A patient came in during the summer of 2022, checked the "yes, you can text me" box on the intake form, got their crown done, and never came back. Four years later, your front desk runs an annual recall campaign, pulls everyone with a text-consent flag, and blasts "You're overdue for a cleaning — book here." That patient is on the list.
Is that text still legal? The honest answer is: it depends on more than the checkbox. Consent doesn't come with a printed expiration date, but the relationship it was attached to does erode, and a stale list is exactly the kind of thing that turns a routine recall into a TCPA exposure problem.
Full disclosure: I work for Ready, an SMS platform used by a lot of clinics and practices. So I have skin in this. But this is a problem you have to solve regardless of who you send through, and the mechanics matter more than the vendor.
Does SMS consent technically expire?
There is no federal rule that says "SMS consent is void after 18 months." The FCC and TCPA framework doesn't put a hard clock on it. If a patient gave clear, documented consent to receive texts, that consent stays valid until the patient revokes it (an opt-out) or until the basis for it changes materially.
That last part is where clinics get sloppy. Consent isn't an abstract permission floating in a database — it's tied to a specific relationship and a specific scope of messaging. When both of those drift far enough from what the patient agreed to, the checkbox stops doing the work you think it's doing.
We wrote a longer piece on this exact distinction: patient SMS consent doesn't expire — but the relationship it's tied to does. The short version: the paper doesn't rot. The context does.
Why an aged patient list is not the same as a consented list
Here's the problem with pulling "everyone who ever checked the box":
- Numbers reassign. Wireless numbers get recycled. A number that belonged to your patient in 2022 might belong to a stranger in 2026. Texting that stranger a "you're overdue" message is a cold text to someone who never consented to anything.
- The relationship lapsed. Someone who hasn't been a patient in four years may not consider themselves your patient at all. A recall to a genuinely active patient reads as a service. The same text to someone who moved practices two years ago reads as marketing spam — and they're far more likely to file a complaint.
- Scope crept. The 2022 consent may have covered appointment reminders. Your 2026 recall is closer to marketing. Those are not the same permission, and mixing them is the line clinics cross most often. We broke that down in a recall text and a promo text need different consent.
None of these are hypotheticals. A single TCPA complaint runs $500 to $1,500 per text in statutory damages. Send a recall blast to 3,000 stale contacts and even a handful of bad numbers is real money.
The re-permission pass: what it is and when to run one
A re-permission pass (or re-consent pass) is a deliberate campaign to confirm that the people on an aged list still want to hear from you — before you resume normal recall sending. Run one when:
- The list has been dormant for 12+ months with no two-way engagement.
- You're changing the type of message (from reminders to recalls, or recalls to wellness offers).
- You inherited the list from a prior system, practice acquisition, or vendor migration and can't verify the original opt-in.
The mechanics are simple. You send one clean message to the aged segment that restates who you are, why you have their number, and gives them an obvious way to confirm or leave. Something like:
"Hi [Name], it's Riverside Dental. You asked us to text appointment and recall reminders back when you were a patient. Still want these? Reply YES to keep them, STOP to opt out. Msg&data rates may apply."
Anyone who replies YES has fresh, dated, documented consent. Anyone who replies STOP is suppressed automatically. Anyone who doesn't respond stays out of your recall blasts until they re-engage — you treat silence as "not confirmed," not "still opted in."
That's the conservative posture, and it's the right one for a list you can't vouch for.
What defensible documentation actually looks like
If you ever have to defend a send, "we think they opted in years ago" is not a record. This is what a defensible trail includes:
| Field | Why it matters |
|---|---|
| Timestamp of opt-in | Proves when consent was given |
| Source of consent | Intake form, keyword reply, checkbox — shows how |
| Exact language shown | Proves what the patient actually agreed to receive |
| Scope of consent | Reminders vs. recalls vs. marketing — the categories aren't interchangeable |
| Opt-out events | Every STOP, with timestamp, so you can prove suppression |
| Re-consent events | Fresh YES replies, dated, replacing the stale record |
The re-permission pass is valuable precisely because it creates a new row in that table. A 2026-dated "Reply YES" tied to a specific message beats a 2022 checkbox you can barely reconstruct.
On the platform side, this is where a few of Ready's compliance features earn their keep:
- Automatic STOP/opt-out handling. When someone replies STOP to your re-permission text, the opt-out propagates so they can't be messaged again across any of your campaigns — you don't have to manually scrub them.
- Consent / attestation capture. Opt-in attestation is recorded for bulk and API sends, so the audit trail builds itself rather than living in someone's spreadsheet.
- Quiet-hours enforcement. Sends are held outside permitted local hours based on the recipient's area — which matters a lot for recall batches, since your evening blast is illegal for the third of your list in a different timezone. (More on that trap here.)
I'll be honest about the limit: none of this makes you lawsuit-proof. Compliance is ultimately the sender's responsibility. What these features do is reduce risk and make good practice the default instead of something your front desk has to remember.
Scrub the aged list before you re-permission it
Before the re-permission pass even goes out, an old list should get scrubbed — because the stalest lists have the highest share of reassigned and litigator-associated numbers.
Ready's TCPA & DNC litigator scrub runs at $0.005 per contact and checks each number against known TCPA-litigator lists and DNC-complainer lists, auto-suppressing matches before send. Do the math against the downside: scrubbing 5,000 aged contacts costs $25. One complaint from a litigator you could have screened out costs $500 to $1,500. That's not a close call.
We laid out that trade in more detail in scrubbing 100,000 contacts costs $500 — one TCPA complaint costs $500 to $1,500 per text, and there's a source-based schedule for how often to re-scrub in a list bought six months ago needs scrubbing 3x more often. Bought or inherited lists are the worst offenders; a list you grew yourself and message regularly decays slower.
A practical sequence for your next annual recall
If you're staring at a recall list right now, run it in this order:
- Segment by recency. Active patients (messaged or seen in the last ~12 months) can get the normal recall. Dormant contacts go into the re-permission bucket.
- Scrub the dormant bucket for litigators and DNC complainers.
- Send the re-permission text to what survives — one clean confirm-or-leave message.
- Move only the YES replies into your active recall flow, with fresh dated consent.
- Suppress the silent and the STOPs. Don't keep re-blasting non-responders.
- Keep the records. Timestamps, language, scope, and every opt-out.
Yes, this shrinks your sendable list. That's the point. A smaller list of confirmed, recent opt-ins outperforms a bloated one full of strangers and complainers — and it costs less to send, since you're not paying per segment to text people who moved on years ago.
The takeaway
Consent doesn't expire on a fixed date, but the relationship and scope it rests on absolutely decay — and a four-year-old checkbox on a dormant contact is thin ground to stand on. The fix isn't complicated: segment by recency, scrub the aged portion, run a re-permission pass, and keep a documented trail of the fresh consent you collect.
If you want to see how the STOP handling, quiet-hours enforcement, and scrub tooling fit together before your next recall, take a look at Ready or start with the 2,500 free credits and run a small re-permission test on your oldest segment first. That's the cheapest way to find out how much of your "consented" list is actually still yours to text.