In November 2019, OCR announced a $3 million settlement under the headline "Failure to Encrypt Mobile Devices." The lesson practices took from it was "encrypt the phones." That is the right lesson, and it is also why Signal keeps coming up in compliance conversations: Signal is the most encrypted messaging app most people have ever installed. So the question arrives with a hopeful tone. Is Signal HIPAA compliant?
No, in the sense practices mean. Signal Messenger LLC does not offer a B.A.A. (Business Associate Agreement), and its Terms of Service and Privacy Policy do not mention HIPAA at all. There is no business plan, no enterprise tier, and no admin console, because Signal is a consumer app built to know as little about you as possible. That design is excellent for privacy and unhelpful for compliance, which needs someone to be accountable, someone to be able to produce records, and someone to be able to turn off a former employee's access on a Tuesday afternoon. This guide explains why encryption alone does not settle the question, where Signal can still fit, and what to use for anything that touches patients.
Is Signal HIPAA Compliant? Encryption Versus the Security Rule
Does Signal Sign a BAA?
No. Signal's legal page describes a service "designed to never collect or store any sensitive information," where "messages and calls cannot be accessed by us or other third parties because they are always end-to-end encrypted." Its terms state plainly that "Signal does not have the ability to access your messages." There is no BAA to request and no plan on which one becomes available.
Whether Signal even needs one is a fair question for counsel. A business associate under 45 CFR 160.103 is a person who "creates, receives, maintains, or transmits protected health information" on behalf of a covered entity. A service that, by its own description, cannot read what passes through it is different from a cloud drive that stores your charts. But that argument only addresses Signal's side of the relationship. It does nothing for yours, and the Security Rule is mostly about yours.
Which Signal Plan Is HIPAA-Eligible?
None, because there are no plans. Signal has one version, funded by donations, registered with a phone number. That single fact drives most of what follows: there is no organizational account, so there is no organization in the picture. Every Signal user is an individual with a personal phone number, including the receptionist who left last month.
What Encryption Does Not Cover
The Security Rule asks for far more than encryption, and most of it lives outside the message pipe. Compare Signal against the standards a practice must meet for any system that carries ePHI:
| Security Rule standard | What it asks for | Signal |
|---|---|---|
| Transmission security, 164.312(e) | "Guard against unauthorized access to electronic protected health information that is being transmitted" | Strong. End-to-end encryption by default. |
| Unique user identification, 164.312(a)(2)(i) | "A unique name and/or number for identifying and tracking user identity" | Weak. Identity is a personal phone number; no organizational directory. |
| Audit controls, 164.312(b) | "Record and examine activity in information systems that contain or use electronic protected health information" | None available to the practice. Signal keeps no server-side record, by design. |
| Termination procedures, 164.308(a)(3)(ii)(C) | "Terminating access to electronic protected health information when the employment of ... a workforce member ends" | Manual only. Someone must remove the person from every group; message history stays on their phone. |
| Device and media controls, 164.310(d) | Policies for "the receipt and removal of hardware and electronic media that contain electronic protected health information" | Entirely on the practice. Messages live on personal devices. |
| Documentation, 164.316(b) | Retain required documentation "for 6 years" | Disappearing messages and device loss make Signal a poor system of record. |
Read the right-hand column as a job description. Every gap is work the practice must do by policy and device management, with no vendor help. That is the honest meaning of "Signal is not HIPAA compliant": the app is not the problem, the absence of a managed environment around it is.
The Phone Is the Real Risk
Signal's terms say it well: "You are responsible for keeping your device and your Signal account safe and secure." Every message a clinician receives on Signal sits decrypted on a handset that gets left in cars, handed to children, and traded in at carrier stores. The 2019 settlement above was about exactly that surface. So was a $1,040,000 settlement in July 2020 over an unencrypted stolen laptop. The controls that matter are the ones in the mobile device security guide: screen lock, full-disk encryption, remote wipe, and a written rule about what may be on the device at all. The first hour after a phone goes missing has its own playbook, and it starts with a remote wipe you set up in advance.
Where Signal Can Still Fit
Some practices land on a narrow, documented use: brief clinician-to-clinician coordination ("room 3 is ready," "call me about the 2:00") on managed devices, with no patient identifiers in the thread. That is a defensible position only if it is written down and the risk has been assessed. 45 CFR 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI, and 164.306(b)(2) lets a practice weigh "the size, complexity, and capabilities" of the organization and "the costs of security measures" in choosing controls. A solo therapist and a fifty-provider group can reach different answers. Neither can reach an answer by not asking.
If Leadership Allows Signal: The Setup Checklist
- Do the risk analysis first and record Signal in it as a system that may carry ePHI on personal or practice-owned phones.
- Write the policy. Permitted uses (short internal coordination), prohibited uses (patient communication, photos of records or screens, anything that belongs in the chart), and the rule that the thread is never the medical record.
- Manage the devices. Screen lock, encryption, remote wipe, current OS. Personal phones that cannot meet this standard cannot be on the list.
- One person, one number. No shared phones, no shared accounts, so the unique-identity requirement is at least met in practice.
- Decide the disappearing-message setting deliberately. Short timers reduce what a lost phone exposes. They also destroy evidence you may need for an incident review. Pick one and document why.
- Build the exit step. Add "remove from all messaging groups and confirm device wipe of practice data" to the termination procedures checklist.
- Keep patients out of it. Patient communication belongs on a channel the practice controls and can document, under the texting rules.
- Train and sanction. The policy needs a training record and a sanction line under 164.308(a)(1)(ii)(C), or it is a suggestion.
What to Use Instead
| Platform | BAA | Admin controls and audit | Notes |
|---|---|---|---|
| Signal | No | None | Best encryption in the group; no organizational layer |
| No | None for a practice | Also consumer-grade; see the WhatsApp analysis | |
| Microsoft Teams (commercial Microsoft 365) | Yes, in-scope | Yes | Covered in the Teams guide |
| Google Chat (paid Workspace) | Yes, via the Workspace BAA | Yes | Requires the Admin console BAA acceptance |
| Slack (Enterprise Grid) | Yes, on the right tier | Yes | See the Slack requirements |
| Purpose-built clinical messaging | Yes, standard | Yes, plus EHR integration | Built for exactly this job |
The pattern is consistent across every row: the platforms that work for a practice are the ones with an organization behind the account, a BAA, and an administrator who can see and stop things. Signal was built to make all three impossible. That is a feature for a journalist and a gap for a clinic, and no amount of encryption changes which one you are.
---
FAQ
Does Signal offer a HIPAA Business Associate Agreement?
No. Signal's Terms of Service and Privacy Policy do not mention HIPAA, and Signal offers no business or enterprise plan under which a BAA could be requested. It is a consumer app funded by donations.
Signal is end-to-end encrypted. Is that not enough for HIPAA?
Encryption addresses transmission security at 45 CFR 164.312(e). The Security Rule also requires unique user identification, audit controls, termination procedures, device and media controls, and documentation. Signal provides none of those to a practice; they all fall on you.
Can clinicians use Signal to coordinate with each other?
Some practices allow brief internal coordination with no patient identifiers, on managed devices, under a written policy and a documented risk analysis. That is a decision for leadership and counsel, not a default.
Can I message patients on Signal?
Patient communication should run on a channel the practice controls, can document, and can produce on request. Signal offers no organizational account, no records, and no BAA, so it is a poor fit for patient messaging.
What should a practice use instead of Signal?
A platform with a BAA and administrator controls: Microsoft Teams on a commercial Microsoft 365 plan, Google Chat on a paid Workspace plan with the BAA accepted, Slack Enterprise Grid, or a purpose-built clinical messaging tool.
Conclusion
Staff messaging is where good intentions and bad tooling collide, and the fix is a policy plus a platform, not a lecture. One Guy Consulting's Full-Scope plan includes the mobile device and messaging policy templates, vendor and BAA management, and consulting time to pick a platform your team will actually use. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- Signal: Terms of Service and Privacy Policy (vendor legal page)
- 45 CFR 160.103 (definitions)
- 45 CFR 164.306 (security standards, general rules)
- 45 CFR 164.308 (administrative safeguards)
- 45 CFR 164.312 (technical safeguards)
Related Reading