HIPAA-Compliant Marketing

HIPAA-Compliant SMS Marketing: TCPA, A2P 10DLC, and Consent Done Right (2026)

Texting is the highest-performing channel most practices are afraid to use. Patients answer texts they'd never answer as calls — industry-reported open rates above 90%, replies in minutes — and yet the average practice either doesn't text at all or texts in a way that violates two federal laws and three carrier policies at once.

The fear is rational. This is the one marketing channel governed by HIPAA and TCPA simultaneously, plus a carrier-enforced registration regime (A2P 10DLC) that will silently drop your messages if you skip it. And enforcement is no longer hypothetical anywhere in the stack: URMC paid $2.85 million and Froedtert $2 million over marketing-adjacent data handling; Cerebral became the FTC's telehealth cautionary tale; Klaviyo deplatformed telehealth senders for having health data in a marketing tool; and on the TCPA side, plaintiffs' firms run text-to-file pipelines where a single unconsented campaign to 1,000 patients is a $500–$1,500-per-message class action.

Here's the entire compliant stack, layer by layer. It's all doable — practices on our platform send patient texts every day. But every layer is load-bearing.

Layer 1: HIPAA — what a text is allowed to contain, and where it lives

A patient's phone number in your CRM, tied to the fact that they're your patient, is PHI. That drives three requirements:

Your texting vendor needs a BAA. Twilio, and platforms built on it, will sign one; consumer marketing tools mostly won't. No BAA, no patient texting — full stop.

Minimum necessary content. Appointment reminders and care communications are permitted without marketing authorization, but keep condition detail out of the message body. "Reminder: you have an appointment Thursday at 2pm" is fine. "Reminder: your herpes follow-up is Thursday" is a disclosure the moment anyone else sees the phone's lock screen. Promotional texts ("20% off filler this month") made using PHI require prior written HIPAA marketing authorization — this is separate from, and in addition to, TCPA consent.

Storage and access controls. Every message you send and receive is now PHI in your systems. On PilotPractice, message records (like leads, calls, and files) carry field-level encryption in the database, every PHI access lands in an append-only HIPAA audit log, and login/insider-threat analytics watch for abnormal access. If your current texting tool can't tell you who read a patient thread and when, it isn't a healthcare tool.

The Telephone Consumer Protection Act is where the class actions live. The 2026 essentials:

  • Prior express written consent for marketing texts sent with an autodialer/platform. That means a signature or affirmative electronic action, a clear disclosure that they're agreeing to receive marketing texts, and disclosure that consent isn't a condition of purchase or treatment. A phone number scribbled on an intake form is not marketing consent.
  • Informational vs. marketing matters. Appointment reminders to established patients ride on lighter "prior express consent." The moment the message promotes a service, you're in written-consent territory.
  • Revocation got stricter. Under the FCC rules effective April 2025, consumers can revoke consent by any reasonable means — not just the keyword STOP — and you must honor it within 10 business days. "Reply STOP to opt out" is the floor; your system also has to catch "please stop texting me."
  • Quiet hours: 8am–9pm in the recipient's local time. Track it by area code and location, not your office clock.
  • State mini-TCPAs (Florida, Oklahoma, Washington, and a growing list) layer on stricter hours and per-day caps. If you market across state lines, the strictest rule wins.

Layer 3: A2P 10DLC — the registration layer that decides whether your texts deliver at all

This is the part almost every "HIPAA texting" article skips, and it's why compliant-on-paper campaigns die in transit. Since carriers finished enforcing A2P 10DLC (application-to-person messaging on 10-digit long codes), every business texting from a regular local number in the US must be registered — or face filtering, per-message surcharges, and outright blocking.

What registration actually involves:

  1. Brand registration — your legal entity, EIN, and identity verified with The Campaign Registry.
  2. Campaign registration — you declare use cases (appointment reminders, marketing, two-way conversational), sample messages, and your opt-in/opt-out flow. Healthcare campaigns get reviewed against carrier content policies.
  3. Number association — each sending number linked to an approved campaign.
  4. Ongoing conduct — carriers monitor complaint rates and opt-out handling; a bad campaign gets suspended, and re-registration after a suspension is slow.

Common rejection reasons for practices: vague sample messages, no opt-in evidence, a website with no SMS privacy language, and — the classic — a privacy policy that says data is "shared with third parties for marketing," which carriers read as lead-gen spam.

On PilotPractice, 10DLC brand and campaign registration is automated as part of onboarding — we file the brand, build the campaign with healthcare-appropriate use cases and samples, associate the numbers, and handle rejections and resubmissions. Practices routinely arrive with texting "mysteriously not delivering"; unregistered traffic is the cause more than half the time.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Layer 4: Enforcement in the send path — because policy documents don't stop a bad message

A written policy fails at 4:55pm on a Friday when someone bulk-texts a promo. Compliance has to live in the machinery. Ours works like this:

  • Every outbound message passes an automated compliance check before it sends — a per-message job that screens content and context against the rules above, not a quarterly training slide.
  • Opt-out enforcement is systemic. A STOP (or any recognized revocation) doesn't set a flag someone might ignore — the platform hard-blocks future sends to that number. Widget and booking channels capture A2P consent as a structured field at the point of opt-in, so consent evidence is a record, not a memory.
  • Automated/AI replies are deterministically capped — a hard limit of 6 automated messages per 24 hours per contact, with human-in-the-loop escalation, medical/legal guard models screening content, and a fail-closed egress guard. Every automated action is written to a compliance log. An AI assistant that can text patients without those rails is a TCPA lawsuit with a typing indicator.

The 2026 HIPAA + TCPA texting checklist (ungated)

  1. BAA signed with your SMS platform/vendor.
  2. A2P 10DLC brand and campaign registered; every sending number associated; approval confirmed (not "submitted").
  3. Written marketing consent captured with the required disclosures — stored as a timestamped record with source.
  4. Consent language on every collection point (web forms, intake, booking widget) — and the booking flow captures SMS consent as its own checkbox, not bundled into terms.
  5. Marketing and informational messages segmented; promotional sends also covered by HIPAA marketing authorization.
  6. STOP/HELP honored automatically; any reasonable revocation honored within 10 business days; opt-outs enforced at the send layer.
  7. Quiet hours enforced by recipient timezone; state mini-TCPA rules applied.
  8. Message content minimum-necessary: no diagnoses, no treatment detail in reminder texts.
  9. Message history encrypted, access-logged, retained per policy.
  10. Every automated sender (drip, AI, workflow) rate-capped and content-screened before send.

Print it, walk your current vendor through it, and count the "we'll get back to you"s.

How to actually run the channel

Done right, SMS is the best reactivation and speed-to-lead channel in healthcare: new web leads texted within a minute book at multiples of the callback rate; recall campaigns refill hygiene and follow-up schedules; two-way texting clears front-desk phone queues.

The practices doing this well aren't compliance experts — they're using infrastructure where the compliance is built in, with a team running the campaigns. That's the PilotPractice model: registered numbers, consent capture wired into your EHR-integrated booking flow, per-message compliance checks, encrypted and audit-logged message history, and our team writing and managing the campaigns under a BAA. You get the open rates; we carry the rulebook.

Not sure what your website and forms are already leaking? Run the free PHI leak scanner — no email required.

Want patient texting that delivers, converts, and survives an audit? Book a demo — we'll show you the consent flow, the registration status screen, and a live reactivation campaign.


Related: HIPAA-Compliant Marketing Automation · Is Podium / Birdeye HIPAA Compliant? · The 2026 Guide to HIPAA-Compliant Marketing

Security details: trust.pilotpractice.com

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Let’s Discuss Your Growth

Monthly Email Blast Cardiologist Marketing Company Banner
Virtual Patient Coordinator Impact
Client: Just Go Lipo in Scottsdale, AZ
Woman in blue bikini with text 'TOP MIAMI PLASTIC SURGERY CENTER' on dark blue background
Shirtless man with sunglasses at beach with text 'Look Good, Feel Good'
Woman's face showing eye makeup with velyss logo and 'SAY IT WITH YOUR EYES' text
Revive Surgical Institute website homepage showcasing cosmetic and plastic surgery services in Miami with before and after gallery and patient testimonials
Exert Clinic Website
New! Voice AI