Skip to content
Start a Free 14-Day Trial

Secure Messaging

Apptoto’s Secure Messaging feature provides enhanced privacy for client communications by sending secure links instead of direct message content. Clients receive a short notification with a link that opens a protected conversation page, ensuring sensitive information stays out of SMS and email previews.

When enabled, clients receive a link to access a private conversation page rather than message content in their inbox. Recipients must click the link within a set timeframe to view messages. Once links expire, users can request new ones directly through the conversation page.

Enable Secure Messaging via the Messaging > Secure Messaging tab.

To activate Secure Messaging:

  1. Navigate to Messaging > Secure Messaging in your account.
  2. Select Try it Now to enable the feature.
  3. Configure the secure message subject (for email), body text, and link expiration timing.
  4. Optionally add a default PIN requirement for accessing messages.
  5. Save your settings.

Adjust secure messaging settings including message content and link expiration timing

Require a PIN for clients to access their secure messages for added security

To specify which automated reminders and confirmations use secure delivery:

  1. Go to Messaging > Appointment Auto Messages.
  2. Select or create a message.
  3. Toggle the Send Securely option on the Message Editor.
  4. Repeat for additional messages.
  5. Save settings.

Edit an existing appointment auto message by selecting the vertical menu

Toggle individual message on to send securely

Using the Compose button, you can send individual secure messages:

  1. Click Compose on the Appointments tab.
  2. Choose text or email.
  3. Check Send Securely and optionally set a PIN.
  4. Click Edit to customize message content.
  5. Preview and send.

Compose a one-time message in Apptoto to anyone on Appointments tab

Compose a one-time message in Apptoto to specific appointments on Appointments tab

Enabled secure messaging checkbox on one-time messaging

Default secure link templates include:

  • Subject: You've received a secure message from {{ user.name_and_company }}
  • Body: Message notification with {{ secure_link }} placeholder

Links expire after 24 hours by default. Alternative timeframes include 10 days, 6 months, or 1 year. Expired links prompt users to request fresh ones automatically.

Three PIN configuration options exist:

  1. Set a default PIN for all contacts via Messaging > Secure Messaging.
  2. Manually assign PINs to individual contacts in the Contacts tab.
  3. Use custom address book fields with dynamic PIN references.

See Secure Message Contact PINs for details.

Access the Tools > Log section to monitor secure message activity. Email logs show open rates and PIN entries; SMS logs display PIN entry confirmation, indirectly confirming message viewing.

While Secure Messaging protects sensitive data, full HIPAA compliance depends on your organization’s usage and policies.