HIPAA Audit Checklist for Anticoagulation Clinics: How to Handle SMS INR Disclosures and Patient Portal Preferences

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Audit Checklist for Anticoagulation Clinics: How to Handle SMS INR Disclosures and Patient Portal Preferences

Kevin Henry

HIPAA

August 21, 2026

7 minutes read
Share this article
HIPAA Audit Checklist for Anticoagulation Clinics: How to Handle SMS INR Disclosures and Patient Portal Preferences

Designating a HIPAA Privacy Officer

Scope of responsibility

  • Oversee policies governing Protected Health Information (PHI) across anticoagulation workflows, including SMS disclosures of INR results and portal messaging.
  • Coordinate risk analysis and risk management with the Security Officer to address texting, device, and portal threats.
  • Maintain and periodically update Notices of Privacy Practices to describe how the clinic uses SMS and patient portals.
  • Manage Business Associate Agreements with texting, EHR, and portal vendors that create, receive, maintain, or transmit PHI.
  • Respond to patient rights requests, including access, amendments, restrictions, and Accounting of Disclosures where applicable.
  • Lead incident and breach response, root-cause analysis, and corrective actions related to misdirected or exposed messages.

Documentation to maintain

  • Written designation of the Privacy Officer and backup designee.
  • Current policies on SMS use, portal security, minimum necessary, and role-based access controls.
  • Vendor BAAs, risk assessments, and training attestations retained for six years.
  • Plain-language disclosure that SMS is not a secure channel and may expose PHI (for example, INR values) if seen by others.
  • The specific phone number, message types (alerts vs. results vs. care instructions), and whether numeric INR values may be sent.
  • Minimum necessary commitment (e.g., default to portal notifications; use SMS with PHI only when the patient opts in).
  • Revocation method (reply STOP, call, or portal toggle) and the effective date of changes.
  • Attestation that the number is personal or that the patient accepts risks if shared (family, employer, caregiver).
  • Capture e-signature or written consent; store the signed record, date/time, staff witness, and scope of disclosures.
  • Record consent status and preferences in the EHR and the texting platform; reconcile any discrepancies daily.
  • Reconfirm at each visit or medication management touchpoint; maintain version history for audits.

Operational tips

  • Verify identity before enabling SMS (e.g., two-factor phone verification) and confirm the number at every INR encounter.
  • Segment content: appointment reminders via SMS by default; INR values via portal unless explicit SMS opt-in exists.
  • Include opt-out language in operational messages where feasible without revealing PHI.

Message templates (examples)

  • No-PHI alert (default): “You have a new test result from the clinic. Please check your patient portal or call us.”
  • With consent, minimal PHI: “INR 2.4 today. Continue current dose. Recheck in 1 week. Questions? Call the clinic.”

Implementing Secure Patient Portals

Security controls to expect

  • Strong authentication (Multi-Factor Authentication), unique user IDs, and automatic logoff.
  • Encryption in transit and at rest, with keys managed by the portal or hosting provider under a signed BAA.
  • Role-Based Access Controls to restrict staff functions and proxy access to only what is necessary.
  • Comprehensive audit controls: logins, message views, result downloads, preference changes, and disclosures.
  • Session safeguards: device recognition, throttling, and anomaly detection for suspicious access.

Operational safeguards

  • Enable a preferences center so patients choose SMS alerts, portal-only delivery, or both.
  • Display INR values and dosing plans in the portal; use SMS primarily to nudge patients to log in.
  • Document the portal’s security posture, backup/restore, and change management within your HIPAA risk management program.

Managing SMS INR Disclosure Risks

Key risks to address

  • Misdirected messages due to wrong numbers, reassigned numbers, or contact entry errors.
  • Lock-screen previews exposing PHI on shared or lost devices.
  • Unsecured staff devices or ad hoc texting outside the approved platform.
  • Over-disclosure (full clinical context) when the minimum necessary would suffice.

Controls and compensating safeguards

  • Default to portal delivery for results; use SMS with PHI only when patients explicitly opt in.
  • Use templates that avoid diagnosis, medication names, or dosing unless consented and clinically necessary.
  • Send a verification code to confirm ownership before first SMS with PHI; re-verify after number changes.
  • Deploy an approved texting platform under a BAA; disable personal/BYOD texting for PHI unless governed by policy and MDM.
  • Establish thresholds: critical INR values require a phone call with identity verification, not SMS.

Response to errors

  • Stop further messages, notify the Privacy Officer, investigate scope, and determine breach obligations.
  • Document the incident, corrective actions, and patient notifications as required.

Enforcing Workforce Training on HIPAA Policies

Curriculum essentials

  • Definition of PHI and minimum necessary in the context of anticoagulation and INR workflows.
  • Approved message templates, identity verification steps, and when to escalate to calls or portal-only delivery.
  • Use of sanctioned systems only; prohibition of personal texting apps for PHI.
  • Handling opt-outs, revocations, and patient restrictions on communications.
  • Recognizing and reporting misdirected messages, suspected breaches, and social engineering attempts.

Program structure

  • Role-based onboarding and annual refreshers with attestations.
  • Spot audits of message content and number verification steps; coaching and remediation documented.

Maintaining Audit Trails and Documentation

What to log

  • SMS metadata: recipient, sender, date/time, template used, and minimal content or a redacted/hashed reference.
  • Portal events: logins, result views, message reads, downloads, and preference changes.
  • Consent lifecycle: versions, timestamps, revocations, and staff actions.

Make logs tamper-resistant

  • Implement Tamper-Evident Audit Logging (e.g., write-once or hash-chained logs) with time synchronization.
  • Restrict log access via Role-Based Access Controls and monitor for privilege abuse.

Retention and reporting

  • Retain HIPAA-required documentation and logs for at least six years or longer if state law dictates.
  • Maintain an Accounting of Disclosures where required (e.g., certain public health, legal, or non-routine disclosures).
  • Produce audit-ready reports that tie each INR communication to consent status and the rationale for disclosure.

Handling Patient Portal Preferences

Preference center design

  • Allow granular choices: alerts only vs. full results by SMS; portal-only vs. combined notifications.
  • Support proxies and caregivers with scoped access and independent notification settings.
  • Surface risks for SMS with PHI and require explicit acknowledgment before enabling.

Operationalizing preferences

  • Sync preferences across EHR, portal, and texting systems; reconcile nightly and after each clinic encounter.
  • Reconfirm preferences at check-in and when anticoagulation plans change.
  • Honor patient restrictions and document exceptions (e.g., emergencies) per policy.

Conclusion

Build your audit program around clear governance, explicit SMS consent, a secure portal with MFA and RBAC, and tamper-evident logging. By defaulting to portal delivery and tightly managing exceptions, you protect PHI while giving patients control over how they receive INR information.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

FAQs

What constitutes a HIPAA-compliant SMS message?

A compliant message follows the minimum necessary standard, aligns with the patient’s documented consent and preferences, avoids unnecessary clinical detail, and is sent through an approved system under a Business Associate Agreement. Prefer portal nudges (“You have a result”) over sending INR values. If the patient opts in to receive INR by SMS, use concise templates, verify the number, include an opt-out method, and log the disclosure.

Obtain written or electronic consent that specifies the phone number, message types, whether INR values may be sent, and the risks of SMS. Record the date/time, staff witness, and version of the consent text. Store it in the EHR and texting platform, link it to the patient record, and maintain a full history of updates and revocations for at least six years.

What security measures are required for patient portals?

Implement administrative, physical, and technical safeguards that include strong authentication (preferably Multi-Factor Authentication), encryption in transit and at rest, Role-Based Access Controls, automatic logoff, and comprehensive audit logging. Manage vendor risk under a Business Associate Agreement, validate backups and incident response, and enforce least privilege across staff and proxy accounts.

How can clinics audit communications involving INR results?

Maintain tamper-evident logs that tie each INR communication to patient identity, consent status at the time of sending, message channel (SMS vs. portal), content template, sender, and timestamps. Reconcile logs across the EHR, portal, and texting vendor; run exception reports for messages sent without active consent; and retain artifacts—policies, BAAs, training attestations, and Accounting of Disclosures where applicable—for audit readiness.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles