Text messaging has become one of the most common ways businesses communicate with customers. Not surprisingly, healthcare practices are increasingly using text messages for appointment reminders, recalls, payment requests, and other patient communications.
As more vendors introduce text-to-pay and patient engagement programs, healthcare providers are asking an important question:
Is SMS texting compliant, and what responsibilities does the practice assume when using it?
The answer is more nuanced than many people realize.
What Is SMS?
SMS (Short Message Service) is the traditional text messaging technology used by mobile phones for decades. It allows businesses and healthcare providers to send text-based communications directly to a patient’s mobile device without requiring a separate application or account.
Its universal compatibility and ease of use are major reasons many healthcare software vendors continue to incorporate SMS into their patient engagement platforms.
The Benefits of SMS Communication
There is no question that text messaging can improve patient engagement.
Patients often respond to texts faster than emails, and text messaging can help reduce no-shows, improve collections, and streamline routine communications.
As a result, many healthcare software vendors have incorporated SMS communications into their platforms, making it easier than ever for practices to communicate with patients.
The SMS Compliance Challenge
While SMS is convenient, healthcare practices must remember that patient information is subject to privacy and security requirements. Unlike many secure messaging platforms, traditional SMS generally lacks end-to-end encryption, detailed audit controls, or other technical safeguards commonly used to protect sensitive healthcare information. As a result, practices should carefully consider what types of information are appropriate to send through SMS and how patient communication preferences are managed and documented.
Federal guidance encourages healthcare organizations to implement reasonable safeguards when communicating electronically with patients and to protect patient information from unauthorized access. The security controls available in traditional SMS messaging are generally more limited than those available in dedicated secure messaging platforms. Recent changes in HIPAA amendments make it clear that text encryption is considered reasonable.
This does not mean text messaging is prohibited.
In fact, federal guidance recognizes that patients may request or agree to receive communications through alternative electronic methods, even when those methods may involve additional risk. Providers should ensure patients understand the nature of the communication channel and should maintain appropriate safeguards and documentation processes.
Why Many Vendors Continue to Use SMS
While advanced messaging technologies continue to evolve, SMS remains the most widely supported mobile communication channel. It works across virtually all phones, is familiar to patients, and is supported by an established messaging infrastructure. Vendors may also find SMS simpler and less expensive to deploy than more advanced messaging solutions.
For many organizations, the decision to use SMS is driven by a combination of patient adoption, operational simplicity, workflow considerations, and cost.
The Real Question: Can Your Practice Manage the Risk?
From a compliance perspective, the most important consideration is not whether a particular vendor offers SMS.The more important question is whether the practice has a process for:
- Obtaining appropriate patient consent.
- Managing patient communication preferences.
- Honoring opt-out requests.
- Documenting authorization decisions (operationally, it can be challenging to exclude opt-out patients)
- Ensuring communications are sent through approved workflows.
- Understanding what information is appropriate to send through various communication channels.
The administrative burden of managing these processes is often overlooked in implementation discussions, and vendors are placing this burden on the practice.
New Website Requirements for SMS Programs
Many practices are also being asked to update their websites before activating texting programs. This is largely driven by carrier and messaging platform requirements rather than a new HIPAA requirement.
Common requirements include:
- Privacy Policies explaining how information is collected and used.
- Terms and Conditions describing messaging programs.
- Opt-in and opt-out language.
- Message frequency disclosures.
- Customer support information.
- “Message and data rates may apply” disclosures.
- Instructions for receiving help or stopping messages.
Healthcare practices should expect these requirements to become increasingly common as messaging providers and carriers tighten oversight of business texting programs.
PPP’s Recommendation
At Practice Performance Partners, we believe practices should carefully evaluate both the convenience and compliance implications of any patient communication platform.
Whenever protected health information may be involved, secure communication methods generally provide the strongest privacy protections and the lowest compliance risk.
At the same time, every practice has different operational needs, patient expectations, and risk tolerances. Our role is not to tell practices which vendor to use. Our role is to help providers understand the privacy, security, documentation, and workflow considerations associated with each approach so they can make informed decisions.
Key Takeaways for Your Practice
Text messaging is likely to remain an important part of patient communications for years to come.
The question is no longer whether practices will communicate with patients electronically. The question is whether they fully understand the compliance responsibilities that come with those communications.
Before adopting any messaging platform, practices should evaluate not only the convenience and cost of the solution, but also the policies, procedures, patient disclosures, and documentation requirements needed to support it successfully.
