A dermatology practice switched on text reminders through its scheduling system in the spring and watched its no-show rate fall from 11 percent to about 6 percent in two months. Then a patient replied "stop" to a reminder, kept receiving them for three more visits because nobody was reading the replies, and sent a demand letter citing the Telephone Consumer Protection Act with a figure of $500 per message. The practice settled. The reminders were a good idea; the setup was not finished.
Texting patients appointment reminders is now standard in outpatient care, and the rules around it come from two directions. The TCPA, enforced by the FCC and by private lawsuits, governs whether you may send an automated text at all and what consent you need. HIPAA governs what the message may contain and how the vendor that sends it must be bound. Practices tend to think about one and not the other.
This article lays out both sets of rules as they stand this summer, the consent record to keep, the opt-out mechanics, the content limits, and the vendor questions to ask before the next reminder goes out.
Key takeaways
- Under the TCPA, a patient who gives the practice a mobile number for care purposes has generally given prior express consent for healthcare-related texts; the FCC also exempts certain treatment-purpose messages from consent entirely, with strict conditions.
- The exemption covers reminders and similar care messages only: 160 characters or less, no more than one per day and three per week, no billing or marketing content, and an opt-out that is honored immediately.
- Since April 11, 2025, any reasonable "stop" request by any method is a valid revocation, must be honored within ten business days, and one confirmation text is allowed.
- The requirement that a revocation apply across all of the sender's message types has been delayed to January 31, 2027; the practice should build for it now.
- Under HIPAA, unencrypted texts are permitted for reminders with minimal PHI when the patient has been warned and agrees, and the texting vendor needs a business associate agreement.
Texting patients appointment reminders under the TCPA
The Telephone Consumer Protection Act restricts automated calls and texts to mobile phones. Its default rule is that an automated text needs the recipient's prior express consent, and a marketing text needs prior express written consent. For healthcare providers, the FCC has said two useful things over the years. First, a patient who provides a mobile number to a provider, on an intake form or verbally, has given prior express consent to receive calls and texts closely related to the purpose for which the number was provided, which covers appointment reminders. Second, in its 2015 order the FCC exempted from the consent requirement certain messages from HIPAA covered entities made for a healthcare treatment purpose, provided they meet a list of conditions.
The exempted categories are appointment and exam confirmations and reminders, wellness checkups, hospital pre-registration instructions, pre-operative instructions, lab results, post-discharge follow-up intended to prevent readmission, prescription notifications and home healthcare instructions. The conditions are the part practices forget.
| Condition for the exemption | What it means in practice |
|---|---|
| Sent only to the wireless number the patient provided | Do not text a number obtained from another source or skip-traced; keep the source of the number in the record |
| States the name and contact information of the provider | Every message identifies the practice and gives a callback number |
| Strictly limited to the exempt purposes | No billing, no balance reminders, no marketing, no "we now offer" content in the same message |
| Concise: one minute or less for voice, 160 characters or less for text | Templates are measured; a long reminder loses the exemption |
| Frequency: one message per day, up to three per week | Reminder cadence is configured within those limits across all message types |
| Easy opt-out offered and honored immediately | Every message tells the patient how to stop; replies are read and processed |
A practice that meets all of these can send reminders without a separate consent step. A practice that fails one of them falls back on the prior express consent from the intake form, which is why we tell practices to build both: collect and record the number with a stated purpose, and configure the messages to meet the exemption anyway. Two safety nets are better than one, and the demand letter comes from a plaintiff's lawyer who will test both.
One legal development changed the ground this year. On June 20, 2025, the Supreme Court decided McLaughlin Chiropractic Associates v. McKesson, holding that federal courts are not bound by FCC interpretations of the TCPA. The practical effect is that the exemption's boundaries can now be argued case by case in litigation rather than settled by the FCC's order. Counsel should read your reminder templates and your consent language; this is not a place for a practice to be creative.
Consent, and the record of it
In a TCPA dispute, the burden of proving consent falls on the sender. The record you need is simple: where the mobile number came from (intake form dated X, portal registration, verbal at check-in with a note), what the patient was told it would be used for, and whether the patient has opted out since. An intake form with a line reading "Mobile number: ____ (we may use this number to call or text you about your appointments and care)" and a signature does the job. A verbal yes at the desk counts, as long as someone records it.
Written consent in the TCPA sense (a signed disclosure that the patient agrees to receive automated marketing texts) is required only for marketing. If your practice ever wants to text about a new service, a flu clinic promotion or a satisfaction survey with a marketing element, that is a separate consent, a separate checkbox, and a separate message stream that can be stopped independently. Most small practices should simply not send marketing texts, and say so in the policy.
Opt-out rules: what is in force and what is coming
The FCC's revocation rules took effect April 11, 2025. A patient may revoke consent by any reasonable means, including replying with words other than "STOP" (an "unsubscribe," "quit," "please stop texting me" or a call to the office all count), and the practice cannot insist on one official channel. The revocation must be honored within ten business days, and one confirmation text within five minutes of the request is allowed and does not need new consent. The dermatology practice in our opening story failed exactly this rule: the reply channel was not monitored.
One further requirement has been delayed twice. The rule that a revocation of consent for one type of message applies to all of the sender's message types and business units was due April 11, 2026, and on January 6, 2026 the FCC pushed it to January 31, 2027 while it reconsiders the rule's scope. Healthcare organizations asked for the delay because reminders, results notifications and billing messages often run through different vendors that do not share opt-out lists. Our advice is to build for the rule anyway: one opt-out list, checked by every system that sends a message. A patient who said stop to reminders and then receives a balance text does not care which vendor sent it.
HIPAA: what the reminder may say
HIPAA permits a covered entity to communicate with patients by unencrypted text or email if the patient has been informed of the risk and agrees, or if the patient initiated the channel. The safer practice for reminders, and the one most vendors follow, is to keep the content minimal: the practice name, the date and time, and the callback number. "Reminder: your appointment with Northside Family Medicine is Tue 8/25 at 2:15 PM. Reply C to confirm or call 555-0100. Reply STOP to opt out." No provider name that reveals a specialty (a reminder from a named oncologist reveals a diagnosis to anyone who sees the phone), no reason for visit, no results, no balances in the same message.
Results and clinical instructions can be texted, but they should go through a secure messaging tool or the patient portal with a text that says only "You have a new message in your patient portal." The appointment reminder exemption under the TCPA covers lab results too, but HIPAA's minimum necessary standard and the risk of a shared or lost phone argue against sending them in the clear.
The vendor and the business associate agreement
Whoever sends the messages (the scheduling system, a reminder service, a patient engagement platform) receives PHI to do it, at minimum the name, phone number and appointment date. That makes the vendor a business associate, and a business associate agreement must be in place before the first message. Beyond the agreement, ask the vendor four questions: how replies and opt-outs are captured and where you see them; whether the templates are locked to the 160-character limit and the identification requirement; whether the system enforces the frequency caps across all message types; and how the opt-out list is shared with any other system that texts your patients. A vendor that cannot answer the fourth question is the reason the cross-system rule was delayed.
Also confirm who owns the phone number the messages come from and whether it is registered for application-to-person messaging with the carriers (10DLC registration in the United States). Unregistered traffic gets filtered, and a reminder that never arrives is a no-show you paid a vendor to produce.
Questions we hear
Do we need a signed consent form before we can text reminders?
Not a separate form, as long as the patient gave you the mobile number for care purposes and you can show that, and the messages meet the healthcare exemption conditions. A line on the intake form that states the purpose and is signed is the cleanest evidence, and adding it costs nothing.
Can we text patients about unpaid balances?
Not under the healthcare exemption, and not in the same message as a reminder. Balance texts are informational, not marketing, so prior express consent (the number given for care purposes) generally covers them, but they must respect opt-outs, state debt collection rules and the frequency limits, and many practices choose a portal notification instead. Get counsel's view before adding a balance message stream.
A patient texted us a clinical question. Can we reply by text?
The patient initiated the channel, which HIPAA treats as an indication that the patient accepts it, but a brief reply directing the patient to the portal or a call is the better habit, and clinical content by unencrypted text should be the exception, documented in the chart. Set the rule in the texting policy so staff do not decide it one message at a time.
What to do this week
- Pull your reminder templates and check each against the exemption conditions: practice name and number, 160 characters, no billing or marketing, opt-out instruction.
- Confirm who reads inbound replies, how often, and how a "stop" in any wording is processed within ten business days.
- Add the purpose statement to the mobile number field on your intake form and portal registration.
- Inventory every system that texts patients and ask each vendor how opt-outs are shared; plan one shared list before January 31, 2027.
- Confirm a business associate agreement exists with every texting vendor and that the sending number is carrier-registered.
Practices that want reminders, intake and payments to run from one place can look at our healthcare website development service, which sets up patient messaging with the consent language and opt-out handling above.
