Rules
How California, Washington, and Florida differ on patient consent for outreach texts
Patient consent rules by state diverge sharply: California CMIA, Washington My Health My Data, and Florida statutes each add duties beyond the TCPA federal floor.
What to take away
- Patient consent rules by state are not one rule: the TCPA sets a federal floor, and California, Washington, and Florida each add their own duties on top of it.
- California CMIA requires patient authorization to disclose medical information, and its limits reach marketing and fundraising uses of that data.
- Washington My Health My Data covers health data far beyond HIPAA, including data a patient generates outside a clinic, and it requires consent before collection.
- Florida consent statutes for outreach sit alongside a data breach notification law that sets its own timelines and content rules.
- When two regimes apply to the same text, the stricter rule wins, so a multi-state campaign has to be built to the tightest standard in the set.
- Whatever the state, you cannot prove consent you did not document: capture source, timestamp, scope, and the exact language the patient agreed to.
The TCPA federal floor for text and email outreach
The Telephone Consumer Protection Act is the baseline every healthcare marketer in the United States already answers to. It restricts automated calls and texts to cell phones, and it treats a text message as a call for that purpose.
The Federal Communications Commission explains the robocall and robotext rules, including the prior express consent a caller needs before autodialed or prerecorded outreach. See the FCC's robocall and text rules.
Consent under the TCPA comes in two strengths. Prior express consent covers informational calls and texts. Prior express written consent is the higher bar, and it applies when the message is marketing. A patient who gives a phone number at check-in for appointment reminders has not necessarily agreed to promotional texts.
That distinction matters for a practice group running appointment reminders and service line promotions through one platform. The reminder may sit at the lower tier. The promotion generally does not.
Email is not covered by the TCPA's robocall provisions, but the CAN-SPAM Act applies to commercial email, and state law can add more. A patient portal message is a different channel again, and it usually falls under HIPAA and the platform's own terms rather than the TCPA.
The federal floor also gives patients a revocation right. A patient can withdraw consent at any time by any reasonable means, and the sender has to honor it. That is a floor, not a ceiling, and the three states below raise it.
Where HIPAA fits
HIPAA governs protected health information held by covered entities and their business associates. It does not require consent for treatment, payment, and operations, but marketing uses of PHI generally need written authorization. The HHS regulations at 45 CFR Subtitle A set out the authorization standard and the content it must include.
HIPAA does not preempt stricter state law. Where a state gives patients more control over their health data, the state rule stands. That is the mechanism that makes this a three-state comparison rather than a single federal answer.
California CMIA consent rules and what they add
The Confidentiality of Medical Information Act is California's medical privacy statute, and it is older and in some respects tighter than HIPAA. It limits disclosure of medical information by providers, health plans, and contractors without patient authorization.
The operative text sits in the California Civil Code, and the state publishes the CMIA consent provisions.
For outreach, CMIA adds three things a federal-only program can miss.
First, authorization is a defined instrument. It has to identify the information, who may disclose it, who may receive it, and the purpose. A blanket consent buried in an intake packet is weak evidence for a marketing disclosure.
Second, CMIA restricts use of medical information for marketing without authorization. California also has a separate requirement that a provider who communicates with a patient about a health-related product or service must disclose whether it received compensation for that communication.
Third, CMIA has a private right of action and statutory damages. That changes the risk profile. A TCPA claim is expensive, but a CMIA claim can be brought by the patient directly, and the statute sets nominal damages per violation.
What this means for a text campaign
If a California patient's phone number was collected in a clinical encounter, using it for a promotional text about a service line is a disclosure of medical information for a purpose beyond treatment. That is the fact pattern to test your consent language against.
A practical approach is to separate transactional messaging from promotional messaging at the point of capture, and to keep the authorization record for the promotional stream. Our article on consent and opt-out rules walks through how that split works in practice.
Washington My Health My Data and its reach
Washington's My Health My Data Act is the broadest of the three. It regulates consumer health data, a category that is defined by what the data reveals about a person's health, not by who holds it. Chapter 19.373 RCW is the controlling text, and the state publishes the My Health My Data chapter.
The law reaches entities that are not covered entities under HIPAA. It also reaches data that never touched a medical record: a search on a symptom, a purchase, a location visit, a wearable reading. If a practice group buys audience data or runs a retargeting pixel on a symptom page, that activity can fall inside the statute.
Consent is the core obligation. A regulated entity must get consent before collecting consumer health data, and it must get separate consent before sharing it. Consent has to be collected in a way that is clear and separate from other terms.
There is also a geofencing provision. It restricts using geofences around health facilities to identify or track people for advertising. A marketing team running location-based ads near a clinic in Washington needs to check that rule before launch.
The law gives consumers rights to access and delete their health data, and it allows a private right of action under the state Consumer Protection Act. That is the same enforcement hook that has made the statute a priority for compliance teams nationwide.
Why it reaches out-of-state groups
My Health My Data applies based on the consumer's location, not the company's. A Texas practice group texting a patient who lives in Washington can be covered. So can a national campaign that includes Washington residents in its audience.
That is the practical trap. A compliance program built on HIPAA alone will not see this statute, because it governs data that HIPAA never covered.
Florida consent statutes and data protection obligations
Florida does not have a single comprehensive consumer privacy statute in the style of Washington. It works through a set of sector rules, plus a data breach notification law that applies to health information.
The Florida Information Protection Act, at Chapter 501 Section 171, sets the state's breach notification duties. It requires covered entities to notify affected individuals and the Department of Legal Affairs after a breach of personal information, including medical information and health insurance policy numbers. The Florida Senate publishes the Florida data protection statute.
The statute sets a notice deadline of 30 days after determination of a breach, which is tighter than the 60 days in the HIPAA breach rule. When both apply, the shorter clock governs. That is a concrete example of a stricter state rule winning.
Florida also regulates the use and disclosure of HIV test results and other sensitive categories through separate statutes, with their own consent requirements and confidentiality duties. A general consent form does not satisfy those provisions.
Florida's telephone solicitation rules add another layer. The state maintains its own do-not-call list and restricts certain automated calls, which is why a Florida campaign should be screened against both the federal and state lists.
What Florida adds for outreach
Florida's contribution is less about a single consent instrument and more about breach exposure and sector rules. If your outreach platform stores patient phone numbers and service line interest flags, that data is personal information under the statute.
A breach in that system triggers the 30-day clock, notice content requirements, and potential civil penalties. Vendor contracts and business associate agreements should name who notifies whom, and by when.
Where the stricter rule wins in each state
Stricter rule analysis is the discipline of comparing two applicable regimes and building to the one that gives the patient more control. It is not a legal opinion. It is an operational choice that keeps one campaign from failing in one state.
The table below shows the comparison at a glance. It is a planning aid, not legal advice, and the citations are the authority.
| Issue | TCPA federal floor | California CMIA | Washington MHMD | Florida |
|---|---|---|---|---|
| Consent for promotional text | Prior express written consent | Authorization to use medical information for marketing | Consent to collect, separate consent to share | Federal standard plus state solicitation rules |
| Data in scope | Phone number and calling data | Medical information held by provider or plan | Consumer health data, including outside HIPAA | Personal information including medical data |
| Private right of action | Yes, statutory damages | Yes, statutory damages | Yes, under Consumer Protection Act | Limited, plus regulatory penalties |
| Breach notice clock | Not applicable | State breach law | State breach law | 30 days under 501.171 |
| Geofencing near clinics | Not addressed | Not addressed | Restricted | Not addressed |
Read the table by column. A California patient in a Washington clinic is unusual, but a national campaign touches all three regimes at once, and the campaign has to satisfy each one for the patients it reaches.
In California, CMIA usually wins over the TCPA on the use of medical information, because it adds an authorization requirement and a purpose limitation. In Washington, My Health My Data wins over both, because it captures data the other two do not reach.
In Florida, the breach notification clock is the stricter rule on security incidents, and the state solicitation rules are stricter than the federal floor on calling.
The rule of the stricter standard
When two rules apply, apply the one that gives the patient more control and requires more of you. That single operating rule resolves most multi-state conflicts without a state-by-state policy for every campaign.
It also simplifies vendor management. One consent standard, set to the highest bar, is easier to audit than three parallel ones.
Consent capture and documentation across three states
Consent documentation requirements are where most programs fail an audit. A patient may well have agreed to texts. If you cannot show what they agreed to, when, and through what channel, the agreement is hard to defend.
Build the record around five fields.
- Identity of the consenting patient, matched to the record you will message.
- The exact consent language shown, stored as a versioned text, not a paraphrase.
- The channel and method, such as a signed form, a portal checkbox, or a recorded verbal consent.
- The timestamp with time zone, because Washington and California patients may be in different zones than your server.
- The scope, naming whether the consent covers transactional messages, promotional messages, or both.
Keep the record for the life of the consent plus the applicable limitations period. State statutes and the TCPA have different windows, so the safe practice is to keep the record longer than the shortest one.
A worked example
A practice group runs a flu shot reminder in October and a wellness program promotion in January. The reminder is transactional and the promotion is marketing.
The intake form captures a phone number and a single checkbox that says the patient agrees to receive text messages. That checkbox is enough for the reminder in most states.
It is not enough for the promotion in California, where the marketing use needs authorization, and it is not enough in Washington, where collection of health data needs its own consent.
The fix is a second, separate opt-in for promotional messages, with its own language and its own record. The patient who declines still gets the reminder. The patient who accepts gets both, and the record shows why.
Checklist before launch
- Consent language names the sender and the message types covered.
- Promotional consent is separate from transactional consent.
- Washington patients have a collection consent and a sharing consent on file.
- California marketing uses have a CMIA-style authorization on file.
- The consent record stores version, timestamp, channel, and scope.
- Vendor contracts name breach notification duties and deadlines.
- Opt-out language appears in every message and is honored on receipt.
Our patient outreach metrics healthcare guide covers the wider program, including the parts that sit outside texting.
Opt-out and revocation handling state by state
A patient can revoke consent, and the revocation does not need to use your preferred method. The TCPA honors revocation by any reasonable means, and state law does not narrow that.
California adds a practical wrinkle. If a patient asks you to stop using their medical information for a purpose, CMIA and the state's privacy framework give that request weight beyond the text channel. The opt-out has to propagate to email, direct mail, and any audience list the patient appears on.
Washington gives consumers rights to delete their health data, not just to stop messages. A deletion request is not the same as an opt-out, and the two need separate workflows. Deletion has to reach backups and vendors, not only the live marketing platform.
Florida's do-not-call list is a separate suppression source. A patient who is on the state list should be suppressed from outbound calling campaigns even if they gave consent, unless a specific exemption applies.
How fast is fast enough
The federal standard is to honor a revocation within a reasonable time, and the practical benchmark most compliance teams use is 10 business days or less. For texts, the expectation is closer to immediate, because the message channel is instant.
A revocation received at 9 a.m. should stop a 2 p.m. send. If your platform batches sends daily, the batch needs a suppression refresh before it goes out.
Record the revocation too
Document the revocation the same way you document consent: who, when, how, and what scope. A record that shows a patient opted out on a given date is your defense if a later message is disputed.
That record also matters for the hipaa compliant call tracking examples that regulators and plaintiffs use to show a pattern, rather than a single error.
Building one outreach policy that satisfies all three
One policy can cover California, Washington, and Florida if you set it to the strictest element in each category. That is the whole method: pick the highest bar for consent, the highest bar for data scope, and the shortest clock for breach notice.
Start with scope. Assume the campaign touches consumer health data, because in Washington it may. That assumption pulls in Washington's consent requirements for collection and sharing, and it forces a data map of every system that holds patient contact data.
Then set consent. Use a separate promotional opt-in with versioned language, and add a CMIA-style authorization for California marketing uses. The Washington consent sits alongside it, not instead of it.
Then set the clocks. Use the 30-day Florida breach notice deadline as the internal standard for every state, because it is the shortest. Use 10 business days as the outside limit for opt-out processing, and shorter for text.
Then set the vendors. Every platform that touches patient contact data needs a business associate agreement where HIPAA applies, and a data processing addendum where it does not. The contract should name notification duties, deletion support, and the suppression refresh cadence.
Assign owners and test
A policy without an owner drifts. Name one person for consent capture, one for suppression, and one for vendor contracts. Review the consent language every time a campaign changes what it promotes.
Run a test each quarter. Send a promotional text to an internal number, revoke consent, and confirm the next send stops. Pull one California authorization and one Washington consent record and check that each has all five fields.
Our healthcare marketing compliance guide covers the program structure around this policy, and the pipeda patient reviews healthcare page collects the recurring edge cases that come up when teams try to run one standard across several states.
Where the policy still needs counsel
This article describes statutes and operational practice. It is not legal advice. Consent language, authorization forms, and breach response plans should be reviewed by counsel licensed in each state where you operate, because the analysis turns on facts about your data flows that no general article can supply.
Common questions
Does TCPA consent satisfy California CMIA? No. TCPA consent covers the call or text itself. CMIA adds a separate authorization requirement for using medical information for marketing, and the two records serve different purposes.
Does Washington My Health My Data apply to a practice group outside Washington? It can, because the statute turns on the consumer's location. If your campaign reaches Washington residents, the collection and sharing consent duties can apply to you.
What is the breach notice deadline in Florida? Chapter 501.171 requires notice within 30 days after determination of a breach, which is shorter than the federal HIPAA deadline. Use the shorter clock as your internal standard.
Can a patient revoke consent by replying STOP? Yes. The TCPA honors revocation by any reasonable means, and STOP is the clearest example. The revocation should propagate to every channel, not just texts.
How long should we keep consent records? Keep them for the life of the consent plus the longest applicable limitations period. Storing version, timestamp, channel, and scope makes the record useful years later.
Which state rule wins when two apply? The stricter rule wins in practice. Build the campaign to the standard that gives the patient more control and requires more documentation from you.


