CompyMax

HIPAA compliant texting platforms

Messaging patients directly. Ordinary business phone systems frequently cover calls while excluding text, so this is a category where the purpose-built tools genuinely differ.

This is the category where general-purpose tools most often fail on the exact thing you bought them for. Business phone systems and staff messaging products frequently cover calls, and sometimes cover internal chat, while excluding SMS and MMS from the agreement — so texting patients, the reason most small practices buy the product, is the part outside it.

The purpose-built tools genuinely differ, and the distinction to understand is between a secure channel and a standard one. App-to-app messaging inside a vendor's own product, where the patient accepts an invitation and creates an account, is typically encrypted in transit and at rest and is the protected channel. Ordinary SMS, email, fax and voice are usually classed by the vendor's own terms as unsecure and capable of being intercepted. Some platforms send an ordinary carrier text containing a link, where only the session the link opens is protected — which means clinical detail must stay out of the invitation itself.

Very few vendors forbid texting patients outright. What they do instead is attach obligations to you: capture opt-in in advance, inform the patient of the limitations, offer the secure alternative, honour a withdrawal of consent, keep content to the minimum necessary, and write the decision and its risks into your policies. Carrier messaging rules stack on top of all that, independently of the agreement.

What to check before you adopt one

  • Confirm in writing that SMS and MMS are covered services, not just voice. This is the single most common exclusion in the category and it removes exactly the capability you are buying.
  • Understand which channels the vendor classes as secure and which as standard, and check whether the vendor's own email or fax is inside or outside the encrypted path.
  • Where the product texts a link, establish that only the linked session is protected, and train staff to keep clinical detail out of the invitation message.
  • Find out what the vendor requires of you: advance opt-in, risk notification, minimum-necessary limits, honouring withdrawal, and a documented policy decision. These are contractual obligations, not suggestions.
  • Ask who can start a conversation. Where engagement is clinician-initiated by design, an inbound patient question has nowhere to land until staff reach out first.
  • Check for categories the agreement excludes regardless of channel — substance use disorder records restricted under 42 CFR Part 2 are a common carve-out.
  • Read any de-identification clause, since some vendors reserve the right to create and own de-identified data derived from your records.
  • Leave sender identification and opt-out handling alone where the vendor says it cannot disable them, because lapses here can suspend your messaging entirely.
  • Know which agreement governs you: some vendors apply a published standard agreement by reference unless your contract negotiated a separate one that displaces it.

The expensive mistake

Buying a business phone system to text patients, on the reasonable assumption that a product sold to clinics covers its own messaging feature. Calls are covered, texting is not, and nobody discovers this until someone reads the agreement properly. The second recurring error is putting the clinical detail in the invitation text rather than in the secure session it opens — the link is the gateway, and the SMS carrying it is ordinary carrier traffic.

Tracking which of these your organization uses?

The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.

Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.