You asked your texting vendor for a signed Business Associate Agreement and got a polite no — or a page in their docs that says "we don't sign BAAs." If you're a practice manager, that feels like a dead end. It usually isn't. It's a design constraint.
Full disclosure: I work for Ready, an SMS platform. We are not a HIPAA-covered messaging vault, and this post isn't me pretending we are. What follows is the line most clinics can actually defend — what appointment and recall texting stays legal without a BAA, and where the wording of a single message quietly pulls you back across the line.
I'm not your compliance officer, and this isn't legal advice. Run anything below past whoever signs off on your HIPAA policy. But the framework is the same one most practices land on.
The BAA question is really a PHI-in-the-message question
A BAA is required when a vendor creates, receives, maintains, or transmits protected health information (PHI) on your behalf. The trigger isn't "we send patient texts." It's what's in the text.
If the body of the message discloses a patient's health condition, treatment, or provider relationship to a third party (the vendor and the carrier both touch that message), you've made a disclosure — and the vendor is now a business associate. That's the case that needs a BAA.
But not every message about a patient is a disclosure of PHI. HIPAA has a well-worn carve-out: appointment reminders and general health communications are permitted, and can be sent without a BAA-level relationship as long as the content is minimal. The OCR has said for years that texting appointment reminders is fine, provided you've warned patients about the risk of unencrypted messaging and they haven't objected.
So the real question a practice manager should be asking a vendor isn't "will you sign a BAA?" It's "can I design my message library so no message needs one?"
For most clinics, the answer is yes for the high-volume stuff — reminders, confirmations, recalls — and no for anything that names a diagnosis, a medication, or a specialty.
The green zone: messages you can send without a BAA
These share a pattern. They reference that an appointment exists without revealing what it's for.
- Appointment reminders — "Reminder: you have an appointment with Dr. Lee on Tue 3/12 at 2:00 PM. Reply C to confirm or call 555-0100 to reschedule."
- Confirmation requests — the reply-to-confirm flow above. (Watch how you parse the reply — a patient who texts "yeah" instead of "C" shouldn't get logged as a no-response. We wrote about that reply-parsing gap here.)
- Generic recall / hygiene reminders — "It's been 6 months — time to schedule your next visit. Call us at 555-0100." No procedure named.
- Waitlist and cancellation slots — "An earlier appointment opened up this Thursday. Want it? Reply YES."
- Practice logistics — office closures, forms to bring, arrive-15-minutes-early, parking, telehealth link (link to your portal, not to a document that names the visit type).
The common thread: a stranger reading the message on a lock screen learns you have an appointment at a medical office. They don't learn you're seeing an oncologist or a psychiatrist or getting a specific medication refilled.
The red zone: content that forces a BAA
The moment the body reveals a health condition or the nature of care, you've disclosed PHI to your vendor and carrier, and you need the BAA.
- Naming the specialty when it implies a condition — "Reminder: your chemotherapy infusion" or "your methadone clinic visit." The specialty is the diagnosis.
- Lab or test results — "Your A1C came back at 8.2." Never in SMS without a BAA-covered channel, and honestly, not in SMS at all — push these to the portal.
- Medication names and refill specifics — "Your Adderall refill is ready" tells a bystander about a controlled-substance prescription.
- Anything with a clinical instruction tied to a condition — "Stop your blood thinner 3 days before your procedure."
- Two-way conversations that drift — a reminder is green, but if a patient replies "is the biopsy result back?" and your staff answers in the same thread, you've just transmitted PHI. Have a scripted redirect: "For results, please call us or check the portal."
A practical rule I give practice managers: if you'd be uncomfortable with the message showing on a phone left face-up on a coffee table, it's red-zone. Design it out or move it to a portal.
Where the two message types collide
Here's the trap that catches clinics running a single opt-in. A reminder text and a "book your flu shot" marketing text feel like the same thing — you're texting your own patients. They're not on the same legal footing. One is treatment communication; the other is marketing, and it needs marketing consent. Sending both from one opt-in is exactly the gap we broke down in this post on the consent wall between reminders and broadcasts. Keep the consent records separate, and keep the message design separate too — a promotional recall is a different animal than a scheduled-appointment reminder.
Message-design workarounds that keep you in the green zone
You can send a surprising amount without ever putting PHI in a body. The tactics:
- Point to the portal, don't restate the PHI. "You have a new message from Dr. Lee's office — view it securely at [portal link]." The sensitive content lives behind authentication; the text is just a knock on the door.
- Use provider name, not specialty, when the specialty is telling. "Appointment with Dr. Chen" instead of "your oncology appointment."
- Strip procedure names from recalls. "Time for your next visit" beats "time for your colonoscopy."
- Give patients a genuine opt-out and honor it instantly — required practice, and the thing carriers and OCR both care about.
- Warn once, at opt-in, that SMS is unencrypted. A short line in your intake form ("We may text appointment reminders. Texts are not encrypted.") documents that the patient understood the channel.
None of this requires a BAA, because none of it discloses more than the fact that an appointment exists.
Where Ready fits — and where it doesn't
Let me be straight about scope. Ready is not marketed as a HIPAA-BAA vendor, and if your workflow genuinely requires PHI in the message body, you need a covered channel or a portal, not a bulk SMS tool. That's the honest line.
What Ready does give a clinic staying in the green zone are the guardrails that make defensible reminder texting operational:
- Quiet-hours enforcement. Sends are held outside permitted local hours based on the recipient's area — so a batch of reminders queued at 6 AM doesn't fire into a patient's bedroom at 4 AM their time. That's TCPA hygiene, and it matters for patient trust as much as compliance.
- Automatic STOP / opt-out handling. When a patient replies STOP, the opt-out propagates so they can't be messaged again across campaigns. One caveat worth knowing: opt-out on one channel doesn't automatically stop calls on another unless your systems are wired for it — we covered that cross-channel gap here.
- Consent / attestation capture. Opt-in attestation is recorded for bulk sends, building the audit trail that shows a patient agreed to be texted.
- Full A2P 10DLC registration in-app — brand plus campaign, roughly ~$10/mo per brand and ~$20/mo per campaign, approval usually 1–3 days. Unregistered healthcare traffic gets carrier-filtered, so reminders that don't arrive are worse than useless.
On cost: reminders are short. "Reminder: appt with Dr. Lee Tue 3/12 2PM. Reply C to confirm." is one 160-character GSM-7 segment. On Standard pricing that's $0.02 + $0.0045 carrier = $0.0245 per reminder. A practice sending 3,000 reminders a month runs about $73.50 plus the ~$30 registration fees — cheaper than most no-shows you'd prevent. See current pricing here.
A quick decision table
| Message | PHI in body? | BAA needed? | Send via SMS? |
|---|---|---|---|
| "Reminder: appt with Dr. Lee Tue 2PM" | No | No | Yes |
| "Reply C to confirm your Thursday visit" | No | No | Yes |
| "Time to schedule your 6-month visit" | No | No | Yes |
| "New secure message — view in portal" | No | No | Yes (link to portal) |
| "Your chemo infusion is confirmed" | Yes | Yes | No — redesign |
| "Your A1C is 8.2" | Yes | Yes | No — portal only |
| "Your Adderall refill is ready" | Yes | Yes | No — redesign |
| Two-way thread that drifts to results | Yes | Yes | Redirect to portal |
The practical takeaway
A vendor refusing to sign a BAA doesn't shut down patient texting. It shuts down PHI-in-the-body texting — and most of your volume, the reminders and confirmations and recalls that actually move your no-show rate, was never supposed to carry PHI anyway. Design those messages so a bystander learns only "you have an appointment," point everything sensitive to the portal, keep a genuine opt-out running, and document your consent.
If you want to see whether green-zone reminders on registered 10DLC routes fit your practice, you can start on Ready with 2,500 free credits, no card, and design a message library that stays on the right side of the line. And when a message genuinely needs a BAA — send it somewhere that has one.