HIPAA Compliant Texting App: What Actually Passes an OCR Audit
TL;DR: Regular SMS, iMessage, and RCS are not HIPAA compliant. Period. You need end-to-end encryption, a signed BAA, audit logs, and remote wipe. Solo practice: BloomText (free tier, BAA included). Mid-market clinic: TigerConnect. Telehealth or dedicated line: iPlum (~$8.99/user/month). Fines run $100 to $50,000 per violation, capped near $2M per year per category (HHS OCR).
I run incident response for healthcare clients most weeks, and staff texting is the single most common exposure I find during a HIPAA readiness review. Not ransomware. Not phishing. Texting. Somebody's front desk manager is sending appointment details from a personal iPhone, and nobody has thought about it in three years.
Let's fix that.
Why Standard SMS, iMessage, and RCS Fail HIPAA
The HIPAA Security Rule at 45 CFR §164.312 requires that electronic Protected Health Information (PHI) be protected in transit and at rest through encryption or a documented equivalent. Standard SMS meets none of that. Carrier infrastructure passes messages as plaintext. There's no access control, no audit trail, and no way for you to produce records if the HHS OCR knocks on your door.
iMessage is better, but only conditionally. Apple's end-to-end encryption applies between Apple devices. The second your recipient is on Android, iMessage falls back to unencrypted SMS. Apple also doesn't sign a Business Associate Agreement for iMessage, which by itself makes it non-compliant regardless of encryption.
RCS has the same problem. Google's BAA covers specific Workspace services, and consumer Google Messages is explicitly excluded. Without a signed BAA covering the exact service you're using, you have a HIPAA violation the moment PHI crosses the wire, whether or not a breach ever happens.
What a Legitimate HIPAA Compliant Texting App Requires
Every vendor claiming compliance needs to check every box below. Not most. Every one.
- Signed Business Associate Agreement (BAA). Legal prerequisite, not a feature.
- End-to-end encryption for any message containing PHI.
- Audit logs covering sender, recipient, timestamp, and message metadata, per 45 CFR §164.312(b).
- Remote wipe capability for lost or stolen devices.
- Two-factor authentication for user login.
- Retention and expiration controls you can set.
- Role-based access controls so staff can't see threads outside their care team.
One thing marketing pages won't tell you: there is no government HIPAA certification for software. "HIPAA compliant" is self-declared by every vendor. The only way to verify is to read the BAA and the security documentation. If you want a broader map of what needs to be in place beyond messaging, our cybersecurity compliance requirements checklist covers the full picture.
BAA Red Flags That Most Comparison Articles Skip
I've reviewed dozens of vendor BAAs during audit prep, and the same patterns keep showing up. These are the clauses that get providers into trouble even when they're technically using a "compliant" app.
Liability caps. Some vendor BAAs cap total liability at $50,000, even if their breach exposes 10,000 patient records. Read the indemnification section. If the cap is small and the exclusions are broad, you're absorbing the risk.
"Improper use" exclusions. If a staff member forwards a message to a personal number, some vendor BAAs void the vendor's liability entirely. Fair on the surface. Also worth knowing before you sign.
Data ownership. Confirm in writing that the vendor cannot use de-identified PHI to train AI models or generate product analytics. This clause has quietly appeared in several updated vendor terms in the last 18 months.
Breach notification timing. HIPAA's Breach Notification Rule (45 CFR §164.404) gives you 60 days from discovery. If the vendor's BAA says they'll notify you within 60 days, you have zero time to comply. Push for 15 days or less.
Termination and data destruction. What happens when you cancel? Require written confirmation of PHI destruction, not a vague "we'll take care of it."
Free-tier limits. BloomText offers a free BAA, which is genuinely rare. Confirm the message volume and feature limits at that tier before you assume it covers your workflow.
App by App: Matched to Real Use Cases
I don't do generic top 10 lists. Here's what I actually recommend based on practice size and workflow.
BloomText. Best for solo therapists and small practices. Free tier includes the BAA, which is unusual and useful. Web and mobile apps. The trade-off is lighter enterprise features, no deep role-based routing, no EHR integration to speak of. If you're a two-person counselling practice, that's fine.
TigerConnect. Best for mid-market hospitals and multi-department clinics. Full audit log export, on-call scheduling, EHR integration hooks, role-based access. Pricing is quote-based, typically in the $15 to $25 per user per month range based on publicly cited figures. Overkill for a three-person practice, appropriate for a 100-bed facility.
iPlum. Best for solo providers and small telehealth practices that need a dedicated HIPAA phone number. Around $8.99 per user per month per iPlum's published pricing. Gives providers a separate business number on a personal device, which matters if you're trying to write a workable BYOD policy. Trade-off: it's not really a team messaging platform. Pair it with our guidance on a HIPAA compliant phone service for therapists if that's your setup.
Qwil Messenger. Positioned for financial and healthcare hybrid use cases. Encrypted messaging with BAA available. Less healthcare native than TigerConnect.
NexHealth. Broader patient engagement platform bundling scheduling, reminders, and compliant messaging. Good if you want everything in one system. Overpriced if messaging is your only need.
Movius. Carrier-level secure messaging aimed at large health systems with existing telecom infrastructure. Enterprise pricing. Not appropriate under 50 employees.
The Real Risk Isn't the App. It's Your Staff.
Here's the uncomfortable part. A compliant app doesn't make your practice compliant. Human behaviour is the failure point I see most often during readiness assessments.
We regularly see the same patterns. Front desk staff screenshotting a patient message from TigerConnect and texting it via personal SMS "because it was faster." Providers forwarding secure messages to personal Gmail "for reference on the weekend." Group texts where two patients can see each other's names in the recipient list. Everyone means well. All of it is a violation.
BYOD without a written policy and mobile device management makes this worse. iPlum's separate business number partially mitigates it. It doesn't eliminate it.
HIPAA requires workforce training under 45 CFR §164.530(b). Deploying an app without a 30-minute training session on what staff cannot do is an audit failure waiting to happen. Your written policy needs to spell out: no PHI in message subject lines, no patient names in SMS appointment reminders without explicit written authorization, no group threads that expose patient identities.
Want to test yourself? Run a tabletop drill. Ask a staff member to try to exfiltrate a fake patient message through any channel they can think of. You'll find your gaps in 20 minutes. For practices without internal security staff to run this, HIPAA compliance outsourced services can handle the tabletop and remediation together.
Migrating From Personal SMS to a Compliant App
The migration itself isn't complicated. It just needs to be done in a specific order.
- Audit current texting volume. How many patient threads exist on personal numbers? Screenshot or export what's there. That content may need to be logged before you migrate.
- Choose the app and sign the BAA first. Not a single PHI message on the new platform before the BAA is executed.
- Notify patients in writing. "We're upgrading our messaging system for your privacy. Starting [date], please contact us at [new number]. Your old message history won't transfer."
- Update your Notice of Privacy Practices under 45 CFR §164.520 if it references specific communication channels.
- Set a hard cutoff. Don't run parallel systems (compliant plus non-compliant) for more than 30 days. Staff will default to whichever is easier.
- Document the migration in your policies and procedures binder. OCR will ask for this if you're ever investigated.
Typical timeline for a 10-provider practice is two to three weeks with a dedicated IT contact. Budget is usually $0 to $500, depending on whether you need MDM enrolment for personal devices. If you're rolling this into a broader compliance uplift, our guide to HIPAA compliant managed IT services walks through where messaging fits in the bigger stack, and our HIPAA compliance guidance for Knoxville practices covers the regional considerations if you're in Tennessee or the surrounding area.
Book the Audit Before OCR Does
If you're within 90 days of a HIPAA audit and haven't locked down your staff messaging policy yet, book a free 30-minute audit with Mike. We'll tell you exactly where you're exposed before OCR does.
FAQ
Is iMessage HIPAA compliant? No. Apple doesn't sign BAAs for iMessage, and encryption falls back to unencrypted SMS when the recipient is on a non-Apple device.
Can I text patients at all under HIPAA? Yes, with patient authorization and a compliant platform that has a signed BAA in place before the first PHI message is sent.
What's the fine for texting PHI on a non-compliant app? $100 to $50,000 per violation depending on culpability tier, capped at roughly $2M per year per violation category under current HHS OCR penalty structure.
Does a free HIPAA texting app actually include a BAA? BloomText does. That's unusual. Verify the BAA in writing before using any free tool. Free doesn't imply a BAA exists.
Do I need a HIPAA compliant texting platform if I only send appointment reminders? If the reminder includes the patient's name plus appointment type ("John, your psychiatry appointment is Thursday"), that's PHI. Yes, you need a compliant platform or explicit written patient authorization for that specific type of communication.
What's the fastest way to get compliant if my audit is in 60 days? Sign up for BloomText or iPlum today (both offer same-day BAA signing), run a 30-minute staff training, document the policy change in your P&P binder, then book a call with us to close the remaining gaps.
Know exactly where your security stands.
Get your free security assessment →Know exactly where your security stands.
Most IT directors are one audit away from a nasty surprise. We remove the guesswork.
- A full assessment of your environment, mapped to SOC 2 and HIPAA.
- A prioritised remediation plan you can act on, whether you hire us or not.
- Managed protection across endpoints, data, and incident response.
- Fixed monthly pricing, so there are no per-incident surprises.
The assessment is free, and the plan is yours to keep.