Agencies run on caregiver texts — call-outs, coverage, schedule questions — and most of it happens over personal phones. Here’s when that texting falls under HIPAA, why ordinary SMS usually doesn’t meet the bar, and what it takes to do it compliantly.
HIPAA governs how covered entities and their business associates handle protected health information (PHI) — health information that identifies an individual. A home care agency that bills Medicaid or insurance is typically a covered entity, so the question isn’t whether HIPAA applies to your agency; it’s whether a given message contains PHI.
This is where agencies underestimate the exposure. A message to a caregiver that names a client — even something as routine as “can you cover Mrs. R’s 9 a.m. visit?” — can be PHI, because it links an identifiable person to the fact that they receive home care services. Add anything about the client’s condition, address, or care needs and it’s squarely PHI. The safe working assumption: if a caregiver text references a specific client, treat it as potentially containing PHI.
When a message contains PHI, the HIPAA Security Rule expects safeguards for that electronic information. Ordinary SMS between personal phones generally provides none of them:
One clarification worth making: getting a caregiver’s consent to be texted is a TCPA question, not a HIPAA one. They’re separate requirements — you can satisfy texting consent and still fall short on HIPAA safeguards, or vice versa.
Compliant caregiver texting is achievable — it just has to be built, not improvised. The practical requirements:
| Requirement | Why it matters |
|---|---|
| Business Associate Agreement | Any vendor sending or processing PHI texts on your behalf must sign a BAA. |
| Encryption | PHI protected in transit and at rest, not left in plain text on devices and servers. |
| Access controls | Only authorized people can see the messages; lost devices can be cut off. |
| Audit logging | A record of who sent and accessed what, so disclosures are accountable. |
| Minimum necessary | Send only the PHI the caregiver needs for the task — no more. |
| No unmanaged personal phones | Keep PHI off ad-hoc personal texting that carries none of the above. |
In practice that means a healthcare-grade messaging platform under a BAA — or designing your caregiver communication so the routine, high-volume traffic runs through a system built for these controls instead of a coordinator’s cell phone.
HeyHomeCare is the caregiver line, built to operate inside this framework rather than around it. The high-volume caregiver traffic — call-outs, shift coverage, schedule and clock-in messages — runs through a system designed for healthcare data, not a personal phone:
It’s the same reason the model matters for after-hours answering and call-out management: the conversations that used to scatter across coordinators’ personal phones move into one accountable, auditable place. For the EVV side of compliance, see EVV requirements by state.
HeyHomeCare handles caregiver calls and texts inside a HIPAA-aligned framework — BAA on every account, encryption, PHI-redacted logs, SOC 2 Type II — instead of over unmanaged personal phones.