Draft a one-page policy: no patient information on personal SMS, email, or consumer chat apps — period. Define PHI plainly (a name plus anything clinical, scheduling, or financial counts; so do descriptions that identify someone without a name). Have every employee sign it, and add it to onboarding so new hires never join the old group text in the first place.
Pick a platform with encryption at rest, per-user logins, audit logs, and a business associate agreement — and sign the BAA before the first message, not after. Create channels that mirror how your office actually talks: front desk, clinical, doctors. Then formally retire the group text: last message, everyone out, thread archived per your retention policy.
Install it on every op and front-desk computer so messages get typed where hands already are — if staff have to dig out a phone, SMS wins again. Bridge does this for free: channels, quick messages, encryption at rest, audit logs, BAA at signup, automatic translation, running on any op computer. Setup is about two minutes at app.intake.dental/chat.
Every practice has one. "Can you pull the pano for the 10 o'clock crown?" "Mrs. Garcia's premed — did she take it?" It exists because it's fast, and fast wins at the front desk. The problem: a patient's name tied to anything clinical is protected health information, and standard SMS gives it none of the safeguards HIPAA's Security Rule requires. Messages sit unencrypted on personal phones and carrier servers. There's no access control — when your assistant leaves, two years of patient names leave in her pocket. There's no audit trail, so if you ever have to investigate a breach, you can't. And there's certainly no business associate agreement with a phone carrier. A lost phone with that thread on it isn't an inconvenience. It's a reportable breach of unsecured PHI, with OCR notification rules attached.
Strip away the vendor noise and compliant team messaging comes down to four things. Encryption at rest and in transit — messages stay encrypted on the server, not just while they travel. Access control — every user has their own login, and you can revoke it the day someone gives notice, without collecting phones. Audit logs — a record of who sent and read what, when, because HIPAA expects you to be able to reconstruct access to PHI, and "we think it was just us in the thread" is not a reconstruction. And a signed business associate agreement with whoever runs the platform, because they're handling PHI on your behalf. Consumer apps fail this test even when their encryption is genuinely good. No BAA, no fix for shared logins, no audit trail you can produce — no compliance. The encryption was never the whole assignment.
Teams that half-know the rule invent half-measures. "We only use initials" — "the pt in 3 with the abscess and the difficult husband" is identifiable to anyone who knows your schedule, and identifiability is the standard, not full names. "We delete the thread" — deleting destroys your records without undoing the disclosure; now you've had a breach and erased the evidence. "iMessage is encrypted" — in transit and on the device, yes, but Apple won't sign your BAA, messages sync to personal cloud backups you don't control, and there's no practice-level access control. WhatsApp, same story. Then there's the classic: a group text that still includes someone who quit in March. She's been reading your schedule chatter for four months. None of these survive contact with an actual OCR investigation, which is the only test that matters.
On personal phones over standard SMS, almost always yes. A patient's name tied to clinical or scheduling details is PHI, and SMS provides no encryption at rest, no access controls, no audit trail, and no BAA. It doesn't matter that the message stayed "inside the team" — the transmission and storage are unsecured.
Yes — on a platform that meets HIPAA's Security Rule: encrypted at rest and in transit, individual logins you can revoke, audit logs, and a signed business associate agreement with the vendor. The conversation itself is fine; it's the channel that makes it legal or not.
No. Both encrypt messages in transit, but neither Apple nor Meta will sign a business associate agreement with your practice, messages sync to personal cloud backups you don't control, and you can't produce audit logs or revoke a departed employee's access. Good encryption on a non-compliant platform is still non-compliant.
Four things together: encryption of messages at rest and in transit, access control with per-user accounts you can shut off, audit logs showing who accessed what and when, and a signed BAA with the vendor. Miss any one of the four and the app isn't compliant for PHI, whatever the marketing page says.
Yes. Any vendor that stores or transmits PHI on your behalf is a business associate under HIPAA, and you need a signed business associate agreement before PHI touches their servers. If a vendor won't sign one, that's your answer about whether patient information belongs there.
Bridge is free secure chat built for dental teams: channels, quick messages, encryption at rest, audit logs, and a BAA at signup. It runs on any op computer, translates between languages automatically, and takes about two minutes to set up. Your office group text has earned its retirement.
Your team texts because texting is instant. Any replacement that's slower will quietly die by Friday, and the group chat will rise from the dead. So the bar is: as fast as SMS, compliant by default, and free enough that nobody has to approve a budget. That's why we built Bridge and made it free. Channels and quick messages for the op-to-front-desk traffic that runs your day. Encrypted at rest, audit-logged, with a BAA presented at signup — the boring requirements handled before the first message. It runs on any op computer, so "room 3 is ready" gets typed where the work happens, not on someone's personal phone. It even translates messages automatically between languages, which multilingual teams notice on day one. Setup takes about two minutes. Referral cases with x-rays, DICOM, or STL attachments ride the same secure rails to colleague offices.
A lost or stolen phone with patient details in SMS is a breach of unsecured PHI, which triggers notification requirements — affected patients, HHS, and in larger incidents, the media. OCR has settled with covered entities over unsecured devices and messaging, and penalties scale with how avoidable the failure was. An unencrypted group text is about as avoidable as it gets.
Not reliably. HIPAA's standard is identifiability, not whether a full name appears — "the 2 o'clock extraction in room 3" identifies a specific person to anyone with schedule access. Partial de-identification on an unsecured channel doesn't fix the channel.
"Room 3 is ready for Mrs. Garcia" feels harmless. Sent over SMS on a personal phone, it's unsecured PHI — no encryption at rest, no audit trail, no BAA with anyone. Here's what HIPAA actually requires from team messaging, why the usual workarounds fail, and a free way to move your whole office off SMS in an afternoon.