HIPAA compliance rules for physical therapy scheduling text messages. Are Your Physical Therapy Scheduling Texts HIPAA Compliant?
Photo by Physio Therapist Scheduling on card

Guides

Are Your Physical Therapy Scheduling Texts HIPAA Compliant?

HIPAA compliant scheduling text messages rely on the conduit exception, vendor agreements and state breach laws. Learn what triggers a violation and who enforces it.

What to take away

  • A reminder text that names a diagnosis, a treatment or a visit type is protected health information, and ordinary SMS is not a permitted channel for it.
  • The conduit exception covers a vendor that only transmits messages, not one that stores them, logs them or schedules on your behalf.
  • Every texting vendor that touches patient data needs a signed business associate agreement before the first message goes out.
  • State breach notification laws can apply even when federal rules would not, and several states treat message content as regulated data.
  • HHS enforcement is complaint driven, and the resolution agreements published so far have all followed a reported breach rather than a routine audit.

Who has jurisdiction over patient texts

HIPAA sets the federal floor. The HHS Office for Civil Rights writes and enforces the Privacy Rule and the Security Rule, and its published guidance on privacy regulations governs how a clinic may use protected health information in any scheduling communication.

States add their own layer. California, Texas, Washington and New York each maintain breach notification statutes with their own definitions of personal information, and some include message content. A clinic in Denver answers to Colorado law as well, which is why a policy copied from a national template rarely holds up.

Private rules arrive through contracts. A payer, a hospital system or a referring physician group can require encryption and audit logs as a condition of the referral relationship. Those terms bind you even where no statute does.

What triggers HIPAA when you text a patient

The trigger is content, not the phone. A message that says "see you Tuesday at 3" carries no health information. A message that says "confirm your pelvic floor therapy session" does.

Three elements decide the answer:

  1. Does the message identify the patient, directly or through a unique identifier?
  2. Does it relate to past, present or future care, payment or treatment?
  3. Does it travel over a channel the clinic controls and can secure?

If the first two are yes and the third is no, you have a disclosure. The Wikipedia summary of HIPAA is a reasonable starting point for staff training, but the operative text sits in the Privacy Rule itself.

The conduit exception, tested

The conduit exception exists. It covers a vendor that transports data and does not persistently store it. A plain SMS gateway can fall inside it.

Most scheduling platforms do not. The moment a vendor keeps a message log, a delivery receipt or an appointment record, it is storing protected health information and becomes a business associate. That vendor then needs a signed business associate agreement, and the clinic needs to be able to produce it.

A quick test:

  • Does the vendor store message content after delivery?
  • Does it hold a patient roster, appointment history or diagnosis codes?
  • Does it send on your behalf without a human review step?
  • Can it produce a signed business associate agreement on request?

Two or more yes answers means the exception does not apply.

The exception is narrow by design. It was written for pipes, not for platforms that remember what moved through them.

Example of a reminder that fails

A five-clinician practice in Ohio sent automated reminders reading "Reminder: your dry needling follow-up with Dr. Alvarez is Thursday." The vendor stored every message and the patient list. No business associate agreement was signed.

A patient whose spouse shared the phone filed a complaint. The practice could not produce an agreement, could not show encryption at rest, and had no message retention policy. The matter settled with a corrective action plan and staff retraining. Nothing about the reminder itself was unusual. The paperwork was missing.

That pattern repeats. Clinics rarely fail because they text. They fail because the vendor relationship was never documented.

What happens if you skip it

Non-compliance carries concrete costs. A breach affecting 500 or more individuals must be reported to HHS, and the report becomes public. Civil penalties under the HIPAA statute are tiered by culpability, and the tiers are adjusted annually for inflation.

The business consequence arrives faster than the legal one. A reported breach can trigger payer contract reviews and, in some networks, suspension of new patient referrals while the investigation runs. For a clinic running on thin margins, that is the real exposure.

State attorneys general can also bring actions under the Health Information Technology for Economic and Clinical Health Act. Those cases have produced settlements in the low six figures for small providers, which is more than most independent clinics hold in reserve.

Documents to have before the first text

Build the file before you send anything, not after a complaint arrives.

  1. A signed business associate agreement with every vendor that stores or processes message content.
  2. A written patient consent that names text messaging as a channel and states what content will appear.
  3. A retention and deletion schedule for message logs, matched to your state's record rules.
  4. A breach response procedure naming who notifies patients, HHS and any affected state agency.
  5. An encryption standard applied to messages at rest and in transit.

The consent step matters more than most owners expect. Patients can decline text contact, and the practice has to record that choice somewhere the front desk can see it. Our guide to HIPAA-compliant scheduling software walks through what to ask vendors about storage and audit logs.

How long approval and setup take

Nothing here moves on a permit clock, but the sequence has its own timing. Vendor security review typically runs 2 to 4 weeks for a small clinic. Business associate agreement negotiation adds 1 to 3 weeks if the vendor uses a standard form, longer if they do not.

Staff training and consent collection usually take another 2 weeks. A realistic runway from decision to first compliant message is 6 to 10 weeks. Clinics that compress this to a few days almost always skip the agreement.

Common questions

Can we text appointment times without a business associate agreement? Only if the vendor is a true conduit and the message contains no health information. If the platform stores the message or the patient list, you need the agreement regardless of what the text says.

Does a patient's verbal consent cover text reminders? It can, but you need to document it. Written consent is easier to produce during a complaint or an audit, and it gives you a record of the patient's preferred channel.

What if a patient texts us first? The patient choosing to text does not remove your obligations. Your reply is still a communication from a covered entity, and the same content rules apply to it.

Do state laws change the answer? Yes. Breach notification thresholds and definitions of personal information vary by state, so a policy that works in Florida may not satisfy Washington. Check your state statute before you launch.

More in Guides

Latest from Reporting Desk