A dermatology practice called us last spring, a little spooked. A patient had replied to one of their promotional texts with "take me off this list, this is harassment," and the owner suddenly pictured a lawsuit and a HIPAA fine landing on the same desk. Was texting patients even legal? Had they been breaking the law this whole time? The truth was more boring and more fixable than the panic suggested. Texting patients is completely legal. They just had two habits that needed cleaning up: they were sending marketing texts on consent meant for reminders, and they had no fast way to process an opt out. Both are easy to fix once you understand the rules.
Here is the honest headline. This is not legal advice, and your own healthcare attorney should sign off on your setup. But the framework is not mysterious. Two laws matter, they cover different things, and once you see what each one is actually worried about, compliant texting stops feeling scary.
First, why this is worth getting right
Texting is not a nice extra anymore. It is where patients live. Surveys of patient communication in 2025 and 2026 found that roughly 90 percent of patients prefer to receive healthcare messages by text, far ahead of email, patient portals, or phone calls, according to Sinch. Text messages carry an open rate near 98 percent and are usually read within three minutes. Data compiled by Dialog Health found that a large majority of patients are more likely to keep an appointment when they get a text reminder, and a meaningful share of younger patients would switch providers over the simple lack of texting.
So the stakes cut both ways. Text your patients well and you fill more chairs and keep more of them. Text them carelessly and you risk complaints, opt outs, and in the worst case a regulator's attention. The goal is to land in the sweet spot: reaching patients where they read, without crossing the lines.
Rule one: the TCPA governs consent
The Telephone Consumer Protection Act, or TCPA, is the federal law that controls automated calls and texts. It does not care what your message says medically. It cares whether the patient agreed to be contacted, and how easy you make it for them to stop. The Federal Communications Commission, which enforces it, lays out the basics in its guidance on unwanted robocalls and texts.
The key idea is that not all texts are equal. The TCPA treats two categories differently:
Informational and treatment related texts
Appointment reminders, prescription notices, pre visit instructions, and similar treatment related messages sit in a lighter category. They generally require prior express consent, which in practice usually means the patient gave you their mobile number for that kind of contact. There is a long standing healthcare allowance in the rules that gives treatment related messages more room than sales pitches, precisely because a reminder about your own appointment is something patients want.
Marketing and promotional texts
The moment a text is trying to sell something, a promotion on a new service, a seasonal offer, a win back campaign to lapsed patients, the bar goes up. These require prior express written consent, meaning the patient clearly agreed to receive marketing messages, not just handed over a number for reminders. This is exactly where the dermatology practice slipped. A number collected to confirm appointments is not permission to blast a Botox promotion. Different purpose, different consent.
The clean way to collect consent
Ask for consent in writing at intake, on paper or online, with two separate checkboxes: one for appointment and care related texts, one for promotions and offers. Record the date, the wording they agreed to, and how they gave it. Keep the two consents separate so a patient can say yes to reminders and no to marketing. When a new number comes in through your website or phone system, capture that consent at the same moment. This one habit prevents the large majority of TCPA headaches.
What changed in 2025: opt outs got stricter
If you set up texting years ago and never revisited it, this is the part to read twice. As of April 11, 2025, the FCC tightened the rules around revoking consent, and law firms tracking it, including Bryan Cave Leighton Paisner, broke down what it means in practice. Three points matter for a medical practice:
- Patients can opt out in any reasonable way. Not just by texting STOP. If someone replies "please stop texting me" or tells your front desk to take them off the list, that counts. You cannot force them into one magic keyword.
- You must honor it within ten business days. Once a patient revokes consent, the clock starts. Dragging your feet is the violation.
- Opt outs can cross channels. A revocation given for texts can extend to related automated calls, so a "stop" is not confined to the one message stream it arrived in.
You are still allowed to send a single confirmation message after an opt out to clarify what they want to stop receiving. Beyond that, silence. Some of the broader cross program pieces of the rule were pushed to a later effective date, but do not let that be your excuse. The direction is clear and permanent: make opting out effortless, and act on it fast. A practice that cannot process a "stop" quickly is a practice waiting for a complaint.
Rule two: HIPAA governs what is inside the message
Where the TCPA asks "did they agree to be contacted," HIPAA asks "what health information are you exposing." A text sits on a lock screen, sometimes visible to whoever is near the phone, and travels over carrier networks. So the rule of thumb is simple: keep protected health information out of ordinary texts.
The U.S. Department of Health and Human Services does not forbid texting patients. Its HIPAA guidance allows providers to communicate with patients electronically, as long as reasonable safeguards are in place and, where appropriate, the patient has been warned of the risks and still chooses that channel. In everyday terms, a compliant text looks like this:
"Hi Maria, this is Lakeside Dermatology reminding you of your visit on Tue Aug 5 at 2:30pm. Reply C to confirm or R to reschedule."
Notice what is missing. No diagnosis, no procedure, no test result, no reason for the visit. Just the practice name, the time, and an action. The less clinical detail a text carries, the smaller your HIPAA exposure, which is the same reason the shortest reminders also perform best. If a patient wants to discuss anything sensitive, move them to a secure channel or the phone. And never run patient texting off a staff member's personal cell phone, where there are no safeguards, no records, and no way to prove compliance later.
Putting it together: a quick compliance checklist
Strip away the legalese and legal, effective patient texting comes down to a handful of habits:
- Get consent, in writing, split by purpose. Separate checkboxes for care texts and marketing texts, with a record of each.
- Match the message to the consent. Never send a promotion on a number that only agreed to reminders.
- Make opting out easy and honor it fast. Accept any reasonable opt out and process it within ten business days.
- Keep clinical detail out of the text. Practice name, time, and an action. Nothing sensitive on a lock screen.
- Use a healthcare grade platform, not a personal phone. One that logs consent, handles opt outs automatically, and keeps records.
- Have your attorney review your setup. Rules shift, and a short review beats a big fine.
If you want the practical side of what a good message actually says once you are cleared to send it, we broke that down in what an appointment reminder text should say. And if you are still deciding whether to text at all, our take on whether medical practices should text patients weighs the upside against the effort. There is also a surprisingly common technical trap where your messages never even arrive, which we covered in why patient texts are not delivered.
Where EtherealMinds fits
Most practices do not get into trouble because they are reckless. They get into trouble because texting is bolted together by hand: a number typed into one system, consent scribbled on a form nobody files, a "stop" reply sitting in an inbox for two weeks. The rules are not the hard part. The plumbing is.
That is the part we build. Inside our patient acquisition and communication system, consent is captured at the point a patient hands over their number, marketing and reminder permissions are tracked separately, and opt outs are honored automatically the moment they come in, so nothing slips past the ten day window. New patient numbers flow in from a website built to collect that consent cleanly, and when a patient texts back, our AI receptionist handles the confirm, the reschedule, or the question in the same thread, day or night, without your front desk chasing it. You get the reach texting gives you, on top of the guardrails that keep it legal.
Want to text patients without the legal knot in your stomach?
Book a free strategy call. We will look at how you collect consent, what your texts say, and how opt outs are handled, and show you where the gaps are before they become a problem.
Book a free strategy call →