A four-provider orthopedic practice sent about 1,900 patient statements a month and collected on roughly a third of them inside 60 days. The practice manager had three vendor proposals for text-to-pay on her desk, each promising to double that. She asked us which one to pick. We asked a different question first: how would a payment made on a phone at 9 p.m. on a Sunday get posted to the right account, against the right date of service, with the right adjustment, by Monday morning? None of the three proposals answered it, and one of the vendors, when asked, said "your staff would post those manually from our daily report." That is not a payment solution. It is a second unposted cash drawer.

Text-to-pay for medical practices is a real improvement over paper when it is set up well, and a real mess when it is not. The technology is simple: the practice sends a text with a link, the patient taps it, sees the balance, pays with a card or bank account, and the payment posts back to the account. Every step of that sentence hides a decision that the practice, not the vendor, has to make. This article is the checklist we run before a practice signs, in the order we run it.

A glossary line. "Card on file" means the patient has authorized the practice to store a payment method (through the vendor, never in the practice's own systems) and charge it under stated terms. "PCI DSS" is the card industry security standard; a practice's obligations under it depend on whether card data ever touches the practice's systems. A "business associate agreement" is the HIPAA contract required with any vendor that handles patient information on the practice's behalf.

Key takeaways

  • Consent to receive texts is a legal requirement, not a preference setting; capture it at registration in writing and record it in the patient record.
  • A balance notification contains protected health information, so the vendor is a business associate and the texts themselves should carry the minimum: a name, an amount and a link.
  • Keep card data out of the practice entirely by using vendor-hosted payment pages; that is what keeps PCI scope small.
  • Posting integration is the make-or-break question; a payment that requires manual posting is a cost, not a saving.
  • Judge the vendor after 90 days on four numbers: percent of patient balances paid within 30 days, average days to pay, statement cost per account and posting exceptions per week.

Consent and the texting rules

The Telephone Consumer Protection Act and the Federal Communications Commission's rules under it govern automated texts, and the penalties for texting people who did not agree are per message. Informational messages about a patient's own account need the patient's prior express consent; marketing messages need prior express written consent. A balance reminder is informational, but practices that let the same vendor send appointment promotions or "book your annual physical" campaigns have crossed into marketing and need the higher standard.

The practical rule is to capture consent in writing on the registration form, with the mobile number the patient wants used, a plain statement of what the texts will contain, and a line about how to opt out. Record it as a discrete field in the practice management system so the vendor can check it before sending. Honor "STOP" replies immediately and automatically. And review the consent language with counsel, because state laws add requirements in several places, and the rules have shifted more than once in recent years.

HIPAA, the vendor and the text itself

A text that says "You have a balance of $142.50 with Riverside Orthopedics, pay here" contains protected health information: it links a named person to a health care provider and a financial detail. That makes the vendor sending it a business associate, and the practice needs a signed business associate agreement before the first message goes out. Ask for the agreement during the evaluation, not after signing the service contract, and ask what the vendor's own security posture is; a vendor that says it is "HIPAA certified" is using a phrase that does not exist, because no federal HIPAA certification exists. "HIPAA compliant" and an independent security report are what to look for.

Keep the text itself minimal. Patient first name, practice name, amount, link. No dates of service, no procedure names, no provider names. The detail lives behind the link, after the patient has verified identity with a date of birth or a code. Our view is that the fewer words in the text, the fewer problems, and the patients do not miss the detail.

Card data and PCI scope

The single most useful design decision is that card numbers never enter the practice's systems. The link opens a payment page hosted by the vendor or its processor; the patient types the card number there; the practice receives a token and a confirmation. Under that design, the practice's PCI obligations shrink to the simplest self-assessment questionnaire, and a breach of the practice's own network does not expose card numbers. Ask the vendor to confirm in writing that no card data is stored, processed or transmitted on practice systems, including the front desk terminal if the same vendor supplies it.

Card on file works the same way: the token is stored by the vendor, and the practice charges against it under an authorization the patient signed. The authorization should state the maximum amount or the rule (for example, "the patient responsibility determined by my insurance, up to $250, after the claim is processed"), the notice the patient will receive before a charge, and how to revoke. Card on file with clear terms is one of the most effective patient collection tools we know; card on file with vague terms produces chargebacks and complaints.

Posting integration: the question that decides it

Back to the orthopedic practice. A payment made through the link has to land in the practice management system as a payment on the correct account, applied to the correct dates of service, with the payment method and the vendor's transaction reference, without a human retyping it. Vendors describe this as "integration", and the word covers everything from a true real-time posting interface to a nightly file that a biller imports to a PDF someone reads.

CheckQuestion to ask the vendorAcceptable answer
Posting methodHow does a payment reach our practice management system?Real-time or same-day automatic posting to the patient account, with transaction ID; not a report for manual entry
Application logicHow is a partial payment applied across multiple dates of service?Configurable rule (oldest first, or patient choice), consistent with the statement
Balance sourceWhere does the amount on the text come from?Live from the practice management system at send time, and re-checked when the link is opened
ExceptionsWhat happens when a payment cannot be matched to an account?Daily exception queue with alerts, not silent suspense
Refunds and chargebacksHow are refunds issued and how do disputes reach us?Refund from within the practice system to the original method; dispute notices by email within one business day
ReconciliationHow do we tie the bank deposit to individual payments?Daily settlement report by deposit, with every transaction listed and fees shown separately
FeesWhat are the total costs per transaction and per month?Written schedule: processing rate, per-transaction fee, monthly platform fee, text fees, and any statement fees; no surcharging to patients unless state law and card brand rules are confirmed
Data and exitWhat happens to stored payment methods and history if we leave?Token migration or documented process; history exportable

The reconciliation row matters more than it looks. Processors deposit net of fees, often batched across days. If the vendor cannot give you a report that ties each deposit to the individual payments and shows the fees separately, the month-end close will never balance, and the practice will end up writing off the difference as a mystery adjustment.

Timing and cadence

The text should follow the adjudication, not the paper. When a remittance posts a patient responsibility amount, a text within two or three days, while the visit is fresh, collects far better than a statement three weeks later. A sensible cadence is a text at adjudication, a paper or electronic statement at 30 days if unpaid, a second text at 45 days, and a call before 90. Practices that keep the old statement cycle and bolt texts onto the end get a fraction of the benefit.

Give the patient the option to set up a payment plan from the same link, with the plan terms from your patient balance policy built in: minimum monthly amount, maximum months, card on file required. A plan a patient sets up at 9 p.m. on a Sunday is a plan; a plan that requires a call to the office during business hours is a balance that ages.

How to judge it after 90 days

Four numbers, measured before the vendor starts and again at 90 days. The percentage of patient responsibility dollars paid within 30 days of adjudication. The average days from adjudication to payment. The statement cost per account, including postage, paper and vendor fees. And posting exceptions per week, which should be near zero by week six. If the first two moved and the last one did not fall, the vendor is collecting money for you and creating work for you at the same time, and the second half of that sentence will eventually cancel the first.

We think most independent practices should adopt text-to-pay, and that most of the disappointment we hear about it comes from the posting integration and the consent capture, not the payments. The vendors are good at the payment part. The practice has to be good at the rest.

Questions we hear

Can we add a convenience fee for card payments?

Surcharging is restricted or prohibited in some states, capped by card brand rules where allowed, and generally not permitted on debit cards. Several payer contracts and Medicare rules also complicate charging patients anything beyond their cost-sharing. Ask counsel before adding any fee; most practices we work with absorb the processing cost.

What about patients without a mobile phone?

Keep paper statements for them, with the same payment link printed as a short URL or a QR code. The goal is one balance, one set of terms, several ways to pay. Patients who never opted in to texts, or who opted out, stay on the paper cycle automatically.

Should the vendor be our practice management system's own payment module or a third party?

The built-in module usually wins on posting integration and loses on fees or features. A third party usually wins on patient experience and loses on posting. Score the table above for each and weight the posting rows heavily; in our experience the integration cost outweighs a small fee difference within a few months.

What to do this week

  1. Measure the baseline: percent of patient responsibility paid within 30 days, average days to pay and statement cost per account for the past three months.
  2. Add a written texting consent field to the registration form and the practice management system, and review the wording with counsel.
  3. Send the table above to each vendor under consideration and ask for written answers, including the business associate agreement and the fee schedule.
  4. Ask your practice management vendor what posting interface it supports and which payment vendors are certified against it.
  5. Design the new cadence (text at adjudication, statement at 30 days, text at 45, call before 90) and decide the payment plan terms before the vendor configures anything.