Is texting patients HIPAA- and TCPA-compliant?
Short answer: yes, when it is done right, and it is a real problem when it is not. Two different laws govern texting patients, and they solve two different things. Get both right and patient texting is not just legal, it is expected. This is a plain-English overview, not legal advice, so pair it with your own attorney.
Two laws, two jobs
HIPAA is about privacy: what health information you can put in a message and who can handle it. TCPA is about consent: whether you were allowed to send the text at all. Satisfying one does not satisfy the other. You need both.
HIPAA: keep it minimum-necessary
If a vendor touches patient names, phone numbers, and appointment context on your behalf, they are a Business Associate, and you need a signed Business Associate Agreement (BAA) with them before any patient data changes hands. That is not optional. Any downstream tool that touches the data needs its own BAA too.
Inside the messages, the rule is minimum-necessary. Appointment reminders and booking texts are fine. What is risky is clinical detail: the treatment, the diagnosis, anything that reveals why someone is a patient. A compliant message names the practice and asks the patient to schedule, and stops there. "Hi Jordan, it is time to schedule your visit at [Practice], reply YES or call us" does the job without exposing anything.
TCPA: consent depends on the purpose
TCPA sorts messages by why you are sending them.
- Replying to an inbound inquiry. When a patient calls or fills out a form and gives their number, that is consent to respond about their request. A fast reply to someone who just reached out is the lowest-risk message there is.
- Proactive marketing and reactivation. A "come back and book" text to a dormant patient is marketing, even for an existing patient. That generally requires prior express written consent: a clear, documented opt-in, not buried, that says marketing texts are okay and are not a condition of treatment.
Two more rules matter. Opt-out must be honored by any reasonable means, not just the exact word STOP, and processed quickly. And messages should only go out during the recipient's local daytime hours, roughly 8am to 9pm, which matters because a patient may live in a different time zone than your practice.
What a compliant program looks like
- A signed BAA between your practice and anyone who handles patient data.
- Messages that are minimum-necessary, with no clinical detail.
- Documented consent for marketing and reactivation texts, and a record that inbound leads provided their number.
- A working opt-out that syncs across text, call, and email, honored fast.
- Sending windows set to the patient's time zone.
- Messages that identify the practice they are sent on behalf of.
None of this makes patient texting off-limits. It makes it professional. The practices that get in trouble are the ones that blast a purchased list with no consent and no opt-out, not the ones that reply quickly to their own patients with a clear way to say stop.
How we handle it
Opswell operates as a Business Associate and signs a BAA with your practice. Messages stay minimum-necessary and go out in your voice on your behalf. Consent and opt-outs are captured and honored. We are not a medical or dental provider, we give no medical advice, and the work is administrative follow-up, not clinical care. For your own protection, we recommend your attorney review the consent language and agreements before any live patient texting begins, and we build to that standard on purpose.
Sources: HIPAA Journal on Business Associate Agreements; HIPAA Journal on texting; ActiveProspect on TCPA consent and opt-out. This article is general information, not legal advice.
Related: dental patient follow-up, chiropractic follow-up.