Legal
Texting patients: the TCPA and HIPAA rules for a telehealth brand's messages
September 28, 2026 · 10 min read
A telehealth brand sends two kinds of text messages, and the TCPA healthcare texting rules treat them as different things. A message that tells a patient their medication shipped, or that a provider has a question about their intake, is a treatment communication. A message that offers a discount on a second program, or asks a lapsed subscriber to come back, is marketing. The federal Telephone Consumer Protection Act sets a different consent bar for each, and HIPAA governs what the treatment message may contain. Brands get into trouble when the two kinds of message come from the same sender, under the same consent checkbox, with the same content rules. The fix is to separate them at three points: who consented to what, which entity is sending, and what goes in the body.
Two laws, two questions
The TCPA is a federal statute, enforced by the FCC and by private lawsuits, that restricts calls and texts made with an automatic telephone dialing system or an artificial or prerecorded voice. Its rules are in 47 CFR 64.1200. It asks one question of every message: did the recipient give the kind of consent this message requires? The answer depends on whether the message is an advertisement or telemarketing, which the regulation defines broadly. An advertisement is "any material advertising the commercial availability or quality of any property, goods, or services," and telemarketing is a call or message "for the purpose of encouraging the purchase or rental of, or investment in, property, goods, or services." A text that does either of those things needs the higher consent tier.
HIPAA asks a different question: is the sender a covered entity or its business associate, and is the message a permitted use of protected health information? The medical practice, the friendly professional corporation that employs or contracts the providers, is a covered entity. The brand's management company, the MSO, is its business associate when it handles patient information on the practice's behalf, under a signed business associate agreement. HIPAA does not ban texting. It requires the practice to have assessed the risk of sending PHI over an unencrypted channel, to send the minimum necessary, and to get a signed authorization before PHI is used for marketing.
The two laws overlap on one useful point. The TCPA carves out messages that deliver a health care message made by or on behalf of a HIPAA covered entity, which is exactly the practice's treatment texting. So the treatment side of the program is lighter under both laws, and the marketing side is heavier under both.
Treatment texts need prior express consent
For messages that are not advertising, the TCPA requires prior express consent from the person receiving them. The FCC has treated a patient giving a phone number to a healthcare provider as consent to receive messages related to that care at that number. A patient who enters a mobile number at intake and is told the practice will text about their treatment has consented to treatment texts. The number has to come from the patient, and the messages have to stay within the scope of what the patient was told.
The regulation goes further for messages to mobile numbers from healthcare providers. Paragraph (a)(9)(iv) of 47 CFR 64.1200 exempts provider messages from the consent requirement altogether when a set of conditions is met: the message goes only to a number the patient provided; it identifies the provider and gives contact information at the start; its content is limited to a listed set of purposes, including appointment confirmations, wellness checkups, pre-registration, pre-operative instructions, lab results, post-discharge follow-up, prescription notifications and home healthcare instructions; it complies with HIPAA; it is short; the sender sends no more than one per day and three per week to a given patient; and each message offers a way to opt out, with a STOP reply honored immediately. The exemption does not cover a message that mentions a price, a promotion or a product the patient has not been prescribed. Most practices collect consent at intake and do not need to rely on it, but it is a good template for the treatment channel: identify the practice, say something the patient's care requires, keep it short, and give them a way out.
Marketing texts need written consent
For an advertisement or telemarketing message sent with an autodialer or a prerecorded voice, the TCPA requires prior express written consent. The regulation defines it at 47 CFR 64.1200(f)(9) as "an agreement, in writing, bearing the signature of the person called that clearly authorizes the seller to deliver or cause to be delivered to the person called advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice, and the telephone number to which the signatory authorizes such advertisements or telemarketing messages to be delivered." An electronic signature counts. A pre-checked box does not, and consent buried in terms of service does not, because the agreement has to clearly authorize the marketing and the recipient has to have been told that consent is not a condition of purchase.
In practice that means a separate, unchecked box at the point where the phone number is collected, with its own disclosure text: that the person agrees to receive recurring automated marketing texts from the brand at the number provided, that consent is not a condition of any purchase, that message and data rates may apply, and how to stop. Keep the record: the timestamp, the IP address, the exact disclosure text shown, and the number. In a TCPA suit, the defense is the consent record, and a brand that cannot produce one for a given number has no defense for the messages sent to it.
Vendors will sometimes tell a brand that their texting system does not count as an automatic telephone dialing system. That question is litigated, the outcome turns on the platform's mechanics, and several states have their own texting statutes with broader definitions, so no brand should build a consent program on the hope that its sender is out of scope. Collect written consent for anything that could be read as marketing.
A message that tells a patient their medication shipped and a message that offers them a discount on a second program are legally different messages, and they should not come from the same sender under the same consent.
What HIPAA lets a text say
A treatment text from the practice may contain PHI, because treatment is a permitted use, but the Security Rule requires the practice to have thought about the channel. SMS is not encrypted and shows up on a lock screen. The standard approach is to treat the text as a notification that points the patient into the portal rather than as the record itself. "Your provider has a message for you in the portal" carries almost nothing. "Your semaglutide 0.5 mg has shipped and your next dose increase is due on the 12th" carries the drug, the dose and the condition. Both may be lawful if the patient was told about the risk and agreed to receive detail by text. The safer default is the first form, with the detail one tap away behind authentication, and a per-patient setting for anyone who explicitly asks for more in the text itself.
The minimum-necessary principle applies to each message: include what the patient needs to act on and nothing else. It also applies to who can see the messages on the sending side. Treatment texts should originate from the clinical platform, keyed to the prescription, the shipment or the provider's note, and the log of those messages is part of the record. Marketing staff and any agency the brand uses should not have access to that log.
Marketing under HIPAA is a separate matter from marketing under the TCPA. The Privacy Rule defines marketing as a communication about a product or service that encourages the recipient to buy or use it, and it requires the patient's written authorization before PHI is used to make one, with exceptions that matter for a telehealth practice: communications about the patient's own treatment, communications describing the practice's own health-related services, and refill reminders, provided that any payment the practice receives for making the communication is limited to its cost. A practice cannot take payment from a pharmaceutical company to text its patients about a drug without authorization. A brand cannot use the practice's patient list to text about a new program unless the message falls inside one of the exceptions or the patient authorized it. The HIPAA obligations guide covers where the MSO's marketing data ends and the practice's PHI begins.
Refill reminders: treatment or marketing
A refill reminder is the message that lands on the line, and the answer depends on what it says and who benefits. Under HIPAA, a reminder that the patient's current prescription is due for a refill is treatment, and a reminder about a drug the patient is currently prescribed is excluded from the definition of marketing so long as the practice is not paid beyond its cost to send it. Under the TCPA, a prescription notification is one of the listed healthcare purposes, and a reminder that says "your refill is ready, reply Y to confirm" is a healthcare message from a covered entity, which the regulation exempts from the written consent requirement.
The same reminder becomes marketing the moment it adds a commercial element. "Your refill is ready, and this month you can add a second program for 20% off" is an advertisement under the TCPA definition, whatever else it contains, and the second half of the message is a use of PHI for marketing under HIPAA, because the practice's knowledge that this patient is on a refill cycle is what triggered it. That message needs written TCPA consent and, if it comes from the practice, either a HIPAA exception or an authorization. The clean design is to keep the two apart: the practice sends the refill reminder, and the brand sends the promotion, to people who signed up for promotions, without using the refill event to decide who gets it.
A subscription telehealth business runs on a refill cycle, and every touch in that cycle is retention work, as the post on moving from visits to recurring care argues. Those touches are treatment messages: dose check-ins, lab reminders, refill confirmations, a provider's question. They belong in the clinical platform and should never be handed to a marketing tool that could append an offer. On Tessic Health's platform the retention automation on the Grow tier and above sends these messages from the clinical side, tied to the prescription and the shipment, which is what keeps them inside the treatment category; a brand assembling its own tools has to draw the same line by hand.
Opt-outs, and what a violation costs
The TCPA's revocation rule, at 47 CFR 64.1200(a)(10), says a consumer may revoke consent by any reasonable means, and it lists examples: an automated opt-out mechanism on a call, the words "stop," "quit," "end," "revoke," "opt out," "cancel" or "unsubscribe" in reply to a text, or a website or phone number the sender designates for opt-outs. The sender must honor the request within a reasonable time not to exceed ten business days of receiving it. A brand's texting platform should recognize all of those words, not just STOP, and should apply the opt-out to the right scope: a patient who replies STOP to a promotion has revoked marketing consent, and that has to propagate to the marketing list immediately. Whether it also stops treatment texts is a design decision the brand should make deliberately, tell the patient about, and apply consistently; the safe reading is that a STOP to a treatment message stops treatment texts and the practice falls back to the portal and email.
The cost of getting it wrong is set by statute. Under 47 U.S.C. 227(b)(3), a person who receives a message in violation of the autodialer and prerecorded-voice rules may recover actual damages or $500 per violation, whichever is greater, and a court may triple that to $1,500 per violation if it finds the violation was willful or knowing. Each message is a violation. A marketing sequence of five texts sent to ten thousand numbers without written consent is fifty thousand violations, and class counsel can do that arithmetic faster than the brand can. There is no cap in the statute, and the fact that a number was on the brand's list because the person was once a patient is not a defense to the marketing count.
Questions operators ask
Can one consent form cover both kinds of text? A single form can contain both consents, but they have to be separate elements: an unchecked marketing box with its own disclosure, and a treatment consent that is part of the intake and telehealth consent. Bundling them into one checkbox makes the marketing consent unenforceable and, if consent is presented as a condition of treatment, may make both unusable.
Who should the sender name be? The practice's name on treatment texts and the brand's name on marketing texts; in a white-label setup the treatment text can carry both. The patient should be able to tell which kind of message they are looking at, and the sending numbers should be distinct so that an opt-out on one does not silently take out the other.
What about texting people who started intake but never became patients? They are leads, not patients, and the practice has no treatment relationship with them, so there is no treatment consent to rely on. An abandoned-intake text that encourages them to finish and buy is marketing and needs written consent collected before the number was submitted.
KEEP READING