
Once your practice has WhatsApp or text messaging connected to your Google Business Profile, as covered in setting up Google Business Profile messaging for a dental practice, it’s tempting to treat it like any other patient communication channel. That assumption is where the risk sits. A standard WhatsApp conversation or a regular SMS text is not automatically a HIPAA-compliant communication method, and neither Google nor most consumer messaging apps are offering a signed Business Associate Agreement (BAA) as part of this feature.
This doesn’t mean the channel is unusable for a dental practice. It means the channel has to be treated the way a practice already treats an unsecured personal email or a public voicemail greeting: fine for logistics, not fine for anything that reveals a specific patient’s health information. The distinction that matters isn’t the app itself; it’s what gets typed into it.
Note: this section provides general compliance awareness, not legal advice. Practices with specific HIPAA questions about their own messaging setup should consult their compliance officer or healthcare attorney, since interpretation can vary by practice structure and state requirements.
Table of Contents
What counts as protected health information in a chat message
HIPAA’s definition of protected health information (PHI) is broad, and in a chat context, it mostly comes down to whether a message links an identifiable person to something about their health, treatment, or payment for care.
Information that’s safe to exchange
General, non-identifying information carries no HIPAA risk regardless of the channel: office hours, whether the practice accepts new patients, parking availability, general insurance networks accepted (without tying it to a specific patient’s claim), and appointment logistics phrased without clinical detail, like confirming a time slot or asking someone to arrive fifteen minutes early for paperwork.
Information that isn’t
Anything that connects a specific, identifiable patient to symptoms, diagnoses, treatment plans, billing specifics, or insurance claim details crosses into PHI. “Your root canal is confirmed for Tuesday at 2 pm” is arguably borderline since it names a procedure tied to an identifiable person in an unsecured channel. “Can you send a photo of the swelling so the dentist can take a look before your appointment” is a clearer example of something that shouldn’t happen over standard text or WhatsApp, since it invites clinical detail and images into a channel without a BAA in place.
Ready-to-use templates for common scenarios
The safest approach is to keep GBP chat conversations logistics-only, and move anything clinical to a phone call or a secured patient portal your practice already uses for HIPAA-covered communication. These templates are written to stay on the safe side of that line while still being genuinely useful to the patient.
Appointment confirmation and scheduling
“Hi [Name], this confirms your appointment at [Practice Name] on [date] at [time]. Please arrive 10 minutes early for paperwork if you’re a new patient. Reply here if you need to reschedule.”
Notice this avoids naming a procedure or reason for the visit, even though the practice obviously knows both internally. Keeping the message generic protects the patient’s privacy in an unsecured channel without making the confirmation feel impersonal.
General inquiry redirect
“Thanks for reaching out to [Practice Name]. For questions about your specific treatment or billing, please call us directly at [phone number] so we can pull up your chart and give you accurate details. For general questions about our practice, feel free to keep messaging here.”
This template does two things at once: it sets a clear boundary for what the channel is for, and it gives the patient an immediate, frictionless path to the right channel instead of leaving them guessing why they got redirected.
When a patient shares PHI anyway
Patients don’t always know where the line is, and a patient describing symptoms or asking a clinical question over text is common regardless of what your welcome message says. A safe response acknowledges them without repeating or expanding on the clinical detail they shared:
“Thanks for letting us know. For anything related to symptoms or treatment, our team will need to call you back to discuss safely and pull up your records. Someone will reach out shortly, or you can call us directly at [phone number].”
Avoid restating the patient’s symptoms back to them in the message, even to confirm understanding. Doing so adds another instance of PHI to the same unsecured thread rather than reducing it.
Training your front desk to catch PHI before it’s sent
The person managing GBP chat, per the ownership structure covered in the messaging setup satellite, needs a simple, repeatable habit: before hitting send, scan the message for a patient’s name paired with any clinical or billing detail. If both are present, the message gets rewritten to remove the detail and redirect to a phone call instead.
A short written policy helps more than relying on memory during a busy day. A single page listing the templates above, plus the general rule (logistics yes, clinical detail no), gives new staff a fast reference without requiring them to reason through HIPAA principles from scratch every time a borderline message comes in.
What happens if a HIPAA-relevant message is sent by mistake
Mistakes happen, and a single accidental message is a very different situation from an ongoing pattern of unsecured clinical communication. If PHI is sent by mistake over GBP chat, the practical response is the same as any other accidental disclosure: document what happened, follow your practice’s existing HIPAA incident procedure, and treat it as a training moment for whoever sent it rather than something to quietly ignore. Practices without a documented procedure for this kind of incident should treat that gap itself as a priority to close, ideally with input from a compliance professional rather than improvising a response after the fact.