Is GroupMe HIPAA Compliant?

GroupMe is owned by Microsoft, but that does not make it HIPAA compliant. Microsoft's BAA covers Teams and Office 365 — not GroupMe.

Get started for freeSchedule a demo →
No

No. GroupMe is a popular free group messaging app that makes casual group coordination easy — but it is not included on Microsoft's list of in-scope HIPAA services. Microsoft will not sign a Business Associate Agreement for GroupMe. Without a BAA, any healthcare practice using GroupMe to discuss patients, share clinical updates, or coordinate care is operating outside HIPAA — regardless of how the groups are named or whether patient names are avoided.

Why?

Microsoft does not offer a BAA for GroupMe

Microsoft publishes a specific list of cloud services covered by its HIPAA Business Associate Agreement, available through the Online Services Data Protection Addendum. That list includes Microsoft Teams, Office 365, Azure, Dynamics 365, and Intune. GroupMe is not on it. Being owned by Microsoft does not make a product HIPAA-eligible — only the services Microsoft explicitly designates as in-scope are covered. There is no enterprise plan or add-on that brings GroupMe into scope.

Source: Microsoft HIPAA and HITECH compliance offering

No organizational admin controls

GroupMe provides no admin-level user management, no centralized access controls, and no ability to revoke a departing employee's access to conversation history. When a staff member leaves your practice, their GroupMe account — and every conversation in it — goes with them. HIPAA requires that covered entities be able to control and revoke access to PHI.

Source: HHS HIPAA Security Rule

No audit trail

HIPAA requires covered entities to maintain records of who accessed PHI, when, and what they did with it. GroupMe provides no admin-accessible audit logs, no message retention controls, and no ability to produce access records for a compliance review or breach investigation.

Source: HHS HIPAA Security Rule

No end-to-end encryption

GroupMe encrypts messages in transit, but does not provide end-to-end encryption. Message content is accessible to Microsoft on its servers. Since Microsoft has no BAA for GroupMe, it has no HIPAA obligation to protect that content. Even if GroupMe were end-to-end encrypted, encryption alone would not satisfy HIPAA — the Security Rule also requires administrative safeguards, access controls, and audit logging.

Source: HHS HIPAA Security Rule

Governed by consumer terms, not enterprise agreements

GroupMe is governed by the Microsoft Services Agreement — the same consumer terms that cover Xbox, Outlook.com, and personal OneDrive. That agreement provides no healthcare-specific protections, no data handling commitments for PHI, and disclaims all implied warranties including fitness for a particular purpose. It does not mention HIPAA.

Source: Microsoft Services Agreement

What GroupMe says

GroupMe's terms of service redirect to the Microsoft Services Agreement, which governs all of Microsoft's consumer services. The agreement does not mention HIPAA, Business Associate Agreements, or healthcare compliance. Section 12 disclaims all implied warranties including fitness for a particular purpose. Microsoft's separate HIPAA compliance page lists the services covered by its BAA — GroupMe is not among them.
Source: Microsoft Services Agreement

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging with a signed BAA on every plan, including the free plan. Group chats for care teams and parents, with patients replying via SMS — no app download required.

TigerConnect

Enterprise clinical messaging platform used by hospitals and health systems. Includes role-based routing and EHR integrations.

OhMD

Patient texting platform with EHR integrations, call-to-text, and website chat for practices that need broader patient communication tools.

Frequently Asked Questions

Is GroupMe HIPAA compliant?

No. GroupMe is a consumer messaging app owned by Microsoft, but it is not included on Microsoft's list of HIPAA-covered services. Microsoft will not sign a Business Associate Agreement for GroupMe. Using GroupMe for communication involving protected health information is not HIPAA compliant.

Does GroupMe offer a BAA?

No. Microsoft offers BAAs for enterprise services like Teams, Office 365, and Azure through the Online Services Data Protection Addendum. GroupMe is not an in-scope service under that agreement, and there is no separate BAA available for GroupMe.

Can a healthcare practice use GroupMe if no patient names are used?

Avoiding patient names does not make GroupMe HIPAA compliant. Protected health information includes any information that could identify a patient in connection with their health condition or treatment — appointment times, diagnoses, treatment notes, even room numbers. The fundamental problem is the absence of a BAA, not the content of individual messages.

What happens to message history when an employee leaves?

GroupMe provides no admin controls for managing departing employees. When a staff member leaves, their personal GroupMe account retains access to every conversation they participated in. The practice cannot revoke access to that history or remove the individual from past conversations. HIPAA requires organizations to control who can access PHI — GroupMe provides no mechanism for this.

Is GroupMe encrypted, and is encryption enough for HIPAA?

GroupMe encrypts messages in transit but does not provide end-to-end encryption — Microsoft can access message content on its servers. But even if GroupMe were end-to-end encrypted, encryption alone would not satisfy HIPAA. The HIPAA Security Rule requires a signed BAA, administrative safeguards, access controls, audit logging, and breach notification procedures. GroupMe provides none of these.

What should a practice use instead of GroupMe?

Healthcare practices need a messaging platform with a signed BAA, organizational admin controls, conversation audit trails, and the ability to revoke access when staff leave. BloomText provides HIPAA-compliant group messaging with a BAA on every plan — including the free plan — and patients reply via SMS without downloading an app.

Sources

Last verified August 25, 2026.

  1. BloomText pricing
  2. Microsoft HIPAA and HITECH compliance offering
  3. Microsoft Services Agreement
  4. HHS HIPAA Security Rule
  5. GroupMe SMS mode announcement

Need HIPAA-compliant messaging?

Get started for freeSchedule a demo →

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care