Texting patients: what is and is not allowed

HIPAA does not prohibit texting patients. It requires safeguards. The rule that actually generates claims against clinics is the Telephone Consumer Protection Act, and it has a trap in it that most aesthetics operators walk straight into.

The TCPA rules carve out health care messages. Under 47 CFR § 64.1200(a)(2), consent is not required in the same way for “a call that delivers a ‘health care’ message made by, or on behalf of, a ‘covered entity’ or its ‘business associate,’ as those terms are defined in the HIPAA Privacy Rule, 45 CFR 160.103.”

Read where that definition points. The exemption is keyed to being a HIPAA covered entity. A cash-pay clinic that bills no insurer frequently is not one, as we set out in HIPAA for med spas. If that is you, the health care message exemption is not yours, and your appointment reminders sit in ordinary TCPA territory.

Three buckets, and only one is comfortable

Message If you are a covered entity If you are not
Appointment reminder, post-care instruction Health care message treatment available Ordinary TCPA rules, consent matters
“Book your next treatment, 20% off” Marketing. Exemption does not reach it Marketing. Consent required
Anything sent by an automated system to a mobile number Consent analysis regardless Consent analysis regardless

The second row is the one that matters commercially. A promotional text is not a health care message, and no clinic’s status changes that. Clinics routinely assume that because the recipient is their patient, the promotional text is clinical communication. It is advertising delivered to a mobile number.

What HIPAA does ask, where it applies

Where you are a covered entity, texting is permitted with reasonable safeguards rather than forbidden. In practice:

  • Minimum necessary. A reminder does not need the treatment name in it. “Your appointment is Thursday at 2” carries less than “Your filler follow-up is Thursday.”
  • Verify the number. Texting a reassigned or mistyped number is a disclosure, and it is the most common small breach in a clinic.
  • The platform is a vendor. A messaging service handling patient information on your behalf is a business associate, and the duty does not end at signature. See who in your stack needs an agreement.
  • Retention. Those messages are records. Decide where they live and for how long, rather than leaving them on a device.

What the TCPA asks, everywhere

  1. Consent, captured and provable. Not “we have their number because they are a patient.” Written, specific to text messaging, with a record of when and how it was given.
  2. Separate consent for marketing. Consent to receive appointment reminders is not consent to receive promotions. Capture them separately or you will be arguing about scope later.
  3. Honor opt-outs immediately and permanently. Across systems. A patient who opts out of the marketing platform and keeps receiving texts from the booking system has an unhonored opt-out.
  4. Mind the automation. How the message is generated affects the analysis, and most clinic tooling is automated by definition.
  5. Keep the records. Consent is a defense only if you can produce it.

The two failure patterns we see

The shared list. One list, used for reminders and for promotions, built from everyone who ever gave a phone number. It works until the first complaint, and then there is no way to show what any individual consented to.

The platform migration. This is worth weighing when you choose the platform rather than after. The clinic changes booking or marketing systems and the opt-out flags do not come across. Patients who unsubscribed two years ago start receiving messages again, which is both the clearest violation and the easiest one to prove from the outside.

What this means for you

Settle your covered entity status first, because it decides whether the health care message exemption is even available to you, and most cash-pay clinics will not like the answer. Then split your lists: clinical communication and marketing, with separately captured consent for each, and an opt-out that propagates everywhere within the hour. Put the consent record in the chart or the CRM where it can be produced, since an unprovable consent is no consent. And before any platform migration, make the opt-out flags a checklist item on the cutover, because that is where the clean record usually dies.

Frequently asked questions

Can I text patients under HIPAA?

Yes, where HIPAA applies to you. It requires reasonable safeguards rather than prohibiting texting: send the minimum necessary, verify the number, treat the messaging platform as a business associate, and retain the messages as records.

Does the TCPA health care exemption cover my appointment reminders?

Only if you are a HIPAA covered entity or its business associate. 47 CFR § 64.1200(a)(2) defines the exemption by reference to those terms as used in 45 CFR 160.103, so a cash-pay clinic outside the HIPAA definition does not get it.

Can I send promotional texts to existing patients?

Not on the strength of the health care exemption, which does not reach marketing. Promotional messages require consent for marketing specifically, captured separately from any consent to receive clinical or appointment messages.

Is consent to appointment reminders also consent to marketing?

No. Treat them as separate permissions, captured separately, with separate records. Clinics that run one combined list cannot later show what any individual agreed to receive.

What happens to opt-outs when I change platforms?

They have to be migrated deliberately, and frequently are not. Patients who unsubscribed reappearing on a new system is a common and easily proven violation, so make opt-out flags an explicit item on any cutover checklist.


This is general information, not legal advice. Rules vary by state and change. Confirm your own facts with counsel.

Share this article with a friend

Reviewed by Victor D. Cruz, MD, founder of MDside, licensed in Florida (ME117105) and New York. Last reviewed 2026-09-20.