Compliance

What makes a messaging app HIPAA compliant?

Nothing about the app by itself. HIPAA compliance is a property of an arrangement — what the vendor has signed, what the software can enforce, and how you have configured it — which is why “is this app HIPAA compliant?” has no answer in the abstract and “will you sign a BAA, and can you show me the audit log?” has two.

The eight requirements below are what a buyer is really checking. The first one can end a procurement conversation in a sentence, and usually should.

The eight requirements.

Ordered the way a call runs rather than the way the regulation is organised. If a vendor fails the first, the rest are academic.

A signed BAA, before any data moves

The vendor handles PHI on your behalf, which makes them a business associate. No agreement means no lawful disclosure, regardless of how the product is built. A vendor who will not sign is not a cheaper option, it is not an option.

Named accounts, one per person

Unique user identification is a required specification, not an addressable one. A shared clinic login, or a channel keyed to a phone number on a personal handset, fails this outright and takes audit trails and revocation down with it.

Audit controls that record activity

The system has to record and examine access to ePHI. In practice: who read which child’s thread, who sent what, and when. If the vendor cannot show you this screen in a demo, assume it does not exist.

Administrative revocation

When a technician resigns on Friday, someone must be able to end their access on Friday, and the conversation history must remain with the practice. This is the requirement that eliminates every personal-device channel.

Role-based access, scoped to caseload

The minimum necessary standard applies inside your own building. A technician who covers four children should not be able to open the other sixty, and a supervisor should be able to see the threads they are accountable for.

Encryption in transit and at rest

Addressable rather than required in the regulation’s language, which is not permission to skip it — it means you would have to document why it was inappropriate, and for parent messaging over the public internet there is no such argument.

PHI-free notification payloads

A push notification is rendered on a lock screen and passes through a third-party delivery service. The payload should say a message is waiting and nothing about who or what, with content fetched after the recipient authenticates.

Retention and export you control

You will eventually need to produce a record, respond to an access request, or leave. Ask what happens to the data at termination and get the answer before signing, not at the point you want it back.

The sentence that reframes the encryption question.

Encryption (Addressable). Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.

45 CFR 164.312, Technical safeguards, paragraph (e)(2)(ii) · checked August 31, 2026

Addressable is not optional — where it is reasonable and appropriate you must implement it, and where it is not you must document why and put an equivalent measure in place. The point is the contrast: encryption is the specification with flexibility written into it, while unique user identification is required outright and audit controls are a standard with no optional wording at all. Those are the two a group chat fails, and they are the two nobody asks about.

Five things that are said, and what they actually mean.

Every one of these is offered in good faith by someone who believes it settles the question. None of them do.

“It is end-to-end encrypted, so it is compliant.”

Encryption protects the message in transit. HIPAA is mostly concerned with the ends: who may see it, who did see it, how long it is kept, what happens when the holder leaves, and whether there is a contract with the operator. In the Security Rule’s own wording, encryption is an addressable specification, while audit controls and unique user identification are not optional at all. A tool can be superbly encrypted and fail every other item on the list.

“The vendor is HIPAA certified.”

There is no such certification. No government body issues one and no auditor can confer it. SOC 2 and ISO 27001 are real audits of real controls and worth having, but they are not HIPAA and they are not a BAA. When a marketing page says "HIPAA certified", the useful response is to ask for the agreement.

“We are on a paid business plan, so it covers healthcare.”

Paying more does not change what the terms say. Several major messaging products explicitly disclaim suitability for entities with heightened confidentiality obligations, on the same page you accept to use them commercially. A business tier buys admin features, not a different legal position.

“It is compliant because the hosting is compliant.”

This is the most common sleight of hand in the category, and it is usually not deliberate. AWS, Azure and GCP all maintain HIPAA-eligible infrastructure and will sign BAAs with their customers. That says something about the vendor’s landlord and nothing about the vendor. Read whose compliance the sentence is actually describing.

“Nobody has complained, so we are fine.”

Enforcement is complaint-driven and breach-driven, so an absence of trouble is an absence of trigger rather than evidence of compliance. The exposure that matters is not a fine; it is that a departing employee holds the only copy of eighteen months of clinical communication and you cannot get it.

The categories of tool, and what each one is actually for.

Most of these are good products failing at a job they were not built for, which is a different problem from a bad product.

Consumer messengers — WhatsApp, iMessage, Signal, Messenger

Excellent products, wrong deployment. The account belongs to the person holding the phone, there is no administrative layer, no audit trail you can produce, and no BAA. WhatsApp’s business terms disclaim healthcare directly. These are not marginal cases.

School and childcare apps — ClassDojo, Brightwheel, Bloomz, Remind

Built in good faith for a different institution and compliant with the statutes that govern it — FERPA, COPPA. That is the answer rather than a gap: a product designed around education records has no business associate concept, because the law it was built for does not have one.

Clinical secure messaging — TigerConnect, Spok and similar

These genuinely are built for covered entities and will sign a BAA. They are designed for clinician-to-clinician traffic in a hospital, which means per-seat pricing, an adoption burden, and a model that assumes both ends are staff. Fine for internal use; a poor fit for reaching a parent who will not install anything.

Practice management messaging — CentralReach, Rethink, Motivity, Theralytics

These vendors act as business associates and say so, so the compliance question is settled. The limitation is scope rather than legality: the messaging is a feature of a clinical and billing system, built around documents and portals, and it is not a channel a technician uses in the ten seconds between transitions.

Purpose-built parent communication — where Cliqit sits

Signed BAA, named staff accounts, an audit trail, no PHI in notification payloads, and no adoption burden on families. We are one of several options and the honest framing is that this category exists because the four above each solve a different problem well.

The constraint that quietly eliminates most options is not compliance. It is that a tool parents will not open is a tool staff will route around, and the channel comes back to personal phones within a term. Compliance without an adoption burden on families is a much shorter list than compliance alone.

Where an ABA clinic differs from a hospital.

Clinical secure messaging was designed for clinicians paging each other about an inpatient. An ABA clinic’s hardest channel runs the other way: a technician who has the child for three hours, and a parent who has no idea how the afternoon went until pick-up. Both ends need to be fast, one end is not staff, and the person with the information is the least senior person in the building.

That shape is why the category exists separately, and it is covered in more detail in HIPAA-compliant parent communication for ABA clinics. For the internal half — RBTs and BCBAs coordinating across a shift — see staff communication.

Questions clinics ask about this.

What makes a messaging app HIPAA compliant?

Not the app on its own. Compliance is a property of the arrangement: a signed business associate agreement with the vendor, unique named accounts, audit controls recording access to ePHI, role-based access limited to what each person needs, the ability to revoke access administratively while the record stays with the practice, encryption in transit and at rest, notification payloads that carry no PHI, and a documented answer to retention and export. Any product can be deployed non-compliantly; some products cannot be deployed compliantly at all.

Is there such a thing as a HIPAA-certified messaging app?

No. There is no official HIPAA certification and no body that issues one. A vendor may hold SOC 2 Type II or ISO 27001, which are meaningful third-party audits, but neither is a HIPAA certification and neither replaces a BAA. Treat "HIPAA certified" on a marketing page as a prompt to ask for the agreement rather than as an answer.

Does HIPAA require encrypted messaging?

Encryption appears in the Security Rule as an addressable implementation specification, both for transmission security and for data at rest. Addressable means you must assess whether it is reasonable and appropriate, implement it if it is, and otherwise document why not and put an equivalent alternative in place. For a clinic sending child updates over the public internet there is no defensible analysis that lands on not encrypting — but note that the specifications which are flatly required, such as unique user identification, are the ones consumer tools fail.

Can we use Slack or Microsoft Teams for PHI?

Both vendors will sign BAAs on appropriate plans, so the legal gate can be passed — which makes them different in kind from consumer messengers. The remaining problems are practical: they are internal tools, so they do not solve the parent channel at all, and a general-purpose workspace makes it very easy for a child’s name to end up in a channel that was not scoped for it. Check your own plan and agreement rather than assuming, because the answer differs by tier.

Is texting parents from a work phone acceptable?

A clinic-owned handset fixes device ownership and nothing else. Ordinary SMS is not encrypted in transit, your carrier is not your business associate, there is no audit trail you can produce, no supervisory visibility, and no way to scope access to a caseload. It is an improvement on a personal phone and still fails most of the list.

What about email?

The Privacy Rule permits providers to communicate with patients electronically, email included, provided reasonable safeguards are applied — and an individual may ask to receive information by unencrypted email having been made aware of the risk. That is a narrower permission than it is usually read as: it concerns correspondence with the individual, it still obliges you to safeguard your side of it, and it says nothing about internal traffic. Practically, email fails on speed rather than on law. It is not a channel a technician uses between transitions.

Does a BAA make a tool safe to use?

It makes it lawful to disclose PHI to that vendor. It does not tell you whether the product has audit controls, whether access can be scoped to a caseload, or whether a departing employee can be locked out — those are questions about the software, and a signed BAA is a floor rather than a verdict. Ask both.

How do we handle the messages already sitting on staff phones?

Find out how many families are in that position first, because the number is always higher than leadership estimates and it is what makes the internal case. Then move the channel before writing the policy: staff started texting because they were solving a real problem quickly, and a prohibition that does not solve it for them produces a quieter version of the same thing.

Related

Sources

Claims about another product on this page are quotes from that product’s own documentation. Claims about what the law says are quotes from the regulation itself, not from anybody’s summary of it. Both are linked below with the date we last read them there.

  1. [1] 45 CFR 160.103Definitions — “Business associate”, paragraph (1)(i) · checked August 31, 2026
  2. [2] 45 CFR 164.306Security standards: General rules, paragraph (a)(1) · checked August 31, 2026
  3. [3] 45 CFR 164.312Technical safeguards, paragraph (e)(2)(ii) · checked August 31, 2026
  4. [4] 45 CFR 164.312Technical safeguards, paragraph (b) · checked August 31, 2026
  5. [5] WhatsAppWhatsApp Business Terms of Service · checked August 26, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.