CompyMax

Is Spruce Health HIPAA compliant?

Only under specific conditions

Yes — the agreement is built into Spruce's standard terms and applies automatically on trials and both paid plans, but Spruce classes SMS, email, fax and phone as unsecure channels, so only app-to-app messaging inside Spruce is genuinely secure.

Applies to Spruce Health phone, secure messaging, text and fax. Last reviewed against Spruce Health's own documentation. Next review January 1, 2027.

Reviewed by Dr. Anita Desai, MD — Psychiatrist, solo private practice.

What you must do

  • Nothing to sign separately. Spruce includes the agreement automatically in its standard terms of service for organizations, effective on your acceptance.
  • It applies to trials and to both paid plans.
  • Understand the two channel types. App-to-app messaging inside Spruce is encrypted in transit and at rest, and the patient must accept an invitation and create a Spruce account.
  • For SMS, email, fax and voice, follow Spruce's guidance: inform the patient of the limitations, offer the secure alternative, and honour their preference if they still choose texting.
  • Capture opt-in before you text — Spruce requires patients to have opted into SMS in advance, such as through your new-patient terms.
  • Leave sender identification and opt-out handling alone; Spruce cannot disable them and lapses can suspend your SMS ability entirely.
  • Keep all users in one organization on the same plan, as Spruce requires.

Does Spruce Health sign a business associate agreement?

Yes. Spruce Health offers one. All plans and trials. Spruce states all trials and paid plans automatically include the agreement where the organization requires one. Nothing to request. It takes effect when you accept the Spruce Terms of Service for Organizations. Save that text for your file.

See their documentation.

What this means in practice

Spruce hands you the agreement without being asked. It is written into the standard terms of service for organizations and takes effect the moment you accept those terms, on trials and on both paid tiers. If your organization is neither a covered entity nor a business associate, the section simply does not apply to you.

What deserves real attention is the line Spruce draws between secure and standard communication. Anything happening app-to-app inside Spruce is encrypted in transit and at rest, and the patient has to accept an invitation and create a Spruce account for it. Everything else — SMS, email, fax and phone — Spruce classes as unsecure communication, and its terms say plainly those channels can be intercepted. Spruce email is explicitly non-encrypted.

None of that bans texting patients. Spruce's own guidance is to inform the patient of the risk, offer the secure alternative and honour their stated preference, with opt-in captured up front in your practice terms. Note separately that the agreement bars substance use disorder records protected under 42 CFR Part 2, whichever channel you use.

How organizations get this wrong

The specific mistakes we see with Spruce Health, not generic advice.

  • Treating every Spruce channel as covered because Spruce signed an agreement — the terms class SMS, email, fax and voice as unsecure regardless.
  • Sending clinical detail through Spruce email, which Spruce states is a standard, non-encrypted method rather than the secure app-to-app channel.
  • Skipping opt-in. Spruce requires patients to have agreed to text communication in advance, typically through your new-patient terms.
  • Loading substance use disorder records into Spruce. The agreement specifically excludes records restricted under 42 CFR Part 2, on any plan.

What the agreement does not cover

  • The security of standard communication end to end. Spruce's terms define unsecure communications as including email, SMS, e-faxing and voice, and warn they could be intercepted.
  • Spruce email specifically, which Spruce states is a standard, non-encrypted method of communication.
  • Substance use disorder records restricted under 42 CFR Part 2, which the agreement prohibits submitting.
  • Organizations that are neither covered entities nor business associates, to whom the agreement does not apply.
  • Carrier behaviour — messages touching regulated categories can trigger review and blocking.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • TigerConnect

    Publishes its standard agreement in full so you can read the terms before signing

  • RingCentral

    If the need is a full phone system rather than patient messaging specifically

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Spruce Health, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Spruce Health’s own published documentation, read on the date shown.

  1. HIPAA and BAASpruce Health. No publication date given. Read July 29, 2026.
  2. Terms of Service for OrganizationsSpruce Health. No publication date given. Read July 29, 2026.
  3. Spruce SMS Messaging: Standard Texting and HIPAA-ComplianceSpruce Health. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Spruce Health’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.