Can you text your clients?
Short answer: yes, within limits. HIPAA does not ban texting. What matters is what is in the message, whether the patient has been warned and has chosen it, and whether that choice is documented.
I am Scott Derby, I am an attorney, and this is one of the most common questions I hear, because texting is simply how people communicate now.
HIPAA does not prohibit texting. What it asks is that you protect patient information wherever it travels, and an ordinary text message travels in the open.
Start with what is in the message. A text that says “see you Tuesday” is a very different thing from one that includes a diagnosis, a medication, or details about why someone is being seen. The more a message identifies a person and connects them to their care, the more protection it needs.
Then there is the patient’s own choice. A patient is allowed to say “I know it is not secure, just text me the reminder.” That path exists. But it comes with a requirement most practices skip: you warn them about the risk, and you document that they chose it anyway. The documentation is what protects you later.
And for anything clinical, there are secure messaging tools built for healthcare, where the vendor will sign a business associate agreement. The same convenience, without the exposure.
So: keep casual texts casual, get the patient’s choice on the record, and use secure tools for anything real.
This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.