Yes, you can text patients, but standard carrier SMS is not automatically HIPAA-safe. You need to separate service messages from marketing, document patient consent and warnings, secure a Business Associate Agreement with any vendor touching protected health information, and satisfy the FCC’s one-to-one consent rule before sending anything promotional.
TL;DR:
- Sending marketing texts without explicit patient consent violates the FCC’s new rule requiring one-to-one, signed, and timestamped opt-in consent for each promotional message.
- Only appointment reminders, billing notices, and similar operational messages are exempt from marketing authorization, though all messages must still follow the minimum necessary standard.
- Most consumer SMS platforms cannot sign a Business Associate Agreement, making them unsuitable for transmitting protected health information securely and legally.
- Implementing encryption, strict access controls, and audit logs are essential safeguards for HIPAA-compliant texting workflows.
- Using templates that direct patients to secure portals and avoiding clinical details in SMS help minimize legal risks and keep messaging compliant.
Table of Contents
- What Counts as HIPAA SMS Marketing vs. a Service Message?
- How the FCC’s One-to-One Consent Rule Changes Marketing Texts
- Technical and Administrative Safeguards for Compliant Texting
- Message Templates That Keep You on the Right Side of the Line
- Vetting an SMS Vendor Before You Send a Single Text
- Keeping Records Straight: Consent, Opt-Outs, and Incident Response
- How Scancompliant Fits Into a Compliant SMS Workflow
- Primary Sources Worth Bookmarking
- The Checklist Nobody’s Selling You
- Sources
What Counts as HIPAA SMS Marketing vs. a Service Message?
HIPAA doesn’t ban texting. It regulates what the text contains and why you’re sending it. A message about an upcoming appointment or a lab result notification is treatment or operations, not marketing, and it doesn’t require patient authorization. The moment a text promotes a product, service, or third-party offer using a patient’s health information, you’ve crossed into marketing that requires signed authorization under 45 CFR 164.508. That authorization has to spell out exactly what protected health information gets used, name who receives it, and explain the patient’s right to revoke it at any time.
The “minimum necessary” standard applies here too: even allowed service messages should share only what’s needed to accomplish the task, not extra clinical detail. This is one of the most common traps compliance teams fall into, treating every outbound text the same way instead of running two distinct tracks with separate rules, logs, and sign-off requirements.
Practical breakdown of what falls where:
- Allowed without authorization: appointment reminders, prescription refill alerts, billing notices, portal login prompts, post-visit instructions.
- Requires marketing authorization: promoting a new service line using a patient’s diagnosis, cross-selling supplements or elective procedures based on visit history, third-party sponsored health content sent to your patient list.
- Gray zone that needs a documented call: wellness newsletters, health education campaigns, and event invitations, depending on whether they reference the individual’s own care.
Document every patient request, preference, or warning about texting directly in the EHR or a dedicated consent log, not in a spreadsheet someone forgets to update.
How the FCC’s One-to-One Consent Rule Changes Marketing Texts
TCPA compliance runs on a separate track from HIPAA, and both apply simultaneously to marketing SMS. HIPAA governs what health information you can share; the Telephone Consumer Protection Act governs how you got permission to text someone in the first place. The FCC’s rule change eliminated blanket “partner consent,” where one signature authorized texts from dozens of affiliated companies. Now marketing texts require prior express written consent tied to one specific sender, not a network of lead-gen partners.
Practical consent-capture steps that satisfy both TCPA and HIPAA when a message is promotional:
- Capture consent through a clear opt-in, checkbox language naming your practice or brand specifically, not a bundled disclosure buried in a longer form.
- Timestamp and store the consent record, including the exact language the patient agreed to and the channel used to collect it.
- Confirm the phone number belongs to the patient who gave consent, rather than a number pulled from an old intake form.
- Build STOP and unsubscribe handling into every marketing send, with automatic suppression across all future campaigns.
- Honor opt-outs immediately. Most legal commentary treats delayed processing as a significant TCPA litigation risk, and courts have not been forgiving of “we’ll get to it next batch” excuses.
HIPAA authorization and TCPA consent are two different documents serving two different laws. Getting a signed marketing authorization does not excuse you from separately collecting TCPA-valid opt-in consent, and vice versa.
Technical and Administrative Safeguards for Compliant Texting
Standard SMS travels the way a postcard does. Anyone with access to the carrier’s infrastructure, a lost phone, or a misdirected message can see it, which is why the HIPAA Security Rule treats encryption as an addressable safeguard your risk analysis has to justify rather than an optional nicety. If your texting platform can’t explain its encryption approach in plain terms, that’s a red flag, not a technicality.
Before texting anything containing PHI, your workflow needs:
- A signed Business Associate Agreement with the SMS vendor, and confirmation the agreement flows down to any subcontractor the vendor uses for delivery or storage.
- Encryption in transit and at rest for any stored message content, consent records, or patient identifiers.
- Role-based access controls so only staff with a legitimate need can view message content or patient phone numbers.
- Audit logs that record who sent what, when, and to whom, retained long enough to support an OCR investigation if one ever comes.
- Number verification procedures that catch stale or reassigned phone numbers before a message goes to the wrong person.
Here’s the part most marketing teams get wrong: most consumer SMS marketing platforms won’t sign a BAA at all. They’re built for retail promo blasts, not regulated health data, and their refusal to sign is itself the disqualifying signal. If a vendor’s sales page never mentions HIPAA compliance and their support team can’t produce a BAA on request within a business day, assume they’re the wrong tool for anything touching PHI.
Pro Tip: Ask a prospective vendor to walk you through their breach notification timeline before you ask about pricing. A vendor who can’t answer in under two minutes probably hasn’t tested the process.
Message Templates That Keep You on the Right Side of the Line
The safest SMS strategy treats text as a notification layer, not a delivery mechanism for clinical detail. Practitioner guidance consistently recommends pointing patients to a secure portal for anything sensitive rather than putting diagnosis, medication names, or treatment specifics into the message body itself.
Safe administrative templates look like this:
- “Reminder: You have an appointment with [Practice Name] on [date] at [time]. Reply C to confirm or call [number] to reschedule.”
- “You have a new secure message waiting in your patient portal. Log in at [portal link] to view it.”
- “Your prescription is ready for pickup at [pharmacy]. Questions? Call [number].”
Marketing copy needs a heavier rewrite pass. Instead of “Your recent A1C results qualify you for our new diabetes management program,” which uses clinical data without authorization, try “We’ve launched a new wellness program. Reply YES to learn more or visit [link].” The second version invites the patient in without referencing their specific health information at all, which sidesteps the marketing authorization requirement entirely.
Red lines, never text these: diagnosis or lab results, medication names or dosages, mental health or substance use details, HIV status, or anything tied to a specific treatment plan. If a message would embarrass a patient shown on a lock screen, it doesn’t belong in SMS.
Vetting an SMS Vendor Before You Send a Single Text
Procurement teams need a short list of pointed questions, not a general “are you HIPAA compliant” checkbox that any sales rep will answer yes to without proof.
- Will you sign a BAA that names our organization directly, and does it flow down to your subcontractors and carriers?
- What encryption standard protects message content and metadata, both in transit and at rest?
- Can you produce audit logs on request, and how long are they retained?
- What is your documented breach notification timeline, and has it ever been tested against a real incident?
- How do you handle number reassignment and verification to avoid texting the wrong person?
Contracts should lock in data location, audit rights, and a specific breach notification window rather than vague “reasonable efforts” language. Once the vendor clears procurement, staff training and role-based access reviews close the loop, covering onboarding, offboarding, and periodic access recertification for anyone who can view patient phone numbers or message content.
Pro Tip: Run a test send to an internal number before launch and pull the audit log immediately after. If the vendor’s logging system can’t show you that single test message within minutes, it won’t hold up during a real OCR audit either.
Keeping Records Straight: Consent, Opt-Outs, and Incident Response
Consent records and patient texting preferences need a permanent, tamper-resistant home, ideally the EHR or a dedicated compliance log that timestamps every entry and can’t be quietly edited after the fact. A verbal “the patient said it’s fine to text her” note scrawled in a chart isn’t documentation; it’s a liability waiting to surface during an audit.
Build these habits into your operational routine:
- Sync opt-out status across every system that sends texts, so a patient who unsubscribes from marketing doesn’t keep getting service reminders through a disconnected platform.
- Run routine deliverability and audit checks to catch bounced numbers, wrong-number reports, and stale consent records before they become a pattern.
- Treat any wrong-number delivery as a potential disclosure event, not a shrug-worthy glitch, and log the review even if it turns out to be nothing.
- Have a written incident response plan that specifies who gets notified, within what timeframe, and how the breach risk gets assessed once a suspected PHI exposure surfaces.
Compliance officers who wait until an OCR inquiry to organize these records almost always find gaps they didn’t know existed.
How Scancompliant Fits Into a Compliant SMS Workflow
Manual review of every marketing text before it ships doesn’t scale once a campaign calendar gets busy, and that’s exactly where mistakes slip through. Scancompliant scans marketing copy, including SMS campaigns, against a database of more than 1,000 risk terms before anything goes out the door, flagging language that edges into implied clinical claims or unauthorized PHI use.
A typical pre-send workflow looks like this:
- Draft the SMS campaign copy in your usual tool.
- Run it through Scancompliant, which flags risky phrasing (a diagnosis reference, an unauthorized health claim, a missing opt-out line) and suggests a compliant rewrite.
- A reviewer signs off inside the platform, creating a timestamped record of who approved what and when.
- The approved copy moves to your texting vendor for send, with the compliance trail archived for later reference.
| What teams need | How the workflow addresses it |
|---|---|
| Catching risky claims before publish | AI scan against 1,000+ risk terms flags marketing copy pre-send |
| Documented compliance trail | Reviewer sign-off timestamped and archived for audit readiness |
| Consistency across campaigns | Same scan standard applied whether it’s SMS, email, or web copy |
Scancompliant has already supported more than 200 health and telehealth brands working through exactly this kind of review cycle. Pairing that scan layer with a signed BAA from your SMS vendor gives compliance and marketing teams a documented, repeatable process instead of a one-off manual check that depends on someone remembering to look closely. Explore the full compliance scanning platform or see how a specialized build handles a tightly regulated category with the GLP-1 marketing compliance scanner.
Primary Sources Worth Bookmarking
Keep these close for audit prep and policy drafting:
- HHS guidance on marketing and patient authorizations, the definitive word on what counts as marketing under HIPAA.
- HHS Security Rule guidance, covering encryption, access control, and audit trail expectations.
- Federal Register notice on the FCC’s one-to-one consent rule, the source text for the TCPA change reshaping marketing consent.
- The FCC’s Report and Order on TCPA text message rules, useful for the technical detail behind the consent rule.
The Checklist Nobody’s Selling You
Most guidance on this topic treats HIPAA and TCPA as separate problems solved by separate vendors, and that’s exactly backward. A texting program that’s HIPAA-airtight but skips one-to-one consent still gets you sued. One that nails consent capture but sends diagnosis codes in plain text still triggers a breach notification. The real work is running both compliance tracks in parallel, with one team owning the intersection.

The most overrated fix in this space is assuming a vendor’s “HIPAA-compliant” badge on their homepage means anything without a signed BAA in hand. The most underrated fix is treating SMS as strictly a notification layer, pointing patients to a portal for anything specific, because that single habit eliminates most of the risk before it starts.
If you’re building or auditing a texting program this year, start with the consent architecture, not the message copy. Get the BAA signed, separate your service and marketing streams in your CRM, and only then start drafting campaigns. Teams that build the guardrails first spend far less time firefighting later.
— Compliant Team
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- HHS — Guidance on marketing and patient authorizations (HIPAA)
- Federal Register / FCC — Targeting and eliminating unlawful text messages (TCPA implementation)
- HHS — HIPAA Security Rule guidance
- Paubox blog — HIPAA-compliant text message campaigns
