HIPAA Tip: HIPAA Compliant Texting to Patients
In February, 2024 Centers for Medicare and Medicaid (CMS) came out with a Memorandum on Texting Patient Information and Orders. The memorandum was specific for hospitals and CAHs; however, this does not mean that all other healthcare organizations are exempt when texting patient data.
Whenever electronic Protected Health Information (ePHI) is transmitted there needs to be appropriate safeguards to ensure the Confidentiality, Integrity and Availability (CIA) of the data to prevent unauthorized access and maintain the security of the ePHI in transit.
Before texting ePHI stay HIPAA-compliant and cover your bases:
- Patient authorization is required before disclosing PHI, especially when transmitting to a third party. Always confirm on the patient consent form they approve texting their data.
- Encryption is the necessary safeguard to protect data from unauthorized access when transmitting ePHI.
- Implement strong access controls to limit who can access and transmit ePHI with unique user IDs and two-factor or multi-factor authentication.
- Only HIPAA-compliant platforms must be used when transmitting ePHI. Additionally, a Business Associate Agreement needs to be in place with the company supplying the software solution.
- Always follow the “minimum necessary” rule when transmitting ePHI; just data that is for the intended purpose.
- Physical safeguards are equally as important when transmitting ePHI. Devices need to be password protected, purge data once transmitted and always ensure cell phones are secure when not in use.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP