Texting is the most effective way to reach patients. Messages get opened within minutes, read at rates email can't touch, and acted on far more often than a voicemail. For appointment reminders, recall, and time-sensitive outreach, SMS isn't just a nice-to-have — it's the channel that actually moves the number. Which is exactly why so many practices rush into it and quietly break two laws at once.
Compliant patient texting isn't hard, but it does require understanding something most practices miss: texting patients is governed by two separate legal regimes, not one. Get either wrong and you're exposed. Here's how the two-law problem works and how to run text marketing that's both effective and compliant.
Most practices know HIPAA applies. Fewer realize the TCPA does too, and that the two are independent.
HIPAA governs the content — the protected health information in your messages. A text that references a patient's appointment, treatment, or condition contains PHI, and HIPAA dictates how that information must be handled and protected.
The TCPA (Telephone Consumer Protection Act) governs the act of texting itself — sending automated messages to someone's phone. It requires consent before you text, and it doesn't care whether the content is medical.
The critical point: a patient's HIPAA authorization does not satisfy the TCPA's consent requirement, and vice versa. They're separate boxes, and you have to check both. A practice that nails HIPAA but ignores TCPA consent is just as exposed as one that does the reverse. This is the single most common mistake in healthcare texting.
The TCPA draws a line between two kinds of messages, and the consent bar is different for each.
Informational / operational texts — appointment reminders, recall for care the patient is already receiving, pre-visit instructions, results-ready notifications — are treated as informational. These require prior express consent, a lower bar typically satisfied when a patient provides their phone number in the context of their care. This covers the bulk of what most practices actually want to send.
Marketing texts — promoting a service the patient isn't already receiving, like texting your medical patients about a new cosmetic offering — require prior express written consent. That's a higher bar: a signed disclosure that names your practice, states the marketing purpose, and isn't bundled into other agreements.
Knowing which category a message falls into determines what consent you need before you send it. When in doubt, treat it as marketing and get written consent.
Beyond getting the consent tier right, a handful of practices keep your texting program on the right side of both laws:
The penalties stack because the laws stack. TCPA violations carry statutory damages of roughly $500 to $1,500 per message — and because texting is done in volume, a careless campaign can generate class-action exposure fast. HIPAA violations pile on top, running from about $100 to $50,000 per violation. A single non-compliant blast to a patient list can turn into a five- or six-figure problem, before you count the reputational damage of mishandling patient privacy.
That's the paradox of SMS: it's the highest-return channel and the highest-risk one, and the difference between those two outcomes is entirely in how you set it up.
Patient Campaign is built so compliant texting is the default, not a legal project. It signs a BAA as a standard part of onboarding and protects PHI by design, satisfying the HIPAA side. And it's designed around the consent and opt-out mechanics the TCPA requires — capturing and documenting consent, honoring STOP requests immediately, and keeping the two-law problem handled behind the scenes. You get the reminders, recall, and reactivation that make SMS the most effective patient channel, running on infrastructure that keeps both HIPAA and TCPA obligations covered instead of leaving them to chance.
Text marketing is the most powerful patient-engagement channel available and the one most likely to get a practice in trouble — because it's governed by two separate laws that most practices treat as one. Satisfy HIPAA on content and the TCPA on consent, match the consent tier to the message, document everything, honor opt-outs instantly, and run it all through a BAA-backed platform. Do that, and texting becomes exactly what it should be: the fastest, most reliable way to keep patients engaged, with none of the exposure that sinks the practices that wing it.
This article is general information, not legal advice; consult qualified counsel for your specific compliance obligations.