PILLAR: Compliance Operations

Best HIPAA Compliant Texting Apps for Patient SMS

The best HIPAA compliant texting app for most small practices in 2026 is OhMD — it text-enables your existing office number for two-way patient SMS, includes a BAA on every plan, and costs $300/month per practice. On a tighter budget, Spruce Health delivers SMS plus a secure app channel for $24 per user. Practices that live inside an EHR should look at Klara (now part of ModMed) or Curogram.

This guide covers patient-facing texting — reminders and two-way SMS with patients. If you need secure chat between providers and staff, that is a different product category: our clinical messaging comparison covers it. All vendor facts verified 2026-08-24.

Best Overall (1–10 providers)

OhMD

Two-way SMS from a text-enabled landline, BAA on every plan, $300/mo per practice

Best Budget

Spruce Health

$24/user/mo, BAA included, SMS plus a secure-app channel for anything sensitive

Best EHR Fit

Curogram / Klara (ModMed)

Curogram bolts onto 20+ EMRs; Klara is the native pick if you already run ModMed

Best Phones + Texting

Weave

VoIP, reminders, and two-way texting in one bill — dental, optometry, vet-style front desks

Cyanotype of a pager lying face down with its belt clip sprung open, beside a coiled cableFIG · 01
A blank-faced pager and a coiled charging cable on a back-office counter.

What actually makes a texting app HIPAA compliant?

Nothing in HIPAA bans texting patients. The rule regulates who stores the messages and what is in them. A platform earns the “compliant” label when it covers the first part and gives your staff guardrails for the second. This is the patient-facing side of the problem — for provider-to-provider chat, see our clinical messaging comparison.

§164.502(e)

A signed BAA with the texting vendor

The vendor stores your patients' names, numbers, and message bodies. That makes it a business associate under 45 CFR §160.103. No BAA, no PHI — regardless of encryption.

§164.312

Encryption at rest + access controls on your side

The SMS hop itself is not encrypted. Compliance comes from the platform (encrypted storage, audit log, unique logins, MFA) and from what you put in the message.

§164.522(b)

Documented patient preference and a risk warning

Patients may ask to be texted (§164.522(b)). You must tell them SMS is not secure, record that they still want it, and honor STOP. That record is what protects you in an audit.

§164.502(b)

Minimum necessary in every message

Date, time, provider, and a callback number are fine. Diagnoses, lab values, and medication names are not — send those through the secure link or portal.

The same logic explains why WhatsApp and iMessage fail: strong encryption, but Meta and Apple will not sign a BAA and you have no audit log. Use our BAA template to check what a vendor's agreement must contain.

Which HIPAA compliant texting apps are worth comparing in 2026?

Five vendors below will sign a Business Associate Agreement on every plan and were verified on 2026-08-24. The sixth card covers the marketing SMS tools practices keep asking about. BAA status is shown top-right on each card.

OhMD

Two-way patient texting from a text-enabled practice line

BAA: All plans

Strengths

  • Text-enables your existing landline — patients text the number they already know
  • BAA and MFA on every plan, including the $300/mo Core tier
  • Voice, video, and voicemail transcription in the same inbox
  • Epic, Cerner, and athenahealth connections on higher tiers

Limitations

  • Per-practice pricing starts at $300/mo — steep for a solo clinician
  • Automation (AI routing, broadcast calling) needs the $500/mo tier
  • Calling usage billed separately on paid plans
Best for: 1–10 provider practices that want the front desk to text like patients do

Spruce Health

Phone, SMS, fax, and secure app messaging under one BAA

BAA: All plans

Strengths

  • $24/user/mo Basic, $49 Communicator; patients never count as users
  • BAA auto-included on trials and paid plans
  • Two channels: standard SMS (no app) and secure in-app chat for sensitive content
  • Shared team inbox, e-fax, and voicemail transcription included

Limitations

  • One-time $19.50 carrier registration fee to turn on outbound SMS
  • Telecom taxes and surcharges added to invoices since Nov 2025
  • Secure channel requires the patient to install the Spruce app
Best for: Solo and small behavioral-health or direct-care practices on a budget

Klara (ModMed)

ModMed's patient engagement layer — texting, intake, reminders

BAA: All plans

Strengths

  • App-free two-way texting plus web chat, call-to-text, and broadcast
  • Automated reminders, digital intake, and post-visit follow-ups
  • Native to ModMed EHRs; also integrates with athenahealth and others
  • Single conversation thread per patient across channels

Limitations

  • No published pricing — quoted by specialty and practice size
  • Roadmap now follows ModMed; standalone customers report slower feature pace
  • Overkill if you only need reminders and a text line
Best for: Dermatology, ortho, ophthalmology, and other ModMed-specialty practices

Curogram

HIPAA two-way texting layered on the EMR you already run

BAA: All plans

Strengths

  • 20+ EMR integrations (eClinicalWorks, athenahealth, Azalea, ModMed and more)
  • BAA executed with every practice; SOC 2 Type II
  • Patients text normally — no app, no login
  • Fast staff onboarding; single secure inbox per location

Limitations

  • Custom, quote-based pricing with no public rate card
  • Less voice/phone depth than OhMD or Weave
  • Smaller vendor — check support SLAs in the contract
Best for: Multi-location groups that want texting inside the EMR workflow

Weave

Front-desk phone system with reminders and two-way texting

BAA: All plans

Strengths

  • VoIP phones, missed-call texting, reminders, and reviews in one bill
  • Business Associate Addendum published online (updated Apr 10, 2026)
  • Pro plan from $249/mo per location, 1,500 bulk messages included
  • Strong fit for dental, optometry, and other appointment-heavy offices

Limitations

  • Per-location billing — two offices pay twice
  • Setup fee ($500–$750) and paid forms migration reported by buyers
  • Elite and above are quote-only; real spend often clears $350/mo
Best for: Offices replacing the phone system and texting at the same time

Generic SMS tools (SimpleTexting, etc.)

Marketing-grade texting platforms — use with caution

BAA: Not confirmed

Strengths

  • Cheap per-message pricing and easy keyword opt-in campaigns
  • Fine for content with zero PHI: office closures, flu-shot clinic dates
  • Some will sign a BAA on request — get it in writing before go-live

Limitations

  • SimpleTexting itself states SMS "is not considered a secure form of communication under HIPAA"
  • No patient-thread audit trail tied to a chart
  • Staff will eventually reply with PHI — the tool gives them no guardrail
Best for: Non-PHI broadcasts only, and only after a signed BAA is on file

Feature comparison: BAA, two-way SMS, EHR, consent capture

The rows that matter most for an audit are the first four. “Secure channel” means the vendor offers an encrypted alternative (portal link or app) so staff can move a conversation off SMS when a patient asks about results or medications.

FeatureOhMDSpruceKlaraCurogramWeave
BAA on every plan
Yes
Yes
Yes
Yes
Yes
Two-way SMS (patient replies land in inbox)
Yes
Yes
Yes
Yes
Yes
No patient app required
Yes
Yes
Yes
Yes
Yes
Secure (encrypted) channel for sensitive content
Partial
Yes
Partial
Partial
No
Text-enable existing office number
Yes
Yes
Yes
Yes
Yes
EHR / PM integration
Partial
Partial
Yes
Yes
Yes
Opt-in / consent capture built in
Yes
Partial
Yes
Yes
Yes
Automatic STOP / opt-out handling
Yes
Yes
Yes
Yes
Yes
Automated appointment reminders
Partial
Partial
Yes
Yes
Yes
Broadcast / recall campaigns
Partial
No
Yes
Yes
Yes
Voice calling in same platform
Yes
Yes
Partial
No
Yes
Audit log of who read / sent
Yes
Yes
Yes
Yes
Yes
Published pricing
Yes
Yes
No
No
Partial

Legend: = Yes · = Partial / higher tier / via integration · = No. Verified against vendor sites 2026-08-24; confirm tier details in your quote.

What does HIPAA compliant texting cost for a small practice?

The gap is wide: a three-person office pays about $72/mo on Spruce and $300/mo on OhMD for a similar SMS feature set. The difference is whether you also want a text-enabled landline, phone tree, and practice-wide seats. Whatever you pick, sign the BAA before the first message and log it in your risk assessment.

PlatformStarting PriceModelExtras to Budget3-Staff Office
OhMD$300/moPer practiceAI & automation tier $500/mo; calling usage extra$300
Spruce Health$24/user/moPer staff user$19.50 one-time SMS registration; telecom taxes$72
Klara (ModMed)Custom quotePer provider / bundleOften bundled into ModMed EHR contractQuote
CurogramCustom quotePer locationEMR integration scoped in quoteQuote
Weave$249/moPer location$500–$750 setup reported; Elite+ quote-only$249+

Prices as of Aug 2026 from vendor pricing pages (OhMD, Spruce, Weave) and buyer reports; Klara and Curogram do not publish rates. Monthly estimates exclude taxes and usage.

When is plain, unencrypted SMS actually OK?

More often than vendors admit. HHS has been explicit since the 2013 Omnibus era that a provider may use an unsecured channel when the patient prefers it, has been advised of the risk, and the choice is documented. The Privacy Rule's confidential-communications right (45 CFR §164.522(b)) even obligates you to honor a reasonable request to be reached by text. What plain SMS never excuses is skipping the minimum necessary standard or texting from an unmanaged personal phone.

Plain SMS is defensible when…

  • The patient asked to be texted, you warned them SMS is unsecured, and you documented both (§164.522(b))
  • The patient texted you first — replying in kind, on the same topic, is treating the channel they chose
  • The message carries minimum-necessary content: date, time, provider name, callback number
  • Every message honors STOP immediately and your system records the opt-out

Never defensible…

  • Test results, diagnoses, medication names or doses in the message body
  • Texting from staff personal phones — no BAA, no audit log, no remote wipe
  • Mass reminders to patients who never opted in to texting
  • Continuing to text after a patient replies STOP or revokes consent

The clean way to capture the preference is a checkbox and initials on your patient intake form (“I consent to receive text messages and understand SMS is not secure”), mirrored in your Notice of Privacy Practices. If that record does not exist, a compliant platform is what saves you — its consent log becomes the evidence.

The TCPA overlap: HIPAA is not the only law in the thread

HIPAA fines come from OCR; TCPA damages come from class-action plaintiffs at $500–$1,500 per text. A practice can be perfectly HIPAA compliant and still lose a TCPA suit over automated reminders sent to a recycled phone number. Since April 2025 the FCC also requires honoring any reasonable revocation (not just STOP) within 10 business days — the broader “revoke-one-revoke-all” rule has been delayed to January 2027.

Message TypeHIPAA SaysTCPA Says
Appointment reminder / confirmationTPO — no authorization needed; minimum necessary appliesPrior express consent (giving you the number is enough)
Two-way conversation the patient startedReply in kind; stay on topic; document preferenceConsent implied by the inbound text
Recall / preventive-care outreach (automated)TPO if treatment-relatedHealthcare-message exemption may apply (2015 FCC ruling), conditions attach
Billing or payment textPayment is TPONOT exempt — needs prior express consent; autodialed billing texts are frequent lawsuit fuel
Marketing (new service line, promotions)Usually requires patient authorization (§164.508)Prior express WRITTEN consent required

Practical rule: collect texting consent once, in writing, at intake — covering both the HIPAA risk warning and TCPA express consent — and only text the number the patient gave you. The FCC's one-to-one consent rule was vacated in January 2025, but consent you captured yourself was never affected. Details on penalties live in our common HIPAA violations guide.

Sample compliant patient texts (copy and adapt)

These are the three messages every front desk needs, plus the one that shows where the line is. They follow HHS guidance on reminders — name, date, time, provider, callback — and bake the risk warning and opt-out language into the first touch. Adapt the wording, keep the structure, and add them to your staff HIPAA training.

Appointment reminder

Hi Maria, this is Lakeside Family Medicine. Reminder: you have an appointment with Dr. Patel on Tue, Sep 1 at 2:30 PM. Reply C to confirm or call (802) 555-0142 to reschedule. Reply STOP to opt out.

Why it works: Name, date, time, provider, callback, opt-out — and nothing about why the patient is coming in.

Consent capture (first text)

Hi Maria, it's Lakeside Family Medicine. You asked us to text you. Standard SMS isn't secure, so we'll keep messages brief and won't include health details. Reply YES to confirm, STOP anytime to opt out.

Why it works: Documents the §164.522(b) risk warning and TCPA express consent in one auditable message.

Results notification

Hi Maria, your recent results are ready. Please log in to your patient portal or call us at (802) 555-0142 to review them with a nurse.

Why it works: Points to the secure channel instead of putting the result in the SMS body.

What not to send

Hi Maria, your A1c came back at 8.2 — Dr. Patel wants to increase your metformin to 1000mg twice daily. Pick it up at CVS on Main St.

Why it fails: Lab value, diagnosis context, drug, dose, and pharmacy in one unencrypted message. This is the text that ends up in a breach report.

Quick Reference Card

If You NeedOur PickStarting At
Best overall patient textingOhMD$300/mo
Tightest budgetSpruce Health$24/user/mo
Already on ModMedKlara (ModMed)Custom
Texting inside another EMRCurogramCustom
Phones + texting in one billWeave$249/mo
Non-PHI broadcasts onlyGeneric SMS + signed BAAVaries

Before go-live: signed BAA on file, texting consent added to your intake form, the platform logged in your risk assessment, and staff trained on the minimum-necessary samples above (log it in your training log).

Related Tools & Guides