Is GroupMe HIPAA compliant?
No. GroupMe is a consumer messaging app owned by Microsoft, but it is not included on Microsoft's list of HIPAA-covered services. Microsoft will not sign a Business Associate Agreement for GroupMe. Using GroupMe for communication involving protected health information is not HIPAA compliant.
Does GroupMe offer a BAA?
No. Microsoft offers BAAs for enterprise services like Teams, Office 365, and Azure through the Online Services Data Protection Addendum. GroupMe is not an in-scope service under that agreement, and there is no separate BAA available for GroupMe.
Can a healthcare practice use GroupMe if no patient names are used?
Avoiding patient names does not make GroupMe HIPAA compliant. Protected health information includes any information that could identify a patient in connection with their health condition or treatment — appointment times, diagnoses, treatment notes, even room numbers. The fundamental problem is the absence of a BAA, not the content of individual messages.
What happens to message history when an employee leaves?
GroupMe provides no admin controls for managing departing employees. When a staff member leaves, their personal GroupMe account retains access to every conversation they participated in. The practice cannot revoke access to that history or remove the individual from past conversations. HIPAA requires organizations to control who can access PHI — GroupMe provides no mechanism for this.
Is GroupMe encrypted, and is encryption enough for HIPAA?
GroupMe encrypts messages in transit but does not provide end-to-end encryption — Microsoft can access message content on its servers. But even if GroupMe were end-to-end encrypted, encryption alone would not satisfy HIPAA. The HIPAA Security Rule requires a signed BAA, administrative safeguards, access controls, audit logging, and breach notification procedures. GroupMe provides none of these.
What should a practice use instead of GroupMe?
Healthcare practices need a messaging platform with a signed BAA, organizational admin controls, conversation audit trails, and the ability to revoke access when staff leave. BloomText provides HIPAA-compliant group messaging with a BAA on every plan — including the free plan — and patients reply via SMS without downloading an app.