Resource · ComplianceUpdated June 202611-minute read

Is texting caregivers HIPAA compliant?

Agencies run on caregiver texts — call-outs, coverage, schedule questions — and most of it happens over personal phones. Here’s when that texting falls under HIPAA, why ordinary SMS usually doesn’t meet the bar, and what it takes to do it compliantly.

By Quinn Stewart, Founder of HeyHomeCare. Informational, not legal advice — see the note below.

The short answer
Texting caregivers can be HIPAA compliant — but standard SMS usually isn’t on its own. If a message contains protected health information (and messages naming specific clients often do), HIPAA expects real safeguards: access controls, transmission security, audit trails, and a Business Associate Agreement with any vendor in the path. Plain texts from personal phones with none of that generally fall short. Compliant texting means a healthcare-grade platform, a BAA, and sending only the minimum necessary.
01 / Does HIPAA apply?

When a caregiver text is PHI.

HIPAA governs how covered entities and their business associates handle protected health information (PHI) — health information that identifies an individual. A home care agency that bills Medicaid or insurance is typically a covered entity, so the question isn’t whether HIPAA applies to your agency; it’s whether a given message contains PHI.

This is where agencies underestimate the exposure. A message to a caregiver that names a client — even something as routine as “can you cover Mrs. R’s 9 a.m. visit?” — can be PHI, because it links an identifiable person to the fact that they receive home care services. Add anything about the client’s condition, address, or care needs and it’s squarely PHI. The safe working assumption: if a caregiver text references a specific client, treat it as potentially containing PHI.

02 / Why plain SMS falls short

Why ordinary texting usually isn’t compliant.

When a message contains PHI, the HIPAA Security Rule expects safeguards for that electronic information. Ordinary SMS between personal phones generally provides none of them:

  • Transmission security. Standard SMS isn’t end-to-end encrypted; messages can sit unprotected in transit and on carrier systems.
  • Access controls. A text lands on a personal device with no guarantee of a lock screen, no way to limit who sees it, and no remote wipe if the phone is lost.
  • Audit trail. There’s no reliable record of who sent or read what — the accountability HIPAA expects for PHI.
  • Vendor handling. If a third-party app or aggregator processes or stores the message, it’s a business associate that needs a BAA — and the narrow “conduit exception” usually doesn’t cover it.
It’s not that texting is banned under HIPAA. It’s that unmanaged texting of PHI doesn’t carry the safeguards the rules expect.

One clarification worth making: getting a caregiver’s consent to be texted is a TCPA question, not a HIPAA one. They’re separate requirements — you can satisfy texting consent and still fall short on HIPAA safeguards, or vice versa.

03 / How to do it right

Texting caregivers within HIPAA.

Compliant caregiver texting is achievable — it just has to be built, not improvised. The practical requirements:

What compliant caregiver texting requires
RequirementWhy it matters
Business Associate AgreementAny vendor sending or processing PHI texts on your behalf must sign a BAA.
EncryptionPHI protected in transit and at rest, not left in plain text on devices and servers.
Access controlsOnly authorized people can see the messages; lost devices can be cut off.
Audit loggingA record of who sent and accessed what, so disclosures are accountable.
Minimum necessarySend only the PHI the caregiver needs for the task — no more.
No unmanaged personal phonesKeep PHI off ad-hoc personal texting that carries none of the above.

In practice that means a healthcare-grade messaging platform under a BAA — or designing your caregiver communication so the routine, high-volume traffic runs through a system built for these controls instead of a coordinator’s cell phone.

04 / Where HeyHomeCare fits

How HeyHomeCare handles it.

HeyHomeCare is the caregiver line, built to operate inside this framework rather than around it. The high-volume caregiver traffic — call-outs, shift coverage, schedule and clock-in messages — runs through a system designed for healthcare data, not a personal phone:

  • A signed Business Associate Agreement on every account.
  • AES-256-GCM encryption for stored integration credentials.
  • PHI redaction applied to log output, so sensitive data isn’t written to logs.
  • HIPAA-aligned operations under SOC 2 Type II controls.
  • Tenant-isolated data, scoped to your agency only.

It’s the same reason the model matters for after-hours answering and call-out management: the conversations that used to scatter across coordinators’ personal phones move into one accountable, auditable place. For the EVV side of compliance, see EVV requirements by state.

FAQ

Frequently asked questions.

Q.01
Is texting caregivers HIPAA compliant?
It can be, but standard SMS usually is not on its own. Whether HIPAA applies depends on whether the message contains protected health information (PHI). When it does, compliant texting requires appropriate safeguards — access controls, transmission security, and audit trails — and a Business Associate Agreement with any vendor that handles the messages. A plain text from a personal phone with no safeguards generally does not meet that bar.
Add the layer on top

Caregiver messaging that’s built for the rules.

HeyHomeCare handles caregiver calls and texts inside a HIPAA-aligned framework — BAA on every account, encryption, PHI-redacted logs, SOC 2 Type II — instead of over unmanaged personal phones.