Skip to content
Start a Free 14-Day Trial

Secure Messaging

Send PIN-protected messages via secure links so sensitive client information stays private.

Secure Messaging protects sensitive information by replacing direct message content with a link to a private conversation page. Clients click the link to read and reply to your messages. This is especially valuable for healthcare, legal, and financial businesses that handle confidential client information.

When you enable Secure Messaging for a message:

  1. Apptoto sends a short notification (SMS or email) containing a secure link.
  2. The client clicks the link and lands on a private conversation page hosted by Apptoto.
  3. If a PIN is required, the client enters it before viewing the message.
  4. The client reads the message and can reply — all within the secure portal.

Links are valid for 24 hours by default. If a link expires, the client can request a new one directly from the conversation page — no action needed from you.

  1. Enable Secure Messaging: Go to Messaging > Secure Messaging and click Try it Now. Toggle Enable Secure Messaging to ON. Enable Secure Messaging via the Messaging > Secure Messaging tab.
  2. Configure the notification message: Set the subject (email only), body, and link expiration. The body must include {{ secure_link }}, which Apptoto replaces with the client’s unique link.

    Default notification body:
    You've received a secure message from {{ user.name_and_company }}, click here to view the conversation: {{ secure_link }}
  3. Optionally set a default PIN: Enter a default PIN that all clients must enter before accessing their messages. You can override this on a per-contact basis. Adjust secure messaging settings including message content and link expiration timing
  4. Optionally add a default PIN requirement for accessing messages. Require a PIN for clients to access their secure messages for added security
  5. Save: Click Save Settings.

After enabling Secure Messaging, you can mark individual auto messages to send securely:

  1. Open the Message Editor: Go to Messaging > Appointment Auto Messages and click an SMS or email message to edit it. Edit an existing appointment auto message by selecting the vertical menu
  2. Toggle Send Securely: Find the Send Securely toggle and switch it ON. Toggle individual message on to send securely
  3. Repeat for other messages: Repeat for every reminder, booking, or follow-up message you want to deliver securely.
  4. Save Click Save Settings.

Using the Compose button, you can send individual secure messages:

  1. Open Compose: Click the blue Compose button on the top of the Appointments tab and enter recipients. Compose a one-time message in Apptoto to anyone on the Appointments tab
  2. Optional: Select appointments: Instead of adding individual contacts, select appointments using the checkboxes, then click Compose. Compose a one-time message in Apptoto to specific appointments on Appointments tab
  3. Choose SMS or email: Secure Messaging does not support voice calls.
  4. Enable Send Securely: Check Send Securely. Optionally, add a PIN for the specific send.
  5. Edit and send: Click Edit to customize message content, then preview and send. Enabled secure messaging checkbox on one-time messaging

Default secure link templates include:

  • Subject: You've received a secure message from {{ user.name_and_company }}
  • Body: Message notification with {{ secure_link }} placeholder

Links expire after 24 hours by default. Alternative timeframes include 10 days, 6 months, or 1 year. Expired links prompt users to request fresh ones automatically.

Three PIN configuration options exist:

  1. Set a default PIN for all contacts via Messaging > Secure Messaging.
  2. Manually assign PINs to individual contacts in the Contacts tab.
  3. Use custom address book fields with dynamic PIN references.

See Secure Message Contact PINs for details.

Access the Tools > Log section to monitor secure message activity. Email logs show open rates and PIN entries; SMS logs display PIN entry confirmation, indirectly confirming message viewing.

While Secure Messaging protects sensitive data, full HIPAA compliance depends on your organization’s usage and policies.