nurse, hospital, halloween, doctor, treatment, medic, surgeon, disease, psychiatric hospital, experiments on people, clinic, health care, operation, the medicine, patient, diagnost. HIPAA-Compliant Patient Texting: The Consent and Opt-Out Rules People Miss
Photo by Sunriseforever on Pixabay

Rules

HIPAA-Compliant Patient Texting: The Consent and Opt-Out Rules People Miss

HIPAA compliant patient texting turns on two rulebooks: TCPA consent and the HIPAA Privacy Rule, plus the opt-out records most clinics never keep.

What to take away

  • Two rulebooks cover one patient text. HIPAA governs the health information inside the message; the TCPA governs permission to send it.
  • A compliant disclosure names the sender, the purpose, the opt-out path, and message and data charges.
  • A STOP reply ends marketing texts until the patient opts in again, and the opt-out log has to survive an audit.
  • Consent records must be producible on request, because the sender carries the burden of proof.
  • State law can add requirements, and the stricter rule governs.

A practice that sends appointment reminders is running a marketing channel whether it calls it that or not.

Who holds jurisdiction over patient text messages

The HHS Office for Civil Rights enforces the HIPAA Privacy and Security Rules, which control how protected health information may be used and disclosed. The FCC and the Federal Trade Commission enforce the TCPA, which controls whether you had permission to send the message at all. The HHS Privacy Rule overview lists the permitted uses and disclosures.

State attorneys general can also bring TCPA actions, and several states run health privacy statutes that reach clinics the federal rule already covers. A practice operating in more than one state needs the Healthcare Marketing Compliance picture before fixing message templates, because a state add-on can change the disclosure itself.

What a compliant consent disclosure contains

The disclosure a patient sees before the first text needs five elements.

  1. The sender identity, using the practice name the patient would recognize on a statement.
  2. The purpose, whether appointment reminders, recall notices, or billing follow-up.
  3. The expected frequency, stated as a range rather than a promise.
  4. Opt-out instructions, meaning the word STOP and what follows it.
  5. The statement that message and data rates may apply.

A TCPA consent is not a HIPAA authorization. If the text promotes a service the patient has not received, the Privacy Rule generally requires a separate written authorization describing the specific use and noting that the patient can revoke it. The HHS guidance on patient communications shows where that line falls.

Email works on a different consent model, where opt-out is often enough. The Healthcare Email Marketing Programs guide covers that channel, and the FTC CAN-SPAM compliance guide sets out the email rules for contrast.

Records to keep when patients opt in

Record What it proves How long to keep it
Consent with a date and time Prior express consent under the TCPA Four years minimum, six is safer
Archived disclosure text The exact language the patient agreed to Six years
Opt-out requests The request was honored promptly Six years
Message logs by number Whether a stray text exposed health data Six years

The HIPAA Privacy Rule requires documentation to be kept six years from creation or from the date it was last in effect. The TCPA gives private plaintiffs four years to sue, so an older consent record proves little in court.

  • Consent captured with a timestamp, not just a signature on a form.
  • The exact disclosure language archived with each consent version.
  • Opt-out requests logged where the sending platform reads them.

Texting also changes the front end of Patient Acquisition: the first contact with a new patient now often happens by message rather than by phone call.

What happens when a patient complains

A complaint to the Office for Civil Rights can end in a corrective action plan, outside monitoring, and civil money penalties. A TCPA suit allows statutory damages for every message sent after consent was withdrawn, so exposure scales with volume rather than with any single patient's harm.

A wrong-number text about lab results can start a breach analysis, because the message itself moved health information to someone who was not the patient.

Example: a reminder that reached the wrong phone

A clinic texts a reminder naming a specialist and a medication. The number was reassigned months earlier and now belongs to a stranger. The content is protected health information, so the clinic has to assess the risk and may owe notification under the HHS breach notification requirements. Keeping clinical detail out of the text and asking the patient to log in or call avoids most of this.

Where the rules differ by place

Florida, Oklahoma, and Washington run their own telemarketing statutes that require prior express written consent with content the federal rule does not demand. Washington's My Health My Data Act adds separate consent for consumer health data.

Quiet hours vary as well. The FCC telemarketing window runs from 8 a.m. to 9 p.m. local time where the recipient is, which matters for patients across time zones. State health privacy laws sit on top of HIPAA rather than replacing it, so the stricter standard governs. How much of the channel mix texting should carry is a Healthcare Marketing Strategy decision before it is a legal one.

Common questions

Does a signature on an intake form cover marketing texts? Usually not. General consent to treatment does not meet the TCPA standard for marketing, which requires prior express written consent naming the sender and the message type.

Can we text a number a family member provided? Only the subscriber or customary user of that number can consent. A spouse's number given for a dependent may cover appointment logistics but not promotion.

How quickly must a STOP reply be honored? The TCPA sets no clock. Carrier messaging rules and OCR guidance both push toward same-day processing, and a text sent after a STOP is the easiest violation for a plaintiff to prove.

More in Rules

Latest from Trade Desk