HIPAA-Safe SMS Communication for ABA Centers
A guide to HIPAA-safe SMS for ABA therapy centers: consent, audiences, a PHI guard on outbound texts, what never to send by text, and when to use email instead.
A snow day closes two of your three locations. Forty families need to know in the next twenty minutes. Email will be read by some of them by lunchtime. A text will be read by nearly all of them before the school bus is cancelled. SMS is the right tool — and it is also the channel where a single careless sentence can turn an operational message into a reportable disclosure.
ABA centers need SMS. Families expect it, and nothing else reaches a parent as fast. The question is not whether to text but how to text without putting protected health information into a channel never designed to carry it. This guide covers consent, audiences, message design, and the guardrail that makes HIPAA-safe SMS a system property rather than a training reminder.
What is HIPAA-safe SMS?
HIPAA-safe SMS is text messaging used by a covered entity in a way that avoids transmitting protected health information over standard carrier networks, or transmits it only with documented patient consent and appropriate safeguards. In practice for an ABA center it means three things: consent is recorded before texting, message content is operational rather than clinical, and the system screens outbound texts so PHI does not slip through by accident.
TargetFlo's Communications module implements this with SMS and email broadcast, audience segmentation, consent tracking, and a PHI guard on every outbound SMS. The rest of this post explains each piece and why it matters.
Why SMS is different from email and portal messages
Standard SMS is not encrypted end to end, sits on carrier infrastructure you do not control, appears on lock screens, and lives on shared family devices indefinitely. Email can be encrypted in transit and delivered to an authenticated inbox. A portal message stays inside a system you control with login and audit. That ranking should drive channel choice:
| Channel | Best for | Avoid for |
|---|---|---|
| SMS | Closures, delays, reminders, "you have a new portal notification" | Anything clinical, anything with a document, anything identifying a diagnosis |
| Newsletters, policy updates, forms with links to the portal | Attachments containing PHI unless encrypted | |
| Parent portal | Plan of Care, consents, assessment results, staff assignments | Nothing — this is where clinical communication belongs |
The parent portal exists so that clinical content has a home. SMS should point families to it, not replace it.
Consent first
Texting a guardian requires their agreement, and that agreement should be recorded on the client or guardian record with a date, the phone number consented, and the scope. Practical rules:
- Capture consent at intake, as part of the packet the family already completes, with clear language about what kinds of messages they will receive.
- Store the consent on the record, not in a spreadsheet or the coordinator's memory. TargetFlo stores communication consent alongside other consents in the Client & Family Hub.
- Honor opt-outs immediately and automatically. A reply of STOP must remove the number from all broadcast audiences without a human step.
- Re-confirm when the number changes. A new phone number is a new consent.
Consent does not make PHI in a text safe; it makes non-clinical texting permissible. Content rules still apply.
Audiences: send to the right people, not everyone
Broadcasts go wrong when the list is wrong. A closure sent to all three locations creates confusion; a staff reminder sent to families creates a disclosure risk. Build audiences from structured attributes rather than exported lists:
- By location: families or staff attached to a specific site.
- By role: guardians, RBTs, BCBAs, front office, external providers.
- By status: enrolled families only, or families in intake, or staff with an incomplete course.
- By consent: only recipients with SMS consent on file, enforced by the system rather than filtered by hand.
Building the audience from the record means the list is current at send time. When a family enrolls or a staff member offboards, they join or leave the right audiences automatically.
The PHI guard: a guardrail that does not depend on memory
Training tells staff not to include diagnoses, dates of birth, or insurance details in texts. Training is necessary and insufficient — the risky message is the one composed in a hurry by someone who knows better.
A PHI guard screens every outbound SMS before it is sent. It looks for patterns associated with protected health information — diagnostic terms, date-of-birth formats, member ID patterns, medication and assessment names — and either blocks the message or requires the sender to revise it. It applies to one-to-one texts and to broadcasts alike, and it applies regardless of who is sending.
In TargetFlo the PHI guard is on by default for SMS, and its flags are logged so an administrator can see what was caught and refine the rules. The result is that the channel enforces the policy. That is the difference between "we tell people not to" and "the system will not let them," and it is the kind of design choice we mean by HIPAA-aware architecture.
What not to text, ever
Even with consent and even with a guard, some content should never go by SMS:
- A diagnosis, an assessment name, or an assessment result
- Date of birth, insurance member ID, or claim information
- Session notes, behavior descriptions, or treatment goals
- Any document, including a photo of one
- Another family's information, even accidentally through a reply-all style thread
- Anything you would not want read aloud on a shared family phone
If the message needs any of these, send a text that says there is an update waiting in the portal and put the content there.
Message templates that stay on the safe side
Good SMS templates are short, operational, and free of specifics. A few that work:
- "TargetFlo Center Northside is closed today due to weather. Sessions will be rescheduled; watch for a portal update."
- "Reminder: your appointment tomorrow at 9:00 AM. Reply C to confirm or call the office to change."
- "You have a new document to review and sign in your family portal."
- "Staff: the updated safety course is due Friday. Log in to Training to complete it."
Templates reduce composition errors because the variable parts are names and times rather than free text.
Email broadcast for everything else
Email carries what SMS should not: longer updates, policy changes, links to forms, and newsletters. It uses the same audience segmentation and consent tracking, and it should still avoid PHI in the body or attachments unless encryption is in place. TargetFlo sends email broadcast through the same Communications module, so a location closure can go out as a short text and a detailed email in one step.
Where SMS fits the operating picture
HIPAA-safe SMS is the fastest reliable line to families and staff when handled with the right guardrails. Pair it with the parent portal for clinical content, keep consent on the record, build audiences from structured data, and let the PHI guard catch what training misses. For how these pieces fit together, see Parent Portal Benefits for ABA Therapy Centers and What "HIPAA-Aware" Software Means for ABA Centers.
- HIPAA aware ABA software
- ABA therapy center software
- SMS broadcast healthcare
- PHI-safe messaging
- ABA parent communication
See it in TargetFlo
Move intake out of the fax inbox
Book a 30-minute demo and we’ll map your referral flow to the 9-stage pipeline, connect your fax provider, and show eligibility checks at intake.
Book a DemoFAQ