Blog / Compliance

HIPAA and iMessage: What to Know Before You Text Patients

Saad Khan4 min readCompliance

TL;DR

HIPAA doesn't ban texting. It regulates protected health information, so the question is never "can we text?" but "does this message carry PHI?" Scheduling logistics, generic reminders, and billing nudges written without health details sit outside the danger zone; anything revealing a condition, treatment, or result needs safeguards, BAAs, and a compliance officer's sign-off. Blue Reacher signs a business associate agreement on Enterprise plans and publishes its HIPAA-relevant controls at /trust. If your use case touches PHI, raise it before you send anything and bring your compliance lead.

Time to first messageAn A2P 10DLC launch runs brand vetting, then campaign review, then carrier approval, and lands in the three to six week range. An iMessage line needs no registration, and most teams send inside a week.A2P 10DLCBrand vettingCampaign reviewCarrier approval3 to 6 weeks, longer on a rejectionBlue ReacherSetupMost teams send inside a week
An A2P 10DLC launch runs brand vetting, then campaign review, then carrier approval, and lands in the three to six week range. An iMessage line needs no registration, and most teams send inside a week.
On this page
  1. 01Who does HIPAA actually cover?
  2. 02Does HIPAA allow texting patients at all?
  3. 03What is a BAA and when do you need one?
  4. 04Which messages are safe because they carry no PHI?
  5. 05Where should you draw the line and get help?
  6. 06Frequently asked questions

Who does HIPAA actually cover?

HIPAA covers providers, plans, clearinghouses, vendors handling PHI. Med spas, dental offices, clinics and their vendors sit inside. Gyms, coaches, wellness brands that never handle health records sit outside.

PHI is individually identifiable health information. Does it identify a person AND mention their health, treatment, or payment? "Your consultation Tuesday" is not PHI. "Your biopsy results ready" is PHI.

Context: "Your appointment at [oncology]" reveals the condition through the sender. Write as if a stranger reads over the shoulder, because one will. Your compliance officer owns the final call.

Does HIPAA allow texting patients at all?

Yes, with conditions. HHS permits electronic communication with safeguards; patients may request a channel. Appointment reminders are recognized treatment communications governed by minimum-necessary principle.

The Security Rule requires safeguards for PHI in transit and at rest. Consumer channels weren't built for medical systems. Most teams split messaging: no-PHI lane (runs freely), PHI lane (vetted systems only).

Two laws sit alongside HIPAA: the TCPA governs consent and opt-outs for all texting, health care included. STOP handling and consent records apply to every message in both lanes. State laws add layers too.

What is a BAA and when do you need one?

A BAA is HIPAA's contract requiring vendors to safeguard PHI, report breaches, accept liability (hhs.gov has samples). If a vendor touches PHI for you, you need a signed BAA first. No BAA, no PHI. No exceptions.

Will this platform carry PHI messages? If yes, it needs a BAA plus security posture. If no, it's ordinary business data under ordinary privacy law, not HIPAA's BA rules.

Get classification right with compliance officer input. Question "HIPAA compliance" claims. Compliance is an arrangement (safeguards, BAA, policies), not a product. Require a BAA and controls to honor it.

Which messages are safe because they carry no PHI?

Most of what health-adjacent businesses want to text never needs to touch PHI. That lane is where texting earns its keep with least risk. The discipline: name logistics, never care.

Messages that work without health information:

  • Scheduling logistics: "You're confirmed for Tuesday at 2pm. Reply R to reschedule." Time, date, location, nothing about why.
  • Generic reminders: "Reminder: your appointment is tomorrow at 10am." No service named, no provider specialty in the sender name if the specialty itself reveals a condition.
  • Intake and paperwork nudges: "Your forms are ready to complete before Thursday's visit," linking to a secure portal rather than embedding anything.
  • Billing logistics: "Your invoice is ready in the patient portal," with no procedure, diagnosis, or amount tied to a service name.
  • Reviews and referrals: "Thanks for coming in today, would you leave us a review?" after the visit, with consent.
  • Waitlist and operational notices: openings, closures, weather delays, new-location announcements.

Where should you draw the line and get help?

Results, diagnoses, prescriptions, treatment details, pre/post instructions, anything a lock screen shouldn't show need PHI-lane systems, BAAs, compliance sign-off. Don't text them otherwise.

When a message could go either way, rewrite it until it can't, or move it to the portal.

Our posture: /trust and /security. The no-PHI lane works: scheduling, reminders, reactivation, reviews, written clean. If PHI-involved, ask us; the honest answer may be your messaging belongs elsewhere.

Frequently asked questions

Is texting patients a HIPAA violation?

Texting itself isn't a violation. HHS permits electronic communication with safeguards; patients can request a channel. Risk comes from content: PHI-carrying text needs safeguards and vendor BAAs. Pure logistics (times, dates, reschedule links) don't carry PHI. Design content first.

Is iMessage HIPAA compliant?

HIPAA compliance is a category error for any consumer channel. Compliance is an arrangement (safeguards, BAAs, policies), not a product. Options: keep PHI out of text and use texting for logistics only, or build a PHI-handling arrangement your compliance officer approves.

Do appointment reminders violate HIPAA?

Appointment reminders are recognized treatment communications under the Privacy Rule, minimum-necessary principle (HHS). Keep lean: date, time, reschedule. Skip procedure names. Consider whether your sender identity reveals a condition, since a reminder from a named specialty can disclose more than the message text.

What is a business associate agreement in plain terms?

A business associate agreement is HIPAA's contract between covered entities and vendors handling PHI. It requires vendors to safeguard data, report breaches, accept responsibilities (HHS has samples). Simple rule: no signed BAA, no PHI to that vendor. If your messages carry no PHI, the BAA question doesn't apply.

Does Blue Reacher sign BAAs or claim HIPAA compliance?

Our posture, DPA, subprocessor list at /trust; technical details at /security. If your plan involves PHI, ask us with your compliance officer. We'll say plainly if we fit. Our health-adjacent customers run the no-PHI lane: scheduling, reminders, reactivation, reviews.

Keep reading

More on compliance

Put this on your pipeline

Blue Reacher runs outbound iMessage for B2B sales teams, from your CRM, with setup handled for you.

Book a demo