Compliance

HIPAA-Compliant Patient Messaging for Telehealth (2026)

HIPAA-compliant patient messaging for telehealth brands: SMS, email and portal rules, TCPA consent, what support may say, escalation and AI limits.

MyOrbitHealth Compliance TeamOctober 6, 202617 min read

HIPAA-compliant patient messaging for a telehealth brand comes down to four rules. First, anything that links an identifiable person to a treatment, a medication or a condition is protected health information (PHI), including a shipping notification that names the drug. Second, the channel determines the safeguards: an authenticated in-app portal is the default for clinical content, email and SMS are permitted for limited content when the patient has been warned of the risk and chooses them, and every vendor in the delivery path that can see message content needs a business associate agreement (BAA). Third, the brand's support team may answer logistics, billing and account questions, but anything about dosing, side effects, symptoms or changing treatment must route to a licensed provider in the affiliated medical group, and emergencies must route to emergency services. Fourth, AI may draft, sort and triage, but a licensed provider makes every clinical decision and signs every clinical reply. The rest of this guide covers the regulatory basis for each rule, the TCPA consent layer for SMS, the 2024 HHS and FTC positions on tracking technology, escalation triggers, audit logs and retention, and how Orbit Intake and OrbitOS fit.

This is general information, not legal advice.

Key takeaways

  • A patient message is PHI as soon as it ties an identifiable person to a health service, so order confirmations, refill reminders and "your provider replied" alerts all fall under HIPAA.
  • HHS permits unencrypted email and, by the same reasoning, SMS for treatment-related communication when the patient has been warned of the risk and still prefers it, and when the content is limited to what is necessary.
  • SMS also sits under the TCPA, which requires prior express consent for informational texts and prior express written consent for marketing texts, separate from HIPAA.
  • A brand's support team should answer shipping, billing and account questions only; dosing, side effects, new symptoms and treatment changes must be answered by a licensed provider, and emergencies must route to 911 or 988.
  • AI can draft and classify patient messages, but under FDA's January 2026 clinical decision support guidance and FSMB's 2024 AI policy, the licensed provider stays responsible for every clinical reply.

Who this is for

  • Founders building a support function for a telehealth brand who need to know what their team may and may not say to patients.
  • Operators replacing a consumer helpdesk or shared inbox with a HIPAA-covered messaging setup.
  • Product leads deciding where SMS, email, push and in-app messaging belong in the patient journey.

What counts as PHI in a patient message?

PHI is individually identifiable health information held or transmitted by a covered entity or its business associate. The threshold is lower than most operators assume. The test is not "does this message contain a diagnosis"; it is "does this message connect an identifiable person to care."

Messages that are PHI:

  • "Your semaglutide order shipped" sent to a named patient.
  • "Your provider has reviewed your intake" with a link to the portal.
  • A refill reminder that names the medication or the program.
  • A support reply that references the patient's last visit, lab or prescription.
  • A billing notice for "GLP-1 program, month 3."

Messages that generally are not PHI: a marketing email to a newsletter subscriber who has not started intake, or a generic site notification that carries no identifiers and no health service. The line moves at the moment a person enters the clinical funnel. A quiz result that says "you may be a candidate for TRT" sent to an email address is already health information tied to a person; whether it sits under HIPAA or the FTC Health Breach Notification Rule depends on who collected it and why, which is why the HIPAA for founders guide treats the marketing funnel as its own risk area.

What does the HIPAA Security Rule require of messaging?

Four technical safeguards under 45 CFR 164.312 apply directly to patient messaging:

  • Access control. Unique user IDs, emergency access procedures, automatic logoff and, as an addressable specification, encryption. In practice: no shared inbox logins, role-based access so support agents see what they need and not the chart.
  • Audit controls. Hardware, software and procedural mechanisms that record and examine activity in systems containing PHI. Every message read, sent or exported should leave a log entry with who, what and when.
  • Integrity. Mechanisms to confirm PHI has not been altered or destroyed improperly.
  • Transmission security. Guarding against unauthorized access to PHI in transit, with encryption as an addressable specification.

"Addressable" does not mean optional. It means the entity must implement the specification if reasonable and appropriate, or document why not and implement an equivalent alternative. HHS proposed a Security Rule update in early 2025 that would make encryption and several other specifications mandatory; check the current status of that rulemaking with counsel, because it changes the defensibility of unencrypted channels.

Two Privacy Rule provisions matter as much. The minimum necessary standard (45 CFR 164.502(b)) limits each use or disclosure to what the purpose requires, which is the regulatory basis for keeping drug names out of SMS. And the confidential communications right (45 CFR 164.522(b)) obligates a provider to accommodate reasonable requests to be contacted by a particular means or at a particular location, which is why a patient's channel preference carries legal weight.

HHS also ended its pandemic-era enforcement discretion for telehealth on May 11, 2023, with a transition period that closed August 9, 2023. Consumer video and chat apps without a BAA are no longer a defensible channel for clinical conversations.

Is texting or emailing patients HIPAA compliant?

Yes, with conditions, and the conditions differ by channel.

Email. HHS's FAQ on using email states that the Privacy Rule allows covered providers to communicate electronically with patients provided they apply reasonable safeguards, that unencrypted email is not prohibited for treatment communications, and that other safeguards, such as limiting the amount or type of information disclosed, should apply. If a patient is warned of the risk and still prefers unencrypted email, the provider may honor that preference and is not responsible for interception in transit. The working rules: confirm the address before the first send, keep content minimal (a link to the portal rather than the clinical content itself), and document the patient's choice.

SMS. HHS has not published a text-specific FAQ, and the conservative reading applies the email logic with a stricter content limit, because SMS has no encryption at rest on the carrier side and shows on lock screens. Most careful telehealth brands send only non-clinical content by text (appointment time, a shipment is on its way, a message is waiting in the portal) and keep medication names, dosing and results in the authenticated portal.

In-app or portal messaging. The default for anything clinical. Authentication, encryption, audit logs and retention all live inside one system under one BAA. The brand's patient portal, as described at /white-label-patient-portal, is where dosing questions, side-effect reports and lab results belong.

The BAA layer. Your email provider, your SMS gateway and your helpdesk are business associates if they can see message content. The HHS cloud-computing guidance limits the conduit exception to services that only transmit and do not store, like the postal service or a telecom carrier; a helpdesk that stores tickets is not a conduit. If a vendor will not sign a BAA, PHI cannot go through it.

Does the TCPA apply to patient texts?

Yes, separately from HIPAA. The Telephone Consumer Protection Act (47 U.S.C. 227) and the FCC's implementing rules at 47 CFR 64.1200 govern automated texts and calls to mobile numbers. Informational messages (appointment reminders, shipment notices, "a message is waiting") require prior express consent, which the FCC has treated as satisfied when a patient provides a mobile number for healthcare-related communications. Marketing texts ("restart your program and save 20%") require prior express written consent with clear disclosure, and every text needs a working opt-out. Keep the two consent types separate in your records; a healthcare-messaging exemption does not cover a promotion.

What did the 2024 HHS and FTC tracking-technology guidance change?

In December 2022 HHS published guidance on online tracking technologies, updated in March 2024, stating that regulated entities may not use tracking technologies in a way that results in impermissible disclosures of PHI, that tracking vendors receiving PHI need a BAA, and that authenticated pages (portals, patient apps) almost always involve PHI. A federal court in Texas vacated part of the guidance in June 2024 concerning unauthenticated pages, but the authenticated-page position and the BAA requirement stand. The FTC, for its part, enforced against GoodRx in February 2023 ($1.5 million civil penalty, the first under the Health Breach Notification Rule) and BetterHelp in March 2023 ($7.8 million) for sharing health data with advertising platforms, and the amended Health Breach Notification Rule took effect July 29, 2024.

For messaging, the practical consequence is this: no pixel, session-recording script or ad SDK may fire inside the portal, the app, the intake flow or any email or SMS link that resolves to an authenticated page unless the vendor is under a BAA. Transactional emails should not carry marketing tracking parameters that leak the program name to third parties.

Which messages may the brand answer, and which must come from a provider?

The MSO model places the brand in business operations and the physician-owned professional corporation (PC) in clinical care; the corporate practice of medicine and MSO guide explains why that split is legally required in most states. Patient messaging is where the split is tested every day, because the patient does not know who is on the other end.

A one-line test for the support team: if a correct answer requires knowing anything about this patient's body, history, medication or lab values, it is clinical and belongs with a provider. The table below is the responsibility map we recommend.

Message type Brand support team Licensed provider (PC) Platform (MyOrbitHealth)
Shipping, tracking, delivery failure Answers; re-ships per pharmacy policy Not involved unless the medication's integrity is in question Surfaces order and dispense status via OrbitOS and webhooks such as prescription.dispensed
Billing, refunds, subscription changes Answers; brand is merchant of record Not involved Hosts checkout and subscriptions on the storefront
Login, app and account issues Answers Not involved Provides the portal and native app
"When is my next refill?" Answers with the scheduled date only Decides whether a refill is appropriate Shows refill schedule; routes refill requests to the provider queue
"Can I take a higher dose?" Does not answer; routes to provider Answers and documents in the encounter Routes and logs the hand-off
"I feel nauseous after my injection" Does not answer; routes to provider same day Assesses, advises, documents; reports adverse events where appropriate Flags, routes, and timestamps the escalation
New symptom, pregnancy, new medication from another doctor Does not answer; routes to provider Assesses and updates the plan Routes and logs
Lab results Does not interpret; may confirm results are posted Reads results into the plan and messages the patient Orbit Labs delivers results to the provider first
Chest pain, trouble breathing, severe allergic reaction, suicidal thoughts Directs to 911 or 988 immediately; notifies the provider Follows up once the patient is safe Red-flag rules in Orbit Intake and support scripts route to emergency instructions

Support agents also need a script for the gray zone: "I'm not able to answer medication questions, but I've sent this to your provider, who will reply in the portal." Staying in that lane protects the patient, the brand and the structure.

Which messages must escalate to a provider, and how fast?

Escalation triggers should be written down, trained, and encoded in whatever routing the platform supports. The minimum list:

  1. Emergency symptoms: chest pain, shortness of breath, signs of a severe allergic reaction, loss of consciousness, severe abdominal pain. Route to 911 instructions first, provider second.
  2. Self-harm or suicidal ideation: route to the 988 Suicide and Crisis Lifeline (call, text or chat, 24/7) and notify the provider immediately.
  3. Any reported side effect or suspected adverse reaction, however mild in the patient's words.
  4. Dosing questions, missed doses, storage questions, "I took two by mistake."
  5. Requests to start, stop, pause or change treatment.
  6. New diagnosis, new medication, pregnancy or planned pregnancy.
  7. Lab results questions.
  8. Anything the agent cannot classify with confidence.

On speed, HIPAA sets deadlines for records access (30 days under 45 CFR 164.524, with one 30-day extension) and breach notification (60 days outer limit), not for message replies. Clinical response time is a standard-of-care and contract matter. Tier it: emergencies get immediate emergency instructions; side effects and dosing get a provider reply the same day; routine questions get a stated window. On MyOrbitHealth, the provider network averages a response under six minutes during business hours with 24-hour visit availability, which lets a brand set a same-day commitment for clinical messages and keep it. See async vs sync telehealth for how reply speed interacts with the care model.

Where should AI stop in patient messaging?

AI is useful in three places: classifying inbound messages into the routing table above, drafting replies for human review, and pulling structured data out of free text. It is not useful, and is increasingly regulated, as the author of clinical answers.

  • FDA clinical decision support guidance (final, January 2026) draws the line between software that supports a licensed professional's decision (while letting them independently review the basis) and software that drives a recommendation to a patient or that the clinician cannot evaluate. The latter can meet the device definition. An AI that tells a patient "your dose is fine, continue" is on the wrong side of that line.
  • Federation of State Medical Boards policy on AI (April 2024) states that boards regulate physicians who use tools, not the tools, and that the physician remains responsible for care delivered with AI assistance.
  • California AB 3030 (signed September 2024, effective January 1, 2025) requires health facilities and clinics using generative AI to produce patient communications about clinical information to disclose that AI was used, unless a licensed provider reviewed the message first. Other states are following; check the states you serve.
  • HIPAA treats the AI vendor as a business associate if it processes PHI, so a BAA is required, and the model's training and retention terms matter.

The pattern that holds up: AI classifies and drafts, a provider reviews and sends anything clinical, and the support team sends only non-clinical replies. Orbit Intake applies this at the front of the funnel: adaptive questioning with severity scoring and red-flag escalation, white-labeled per brand, with the licensed provider making every clinical decision on the completed intake.

What audit logs and retention does patient messaging need?

Audit logs. 45 CFR 164.312(b) requires audit controls; 45 CFR 164.308(a)(1)(ii)(D) requires regular review of system activity. For messaging that means immutable logs of message creation, reads, edits, exports and routing decisions, tied to a unique user ID, retained for the period your risk analysis sets. OrbitOS keeps a full HIPAA audit trail with role-based access across patients, encounters, prescriptions and providers, which is the record you will need when a patient or regulator asks who saw what.

Designated record set. Under 45 CFR 164.501, the designated record set includes medical and billing records and anything used to make decisions about individuals. A provider's reply about dosing is part of the medical record. A support ticket about a delayed package usually is not, but it still contains PHI and still needs safeguards. Decide in advance which messages land in the chart and make sure clinical replies do.

Retention. HIPAA requires documentation of policies, procedures and required actions to be retained six years (45 CFR 164.530(j)). Medical record retention is governed by state law, commonly five to ten years from the last encounter and longer for minors; the telehealth EHR guide covers how a virtual-clinic record should be structured. Support-ticket retention should follow a written schedule, and deletion should be logged.

How does patient messaging work on MyOrbitHealth?

MyOrbitHealth supplies the infrastructure; the brand runs support; the affiliated licensed providers run care. Concretely:

  • Channels. A branded patient portal and a native white-label iOS/Android app are included in the platform, so clinical conversations have an authenticated home. Transactional email and SMS carry minimal content and link back to the portal.
  • Intake and escalation. Orbit Intake collects history through adaptive questioning, scores severity and escalates red flags before a provider sees the case, white-labeled to your brand.
  • Provider response. 2,400+ board-certified MD/DO/NP/PA providers across 38+ specialties in all 50 states, with an average response under six minutes during business hours and 24-hour availability, live availability and intelligent load balancing.
  • Audit and access. OrbitOS provides role-based access and a full HIPAA audit trail; your support role sees order and account status, your providers see encounters and prescriptions.
  • Paper. A BAA in every contract, SOC 2 Type II, HITRUST-aligned architecture and US-region encrypted PHI.
  • Events. Signed webhooks such as appointment.completed and prescription.dispensed let your own support tooling react to status changes without storing clinical content, which keeps your helpdesk out of the chart.

What stays with the brand: the support team and its scripts, BAAs with any helpdesk, email or SMS vendor you choose to add, TCPA consent capture, workforce training, and keeping trackers out of authenticated surfaces. The telehealth vendor due diligence checklist lists the documents to request from any platform, including ours, before you commit. For a side-by-side of platforms by HIPAA posture, see /hipaa-compliant-telehealth-platforms.

How should you set up patient messaging, step by step?

Step MyOrbitHealth runs You run
Choose channels Provides the portal and native app as the clinical channel Decides which notifications go by email, SMS and push, with minimal content
Paper the vendors Signs the BAA included in every contract; publishes its subprocessor list Signs BAAs with any helpdesk, email or SMS vendor you add
Capture consent Stores channel preferences in the patient record Captures TCPA consent (informational and, separately, marketing) with opt-out
Write the routing table Encodes red-flag escalation in Orbit Intake; routes clinical messages to the provider queue Writes support scripts and trains agents on the clinical/non-clinical line
Set response tiers Supplies provider availability under six minutes average during business hours Publishes response commitments to patients and monitors them
Configure AI Runs Orbit Intake severity scoring under provider review Keeps any AI you add on draft-and-classify duty with a BAA and provider sign-off
Audit and retain Keeps the OrbitOS audit trail and record exports available at any time Sets ticket-retention schedules; reviews access logs; removes trackers from authenticated pages

Frequently asked questions

What is HIPAA-compliant patient messaging?

Messaging that keeps PHI inside systems covered by a BAA, applies access controls, audit logs and transmission security, limits content to the minimum necessary for each channel, and routes clinical questions to licensed providers. For a telehealth brand it also means the support team never answers medical questions and emergencies route to 911 or 988.

Is texting patients HIPAA compliant?

It can be, with safeguards. HHS permits electronic communication with patients when reasonable safeguards apply and the patient has been informed of the risk, and most telehealth brands limit SMS to non-clinical content such as appointment times and portal alerts. SMS also requires TCPA consent, and the SMS vendor must sign a BAA if it can see message content.

Can a telehealth brand's support team answer medication questions?

No. Dosing, side effects, missed doses, storage, new symptoms and any request to change treatment are clinical questions that must be answered by a licensed provider in the affiliated medical group and documented in the record. Support should acknowledge the message, route it, and tell the patient where and when the provider will reply.

Can AI answer patient medical questions in a telehealth app?

Not on its own. AI can classify messages, draft replies and extract data, but FDA's January 2026 clinical decision support guidance, FSMB's 2024 AI policy and state laws such as California AB 3030 all point to the licensed provider reviewing and owning any clinical communication. The AI vendor also needs a BAA.

Do I need a BAA with my helpdesk or email provider?

Yes if the vendor stores or can access message content that includes PHI, which covers nearly every helpdesk, CRM and email service. The conduit exception applies only to services that purely transmit data, such as a telecom carrier. A vendor that will not sign a BAA cannot receive PHI.

How long should patient messages be retained?

Clinical messages belong in the medical record and follow state record-retention law, commonly five to ten years from the last encounter and longer for minors. HIPAA separately requires policies, procedures and required documentation to be retained six years under 45 CFR 164.530(j). Support tickets should follow a written retention schedule with logged deletion.

What should a telehealth company do when a patient reports a side effect by message?

Route it to a licensed provider the same day, do not let a support agent respond with advice, and tell the patient how to reach emergency services if symptoms are severe. The provider assesses, documents the encounter and, where appropriate, reports the event through FDA MedWatch or to the dispensing pharmacy.

Sources

Put clinical messages where providers can answer them

A brand should never be the one deciding whether nausea after an injection is a problem. On MyOrbitHealth, Orbit Intake flags red flags before a provider opens the case, the patient portal and app give clinical conversations an authenticated home, and OrbitOS logs every access. Book a demo to see the routing in practice, or review the platform overview first.

Verify Approval for www.myorbithealth.com

LegitScript certified. MyOrbitHealth (myorbithealth.com) is LegitScript certified. Click the seal to verify.

Related reading

Launch your telehealth brand with MyOrbitHealth.

We power the medical, regulatory, and pharmacy layer. You own the brand and the customer.