Secure vs. insecure texting and HIPAA
When to send a secure text with link and when an insecure text is fine. Why a BAA doesn't make plain texts safe for PHI, with examples and a quick decision guide.
Overview
BloomText gives you two ways to text a patient:
- Secure text with link. It can contain PHI (protected health information). The patient gets a text with a link and reads your message in BloomText.
- Insecure text. It can't contain PHI. The patient gets your message as a regular text message.
This article explains the difference, why a signed BAA doesn't change it, and how to pick the right one in a few seconds.
Your message is sent as a regular text message and arrives in the patient's Messages app, word for word.
- The carrier and the phone store it unencrypted.
- It stays in the phone's messages for as long as it's kept.
- It can't be recalled once it's sent.
Use it only for messages with no PHI, like an appointment reminder or “Please call our office.”
1. A text with a secure link. Your message isn't in it.
2. Tapping it opens your message in BloomText, over HTTPS.
The patient reads and replies in the browser. There's no app or account. The link expires after 7 days, and you can recall a message.
The short answer
- Does your message contain PHI? Use Secure text with link.
- No PHI at all? An insecure text is fine. For example: "You have an appointment tomorrow. Call us with any questions."
- Not sure? Use Secure text with link. It works for every message.
An insecure text is simpler for the patient: they read it right in their messages, with no link to tap. That's why it's handy for short, general messages.
Why BloomText for secure texting
BloomText makes it easy to send patients secure messages by text. There's no app to download and no account or password to set up. The patient taps the link and they're in the conversation, where they can read your message and reply.
What makes the link secure:
- Your message never travels in the text. The text holds only the link.
- The link opens over HTTPS, an encrypted connection.
- Every link expires after 7 days. The patient can get a new one with a tap, sent to the phone number on file.
- You can recall a message you've sent.
Secure texts work for groups too. One secure chat can include several patients or family members, plus coworkers and teams, and each person gets their own link. See group conversations. An insecure text goes to one patient at a time.
BloomText is built for sending PHI by text, under a signed BAA.
A BAA doesn't make plain texts safe for PHI
A Business Associate Agreement (BAA) is a contract. When a vendor handles PHI for your organization, HIPAA requires one. BloomText offers a free signed BAA (see Business Associate Agreement).
A BAA sets out each party's legal obligations. It doesn't change how a regular text message travels. HHS makes a similar point in its guidance on cloud service providers: besides signing a BAA, your organization still has to understand the service and run its own risk analysis.
A regular text message leaves BloomText and goes through the mobile carriers to the patient's phone. Along the way:
- carriers and the patient's phone store it unencrypted;
- it stays in the phone's messages, readable by anyone who picks up or unlocks the phone, for as long as it's kept;
- once it's sent, it can't be recalled.
A BAA with BloomText doesn't change any of this, so an insecure text must not contain PHI. You can still use one for messages with no PHI.
What counts as PHI in a text
HHS defines PHI as health information that identifies the patient. That includes anything about their health or condition, the care they receive, or payment for that care. A text goes to the patient's own phone number, so it's already tied to them. Ask yourself: beyond "you have an appointment" or "please call us", does this message reveal anything about their health, their treatment, the kind of care they get, or their bills? If it does, it contains PHI.
| Message | Contains PHI? | Send as |
|---|---|---|
| "You have an appointment tomorrow at 2 pm. Call us with any questions." | No | Insecure text is fine |
| "Our office is closed Monday for the holiday." | No | Insecure text is fine |
| "Please call our office." | No | Insecure text is fine |
| "Your appointment with Dr. Lee in oncology is tomorrow." | Yes: it reveals the kind of care | Secure text with link |
| "Your lab results are ready: your A1C is 7.2." | Yes | Secure text with link |
| "Your prescription for sertraline is ready for pickup." | Yes | Secure text with link |
| "Your balance for your MRI is $240." | Yes | Secure text with link |
| Any file: referral, record, image, form | Treat as PHI | Secure text with link |
For reminders, HHS suggests including only the information needed to confirm the appointment, or asking the patient to call back. Keep insecure texts that short. An insecure text is sent exactly as you type it, from your team's number. If your organization's name alone reveals the kind of care (for example, a specialty clinic), follow your organization's policy on whether plain reminders are acceptable.
How a secure text with link protects PHI
When you send a Secure text with link:
- The text holds a link, never your message. The patient gets a text that
reads like "Your name from your organization
just sent you a secure message. Click the link to read it:" followed by a
blm.carelink. Your message itself never goes through the carriers or sits in the phone's message history. - The patient reads it in BloomText. The link opens your conversation in the patient's browser over an encrypted (HTTPS) connection. The patient can reply and attach files there, too. The message stays on BloomText's servers. See Security and HIPAA compliance for how BloomText protects stored data.
- An email goes out too. If the patient has an email address on file, they also get an email with the same link. It doesn't contain your message.
- Links expire after 7 days. An expired link shows Text me a new link, which texts a fresh link to the phone number on file. Each new message you send also includes a new link.
- You can recall a message. If you recall a message, the patient sees "This message was recalled" in its place. The text they already got only ever held the link. Recall can't undo a message the patient has already read.
- You can see when the patient opened it. After the patient opens the conversation, their icon appears under the message they've seen.
The link opens the whole conversation, not just one message. Anyone who has an unexpired link can open it, so check that the phone number and email address belong to the patient before you send.
What an insecure text is
An Insecure text is a regular text message (SMS) sent from your team's number. The patient reads it and replies in their phone's messaging app, and replies land in the same BloomText chat.
Use it when the message has no PHI, such as general reminders, office hours, directions, or "please call us". Don't use it for results, diagnoses, medications, referrals, bills for a specific service, or any file.
Keep in mind:
- It can't be recalled. BloomText doesn't offer a recall option in insecure-text chats. The message is already on the patient's phone.
- Files aren't protected. If you attach a file, the patient gets a text with a download link that works for anyone who has it, for 7 days. Send files by Secure text with link.
- There's no read confirmation. Carriers don't tell BloomText whether a regular text was read.
- Patients may reply with PHI. A patient can text back anything, such as "my rash is worse". Don't answer with PHI in the same insecure chat. Start a new chat with Secure text with link to reply.
If you send PHI in an insecure text by mistake, you can't take it back. Tell your privacy officer or supervisor right away, and follow your organization's process for reporting it.
Where you see this in BloomText
- Send via… In the new-chat dialog, you choose Secure text with link (closed lock) or Insecure text (open lock). In this dialog, Insecure text appears only when you send from a team with a phone number to one patient. When you pick it, the More information link turns into an orange alert chip as a reminder. It doesn't stop you from sending.
- The "+" menu (web). Send a secure text with link: "Patient gets a text with a link to your secure message. Can contain PHI." Send an insecure text: "Sent as a regular text message. Can't contain PHI."
- Broadcasts. When you message many patients at once, the Message Type field offers the same two choices. Secure text with link texts each patient a secure link to your message. Insecure text sends each patient your message as a regular text message. See Broadcasts.
- Insecure text chats. In the inbox, an insecure-text chat shows an orange open-lock icon. In the chat, the header shows an Insecure text label, and the message box reads "Insecure text: don't include PHI" (web) or "Insecure text: no PHI" (mobile).
- More information. The More information explainer compares the two side by side under Can contain PHI and Can't contain PHI. On the web, hover over the inbox icon or the header label to open it. On mobile, tap the header label.
For the full steps to set up texting and send a message, see SMS messaging with patients.
Common questions
We signed a BAA with BloomText. Can we send PHI in an insecure text now?
No. A BAA is a contract about how BloomText handles PHI for you. It does not change how a regular text message travels: carriers and the patient's phone still store it unencrypted, and it cannot be recalled. Use Secure text with link for anything with PHI.
Can a patient ask us to text them PHI directly?
HHS guidance does not address texting specifically. For email, HHS says a patient has the right to receive copies of their records by unencrypted email if they ask for it that way. The provider must first briefly warn them of the risk and confirm they still want it. HHS also says a provider cannot require a patient to accept an unsecure method. Whether and how your organization honors a request to receive PHI by regular text is a policy decision, so follow your organization's policy or ask your privacy officer. In the meantime, Secure text with link lets the patient read PHI on their phone without it sitting in their text messages.
Is BloomText HIPAA compliant?
BloomText is built to protect PHI and offers a signed BAA. Compliance, though, depends on how your organization uses any tool, including what staff put in insecure texts. Send PHI only by Secure text with link. See the Security and HIPAA compliance article for how BloomText protects data.
What about photos, files and picture messages (MMS)?
Send files by Secure text with link. The patient views them in the secure conversation, and they can attach their own files there. In an insecure text, BloomText sends a file as a download link that anyone who has it can open for 7 days. If a patient texts a photo to your number, it arrives in the chat, but it traveled as a regular picture message. Ask patients to reply through a secure link when they need to send something with PHI.
Is an appointment reminder PHI?
A short reminder with no clinical details, such as "You have an appointment tomorrow at 2 pm", is fine as an insecure text. A reminder that reveals the kind of care, such as the department, doctor specialty, or reason for the visit, should go by Secure text with link.
The patient says the link does not work.
Links expire after 7 days. The patient can tap Text me a new link on the expired page to get a new link at the phone number on file, or you can send a new message, which includes a fresh link.
Sources
- HHS, Guidance on HIPAA & Cloud Computing (BAAs and your own risk analysis).
- HHS, Summary of the HIPAA Privacy Rule (what counts as PHI).
- HHS FAQ, May providers leave messages or send appointment reminders?
- HHS FAQ, Do individuals have the right to have copies of their PHI transmitted in the manner they request, even if it is unsecure?
- HHS FAQ, May providers use e-mail to discuss health issues with patients?
Related flows
- SMS messaging with patients
- Group conversations with multiple participants
- Broadcast (mass) SMS to patients
- Recall a message
- Business Associate Agreement
- Security and HIPAA compliance
This article is general information, not legal advice.
SMS messaging with patients
Upgrade to SMS, pick a phone number, add patients, and send SMS or secure patient chats — with read receipts and inbox auditing.
Group conversations with multiple participants
Add several patients, family members, caregivers, and staff to one secure conversation. Everyone messages in the same thread, each reply is labeled by sender, and the history stays on your organization account.