THE MOXCARES FIELD GUIDE / Security & Compliance
HIPAA-Compliant Patient Messaging: A Clinic Checklist
Make it easy to reach the clinic without scattering clinical conversations across personal devices. This is a workflow checklist, not legal advice or a guarantee of compliance.
Do not rely on a disclaimer
A disclaimer does not authenticate a recipient or protect the contents of a message. Evaluate the actual safeguards and how staff use them.
HIPAA does not impose a blanket ban on email. HHS explains that providers may use electronic communication with reasonable safeguards and appropriate Security Rule protections. Moxcares uses a notification-and-private-link design: clinical messages stay in the authenticated conversation, rather than the notification.
Separate the notification from the conversation
A patient receives a private link, authenticates and opens the conversation. Staff should verify contact details and use the practice's approved process for identity questions, caregiver access and wrong-recipient concerns.
Test the real patient experience before rollout. Check what a notification reveals, what happens when a link is forwarded and how access is restricted. Ask the vendor to demonstrate those behaviors; a lock icon is not evidence on its own.
Be clear about what the patient is agreeing to
Record communication preferences and any consent required for your message types. Distinguish care-related communication from marketing, honor opt-outs and have counsel confirm the applicable telecommunications and state requirements.
Tell patients when staff monitor the inbox and how to seek urgent help. A routine message channel should not imply immediate clinical attention. Assign a staff owner for unanswered conversations and exceptions.
Keep attachments with the exchange
Moxcares supports two-way messages and attachments inside the secure conversation. Staff can review the patient's information with the relevant context instead of forwarding it through personal accounts.
Decide which team members need access, how the exchange informs the chart and when a clinician must review it. Sharing a document with the clinic is not the same as approving its contents as a clinical record.
Check the control, then the policy
Review encryption, role-based access, attributable activity and the relevant BAA. Ask which vendors handle PHI and which do not. Review security documentation and incident-response responsibilities with your practice's privacy lead.
Do not treat a product's audit-log retention period as a universal medical-record retention rule. Set message and chart retention with your compliance adviser, accounting for applicable recordkeeping duties. HIPAA-required policies and documentation have their own retention requirements.
Start with one conversation type
Pilot a routine workflow, such as a patient sending a requested document. Test notification delivery, authentication, staff response, attachment handling and the activity record. Keep an alternative route for patients who need assistance.
Track failed access, unresolved conversations, response time and patient feedback. Review exceptions with staff before adding more message types. Technology is one part of the workflow; the practice still owns appropriate access and use.
Primary sources and further reading
Put the guide into practice
Common questions
Does an email disclaimer make a message compliant?
No. A disclaimer alone does not provide safeguards such as recipient verification or appropriate access. Your practice must assess the actual communication workflow.
How does Moxcares handle clinical messaging?
The patient opens a private link and authenticates to exchange clinical messages and attachments. Notification text and the protected conversation are separate.
Does a BAA replace the practice's own compliance work?
No. A BAA and software safeguards support the relationship. The practice remains responsible for its policies, staff access and appropriate use.
PUT IT INTO PRACTICE
See the protected conversation, end to end.
Review the patient experience, the staff inbox and the controls supporting each step.
Request a walkthrough →Keep reading

Secure patient messaging: why HIPAA disclaimers fail
If your email needs a confidentiality footer, the channel is already broken.

AI medical scribe privacy: why we delete the audio
The recording exists only while it's being processed. Then it's gone.

Why bolting AI onto old software doesn't work
What an AI-native platform looks like when it's designed for agents from day one.