By Fisher, JD, CHC, CCEP
CMS Clarifies Texting Rules for Physician Orders
CMS has clarified its position on the texting of physician orders. While the agency reaffirmed that patient information may be texted among healthcare team members through a secure, encrypted platform, it continues to prohibit texting physician orders, regardless of the platform used.
This alert summarizes CMS guidance in S&C 18-10-ALL and outlines practical compliance considerations for healthcare organizations that use secure text messaging for clinical communications.
On December 28, 2017, the CMS Center for Clinical Standards and Quality/Survey & Certification Group released S&C 18-10-ALL to clarify the use of text messaging in clinical settings. The memorandum addresses three issues of particular importance to healthcare organizations:
Key Points from CMS Guidance
Texting of PHI Within the Health Care Team. CMS states that texting protected health information among care team members is permissible when conducted through a secure platform. Providers should maintain policies governing care-team texting and evaluate whether additional conditions, limitations, or prohibitions are appropriate. In developing provider-specific policies, organizations should consider CMS guidance, HIPAA requirements, and other applicable legal and regulatory standards. State laws may impose additional requirements, and certain categories of information may be subject to heightened restrictions.
Texting of Patient Orders. Although secure texting may be permissible for certain care-team communications, CMS makes clear that patient orders may not be texted, even through a secure platform.
Preferred Use of CPOE. CMS identifies Computerized Provider Order Entry (CPOE) as the preferred method for entering patient orders. Providers should review policies governing acceptable order platforms, with particular attention to texting practices. Because verbal orders also present compliance and liability concerns, organizations should confirm that verbal-order policies are consistent with CMS requirements and followed in practice.
Policy Considerations for Providers
Organizations should clearly distinguish between permissible care-team messaging and impermissible order transmission, and should reflect that distinction in written policies, staff training, and audit procedures.
CMS Rationale and Compliance Risk
CMS’s position reflects continuing agency concern regarding patient safety, data integrity, and compliance with federal requirements. CMS emphasizes that orders must be entered directly into the medical record through CPOE or, when appropriate, issued as written or verbal orders and documented in accordance with hospital policy. Texted orders, including those sent through secure messaging systems, are not compliant with CMS Conditions of Participation.
Recommended Policy Updates
Healthcare organizations should review current practices to confirm that staff understand and follow this guidance. Policies should be updated as needed to prohibit texting physician orders and to reinforce the use of secure, HIPAA-compliant communication channels for other permissible clinical communications. Noncompliance with CMS requirements may result in survey deficiencies and potential penalties.
Key Compliance Risks
- Texting physician or patient orders, including through secure messaging platforms, may violate CMS requirements and the Conditions of Participation.
- Failure to use CPOE, written orders, or properly documented verbal orders may create documentation, authentication, and survey risks.
- Policies that do not distinguish between permissible care-team messaging and impermissible order transmission may lead to inconsistent staff practices.
- Improper use of secure messaging for protected health information may create exposure under HIPAA, state law, and other applicable legal or regulatory standards.
- Insufficient training, auditing, or enforcement may increase the likelihood of survey deficiencies, corrective action obligations, and potential penalties.
Risk Mitigation Considerations
- Revise written policies to prohibit texting physician or patient orders and to define permissible secure messaging practices for care-team communications.
- Reinforce CPOE as the preferred order-entry method and ensure that written and verbal orders are documented in accordance with applicable policy and CMS requirements.
- Train providers, nurses, and other care-team members on the distinction between care coordination messages and patient orders.
- Limit clinical texting to approved secure messaging platforms with appropriate access controls, retention settings, and HIPAA-compliant safeguards.
- Conduct periodic audits of secure messaging, order-entry practices, and verbal-order documentation, and document corrective action when issues are identified.
- Maintain current policies, training records, audit findings, and remediation materials to support survey readiness.
Next Steps
If you have questions about this alert or need assistance updating your organization’s policies to align with CMS guidance, please contact our healthcare compliance team.
