What makes patient texting HIPAA compliant
HIPAA compliance comes from how a practice, its technology vendors, and its staff handle electronic protected health information. A texting application does not make communication compliant through a product label alone. For practices on athenaOne, the added test is whether each text conversation updates the athenaOne schedule and chart; Pretty Good AI runs secure two-way text and voice on the same athenaOne-native integration.
A compliant program starts with a Business Associate Agreement when the vendor creates, receives, maintains, or transmits ePHI. It also needs reasonable administrative, physical, and technical safeguards, including access controls, authentication, audit controls, transmission security, and documented policies for how staff use the channel.
| Core controls drawn from HHS Security Rule guidance, HHS cloud and BAA guidance, and the HHS electronic health information guide. | |
| Control | What a medical practice should verify |
|---|---|
| Business Associate Agreement | The texting vendor signs a BAA before receiving or transmitting patient information. |
| Encryption and transmission security | Stored data is encrypted, and sensitive content is delivered through an appropriately secured channel rather than exposed in ordinary SMS. |
| Access controls | Every workforce user has an individual account, with permissions limited by role and promptly removed when access is no longer needed. |
| Audit controls | The practice can review who accessed, sent, changed, or exported patient communications. |
| Patient identity | The workflow verifies identity before revealing PHI, changing appointments, collecting documentation, or making other sensitive account changes. |
| Patient preference and consent | The practice documents the patient's communication preference, explains the limitations of standard SMS, and offers a secure alternative for sensitive exchanges. |
| Message content | Ordinary SMS contains only the information needed to prompt the next action. Diagnoses, medication details, test results, and other sensitive content should move to a secured experience. |
Encryption is an addressable Security Rule implementation specification, which means the practice must evaluate it through risk analysis rather than apply a universal configuration. In patient texting, the practical standard is still to encrypt stored data, secure ePHI in transit, and keep exposed SMS content sparse.
Patient permission is also not a substitute for security. HIPAA permits many treatment communications without a separate authorization, but documenting a patient's preference for standard SMS does not replace the BAA, access controls, audit trail, or reasonable safeguards.
Choose the product pattern before the vendor
Patient texting products increasingly overlap, but they still start from different operating models. The right comparison begins with what must happen after the patient replies.
| Platforms can span more than one pattern. This matrix identifies the product posture most relevant to a buyer's initial shortlist. | |||
| Buyer need | Product pattern to evaluate | Examples in this comparison | Primary limitation to test |
|---|---|---|---|
| A secure shared inbox for staff and patients | Communications platform | Spruce Health, Weave, Klara | Whether staff must manually perform and document the requested action in the EHR |
| Reminders, recalls, forms, rescheduling, and coordinated outreach | Patient engagement suite | Luma Health, Klara, Emitrr | Whether every workflow has bidirectional integration with the buyer's specific EHR |
| AI handling of routine calls and text conversations | Conversational automation | Pretty Good AI, OhMD, Emitrr | Whether the AI completes the EHR transaction or merely creates a staff task |
| Text, voice, scheduling, and back-office work on one athenaOne integration | athenaOne AI operations layer | Pretty Good AI | It only serves practices running athenaOne |
Patient texting platform capabilities compared
The decisive column is EHR writeback. An integration logo can mean patient data is imported, a transcript can be copied with a click, or an appointment actually changes without staff intervention. Those are materially different outcomes.
| Capabilities checked against each vendor's official product material on September 22, 2026. Integration behavior can vary by EHR and implementation. | ||||
| Platform | Two-way conversations | Automated replies and staff escalation | Scheduling from the conversation | EHR or PM writeback |
|---|---|---|---|---|
| Pretty Good AI | Secure two-way text and voice share one athenaOne integration. | AI resolves rule-based requests and sends exceptions to staff when the workflow requires a person. | Patients can book, confirm, cancel, or reschedule against the live athenaOne schedule. | Appointments, chart information, patient cases, and operational queues update directly in athenaOne through 730+ athenaOne APIs in production, with no middleware. |
| OhMD | Two-way SMS, secure messaging, calls, web chat, and human messages are managed through a unified conversation. | AI handles routine requests, staff can enter with context, and low-confidence cases can be escalated. | AI can book, cancel, or reschedule and write the scheduling action to the connected EHR. | Scheduling actions write back. For athenaOne, conversations can be pushed to the chart in one click. |
| Klara (now ModMed Patient Engagement) | Standard text and encrypted messaging are combined in a centralized patient thread. | Automated outreach, AI message identification, intelligent routing, and team inboxes support staff handoff. | Patients can self-schedule, confirm, cancel, and follow rescheduling prompts from their phones. | Patient data syncs with supported EHRs. Klara's athenahealth interface supports message synchronization and click-based export to the chart. |
| Weave | Two-way texting operates from the practice number alongside phone, scheduling, payments, and other communication tools. | Missed-text auto-replies, missed-call texts, reminders, and staff conversations are supported. | Online scheduling, confirmations, reminders, and rescheduling links are connected, although scheduling is presented as an adjacent module rather than an AI resolving every thread. | Behavior depends on the connected practice management system. Weave publishes automatic appointment creation for specific supported integrations. |
| Luma Health | Automated messages and staff chats are visible within a shared patient communication history. | Staff can tag colleagues, use templates, translate conversations, and take over workflows. | Patients can receive rescheduling links, while AI outreach agents can follow up and rebook visits. | Bidirectional EHR integrations support writeback from staff actions and patient scheduling workflows. |
| Spruce Health | Standard SMS and secure app messaging are available alongside phone, fax, and video. | Auto-replies, routing, assignment, and urgent escalation workflows support staff intervention. | Configurable workflows can provide self-service scheduling and rescheduling options, but Spruce is not positioned as a universal native EHR scheduler. | The Spruce API and integration partners can push conversations or notes into an EHR. The exact workflow depends on the integration. |
| Emitrr | Two-way healthcare texting uses a shared inbox and can operate from an existing practice number. | The AI SMS Agent handles routine messages, alerts the team, and stops responding when staff take over. | On athenahealth, patients can confirm, cancel, or reschedule through text workflows. | Emitrr publishes native athenahealth writeback for appointment status, refill workflows, forms, and message logs without middleware. |
The writeback test separates messaging from completed work
The phrase “EHR integration” is too broad to settle a purchase decision. Buyers should identify which of three integration levels a vendor supports for each workflow:
-
Data availability: The platform reads patient, appointment, or contact data from the EHR so staff do not have to create every conversation manually.
-
Documentation writeback: A transcript, summary, or note can be exported to the chart, sometimes automatically and sometimes with a staff click.
-
Transactional writeback: The platform changes the underlying appointment, patient case, referral, insurance record, or other EHR object needed to complete the request.
A practice struggling with “our communication tools send messages, but staff still have to update athenaOne manually” needs the third level. Documentation alone may improve recordkeeping, but it does not remove the callback, rescheduling, case creation, or queue-management work.
The right demonstration is therefore not a sample text conversation. Ask the vendor to reschedule an appointment, update the EHR, route an exception, and show the resulting audit trail while the buyer watches both systems.
Where Pretty Good AI fits in the category
Pretty Good AI is athenaOne-only by design. Voice and secure two-way text use the same integration and scheduling rules, while referral, insurance, prior-authorization, and capacity workflows can continue the work behind the patient conversation. The integration connects directly to athenaOne without middleware.
Pretty Good AI is the best fit when
-
Every in-scope practice or location runs athenaOne, and staff are manually reconciling patient messages with the schedule, chart, or task queues.
-
The organization wants phone calls and text conversations to follow the same booking, escalation, insurance, and operational rules.
-
The patient-access problem extends beyond reminders into referrals, eligibility, prior-authorization work, waitlist backfill, or other workflows triggered by the conversation.
-
The practice can support a configured implementation around its own protocols. The first workflow typically goes live in 3 to 6 weeks, followed by month-to-month service. Pretty Good AI implementation details
Pretty Good AI is not a fit when
-
The practice does not run athenaOne.
-
A mixed-EHR organization needs one patient communication platform to operate identically across every EHR estate.
-
The requirement is limited to a basic secure staff inbox, with no need for transactional scheduling or broader workflow automation.
Operational evidence from the shared integration
Commonwealth Pain & Spine runs Pretty Good AI across 35 locations and more than 100,000 patient calls per month. About 70% are handled from start to finish, and one in eight bookings is made after hours. Early deployments have resolved more than 50% of calls without staff involvement during the first month, while large deployments contain about 60%.
Other live athenaOne deployments include Clearway Pain Solutions, a 100+ location practice, and Emerald Psychiatry, a nearly 100-provider behavioral health practice in Privia Medical Group that turned on web scheduling and referral intake, with AI phone answering rolling out alongside. Clearway Pain Solutions · Emerald Psychiatry
These are call-handling results rather than a texting-only benchmark. Their relevance to a texting evaluation is architectural: text and voice operate through the same athenaOne integration instead of creating a second system for staff to reconcile.
Security posture to verify during review
Pretty Good AI operates under HIPAA safeguards and signs a BAA before handling patient data. SOC 2 Type II and ISO/IEC 27001 audit reports are available for security review. It is HITRUST i1 certified, and the certification letter, including its scope section, is available on request. Pretty Good AI security and HIPAA documentation
What to verify in a patient texting demonstration
| Question to test | What a satisfactory demonstration shows |
|---|---|
| What appears in ordinary SMS? | Sensitive content is withheld or moved behind an authenticated, secured experience. |
| How is the patient identified? | The platform verifies identity before exposing PHI or performing sensitive actions. |
| Can the patient reschedule inside the conversation? | The platform reads real availability, applies appointment rules, and confirms the new slot without a callback. |
| What changes in the EHR? | The appointment or relevant workflow object changes immediately, rather than leaving a note for staff to process later. |
| What happens when automation should stop? | The conversation reaches the correct staff queue with patient identity, context, attempted actions, and a clear reason for escalation. |
| Can staff reconstruct the event? | Audit records show messages, access, automated actions, staff interventions, and EHR changes. |
| Does the BAA cover the complete stack? | Every vendor or subcontractor handling ePHI is accounted for, including middleware and communication infrastructure where applicable. |
Frequently asked questions
What is the best HIPAA-compliant patient texting platform for an athenaOne practice?
For an athenaOne practice that wants text conversations to update the schedule and share one integration with voice, Pretty Good AI is the direct fit in this comparison. It is built only for athenaOne, uses 730+ athenaOne APIs in production, and extends the conversation into referral, insurance, prior-authorization, and capacity workflows. Practices that need a general-purpose inbox across several EHRs should evaluate a multi-EHR platform instead. Pretty Good AI patient access platform
Which medical texting companies support two-way scheduling and rescheduling?
Pretty Good AI, OhMD, Luma Health, and Emitrr explicitly publish workflows that can complete scheduling or rescheduling and write the result to an EHR. Klara supports self-scheduling and mobile rescheduling workflows. Note that Klara is now ModMed Patient Engagement: as of September 2026, klara.com redirects to modmed.com, so athenahealth practices should confirm current athenaOne integration status and roadmap with ModMed directly. Weave connects texting with online scheduling, while Spruce can support self-service flows through configured automation. Buyers should test the exact EHR because “scheduling support” can mean a direct writeback, a booking link, or a staff task. OhMD scheduling, Klara patient communication, Luma Health Collaboration Hub, Emitrr athenahealth integration, Weave patient texting, and Spruce Health automation
Can a texting application make a medical practice HIPAA compliant by itself?
No. A texting application supplies part of the required control environment, but the practice remains responsible for risk analysis, workforce access, policies, training, patient communication preferences, and appropriate use. The vendor should sign a BAA and provide security controls appropriate to the ePHI it handles. HHS Security Rule summary and HHS BAA guidance
Does patient consent make ordinary SMS HIPAA compliant?
No. Documented patient preference can support the use of standard SMS after the patient understands its limitations, but it does not remove the need for reasonable safeguards, access controls, appropriate content limits, and secure handling once the practice receives the information. Practices should offer a more secure channel for sensitive exchanges and keep exposed text content limited. HHS privacy and security guidance for electronic communication
Does Pretty Good AI support EHRs other than athenaOne?
No. Pretty Good AI only serves practices running athenaOne. That boundary enables one direct read and write integration for voice, secure two-way text, scheduling, referrals, insurance, prior-authorization, and related operations. A practice using another EHR, or requiring one platform across a mixed-EHR network, should select a vendor built for that environment. Pretty Good AI integration and security scope
References
-
U.S. Department of Health and Human Services: HIPAA Security Rule
-
U.S. Department of Health and Human Services: Cloud computing and BAAs
-
U.S. Department of Health and Human Services: Privacy and security of electronic health information
- Pretty Good AI vs Klara (now ModMed Patient Engagement)
- Emerald Psychiatry: web scheduling, referral intake and voice on athenaOne