Skip to main content

Data Security, Compliance & HIPAA

We protect your data and help you use SMS responsibly. Here’s what you can send, what to avoid, and where to find our security documentation.

TL;DR

  • SMS isn’t end-to-end encrypted. Use it for non-PHI communications only.
  • HIPAA: You may not send PHI by text via MessageDesk today, and we can’t sign a BAA yet. Our HIPAA evaluation is underway, and we expect to finish it by the end of Q4 2026.
  • SOC 2 Type II: Certified.
  • Trust Center: Get policies, control mappings, and audit materials: security.messagedesk.com.
  • Legal: See our Privacy Policy, Terms of Service, and Use Agreement.

HIPAA and texting: what’s allowed (and what isn’t)

SMS is a carrier-routed channel and can’t be made fully end-to-end encrypted. That means don’t send PHI (Protected Health Information) over SMS.

What you can send (non-PHI)

  • Appointment reminders without health details
  • General practice information (address, parking, directions)
  • Office hours and contact information
  • Non-specific follow-ups (“Thanks for visiting, complete your post-visit survey”)

What you should not send (PHI)

  • Diagnoses or symptoms
  • Treatment or care plan details
  • Prescriptions or medication names/dosages
  • Lab or test results
  • Any other patient-identifying health information
We can’t sign a BAA yet. MessageDesk isn’t currently in a legal position to sign Business Associate Agreements. If your organization needs one today, MessageDesk isn’t the right fit for PHI workflows right now.
HIPAA support is in progress. We’re working through a HIPAA compliance evaluation and expect to complete it by the end of Q4 2026. Once we do, we can provide a BAA to customers who need one.Until that work is finished, the guidance on this page stands: keep PHI off SMS. If a BAA is part of your buying decision, talk to our team so we can tell you where things stand and let you know when it’s ready.

Best practices for healthcare teams

  1. Train your staff on PHI restrictions and when to switch channels.
  2. Use templates that exclude PHI and include clear, neutral language.
  3. Keep reminders generic (date/time/location only).
  4. Redirect PHI to secure portals, phone calls, or in-network tools.
  5. Document your policy for when SMS is appropriate vs. not.
  6. Reference our Privacy Policy for how we handle personal information.

Our security posture (at a glance)

  • Hosting: AWS (US).
  • Encryption: AES-256 at rest, TLS in transit.
  • Access controls: MFA support; RBAC with granular permissions (Admin, Manager, Operator + resource-level controls).
  • Vulnerability management: SLAs to remediate Critical/High/Medium findings within defined windows.
  • Segregation: Separate staging/production; change management and rollback procedures.
  • Monitoring & logs: Auth and configuration events logged and retained.
  • Pen test: Most recent third-party test reported no critical/high findings.
For full details (policies, controls, audit artifacts), request access to our Trust Center.

SOC 2, compliance, and Trust Center

MessageDesk has achieved SOC 2 Type II certification. Legal references: Terms of Service and Use Agreement.

Request access to our Trust Center

  1. Visit security.messagedesk.com
  2. Click Request Access
  3. Complete the form and submit
  4. We’ll email you once access is approved

Trust Center

Get policies, control mappings, and audit materials in the MessageDesk Trust Center.

Frequently asked data and compliance questions

Is MessageDesk HIPAA compliant?
Not yet. Today you can use MessageDesk for non-PHI communications like generic appointment reminders, but don’t send PHI by text. We’re completing a HIPAA compliance evaluation and expect to finish by the end of Q4 2026.
Will you sign a BAA?
Not today. Once our HIPAA evaluation is complete, planned for the end of Q4 2026, we can provide a BAA to customers who need one. Contact us if a BAA matters to your timeline and we’ll keep you posted.
Can I include links in reminders?
Yes. Use links to your secure patient portal for PHI. Keep the SMS itself generic.
Are you SOC 2 certified?
Yes. MessageDesk has achieved SOC 2 Type II certification. You can request access to our audit report via the Trust Center.
Where is our data stored?
In the United States on AWS. Data is encrypted at rest and in transit. See our Privacy Policy for more on data handling.
Can we enable SSO and MFA?
Yes. We support SSO (SAML/OIDC) and MFA. See our Trust Center and Use Agreement for additional terms.
How do Terms apply to my workspace?
Your use of MessageDesk is governed by our Terms of Service and Use Agreement.