Insights · Behavioral Health

Your clients want to text you. Here's how to say yes without breaking HIPAA.

Texting is how most people communicate now, and refusing it costs you appointments. The answer isn't a ban — it's a written policy, consent on file, and knowing which details never belong in a text.

By Andrew · NextGen Strategy PartnersSeptember 28, 20265 min read

A client misses a session, and the front desk calls twice with no answer. A text would have gotten a reply in ninety seconds. Every behavioral health practice runs into this, and most handle it one of two ways: a blanket "we don't text," or an unwritten habit where some staff text from personal phones and nobody has decided what's allowed.

Both are bad outcomes. The ban costs you attendance — for many clients, especially younger ones and those in crisis, a phone call is the least likely channel to get a response. The unwritten habit spreads protected health information across personal devices with no policy, no consent, and no record. The workable answer sits between them, and it takes about an afternoon to set up.

What HIPAA actually says about texting

HIPAA does not ban texting clients. It requires you to safeguard protected health information, to have told the client about the risks, and to have documented their choice. A client is allowed to receive communication through a channel that isn't fully secure, as long as they were informed and agreed. What you cannot do is decide that for them, or pretend the channel is more private than it is.

The compliance failure is almost never the text itself. It's that nobody wrote down what's allowed, what was disclosed, and what the client agreed to.

The four decisions to make in writing

The part that gets missed: what happens to the record

Texts about care are part of the record. If they live on a personal phone, you can't produce them on request, you can't retain them consistently, and you can't remove them when someone leaves — the same gap we wrote about with departing staff and lingering access. Decide up front where messages are stored, how long they're kept, and who can see them.

The practical takeaway

Write the one-page policy, add the consent language to your intake packet, and tell staff plainly which number to use. We've put our template in the free resources library — policy language, consent wording, and a staff quick-reference card you can post at the front desk.

Clients are telling you how they want to be reached. Meeting them there is good clinical practice; doing it deliberately, with consent on file and limits everyone knows, is what keeps it compliant.

Andrew, founder of NextGen Strategy Partners

Andrew — Founder, NextGen Strategy Partners

Veteran-owned managed IT for the nonprofits, schools, behavioral health providers, and medical & dental practices of McHenry & Lake Counties. Request a free security assessment →

Find out where you stand — before someone else does.

Our free IT security assessment gives your leadership a plain-English report on your risks, your compliance gaps, and exactly what it would cost to fix them. No obligation, no jargon.

Request the free assessment