Texting riders and drivers under HIPAA: what you can send and how
HIPAA does not ban texting. HHS lets health care providers message patients electronically when they take reasonable precautions, like confirming the number and keeping the details to a minimum. For NEMT, that means texting riders the pickup time, place, and vehicle, never the clinic type or reason for the trip. Keep rider details between dispatch and drivers in a secured, access-controlled channel instead of personal group texts.
On this page
Texting is how a NEMT day actually runs. Riders get a confirmation the night before and an “I’m outside” when the van pulls up. Drivers get address changes and new pickups between stops. Every one of those messages can carry protected health information, because a rider’s name next to a pickup at a dialysis unit says something about their health.
HIPAA allows all of it, with conditions. This guide covers what HHS says about texting, what belongs in a message to a rider or a driver, how to handle personal phones and group texts, and what to do when a text lands in the wrong place. These rules reach your company once it is a HIPAA covered entity or works as a business associate for one, a question our HIPAA guide for NEMT providers answers. Broker contracts often add their own messaging rules on top.
What HHS says about texting patients
HIPAA has no rule written specifically for text messages. The closest guidance is HHS’s answer on email, which treats electronic messages to patients as allowed when you take reasonable safeguards.
Four pieces of HHS guidance set the ground rules:
- Electronic messages to patients are permitted. HHS FAQ 570 says covered providers may reach patients electronically as long as they use the reasonable safeguards required by 45 CFR 164.530(c). Its examples include checking the address before sending and confirming it with the patient first. It adds that the Privacy Rule does not forbid unencrypted messages to patients about their treatment, and suggests limiting the amount or type of information they contain.
- Short messages beat detailed ones. FAQ 198, on leaving messages at a patient’s home, suggests leaving only the provider’s name and number and what is needed to confirm an appointment, or simply asking the patient to call back.
- The Security Rule still governs the transmission. FAQ 2006 says the Security Rule does not prohibit sending electronic PHI over the internet. The access control, integrity, and transmission security standards in 45 CFR 164.312 apply, and encryption in transit is an addressable specification. Addressable means you assess the risk, pick a reasonable protection, and document the choice.
- A rider can accept the risk of plain email. In the 2013 Omnibus rule, HHS said covered entities may send individuals unencrypted email after warning them of the risk, if they still prefer it. HHS said this in the context of patients receiving copies of their own records.
One detail trips people up. The minimum necessary standard does not apply to disclosures made to the individual. The safeguards rule still does, and it requires reasonable steps to limit incidental disclosures. A reminder that lights up a shared phone or a lock screen is exactly that kind of disclosure, so write every rider text as if someone else will read it first.
What a rider text should say
A good rider text carries what the rider needs to be ready at the curb and nothing that describes their care. Keep the content fixed in a template so dispatchers are not composing from scratch.
| Put in the text | Keep out of the text |
|---|---|
| Your company name | The clinic or program name when it reveals the care (dialysis, cancer center, methadone, behavioral health) |
| Pickup date and time, or the window | The reason for the trip or any diagnosis |
| Pickup address or landmark | Medicaid or member ID numbers |
| Vehicle color and type, driver’s first name | Date of birth or full legal name |
| A number to call, and how to confirm or cancel | Balances, copays, or billing details |
An example, with a made-up company and times: “Harbor Point Rides: pickup tomorrow 7:10 to 7:25 AM at the main entrance. Gray minivan, driver Luis. Reply C to confirm or call 555-0142 to change.” The rider knows when and where to be. A family member glancing at the phone learns nothing about the rider’s health.
Timing, consent, and opt-out rules for automated reminders come from a different federal law, the Telephone Consumer Protection Act. The guide to ride reminders and tracking links covers them.
Rider preferences and caregivers
Some riders do not want texts at all, or want them sent to another number. A covered health care provider must accommodate reasonable requests to receive communications by alternative means or at alternative locations, under 45 CFR 164.522(b). You may require the request in writing. You may not require the rider to explain it.
HHS’s email FAQ gives the practical version. If a patient finds unencrypted electronic messages unacceptable, offer and honor another method, such as a phone call. If a patient starts an email exchange, the FAQ says the provider may treat email as acceptable unless the patient says otherwise, and may point out the risks and let the patient decide.
Caregivers need their own rule. Under 45 CFR 164.510(b), a covered entity may share information directly relevant to a family member’s or friend’s involvement in the rider’s care:
- When the rider is available, get their agreement, or give them a chance to object and proceed if they do not.
- When the rider is not available or cannot decide, use professional judgment about whether sharing is in their best interest, and share only what the caregiver’s role needs.
For a daughter who handles her father’s rides, that usually means the pickup time, the driver’s arrival, and any delay. Before trip details go to a new number, confirm it with the rider or against the contact already on file, the same accuracy check HHS describes for email addresses. Record every preference on the rider’s profile, where the dispatcher on duty and the assigned driver will both see it.
Texting between dispatch and drivers
Drivers need protected information to do the job: a name, an address, a time, and mobility needs. Minimum necessary does apply here. 45 CFR 164.514(d) asks you to identify which staff need access to what, and to limit their access to that. A driver needs “uses a walker, help on the front steps,” not the diagnosis behind it.
Broker manuals turn this into specific driver rules:
- Contact only for the trip. MTM’s Rhode Island handbook (updated July 1, 2026) bars drivers from contacting a member, family, attendant, or escort for anything beyond what the assigned trip requires. When a member is not ready, the driver should call or text to say they are outside or about to leave. It also says drivers must not text while driving.
- Notify before a no-show. MTM’s Virginia handbook (May 2026) has the driver try to reach the member by call or text before leaving a pickup and recording a no-show.
- Secure written channels. CareOregon’s provider manual (February 2024) says email or other correspondence containing PHI must go through a secure email portal. Drivers are told to keep screens and papers with member details out of other people’s view, and to hold phone or radio conversations about a member only where nobody else can hear.
The dispatcher and driver communication guide covers call-or-message rules and hands-free laws.
Personal phones
Texts on a driver’s own phone leave your control the moment they arrive. They can sync to a personal cloud backup, appear on a family tablet signed into the same account, and stay on the device after the driver quits. The Security Rule addresses each of those points:
| Requirement | Citation | What it means for texting |
|---|---|---|
| Device and media controls | 45 CFR 164.310(d) | Policies for hardware that holds rider data, including disposal and reuse |
| Termination procedures (addressable) | 45 CFR 164.308(a)(3)(ii)(C) | A way to cut off access to rider data when someone leaves |
| Unique user identification (required) | 45 CFR 164.312(a)(2)(i) | Every person has their own login, so messages trace to a person |
| Automatic logoff (addressable) | 45 CFR 164.312(a)(2)(iii) | Sessions close after inactivity |
| Audit controls (required) | 45 CFR 164.312(b) | Activity is recorded so you can review who saw or sent what |
Plain text threads on personal phones meet almost none of these. If drivers must use their own devices, require a passcode and encryption, hide message previews on the lock screen, and move rider details into a tool you can shut off per person.
Group texts
A group thread is the fastest way to lose track of who has seen a rider’s information. One wrong contact added to the thread is a disclosure. A driver who left in March still receives April’s trip changes. And there is no record of who read what.
HIPAA does carve out one mistake. A disclosure made by mistake from one person authorized to access PHI to another authorized person in the same company is not a breach, as long as the information goes no further (45 CFR 164.402). A pickup sent to the wrong driver on your own team usually fits. The same text sent to a former driver or a rider’s neighbor does not.
Choosing a secure messaging channel
Where a message is stored decides who is responsible for it. HHS’s 2013 Omnibus rule treats phone carriers as conduits: they transmit messages and hold them only briefly along the way, so they are not business associates. An app or platform that stores messages for you is different. HHS said an entity that maintains PHI on your behalf is a business associate even if it never looks at the information, so it has to sign a business associate agreement with you first.
Look for these features in any tool that will carry rider details:
- A signed business associate agreement
- Individual logins with access limited by role
- Removing a person’s access in one step, the day they leave
- Message history held under the company’s control, not on personal accounts
- Encryption in transit and on the device
- Lock-screen notifications that do not show rider details
- A record of who sent and read each message
Hospitals set the pace here. A CMS memo of February 8, 2024 (QSO-24-05) says hospital care teams may text patient information and orders when they use a HIPAA compliant secure texting platform and meet Medicare’s conditions of participation. For a broader vendor checklist, see HIPAA-compliant NEMT software.
Encryption also changes what a lost phone costs you. Under HHS guidance, electronic PHI encrypted to NIST-tested standards stops counting as “unsecured” as long as the decryption key itself is not compromised, and the breach notification rules cover only unsecured PHI. A locked, encrypted phone left in a restaurant is a device problem. An unlocked phone full of plain text threads can become a reportable breach.
When a text goes to the wrong person
Treat a misdirected text as a possible breach from the first minute. HIPAA starts from the presumption that an unpermitted disclosure is a breach. Only a written risk assessment that finds a low probability of compromise overcomes it.
- Contain it. Ask the recipient to delete the message and confirm that they did. Note the time and their answer.
- Assess it. Work through the four factors in 45 CFR 164.402: what information was involved, who received it, whether anyone actually read it, and how much the risk was reduced.
- Decide and document. Write down the conclusion either way. The record is your defense if the decision is questioned.
- Notify if required. Affected riders must be notified promptly, within 60 calendar days of discovering the breach at the latest (45 CFR 164.404). Breaches affecting fewer than 500 people go in a log and are reported to HHS within 60 days after the end of the calendar year (45 CFR 164.408).
- Tell the broker as your contract requires. The MTM provider agreement that Pennsylvania posts, for example, has providers report any breach of rider information to MTM and sign its business associate agreement.
- Fix the cause. A wrong number from a stale rider profile is a data problem. A wrong group thread is a channel problem.
A one-page texting policy
- Every rider text comes from an approved template that names the company, the pickup, the vehicle, and a phone number.
- No diagnosis, clinic type, member ID, or billing detail in any text.
- Rider contact preferences live on the rider’s profile, and everyone follows them.
- Trip details between dispatch and drivers go only through the company’s messaging tool.
- No group texts that contain rider details.
- Phones used for work have a passcode, encryption, and hidden lock-screen previews.
- Access ends the day someone leaves.
- Any misdirected message is reported to the privacy lead the same day.
Train on it at hire and whenever it changes, and keep it with your policies and procedures.
Messaging without personal phones in HealthRide
HealthRide is HIPAA compliant, and it gives dispatch and drivers one place to talk. Team chat carries trip messages, voice notes, and read receipts, and each person sees only what their role allows. Phone lock screens never show rider details in the driver app, and riders receive a reminder text ahead of each ride plus a link to follow the van as it approaches.
Frequently asked questions
- Does texting a rider their pickup time violate HIPAA?
- No. HHS guidance allows electronic messages from health care providers to patients as long as the provider takes reasonable precautions, and a pickup reminder is a routine patient communication. The safeguards are what matter: confirm the number belongs to the rider, and limit the text to who you are, when and where the van will arrive, what it looks like, and how to reach you. The clinic, the treatment, and member ID numbers stay out.
- Can my drivers use their personal phones to text riders?
- It is allowed, but it moves rider information onto devices you do not control. Texts on a personal phone can sync to the driver's own cloud backup, show up on a family tablet, and stay there after the driver quits. The Security Rule expects device controls and a process for ending access when someone leaves. A company number or a messaging tool you manage solves most of that.
- What if a rider asks us to stop texting and call instead?
- Do it. HIPAA requires covered health care providers to honor reasonable requests for contact by another method or at another place, and they cannot make the rider give a reason. You may ask for the request in writing. Record the preference on the rider's profile so every dispatcher and driver sees it, and switch that rider's reminders to calls.
- Can we text a rider's daughter or caregiver about the ride?
- Yes, within limits. HIPAA lets a covered entity share information directly relevant to a family member's or caregiver's involvement in the rider's care. If the rider is available, get their agreement or give them a chance to object first. If not, use professional judgment and share only what the caregiver needs, such as the pickup time and whether the driver has arrived.
- A dispatcher texted a rider's trip details to the wrong number. Is that a breach?
- Presume it is until you assess it. Under HIPAA, a disclosure the rules do not permit counts as a breach unless your written assessment finds only a low probability of compromise. Ask the recipient to delete the message, weigh what was sent and who received it, and record the outcome. If it is a breach, the rider must be notified within 60 days of discovery.
- Does our texting app have to sign a business associate agreement?
- Usually yes. A phone carrier that only transmits messages is treated as a conduit and needs no agreement. A company that stores or maintains messages for you is a business associate even if it never reads them, so it has to sign one before rider details go through it.