Compliance

HIPAA-Compliant Messaging 2027: Email vs Portal vs Secure Chat

HIPAA-compliant messaging for private practices: when to use email, portal messages, secure chat or SMS for reminders, billing, refills, results and clinical notes.

Back to Intelligence
Share This Dispatch

Most private practices don't pick a messaging channel; they end up with five. Reminders go by text, billing questions arrive by email, a patient sends a photo through the portal, and a clinician answers a refill request from a personal phone. HIPAA-compliant messaging isn't about finding one perfect tool. It's about deciding which channel carries which kind of message, putting the right agreements in place, and writing it down so staff don't have to guess. This guide takes each everyday use case in turn and says where it belongs.

Quick Answer

Use SMS and plain email for logistics (appointment times, reminders, "your statement is ready") with as little health detail as possible. Use patient-portal messaging for anything clinical: results, symptoms, medication questions and documents. Use secure chat only if the tool is covered by a BAA and messages end up in the patient's record. Plain email with clinical detail is allowed only when the patient has been warned of the risk and still asks for it. Whatever you choose, get a Business Associate Agreement with every vendor that carries patient information, and write a one-page policy that tells staff which channel to use for what.

Email, portal messages and reminders in one place

ClinikEHR keeps patient email, secure portal messages and reminders beside the chart, and ClinikMail is covered by our BAA.
Get Started Free →
★★★★★4.9/5 Rating
No credit card required to start

Note: This guide is educational, not legal advice. Check your state's rules, especially for minors, behavioral health and substance use records. If you're choosing an email provider, see our HIPAA-compliant email buyer's guide; for tools, see the best secure messaging tools.

What Does HIPAA Actually Require for Patient Messaging?

HIPAA doesn't ban any channel. It asks you to protect patient information with reasonable safeguards and to have the right contracts in place. Four ideas cover most day-to-day decisions.

1. A BAA with every vendor that handles PHI. HHS explains that a covered entity may share protected health information with a business associate only with "satisfactory assurances," in the form of a contract, that it will be safeguarded (HHS: Business Associates, checked September 2026). Your email host, texting service, portal and chat app all fall into this if patient information passes through them.

2. Email and texting are allowed with safeguards. HHS's FAQ says the Privacy Rule doesn't prohibit unencrypted email for treatment-related communication, but that other safeguards should apply, such as limiting the amount or type of information shared (HHS FAQ on email, checked September 2026).

3. Patients can choose less secure channels, after a warning. Under the right of access, HHS says individuals can ask to receive their information by unencrypted email. You give a brief warning about the risk; if the patient still wants it, you must comply (HHS FAQ 2060, checked September 2026). Patients can also ask for communication by alternative means under the confidential-communications right (45 CFR 164.522), and you should accommodate reasonable requests.

4. Minimum necessary. HHS's minimum necessary guidance asks you to limit what you share to what the purpose requires. It doesn't apply to disclosures to the patient themselves or to another provider for treatment, but it's still good practice for anything that might be read by someone else, such as a text on a shared family phone.

Our guide on how to email patients securely goes deeper on consent wording and the email rules specifically.

The Four Channels, Compared

Before the use cases, here's what each channel is good and bad at.

Plain email reaches everyone and needs no login, which is exactly its weakness: anyone who can open the patient's mailbox can read it. It's fine for logistics. For clinical detail, use it only with the patient's recorded agreement, and never put more in than the message needs.

Secure email keeps the content off the open internet. The most common pattern is a short notification ("you have a secure message") with the content behind a login. Some services encrypt the message itself instead. It feels like email to staff but protects like a portal.

Patient-portal messaging keeps the whole conversation inside a signed-in area tied to the patient's record. It's the strongest default for clinical questions because the thread lives with the chart, and the patient has to prove who they are to read it. The trade-off is friction: patients must log in, so response times can be slower.

Secure chat and in-app messaging means a chat-style app built for healthcare, or chat inside your EHR or patient app. It's quick and familiar. It's only suitable for PHI if the vendor signs a BAA, access is controlled, and messages are saved to (or linked from) the patient's record. A general consumer chat app is not a clinical channel.

SMS is the channel patients actually read, which makes it ideal for reminders and confirmations. Standard text messages aren't encrypted end to end and can be seen on a lock screen or a shared phone, so keep health detail out. Texting also brings consent rules of its own under the Telephone Consumer Protection Act, so collect permission and honor opt-outs.

Channel by Use Case: Recommended, With Care, Avoid

This table is practice guidance based on the HHS pages above, not a legal rule. "With care" means acceptable with minimum detail, the patient's agreement where needed, and a BAA-covered vendor.

Use casePlain emailSecure email / portal linkPortal messagingSecure chat (BAA)SMS
Appointment scheduling and remindersRecommendedAcceptableAcceptableAcceptableRecommended
Billing questions and statementsWith careRecommendedRecommendedWith careWith care (no amounts or services)
Refill requestsAvoidWith careRecommendedWith careAvoid
Administrative messages (hours, forms, policies)RecommendedAcceptableAcceptableAcceptableRecommended
Clinical communication (symptoms, advice)Avoid unless patient consentedRecommendedRecommendedWith careAvoid
Sending documents and resultsAvoid unless patient consentedRecommendedRecommendedWith careAvoid (send a "log in to view" nudge instead)

Appointment Scheduling and Reminders

This is where SMS and plain email earn their place. A reminder needs a date, a time, a location and a way to confirm or reschedule. It doesn't need the service name if that would reveal something sensitive: "your appointment with Dr. Lee on Tuesday at 3 p.m." is fine, "your HIV follow-up on Tuesday" is not. Keep the clinic name generic if your practice name itself reveals a specialty that a patient might not want a family member to see, or let patients choose how they're reminded.

Automated reminders should respect each patient's notification preferences and stop when they opt out. For choosing a reminder tool, see the best appointment reminder apps.

Billing Questions

Billing messages carry more than they seem to. An amount owed plus a service description can reveal a diagnosis. A safe pattern is a plain "your statement is ready" by email or text, with the itemized statement and payment link behind a login. When a patient replies with a question about a specific charge, move the conversation into the portal or a secure email thread rather than answering line items by text.

Refill Requests

Refill requests come from two directions. Pharmacy-initiated requests should arrive electronically through your e-prescribing system, where a prescriber can approve them in a queue. Patient-initiated requests belong in the portal, where the request is tied to the right record and the medication list. Avoid taking refill requests by text or plain email: they contain a medication name, and a quick reply from a personal phone leaves no record in the chart.

Administrative Messages

Office hours, holiday closures, intake reminders, new policies and "please complete your forms" notices contain no health information, so any channel works. The one caution is who you're sending to. If a notice goes to your whole patient list, use a proper email platform that honors unsubscribes, and keep marketing separate from care messages, because promotional content has its own HIPAA marketing rules.

Clinical Communication

Questions about symptoms, side effects, test meaning or treatment plans are PHI in its most sensitive form. The portal is the right default: the patient is authenticated, the thread is saved with the chart, and staff can see the history. Secure email that keeps content behind a login is a close second.

Two points worth writing into policy. First, messaging isn't for emergencies: every auto-reply and portal page should tell patients to call emergency services or your urgent line instead. Second, set a response-time expectation (for example, one business day) so patients know when to call instead of waiting.

Sending Documents and Results

Results, visit summaries, letters and forms should go through the portal or a secure link. If a patient asks for their records by plain email, the HHS right-of-access FAQ says you can send them after a brief warning, and must if they still want it. Record that you gave the warning. Never send a document by text; send a short nudge that something is waiting to be viewed instead.

Write a Staff Messaging Policy (Sample Outline)

A one-page policy prevents most mistakes. Adapt this outline to your practice and have it reviewed by your compliance adviser.

  1. Approved channels. List each channel your practice uses and the vendor, and confirm a BAA is on file for each. Personal phones, personal email and consumer chat apps are not approved for patient information.
  2. Channel by purpose. Paste the table above, adjusted to your practice.
  3. Patient preferences and consent. How staff record a patient's channel preference, the warning they give before sending clinical detail by plain email, and how a patient withdraws consent.
  4. Minimum necessary content. What goes in a reminder, a billing message and a notification, and what never does.
  5. Response times and emergencies. Target reply times, who covers the inbox, and the standard emergency wording.
  6. Documenting in the chart. Clinical messages are saved to, or linked from, the patient's record.
  7. Mistakes and misdirected messages. Who to tell and how quickly, so the practice can assess whether it's a reportable breach.
  8. Access and devices. Two-factor sign-in, who can read shared inboxes, and what to do when a device is lost.
  9. Training and review. Train new staff before they send their first message, and review the policy once a year.

How an EHR Centralizes Secure Communication

The strongest argument for messaging inside your EHR isn't encryption; most reputable tools have that. It's that the conversation ends up in the same place as the chart. When email, portal messages and reminders run through separate products, each needs its own BAA, its own staff accounts and its own offboarding, and clinical conversations end up in places the chart can't see. A single system also makes a policy easier to enforce, because the safe option can be the default rather than a choice staff have to remember.

When comparing systems, ask where messages are stored, whether they link to the patient record, whether the vendor's BAA covers messaging and email, and what the patient has to do to read a message. Our companion guide on EHR integrations has more questions to ask about the email, texting and portal pieces.

How ClinikEHR Handles Messaging

Here's what ClinikEHR offers for each channel, with the plan it's on. Plan details come from our pricing page.

  • ClinikMail (email) is on every plan: 3 mailboxes and 5 GB on Free, 25 mailboxes and 50 GB on Essential, 50 and 120 GB on Team, on a domain you own or a free @clinikmail.com address. ClinikMail is covered by our BAA. When you write to a patient, it sends a secure message by default: the patient gets an email saying a secure message is waiting, with no subject or clinical detail in it, and reads and replies in their portal. Ordinary email unlocks only after you record the patient's consent, and every new message still starts on secure. You get a warning before sensitive detail leaves in plain text, and you can link a thread to the patient's chart timeline. Two limits to know: secure messages need the client portal switched on, and attachments don't travel on a secure message yet (share the file from the patient's record in the portal instead). See ClinikMail.
  • Patient-portal messaging: secure client messaging and the client portal, where clients book, pay, message and read their documents, are on Essential. Patients sign in with a one-time code sent to their email, can send a private, encrypted message with a photo or file attached, and can read the results, visit summaries and prescriptions you choose to share.
  • SMS and reminders: email reminders are on every plan. On Essential, reminders go by text once you add a practice number, and Team adds voice. The number is a dedicated SMS, voice and fax line for the US and Canada at $15 a month plus a $25 one-time set-up, with 200 message credits a month on Essential and 1,000 on Team, and more from $15 per 500.
  • Refills: pharmacy refill requests arrive electronically with the e-prescribing add-on ($49 a month per clinician plus a $99 set-up fee).
  • ClinikReach (email campaigns) is covered by our BAA too. It makes you choose whether a campaign is a newsletter, a message to your own patients about their care, or paid promotion, and won't send the last until you confirm you hold written authorization.

Frequently Asked Questions

Is texting patients HIPAA compliant?

It can be, for the right messages. Appointment reminders and confirmations with minimal detail are common. Keep clinical detail out of standard texts, use a vendor that signs a BAA if patient information passes through it, and collect consent to text.

Is a patient portal more secure than email?

Generally, yes. A portal requires the patient to sign in, and the conversation stays with the record. Secure email that keeps the content behind a login offers similar protection. Plain email is only as private as the patient's mailbox.

Can I email a patient their test results?

Yes, if the patient asks for plain email after you warn them of the risk. HHS says you must then comply. Otherwise, send a notification and let them read the results in the portal.

Do I need a BAA for my email or texting provider?

If the provider creates, receives, stores or transmits protected health information for your practice, it is a business associate, and you need a BAA with it.

Should refill requests come by text?

No. Refill requests name a medication and should be tied to the patient record. Take pharmacy requests through e-prescribing and patient requests through the portal.

What should a practice messaging policy include?

Approved channels with a BAA for each, which channel to use for which purpose, how to record patient preferences and consent, minimum necessary content, response times and emergency wording, documentation in the chart, and what to do after a misdirected message.

Conclusion

No single channel fits every message. Put logistics on SMS and email, clinical conversations in the portal or secure email, and keep secure chat for tools covered by a BAA that save to the record. Write it on one page, train your team, and let your EHR make the safe choice the default.

Make the safe channel the default

ClinikMail sends patients a secure portal message by default and unlocks ordinary email only after you record consent. Covered by our BAA.
See ClinikMail →
★★★★★4.9/5 Rating
No credit card required to start

Related Articles

Stay in the loop

Subscribe to our newsletter for the latest updates on healthcare technology, HIPAA compliance, and exclusive content delivered straight to your inbox.

Weekly updates
Healthcare insights
HIPAA updates
Subscribe to our Newsletter
Join over 100,000 healthcare professionals

We respect your privacy. Unsubscribe at any time.