> ## Documentation Index
> Fetch the complete documentation index at: https://handbook.helendelovely.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Devices, Mobile, and Texting

> The device standard, and the one rule about texting clients: only through the practice system.

## The device standard

Any device that touches client information, yours or the practice's, must meet this standard before it's used for work:

| Requirement                                                                                      | Why                                         |
| ------------------------------------------------------------------------------------------------ | ------------------------------------------- |
| Passcode or password required, auto-lock at 5 minutes or less                                    | Anyone who picks it up can't get in         |
| Full-disk encryption on (FileVault, BitLocker, or default phone encryption)                      | A lost device is a locked box, not a breach |
| Operating system and apps kept current                                                           | Old software is how attackers get in        |
| Enrolled in the practice's mobile management, so the work profile can be wiped remotely          | A lost phone can be wiped in minutes        |
| Practice apps only in the managed work profile; no client data in personal apps or local storage | Personal and practice data stay separate    |

Enroll before any client data reaches the device. Zack sets this up during onboarding. See SOP 20 in the [SOP library](/operations/sop-library).

## Practice-issued equipment

If the practice issues you a laptop or other equipment, it's for practice work, it's tracked on an equipment form, and it comes back when you leave. Treat it like your own, and report damage or loss immediately.

## Texting clients

**Client communication goes through PracticeOS, always.** Every text, email, and call to a client runs through the practice system, where it's logged, associated with the record, and covered by our business associate agreement.

Never:

* Text a client from your personal number
* Email a client from a personal account
* Message a client on social media, WhatsApp, Signal, or any other app
* Give a client your personal number

If a client texts your personal phone somehow, reply once, briefly, telling them to reach you through the practice number, then log the contact in PracticeOS. Don't continue the conversation on your phone.

> **Why.** Text is not a secure channel. Sending through the practice system limits what's exposed, keeps the record complete, and keeps your personal phone out of a client's record forever.

## What's OK to text

Even through PracticeOS, keep texts to logistics: appointment confirmations, reschedules, links to the portal. Clinical content, diagnoses, and anything sensitive belong in session or in the portal, not in a text.

## Internal messaging: the channel rule

The practice doesn't force one chat tool on the team. It sets one rule about what goes where, and trusts you to follow it.

**Client information travels only on covered channels.** A covered channel is one the practice has a signed business associate agreement for and has configured for client data. Today that means PracticeOS (messaging, notes, and the care portal) and a phone call. The practice manager keeps the current list of covered channels in the [SOP library](/operations/sop-library), and it changes only when a new agreement is signed.

**Everything else can go anywhere.** Scheduling chatter, team logistics, links, jokes, questions about the copier: use whatever the team is using, WhatsApp, Signal, Google Chat, text, doesn't matter. The rules from SOP 15 apply on any uncovered channel:

* Initials only, never full client names
* No diagnoses, no clinical details, no insurance or member IDs, no photos of anything with a name on it
* OK: "TTS appointment today," "JS moved to Thursday at 3"
* Anything clinical or identifying goes in PracticeOS or a phone call

> **Important.** Flexibility is the trade for responsibility. If you're unsure whether something counts as client information, it does. Move it to a covered channel. A slip on an uncovered channel is a reportable incident; see [Breach and incident reporting](/privacy-and-security/breach-and-incident-reporting).

> **Why.** Forcing one tool doesn't make people safe; understanding the line does. Annual HIPAA training covers this rule with examples, and the practice would rather train the judgment than police the app.

## Voicemail

Practice voicemail greetings shouldn't reveal that a caller is reaching a therapy practice in a way that would expose a client who calls from a shared phone. Use the practice's approved greeting. When leaving a voicemail for a client, say your name and the practice's callback number, and nothing else, unless the client has told us in writing that detailed messages are fine.

## Lost or stolen

Tell Zack and the practice manager immediately, day or night. Every hour matters. See [Breach and incident reporting](/privacy-and-security/breach-and-incident-reporting).
