Insights

Secure Texting HIPAA: What LTC Admins Must Know

Secure Texting HIPAA: What LTC Admins Must Know

Secure Texting HIPAA: What LTC Admins Must Know

LTC administrator reviewing CMS compliance memo

Texting PHI in a long-term care facility is permitted under HIPAA, but only through a purpose-built secure texting platform (STP) under a signed Business Associate Agreement (BAA). That is the one-sentence verdict. CMS guidance QSO-24-05 makes the conditions explicit: texted orders must be promptly entered into the EHR, authenticated, and retained in the medical record. Computerized Provider Order Entry (CPOE) remains the preferred method. Standard SMS is not acceptable for PHI under any circumstances.

Three immediate constraints every administrator must act on before allowing any text-based PHI:

  • Sign a BAA with the vendor before a single message containing PHI is sent.
  • Block SMS fallback for clinical content. Carrier SMS cannot be used for PHI even as a backup.
  • Confirm CMS documentation rules apply: texted orders enter the EHR promptly, are authenticated, and are retained.

Pro Tip: Print the CMS QSO-24-05 memo and attach it to your next compliance meeting agenda. It is the single document that settles the “can we text orders?” debate and defines what “promptly” means for EHR entry.


Table of Contents

What does “secure texting” actually mean under HIPAA?

“HIPAA-compliant texting” is not a product category HHS certifies. There is no government-approved app list. Compliance is a framework the facility must maintain, and responsibility always resides with the covered entity, regardless of what a vendor’s marketing says.

A secure texting platform earns that label operationally when it enforces all of the following:

  • Authenticated user accounts (no shared logins)
  • Encrypted message transport and encrypted storage at rest
  • Server-side message retention with tamper-evident audit logs
  • A signed BAA with the vendor
  • No local caching of PHI on personal devices
  • Integration path to the EHR or clinical task system

The distinction between a secure platform and consumer SMS comes down to four gaps: encryption guarantees, auditability, BAA availability, and device backup controls. Standard SMS lacks all four. Carriers will not sign BAAs. Messages can be cached in device backups. There is no audit trail an administrator can pull for a survey or investigation.

One nuance worth knowing: enterprise-grade LTC platforms often deliberately avoid consumer-style end-to-end encryption. The reason is administrative visibility. When a staff member is terminated or a message is subpoenaed, the facility needs server-side access to that content. Consumer E2E encryption can block that access entirely.

Healthcare workers reviewing secure texting documents


The covered entity, meaning your facility, retains full HIPAA compliance responsibility even when a vendor handles the technology. A vendor claiming “HIPAA-compliant” in their sales deck does not transfer your liability.

BAA requirements. A BAA is mandatory whenever a vendor creates, receives, maintains, or transmits PHI on your behalf. The BAA must flow down to subcontractors and must cover audit support and data deletion procedures. Minimum BAA elements to insist on in writing:

  • Subcontractor flow-down clause
  • Breach notification timeline (HHS requires 60 days; negotiate shorter)
  • Data deletion and portability terms on contract termination
  • Audit support obligations (log exports, investigation cooperation)
  • Incident response SLA

CMS Conditions of Participation. For skilled nursing facilities, CMS CoPs require that clinical orders be authenticated and placed in the medical record promptly. A texted order that sits in a messaging app without EHR entry is a CoP violation, not just a HIPAA risk. Auditors and surveyors look for documented controls and BAAs, not vendor marketing language.


Which technical controls should you require in writing from any vendor?

Translate compliance requirements into procurement language. These are the specs to put in your RFP and verify before signing.

Infographic listing legal must-haves for secure texting

Control Area What to Require Red Flag
Encryption in transit TLS or higher “Encrypted” with no protocol stated
Encryption at rest AES-level encryption Vendor cannot confirm storage encryption
Audit logs Immutable timestamps, user IDs, exportable Logs not exportable or deletable by users
Device controls MFA, remote wipe, no local caching BYOD with no MDM requirement
EHR integration Secure API or certified connector Manual copy-paste as the only workflow
BAA Available, covers subcontractors “We’ll send it after you sign up”
Offboarding Automated, tied to HR/SSO Manual ticket required to revoke access

CNA turnover in LTC is very high in some facilities in some facilities. At that rate, manual access revocation is not a process, it is a liability. Platforms must integrate with your identity system so terminated staff lose access programmatically the moment HR closes the record.

One technical decision that surprises many administrators: preventing local caching is as important as encryption. A message encrypted in transit can still persist in a phone’s photo library or iCloud backup after an employee leaves. Require cloud-only message handling, disable screenshots where the platform allows it, and test remote wipe during the pilot.

Pro Tip: Ask vendors for their most recent SOC 2 Type II report and penetration test summary before the demo. A vendor who hesitates on either document is telling you something about their security posture.

Additional operational controls to specify:

  1. Message expiration and revocation capability
  2. Content tagging to distinguish PHI messages from non-PHI notifications
  3. Hard block on SMS fallback when PHI is present
  4. Session timeout and screen lock enforcement

How do LTC-specific workflows change your policy requirements?

Generic HIPAA policy templates fail nursing homes because they do not address shift handovers, shared workstations, or coordination with contracted therapy and hospice staff. Your policies need to cover all three.

Shift handovers. Structured message templates with required fields (resident ID, issue, action taken, follow-up needed) reduce transcription errors and create a documented handover record. Tag handover messages explicitly so they can be reconciled against the EHR at shift close. Automatic task creation in your facility’s task system turns a texted note into a trackable, closeable item.

BYOD and shared devices. Every personal device used for clinical messaging needs containerization or MDM enrollment. Require:

  • Mandatory screen lock with a short timeout
  • No local message storage or photo backup to personal cloud accounts
  • Documented device inventory updated at each onboarding

Contracted and agency staff. Hospice partners, contracted therapists, and agency nurses need temporary access windows tied to their shift or engagement period. Require subcontractor BAAs before granting directory access, and configure automatic expiration so access ends when the contract does. Scope their directory access to the residents they are assigned to, not the full facility roster.

  1. Draft a policy addendum specifically for contracted staff access.
  2. Add a BAA requirement to every staffing agency contract.
  3. Test access revocation for a contractor during the pilot phase.

What questions should you ask vendors during procurement?

Score vendors across eight dimensions. Demand written proof, not verbal assurances.

Dimension What to Expect Red Flag
Security features TLS + AES-level encryption, documented Marketing language only
BAA terms Available pre-signature, covers subs Delayed or incomplete
Audit & logging Exportable, immutable, retained per policy No export function
Device & identity MFA, SSO/SAML, remote wipe Password-only login
EHR/task integration API or certified connector Manual workflow only
Frontline usability Mobile-first, minimal taps Desktop-primary design
Support & pilot Named onboarding contact, pilot option No pilot, long-term lock-in only
Pricing model Per-facility or per-user, transparent Opaque bundling

Sample questions to send in writing before the demo:

  1. Provide your most recent SOC 2 Type II report or equivalent third-party audit.
  2. Share your standard BAA text, including subcontractor flow-down language.
  3. Describe your breach notification SLA and incident response process.
  4. How does your platform prevent local caching on personal devices?
  5. What is your data deletion process on contract termination?
  6. How does your platform integrate with [your EHR system name]?

How do you run a pilot and know when to scale?

A 6–12 week pilot on one unit is the right scope. Keep it narrow enough to control variables, wide enough to surface real workflow friction.

  1. Select one unit and two to three user roles (charge nurse, floor CNA, unit manager). Limit the pilot to that scope.
  2. Integrate one EHR workflow — order entry or shift note reconciliation — so you can measure time-to-EHR-entry from day one.
  3. Train the cohort with role-specific scenarios, not generic HIPAA slides. Document attendance using your facility’s training records.
  4. Track four metrics weekly: message error rate, time-to-EHR-entry for any texted orders, audit log completeness (spot-check 10% of messages), and user adoption rate.
  5. Set go/no-go thresholds before the pilot starts: for example, zero unresolved audit log gaps, EHR entry within the facility’s defined window, and no PHI found in local device storage during a mid-pilot check.
  6. Evaluate at week six. If thresholds are met, expand to a second unit. If not, identify the specific failure point before scaling.

Incident and near-miss counts are the metric most pilots ignore. A single near-miss (PHI sent to the wrong recipient, a message not entered in the EHR) during the pilot is valuable data. It tells you where the policy or the platform needs adjustment before you are operating at full scale.


Myltcapps supports your compliance operations from day one

Secure messaging compliance does not end when a message is sent. The harder problem for most LTC facilities is capturing what was communicated, assigning it to the right staff member, and reconciling it against the clinical record before the next survey.

Myltcapps

Myltcapps is a phone-first operations suite built specifically for long-term care. Where a secure texting platform handles the message, Myltcapps handles what comes next: the task gets created, assigned, tracked, and closed in a documented workflow your DON and administrator can see in real time. The compliance task and checklist module converts verbal and texted actions into auditable records. The alerts and communication system ties notifications to tasks so nothing falls through the gap between a message and a documented action. Seeded compliance libraries cover HIPAA, QAPI, and CMS Conditions of Participation so your team is not building policy frameworks from scratch.

For facilities without a large IT department, Myltcapps deploys on personal devices with minimal configuration. Staff need a phone and a few minutes of onboarding. Administrators get surveyor-ready reporting exports without a data analyst.

Request a pilot at myltcapps.com and see how the platform fits your current workflows before you commit.


Key Takeaways

Secure texting is HIPAA-permissible in LTC only when a signed BAA, a purpose-built platform, and CMS-compliant EHR documentation are all in place simultaneously.

Point Details
BAA is non-negotiable Sign a BAA with the vendor before any PHI enters the messaging platform.
SMS cannot carry PHI Standard carrier SMS lacks encryption, audit controls, and BAA availability.
CMS requires EHR entry Texted orders must be authenticated and entered in the medical record promptly per QSO-24-05.
Automate offboarding With high CNA turnover, manual access revocation fails; require SSO and automated offboarding.
Myltcapps closes the loop The task and alerts modules convert texted actions into auditable, surveyor-ready records for LTC facilities.

The gap most facilities miss

The compliance conversation around secure texting in nursing homes almost always focuses on the platform: did you buy the right app, does it have a BAA, is it encrypted? Those questions matter. But the real compliance gap is what happens after the message is sent.

A texted order that never makes it into the EHR is a CoP violation whether or not the messaging app was “HIPAA-compliant.” A task communicated over a secure platform but never assigned, tracked, or closed is an operational failure that a surveyor will find. The platform is the entry point. The workflow is where compliance actually lives.

Facilities that treat secure texting as a technology purchase and skip the policy and workflow work are the ones that get cited. The ones that do it right spend as much time on shift handover templates, EHR reconciliation steps, and contracted staff access controls as they do on vendor selection. That is not a popular message for vendors to deliver, which is probably why it rarely appears in their sales materials.

Compliance stays with the facility. A vendor’s BAA does not change that. What it does is give you a contractual partner who shares the obligation to protect PHI. Choose that partner carefully, document everything, and test your incident response before you need it.

If you want to talk through how Myltcapps fits into a secure-text rollout for your facility, or if you want to see the compliance task module in action, reach out through myltcapps.com. Come with your current EHR system name and a rough headcount. That is all the information needed to scope a pilot conversation.


Useful sources for your procurement and policy packets

Save these documents in your compliance, IT, and risk management folders. They are the primary references surveyors and auditors expect you to have reviewed.

  • CMS QSO-24-05 (Hospital/CAH): The governing CMS memo on texting of patient information and orders. Cites the STP requirement and EHR documentation rules. Reference this in your policy approval documents.
  • AMA: Can clinicians communicate orders via text?: Plain-language summary of CMS and Joint Commission positions. Useful for briefing clinical leadership.
  • HIPAA Journal: Is texting a HIPAA violation?: Covers the factors that determine whether a specific message is a violation. Useful for training materials and policy drafting.
  • AccountableHQ: HIPAA-compliant text messaging: Practical checklist covering risk analysis, safeguards, BAAs, training, and incident response. Use as a procedural companion to this guide.
  • 360training: Understanding HIPAA-compliant texting: Good overview of what HIPAA allows and why standard texting is risky. Suitable for staff training context.
  • LTC News: HIPAA-compliant communication tools for LTC: Addresses LTC-specific risks including high turnover and the case for automated offboarding.

For a facility-specific HIPAA compliance checklist tailored to LTC, Myltcapps publishes a step-by-step guide that maps directly to the documentation surveyors request.

This article provides general compliance information for educational purposes. It is not legal advice. Confirm current HIPAA requirements, CMS Conditions of Participation, and state regulations with qualified legal counsel or your compliance officer before implementing any secure texting program.

Request a demo

See the apps on your own phone.

Drop your details and we'll email you a link to the live demo. Click around on your own time — pricing is right here whenever you're ready to sign up.

We email your link within one business day.