What HIPAA actually requires when you text patients, why personal-phone workarounds fall short, and how to set up compliant patient texting that works like regular SMS.
Get started for freeSchedule a demo →You can text patients, but not from your personal phone. Personal-phone texting exposes your private number, mixes patient messages with personal ones, and leaves no audit trail your organization controls. HIPAA does not ban texting. It requires a signed BAA with the platform, encryption, access controls, and audit logs. BloomText gives your practice a dedicated number patients text over SMS, keeps messages in a shared team inbox instead of your personal phone, and includes a signed BAA on every plan, including the free plan.
Most practitioners who text patients from their personal phone already know it is not ideal. A solo therapist whose client messages arrive between texts from family. A small practice where the front desk texts appointment reminders from a personal cell. A provider who gave out a personal number years ago and now cannot take it back.
The problem is not that texting is wrong. Texting is the fastest way to reach patients, and patients prefer it. The problem is the phone. A personal device has no BAA, no encryption the organization controls, no access controls, and no audit trail. The moment a text ties a name to a visit, that message contains protected health information, and it is sitting unprotected in your personal Messages app.
Your organization cannot revoke access to those texts when you leave. It cannot produce them for an audit. It cannot even confirm they exist.
A second phone. Some practices buy a dedicated device for patient texting. That solves the personal-number problem but creates a new one: a phone that sits in a drawer, runs out of battery, and gets carried by whoever is on shift. If the phone is lost, every patient conversation on it is an uncontrolled breach.
Google Voice or Grasshopper. These give you a separate number without a second device. But neither will sign a BAA. Google Voice reserves its BAA for paid Google Workspace plans and does not offer one for the standalone app. Grasshopper has no BAA at all. Using either for patient communication is a HIPAA violation regardless of how convenient it feels.
A patient portal. Your EHR may offer one. Portals work for forms and records, but patients do not log in to read a two-sentence follow-up. A provider sending a brief check-in needs something the patient actually sees. Portal messages sit unread.
Enterprise clinical messaging platforms exist. Some cost over a hundred dollars per provider per month. Others require annual contracts starting in the hundreds. They were built for hospital systems with IT departments, not for a six-person practice or a solo provider who needs to start texting patients this week.
Then there are the tools that do sign a BAA but require patients to download an app or create an account. Patients will not do that for a quick message. The result is the same as the portal: the compliant channel exists, nobody uses it, and staff go back to texting from their personal phones.
Practices that have shopped this problem describe evaluating dozens of platforms. The gap is consistent: tools built for hospitals are too heavy, tools patients will actually use are not compliant, and the ones in between still require an app download. See what makes texting HIPAA compliant for the full set of requirements.
You need four things. A dedicated work number so your personal number stays private. A signed BAA so the platform is legally accountable for protecting patient information. Encryption and access controls so messages are protected in transit and at rest. And a shared inbox so conversations belong to the practice, not to whoever is holding the phone.
That last point matters more than it sounds. When messages live on a personal phone, they leave with the person. When messages live in a shared team inbox, the organization keeps the full history, controls who has access, and can revoke access the same day someone leaves.
BloomText gives your practice a dedicated number. Patients text it like any other number and receive a secure link over SMS. They tap the link, read the message, and reply — all from their phone's browser. No app download, no portal login, no account creation on the patient side.
Messages arrive in a shared team inbox your staff access from any device. Multiple team members can see and respond to patient conversations. When someone leaves, admins revoke their access and the conversation history stays with the practice.
Every plan includes a signed BAA, encryption in transit and at rest, access controls, and audit logs. The free plan includes all of this. If you want to keep the number your patients already know, BloomText can check whether your existing number qualifies for porting or hosted SMS. See pricing for current plans.