HIPAA Training for Lactation Consultants: What to Know Before Texting CGM Screenshots to Family Members
Understanding HIPAA Privacy Rule
Continuous glucose monitor (CGM) images that show readings, timestamps, or app identifiers are Protected Health Information (PHI) when held by a covered provider or their business associate. When stored or sent electronically, they are electronic Protected Health Information. Even a cropped screenshot without a name can be PHI if it can reasonably be linked to a specific patient.
The HIPAA Privacy Rule permits sharing PHI for treatment and, in limited cases, with family or others involved in the patient’s care. If the patient is present and agrees—or is given the opportunity to object and does not—you may disclose information relevant to that person’s involvement. If the patient is not present or cannot agree, you may use professional judgment to act in the patient’s best interest and share only what is necessary for that moment.
Apply the minimum necessary principle for disclosures to family or caregivers. Limit screenshots to the specific data point needed (for example, a current glucose trend) rather than the full CGM history or unrelated notes.
Implementing HIPAA Security Rule Safeguards
The Security Rule requires administrative, physical, and technical protections that fit your risks. Administrative safeguards include a documented risk analysis, workforce training, sanction policies, vendor due diligence, and procedures for approving texting workflows that involve PHI.
Technical safeguards should cover strong authentication, automatic lock, role-based access, audit controls, integrity monitoring, and secure transmission. On mobile devices, enforce device encryption, remote wipe, short auto-lock, and no screenshots saved to personal photo galleries or unvetted cloud backups.
Physical safeguards should address where devices are stored, who can access them, and how lost or stolen phones are reported. Build incident response steps for misdirected texts, including containment, risk assessment, and breach notification if required.
Using HIPAA-Compliant Texting Platforms
Standard SMS, consumer messaging apps, and personal email are not designed for PHI. Use a HIPAA-compliant platform backed by a Business Associate Agreement (BAA), secure texting encryption, user-level access controls, audit trails, message expiration, remote revoke, and the ability to prevent copy/paste and downloads.
Before adopting a vendor, verify: covered entity obligations addressed in the BAA; encryption in transit and at rest; unique user IDs and multifactor authentication; logging and exportable audit reports; administrative controls for onboarding/offboarding; and patient-facing options when needed. Test that CGM screenshots stay inside the secure container and never sync to consumer clouds.
If a patient insists on a non-secure channel, first attempt to route through the HIPAA-compliant platform. If the patient still prefers otherwise, document that preference, explain risks, and limit disclosures to the minimum necessary. When the recipient is a family member, confirm the patient’s direction in writing and record the exact phone number or address authorized.
Obtaining Patient Consent for Texting PHI
Distinguish between general consent to communicate, permission to involve specific family members, and a formal authorization. For routine care coordination with a spouse or caregiver, obtain the patient’s agreement (verbal or written) and document it. For broader or ongoing sharing, get written permission naming the recipient and types of information permitted.
Use a confidential communications request to capture how the patient wants you to communicate (for example, “Send CGM alerts to my partner at this number”). Note any security tradeoffs discussed, the channel approved, and how long the preference remains in effect. Provide a simple way for the patient to change or revoke permissions.
Always verify the recipient’s identity and relationship before sending. For recurring exchanges, create a contact entry inside the secure platform and confirm it with the patient to reduce misdirected messages.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Exercising Professional Judgment in PHI Disclosures
Professional judgment disclosures allow sharing PHI with family or others involved in care when the patient cannot agree and the disclosure is in the patient’s best interest. In a hypoglycemia emergency during a home visit, sending a current CGM reading to a caregiver who is actively assisting may be appropriate—provided you limit the information to what the caregiver needs to act safely.
Use a quick test: Is the patient present and able to agree? If yes, ask first. If not, is the disclosure necessary to prevent harm or support immediate care? If yes, share the minimum necessary and document your rationale. If the patient later objects, cease further disclosures and update their preferences.
After any professional judgment disclosure, record who received the information, what was shared, why it was necessary, and the outcome. Incorporate this into your compliance logs and case notes.
Compliance Responsibilities for Lactation Consultants
Your role determines your obligations. If you are a health care provider who transmits standard electronic transactions (such as electronic claims) or you work under contract for one, HIPAA applies and you must meet covered entity obligations or business associate requirements. Independent consultants who are not covered by HIPAA may still be bound by contracts, payer rules, and state privacy laws—so adopting equivalent safeguards is a prudent baseline.
Maintain written policies for texting PHI, complete annual risk analyses, train all staff on secure messaging, and keep signed BAAs with any vendor handling PHI. Establish retention rules for message content, consistent with your documentation policies, and define how screenshots become part of the clinical record when clinically relevant.
Have an incident response plan for misdirected or lost messages, including steps for containment, risk assessment, and required notifications. Review and test that plan regularly.
Best Practices for Secure Communication
Quick-send checklist for CGM screenshots
- Confirm patient preference and recipient authorization; update or obtain a confidential communications request when needed.
- Use a HIPAA-compliant platform with secure texting encryption, access controls, and audit logs; avoid consumer SMS or messaging apps.
- Verify the recipient’s identity and role each time sensitive data is shared, especially when numbers or contacts change.
- Share the minimum necessary: crop or annotate to highlight the specific reading or trend needed for care.
- Keep messages inside the secure container; disable auto-save to device galleries and unapproved cloud backups.
- Document what was sent, to whom, when, why, and under what permission or professional judgment.
- If something goes wrong (wrong number, lost device), trigger your incident response steps immediately.
Conclusion
Texting CGM screenshots can support timely lactation and diabetes care, but only within clear permissions and secure workflows. Anchor decisions to the Privacy and Security Rules, prefer a HIPAA-compliant platform, apply minimum necessary, and document consent or professional judgment disclosures every time.
FAQs.
When is it permissible to text CGM screenshots to family members under HIPAA?
It is permissible when the patient agrees or does not object after being informed, and the information shared is relevant to the family member’s role in care. If the patient cannot agree, you may rely on professional judgment to disclose the minimum necessary information in the patient’s best interest and document your rationale.
How can lactation consultants ensure texting platforms are HIPAA-compliant?
Select a vendor that signs a BAA and provides secure texting encryption, authentication controls, audit logs, message retention and recall, and administrative oversight. Test that screenshots never leave the secure container or sync to personal clouds, and confirm onboarding/offboarding, remote wipe, and logging work as intended.
What types of patient consent are required before texting PHI?
Obtain the patient’s agreement to involve specific family members and to use the selected channel. For ongoing or broader sharing, use written permission that names the recipient, scope, and duration. Capture their preferences in a confidential communications request, note any security risks discussed, and provide a simple way to revoke.
How should lactation consultants apply professional judgment in sharing PHI?
Use it only when the patient is not present or cannot agree, and when disclosure will directly support care or safety. Share the minimum necessary (for example, the current CGM trend), send via a secure channel, and promptly document the recipient, content, reason, and outcome. Stop future disclosures if the patient later objects.
Table of Contents
- Understanding HIPAA Privacy Rule
- Implementing HIPAA Security Rule Safeguards
- Using HIPAA-Compliant Texting Platforms
- Obtaining Patient Consent for Texting PHI
- Exercising Professional Judgment in PHI Disclosures
- Compliance Responsibilities for Lactation Consultants
- Best Practices for Secure Communication
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.