Two-Way Patient Texting and HIPAA: What Is Allowed and What Is Not

Texting patients is allowed under HIPAA. What is not allowed is texting protected health information from a personal phone, through an unlogged consumer app, without a business associate agreement covering the vendor, and without the patient having agreed to be reached that way. Every compliance article says some version of that. What they leave out is the operating layer: which texts carry PHI and which do not, what your shared inbox has to record, what an AI auto-reply may and may not say, and what happens to the 17% of patient texts that arrive when nobody is at the desk. This article covers that layer.

The volume is the reason to get it right rather than ban it. Across several hundred practices, patients sent more than 100,000 inbound texts between June 1 and September 26, 2026, and over twelve months practices received over 300,000 inbound texts and sent 2.4 for every one they received (KloudMD platform data). Patients already text you. The question is whether those messages land on a system you control.

The four conditions, briefly

You will find these in every guide, so here they are without the padding:

  1. A business associate agreement with any vendor whose system stores or transmits PHI on your behalf. This is the line between a consumer messaging app and a compliant texting platform. No BAA, no PHI.
  2. Access controls and an audit trail. Every staff member has their own login, and the system records who read and sent what. A shared front-desk login defeats this.
  3. Minimum necessary. Put the least PHI in the message that the workflow needs. An appointment reminder needs a date and time; it does not need the diagnosis.
  4. Patient consent and opt-out. The patient agreed to be texted, that agreement is recorded, and STOP works.

Now the parts that actually determine whether your front desk is compliant on a Tuesday afternoon.

Personal phones are the real risk, not the texting

The most common violation is not exotic. A hygienist texts a patient from her own phone to confirm a time, or a coordinator sends a before-and-after photo from his iPhone. The PHI is now on a device the practice does not control, in a thread with no audit record, and it leaves with the employee.

The fix is to make the compliant route the easiest one: text-enable the practice’s existing phone number so patients text the number they already know, and put every conversation in a shared team inbox where the thread sits on the patient record next to calls and forms. When the office line is textable and the inbox is on staff phones through a mobile app, there is no reason for anyone to reach for a personal number.

Which texts carry PHI and which do not

Not every text is PHI, but more of them are than people assume. The fact that a named person has an appointment at a medical practice is health information. A practical sorting:

Message PHI? How to handle
“Are you open Saturday?” and the reply No Answer freely, including by AI
Appointment reminder: date, time, location Yes (minimal) Send from the platform; no service name or diagnosis in the body
“Do you take Aetna?” Borderline Answer from your accepted-plans list; do not discuss the patient’s coverage details
Booking a specific service (“Botox consult”, “root canal”) Yes Fine inside the platform; keep the confirmation text generic
Test results, medication questions, symptoms Yes, clinical Do not answer by text; route to a clinician through the practice’s clinical channel
Photo of an insurance card or a wound Yes Received into the platform, stored there; never forwarded by email

The pattern: templates should ask the next question, not dump a chart into SMS. “Reply YES to confirm your appointment Thursday at 2:10” is compliant and effective. “Reply YES to confirm your Thursday 2:10 follow-up for your anxiety medication” is neither necessary nor wise.

Consent to text is simple to obtain and easy to lose track of. Record it on the patient record, not in a paper form in a drawer: the date, the channel (intake form, booking page checkbox, verbal at the desk), and the phone number it applies to. When a patient texts you first, that is a reasonable basis to reply by text about the thing they asked, but it is still worth capturing an explicit opt-in for reminders and outreach.

Opt-out must be automatic. A STOP reply should suppress every further outbound text to that number, including reminders, and staff should see that status on the record before they hit send.

Carrier registration is a compliance issue too

This one never appears in HIPAA articles because it is a carrier rule, not a HIPAA rule, but it decides whether your compliant texts arrive at all. Business texting in the US runs on registered 10DLC numbers (application-to-person, or A2P). A practice number that is not registered with the carriers will have messages filtered, often silently. Unregistered 10DLC is the reason many reminder tools appear to work and then quietly stop delivering. Ask your vendor whether your number is registered and under which campaign use case.

What an AI auto-reply may and may not do

More practices are letting an AI agent handle first replies. That is compatible with HIPAA under the same conditions as staff texting, plus three controls specific to automation:

  • Draft mode versus auto-send, set per channel. Start in draft mode, where the AI proposes a reply and a staff member approves it. Turn on auto-send only for the message types you have watched it handle well, and only within hours you set. Auto-send should be off by default.
  • Clinical and urgent guardrails. Anything clinical, urgent, or unusual must be intercepted before a reply is sent and routed to a named person. An AI that answers “is this normal after my procedure?” is a liability regardless of how good the answer is.
  • Audit logging on every AI action. Each AI reply, booking, or escalation is recorded the same way a staff action is, so you can show exactly what was said to whom.

Booking inside the conversation is the highest-value AI use. Across the platform, 17% of inbound patient texts arrive outside 8am to 5:59pm (11% between 6pm and 11:59pm, 6% overnight), and evening texts from 6pm to 11pm made up roughly one in nine of all inbound texts over the summer (KloudMD platform data, Jun to Sep 2026). Those are mostly “can I get in this week” and “need to move Thursday” messages. An AI that books against the live schedule and writes to the EHR closes them at 8pm; a person reads them at 8am. Both are compliant. Only one fills the slot. For the hour-by-hour pattern see when patients text their doctor.

Volume and the 2.4 to 1 ratio

One more number from the platform data shapes policy. Practices send 2.4 outbound texts for every inbound patient reply over twelve months, and 39% of the outbound messages were appointment-related reminders and confirmations. Most of your texting is one-directional and templated. That is where the minimum-necessary rule does the most work: get the reminder and confirmation templates right once and the bulk of your PHI exposure is handled. Then the two-way conversations, which are fewer, get staff attention. Reminder wording and timing are covered in appointment reminder texts: cadence and wording.

A policy your staff can actually follow

  • Patients text the office number. Nobody texts patients from a personal phone, ever.
  • All replies go through the shared inbox, from an individual login.
  • Reminders and confirmations state date, time, and location only.
  • Clinical questions get a scripted redirect (“A clinician will call you about that; if this is urgent call 911”) and a task to the right person.
  • Photos and documents stay in the platform; never forward by email.
  • Consent and STOP status live on the patient record; check before outreach.
  • AI replies start in draft mode; auto-send is enabled per channel after review, with clinical guardrails on.

How KloudMD handles this

KloudMD text-enables the practice number patients already call, and every conversation lands in a shared team inbox on the patient record, with access controls, individual logins, and logging of every action. KloudMD signs a BAA, and templates are built to ask the next question rather than put chart detail in SMS, with consent tracking on the record. Carrier registration (A2P 10DLC) is included so messages deliver. The AI texting agent runs in draft-only or auto-send mode per channel with its own hours, auto-send off by default, and layered guardrails that hold clinical and urgent messages for a named staff member; it can book real appointments into your EHR inside the thread. See two-way texting, AI texting and chat, and the HIPAA overview for the BAA and security details.

Get started with KloudMD and we will walk your texting policy on the demo.