Compliance

    HIPAA-Compliant Patient Communication: Channels, BAAs, and PHI Rules

    HIPAA does not ban specific communication channels. It sets requirements for how PHI is transmitted, stored, and accessed through any channel. Providers need to understand which channels meet Security Rule requirements, which vendors need BAAs, and how the Minimum Necessary Standard applies to aftercare.

    Channel-by-Channel PHI Transmission Rules

    • Email: The HIPAA Security Rule (45 CFR 164.312(e)(1)) requires encryption for electronic PHI in transit. TLS 1.2 is the current minimum. Standard Gmail, Yahoo, and Outlook consumer accounts do not guarantee TLS between all hops. HIPAA-compliant email services (Paubox, Virtru, LuxSci) encrypt end-to-end or enforce TLS verification.
    • SMS/MMS: Standard cellular SMS is not encrypted and travels through carrier infrastructure in plaintext. HHS has not issued formal guidance banning SMS, but the lack of encryption means PHI should not be included in message bodies. Links to authenticated portals with no PHI in the URL are acceptable.
    • Patient portals with authentication: These satisfy HIPAA access controls (45 CFR 164.312(d)) when they require identity verification before displaying PHI. Multi-factor authentication is not explicitly required by HIPAA but is considered a best practice by OCR.
    • Fax: Still considered HIPAA-compliant under the existing rules because it transmits point-to-point over phone lines. However, misdirected faxes are a top source of small breaches reported to OCR.

    BAA Requirements for Aftercare Vendors

    • Any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate (45 CFR 160.103). A signed BAA is required before any PHI is shared. Violation of this rule is a standalone HIPAA violation even if no breach occurs.
    • Common aftercare vendors requiring BAAs: cloud hosting (AWS, Azure, GCP, Render), email delivery services (SendGrid, Resend, Postmark), patient communication platforms, EHR systems, and any analytics tool that processes identifiable patient data.
    • Vendors that do NOT require BAAs: services that never access PHI (payment processors handling only billing data, website analytics with no patient identifiers, general business tools with no health data).
    • OCR enforcement actions have specifically cited missing BAAs as violations. In 2023, OCR settled with a provider for $1.25 million partly due to a missing BAA with a cloud storage vendor (North Memorial Health Care resolution agreement).

    Minimum Necessary Standard in Practice

    • The Minimum Necessary Standard (45 CFR 164.502(b)) requires providers to limit PHI disclosure to the minimum needed for the purpose. In aftercare, this means the communication method matters less than what you put in it.
    • Aftercare emails should contain only a first name and a link to an authenticated portal. Including procedure names, medication lists, or diagnosis codes in an email body violates Minimum Necessary even if the email is encrypted.
    • AI features that process care plan content for FAQ generation or translation should receive procedure-level instructions only, not patient identifiers, diagnosis codes, or insurance information.
    • Audit logs should record access events (who, when, what resource) without duplicating the PHI itself in the log entries.
    Related
    Frequently asked

    Questions patients ask.

    Can I text appointment reminders to patients?

    Yes. HHS has not prohibited SMS for non-PHI communications. An appointment reminder that says 'You have an appointment tomorrow at 2pm' without naming the provider type, procedure, or condition is generally acceptable. Including 'your colonoscopy is scheduled' would include PHI and should not be sent via unencrypted SMS.

    Does my email service need a BAA?

    If you send emails that contain any PHI (patient name plus any health information), yes. If you only send emails with a first name and a link to an authenticated portal with no health details in the email body, the risk is lower, but most compliance officers still recommend a BAA with your email provider as a safeguard.

    What counts as a HIPAA breach for aftercare communication?

    Any unauthorized access, use, or disclosure of PHI. Common aftercare breaches include: sending care plan details to the wrong email address, leaving PHI visible in a URL that gets logged by a browser or proxy, an unencrypted email intercepted in transit, or a vendor accessing PHI without a signed BAA.

    For practices

    Bring this to your own practice.

    QR Rx turns every procedure into a branded recovery plan that keeps patients engaged and brings them back. Start free in minutes, or see it live in a 20-minute demo.

    Start free trial

    This blog provides general information about healthcare compliance and aftercare best practices. It does not constitute legal, medical, or regulatory advice. Consult qualified professionals for guidance specific to your practice.