GuideSecurity & Compliance

HIPAA-compliant patient messaging

A checklist for independent clinics that want to text patients properly: consent that holds up, a unique link the patient authenticates, real two-way threads with attachments, and an audit trail you can export.

01 — The rule in one line

The channel, not the message, is what HIPAA cares about

Patients want to text. Clinics want to text back. The compliance question is not whether texting is allowed — it is whether protected health information ever travels over a channel you do not control, to a device you have not verified, with no record that it happened.

Plain SMS fails on all three counts. It is unencrypted at rest on carrier infrastructure, it authenticates a phone number rather than a person, and it produces no audit trail you can hand an auditor. That does not make SMS useless. It makes SMS a notification layer, not a conversation layer.

The pattern that works: a plain, PHI-free text tells the patient something is waiting, and a unique link takes them to an authenticated session where the actual conversation happens. We wrote about why the alternative fails in the disclaimer is the confession.

02 — Consent

Get consent, timestamp it, and make opting out one word

Every compliant messaging program starts with documented consent captured at a specific moment, not implied by the fact that a mobile number sits in the chart. Three things to record:

  • What they agreed to. Appointment reminders, clinical follow-up, and marketing are separate permissions. Bundling them is the most common finding in a messaging audit.
  • When and how. A timestamp, the source (intake form, front desk, web form), and the exact language shown to the patient.
  • How they left. STOP must work instantly, propagate across every message type, and be recorded as an event rather than a flag someone can flip back.

Carrier rules matter alongside HIPAA here. A registered 10DLC brand and campaign, clear sender identification, and honored opt-outs are what keep your messages deliverable in the first place.

03 — Authentication

A unique link the patient verifies, not a portal they abandon

Patient portals solved authentication and created a new problem: nobody logs in. Portal adoption at independent clinics routinely sits under 30%, and the password reset queue lands on your front desk.

The middle path is a per-conversation link. Moxcares secure messaging works like this: the patient receives a short text with no clinical content and a unique link. Opening it starts a verification step — date of birth or a one-time code sent to the number on file. Once verified, the patient is inside an encrypted, time-limited session tied to their chart. No account to create, no password to forget, and every open is logged.

Links expire, are single-patient scoped, and can be revoked. A forwarded link does not become a leak, because verification is per-session rather than per-URL.

04 — Two-way and attachments

Real conversations, including the photo of the rash

One-way reminders are the easy half. The clinical value shows up when the patient can reply: confirm a symptom, ask about a medication, send a wound photo, upload the new insurance card, or return a signed form.

Inside the authenticated session, Moxcares supports genuine two-way messaging with attachments — images, PDFs, and insurance cards — that file directly to the patient's chart rather than sitting in a staff inbox. Staff reply from the same thread in the platform, so the whole exchange stays on one record instead of splitting across a personal phone, a shared email box, and a sticky note.

Because intake, charts, messaging, and documents run on the same spine, an attachment a patient sends on Tuesday is already on the chart when the provider opens it on Wednesday. No re-upload, no scanning, no re-keying.

0

Characters of PHI in the text message itself

The SMS is a doorbell. The conversation happens behind a unique link the patient verifies, on a system covered by a BAA with an append-only audit trail.

05 — The safeguards to insist on

What to verify before you turn messaging on

  • Signed BAA covering the messaging vendor and any subprocessor that touches message content.
  • Encryption in transit and at rest, with PHI never placed in the SMS body itself.
  • Identity verification before any clinical content is displayed.
  • Role-based access so a front-desk seat sees scheduling threads, not every clinical exchange.
  • Append-only audit trail recording sends, opens, verifications, replies, and staff views — exportable without a support ticket. Our security page describes how we hash-chain those records.
  • Retention and export that treat messages as part of the chart, with deletion recorded rather than silent.
  • Breach response — a documented process and a named contact, not a promise on a sales call.
06 — Rollout

Two weeks, one message type at a time

Week one: register your 10DLC campaign, load consent language into intake, and turn on a single PHI-free message type — appointment reminders with a reschedule link. Watch delivery rate and opt-out rate.

Week two: enable authenticated two-way threads for one workflow, usually post-visit follow-up or results questions. Set an internal response-time target and staff it like the phone line, because patients will treat it that way.

After that, add attachments (insurance cards and photos), then billing questions with text-to-pay. Each addition is a message type, not a project.

07 — FAQ

Common questions about HIPAA-compliant messaging

Is texting patients HIPAA compliant?

Plain SMS is not a compliant channel for protected health information on its own. Texting patients is compliant when the message itself carries no PHI, the patient has documented consent, and any clinical detail lives behind an authenticated link on a system covered by a BAA with an append-only audit trail.

Do I need patient consent to text appointment reminders?

Yes. You need documented consent to contact the patient by SMS, captured with a timestamp and an easy opt-out (STOP). Consent for appointment reminders is separate from consent for marketing messages, and both must be recorded and revocable.

Can patients send photos or documents to the clinic securely?

Yes, provided the upload happens inside an authenticated session rather than as an MMS attachment. In Moxcares the patient opens a unique link, verifies identity, and can then attach photos, insurance cards, or PDFs that file directly to their chart.

Does a HIPAA disclaimer at the bottom of an email or text make it compliant?

No. A disclaimer is a notice, not a control. It does not encrypt the message, authenticate the recipient, or create an audit record. If a disclaimer is the only safeguard on the channel, the channel is the problem.

How long should patient messages be retained?

Treat messages as part of the designated record set. Retain them for the same period as the rest of the chart under your state's requirement (commonly six to ten years), keep them exportable, and make sure deletion is recorded rather than silent.

Measure

Track four numbers

  • Link open ratePercent of patients who open and verify the secure link within 24 hours.
  • Opt-out rateSTOP requests per 1,000 messages. Above 1% means you are messaging too often.
  • Clinic response timeMedian minutes from patient reply to staff response during business hours.
  • Calls deflectedInbound phone volume before and after messaging goes live, by reason code.

Secure two-way messaging, built in

Moxcares sends a PHI-free text with a unique link, verifies the patient, and opens a two-way thread with attachments that file straight to the chart — all on an append-only audit trail. From $99 per clinic per month, month to month, with a 7-day trial.

Request a walkthrough

End of guide