not treat a product's audit-log retention period as a universal medical-record retention rule. Set message and chart retention with your compliance adviser, accounting for applicable recordkeeping duties. HIPAA-required policies and documentation have their own retention requirements.

06 — A manageable rollout

Start with one conversation type

Pilot a routine workflow, such as a patient sending a requested document. Test notification delivery, authentication, staff response, attachment handling and the activity record. Keep an alternative route for patients who need assistance.

Track failed access, unresolved conversations, response time and patient feedback. Review exceptions with staff before adding more message types. Technology is one part of the workflow; the practice still owns appropriate access and use.

FAQ

Common questions

Does an email disclaimer make a message compliant?

No. A disclaimer alone does not provide safeguards such as recipient verification or appropriate access. Your practice must assess the actual communication workflow.

How does Moxcares handle clinical messaging?

The patient opens a private link and authenticates to exchange clinical messages and attachments. Notification text and the protected conversation are separate.

Does a BAA replace the practice's own compliance work?

No. A BAA and software safeguards support the relationship. The practice remains responsible for its policies, staff access and appropriate use.

PUT IT INTO PRACTICE

See the protected conversation, end to end.

Review the patient experience, the staff inbox and the controls supporting each step.

Request a walkthrough →