
Texting Patient Information Is Allowed When Colleagues Chat
Care coordination often comes down to how fast information moves between providers — and for a long time, that meant phone calls, faxes, and whatever made it into the EHR. A systematic review found direct communication between inpatient physicians and PCPs happened in only 3–20% of hospitalizations, which says a lot about how much information was getting lost in those gaps. As of February 2024, CMS has caught up: texting patient information between care team members is now explicitly allowed.
The 2024 CMS Update, Explained

In a February 8, 2024 memo, CMS clarified that healthcare staff at hospitals and critical access hospitals (CAHs) can send patient information and orders via SMS text to other care team members, provided they're using a secure texting platform that complies with HIPAA and the HITECH Act. This is a real shift: CMS is acknowledging that modern communication tools are now part of how care actually gets coordinated, not a workaround to be tolerated.
That said, CMS still prefers order entry through the EHR. Computerized Provider Order Entry (CPOE) remains the gold standard because orders get dated, timed, authenticated, and recorded automatically the moment they're entered. Secure texting is the accepted alternative when CPOE isn't practical in the moment — not a replacement for it.
Why CMS Changed Its Position
CMS's original 2018 guidance was cautious, largely due to concerns about privacy, record retention, and system integrity around texting patient orders. Secure texting technology has improved enough since then that CMS revisited its stance. Providers can now use HIPAA-compliant secure texting platforms (STPs), as long as they still meet the Conditions of Participation (CoPs) for inpatient and outpatient records.
The American Hospital Association has backed the change, calling it a real step forward for both patient care and provider efficiency.

What This Means in Practice
Platforms like OhMD's Secure Internal Chat are built around the CMS update directly, and the value shows up differently depending on the situation:
General care team communication. The core platform aligns with CMS's Conditions of Participation, giving care teams a compliant channel for sharing patient information and orders in real time instead of relying on the EHR alone or phone tag between departments.

Physician-to-physician collaboration. For multidisciplinary cases specifically, instant messaging means physicians, nurses, and specialists can all see the same information at the same time — a specialist doesn't have to wait for a callback to weigh in, and nobody's working off outdated information because a message got lost between shifts.

Care transitions and handoffs. This is where the risk is highest: a patient moving between departments, or a shift change where critical context can get lost in translation. Secure texting gives outgoing and incoming teams a direct channel during the handoff itself, rather than relying on a written note or a rushed verbal update.

Time-sensitive clinical decisions. When a clinician needs information immediately — a lab result, a medication history, a specialist's read on a case — instant access to that data via text can be the difference between a fast, informed decision and a delayed one.
Staying HIPAA Compliant Under the New Rules
The rule change doesn't loosen HIPAA — it just clarifies that texting can be part of a compliant workflow. HIPAA governs how PHI (protected health information) can be transmitted electronically, texting included, and that responsibility doesn't shift just because CMS has blessed the practice.
A few things matter here regardless of which platform a practice uses:
Regular compliance audits — of both the software and the actual workflows staff use day to day, not just the platform's certifications
Technical safeguards — the HIPAA Security Rule requires proper authorization controls for anyone accessing patient information
Ongoing staff education — a compliant platform doesn't help if staff aren't trained on how to use it compliantly
Every healthcare organization's setup is different, so it's worth reviewing the official HIPAA documentation directly rather than assuming a platform's compliance covers every use case in your specific workflow.
This update reflects something that was already true in practice — secure texting had become part of how care teams actually communicate, and CMS finally caught up to it. The opportunity now is picking a platform that meets both the CMS and HIPAA requirements, rather than treating compliance as something to figure out after adoption.
This article is meant to inform, not serve as legal or compliance advice — check the official CMS memo and HIPAA documentation for guidance specific to your organization.


