Does texting resident information violate HIPAA?
Not by itself. HIPAA never names text messaging and does not prohibit it. What the rule asks is that you assess the risk and apply safeguards you could defend to a reviewer — and ordinary phone-to-phone texting usually struggles on the safeguards that are mandatory. The problem is the channel, not the act of sending a message.
What the rule actually asks for.
The Security Rule does not hand you a list of approved apps, and it does not set one universal bar every channel must clear. It asks you to run a risk analysis for your own organization and then apply safeguards that are reasonable and appropriate for what that analysis found.
Those safeguards come in two kinds, and the difference is the part most summaries get wrong:
- Required specifications have to be implemented. Unique user identification and audit controls are the two that matter most for messaging.
- Addressable specifications, including encryption, are not optional but are not automatic either. You assess whether each is reasonable and appropriate, implement it if so, and if not, document why and put an equivalent alternative in place.
So the honest question is not whether a channel ticks a fixed checklist. It is whether you could defend your choice of channel, in writing, to someone reviewing it later.
Where ordinary texting struggles.
Notably, it struggles on the required safeguards rather than the addressable ones. Encryption is the detail people reach for first, but it is not usually what makes the analysis fail:
- Messages sit on personal phones the facility does not administer, so unique user identification and access control are hard to demonstrate.
- There is no audit trail to produce during a review, because the history belongs to the handset.
- When someone leaves, the resident information in their thread leaves with them and cannot be retrieved or removed.
There is also a point about business associate agreements that runs opposite to the way it is usually told. Your mobile carrier almost certainly will not sign one, and generally does not need to: HHS treats organizations that merely transport information as conduits rather than business associates. That is not reassurance. It means nobody has accepted responsibility for that data except you.
None of this is fixed by asking staff to be careful. People text because it is the fastest way to reach a colleague who is not at a desk. Remove the fast option without replacing it and the texting continues, just less visibly.
What long-term care teams do instead.
The workable answer is not a policy telling people to stop. It is a channel quick enough to actually get used, whose safeguards you can point at during a review without reconstructing anything.
That is what Dexzyle is for. Conversations about a resident stay inside a system built for PHI, with encryption in transit and at rest, signed document access, and audit-oriented logging. A BAA is part of onboarding rather than a procurement errand. Staff still get the speed of a message; the facility keeps a record it can stand behind.
Because the conversation already carries resident context from the systems you run, the message can also be filed to the PointClickCare resident chart where enabled for your organization, so the exchange that resolved something is not stranded in a thread nobody can find later.
Is it safe if we leave the resident's name out?
Rarely. Protected health information covers any detail that could reasonably identify someone, and a room number, an admission date, or a diagnosis attached to a single facility often does. Teams that lean on stripping identifiers drift back to full detail under time pressure, because the vague version is not useful enough to act on.
Dexzyle is built for PHI in HIPAA-regulated care settings: encryption in transit and at rest, signed document access, and a BAA as part of onboarding. See our security practices →
This page describes how the Security Rule is generally applied in long-term care operations. It is not legal advice, and it is not a substitute for your own risk analysis. Your compliance officer owns the determination for your organization.