Here's the mistake I see in almost every clinic that starts texting patients: they collect one signature at intake, file it, and treat it as blanket permission to say anything to anyone by text. Then a patient's spouse sees "Your HIV test results are ready" on a shared phone, or a patient who only agreed to appointment reminders gets a "book your Botox special" blast — and the clinic discovers the hard way that it needed two permissions and only had one.
Full disclosure: I work at Ready, an SMS platform that a lot of healthcare practices use. So I have skin in this. But the point of this post isn't to sell you texting — it's to keep you from conflating two legal permissions that live in different statutes, cover different things, and fail independently. Get one and assume both, and you've exposed yourself on two fronts at once.
The two permissions, in plain terms
There are two separate questions every patient text has to answer, and they don't share an answer.
Question one — TCPA: "Am I allowed to send an automated text to this number at all?" The Telephone Consumer Protection Act governs the act of contacting a mobile number with automated messages. It doesn't care what's in the message. It cares whether the recipient agreed to receive texts, and what kind of texts.
Question two — HIPAA: "Am I allowed to put this specific health information in the message body?" HIPAA governs the disclosure of protected health information (PHI). It doesn't care whether the patient wanted a text. It cares whether the content — and the channel it travels over — is a permitted disclosure.
A single intake form checkbox that says "I agree to receive text messages" answers question one for reminders. It answers neither question fully for a message that contains a diagnosis, and it answers nothing about marketing. Three different gates, and clinics routinely walk through all three on one signature.
What TCPA consent actually buys you (and what it doesn't)
TCPA consent is tiered. The level you collected determines the kind of message you can legally send:
| Message type | TCPA consent needed | Example |
|---|---|---|
| Care/treatment (reminders, results-ready, recall) | Prior express consent — the number, given for this purpose | "Your appointment is Tue 3pm. Reply C to confirm." |
| Marketing/promotional | Prior express written consent — a higher bar, clearly for marketing | "20% off teeth whitening this month!" |
The gap most clinics cross: a patient hands you a number to get appointment reminders. That's express consent for treatment-related texts. It is not written consent for promotions. We wrote a whole piece on exactly this line — a recall text and a promo text need different consent — because it's the single most common accidental violation in healthcare SMS.
Notice what TCPA consent does not do: it says nothing about whether "Your HIV test came back positive" is legal to send. That's a HIPAA question, and TCPA consent is silent on it.
What HIPAA authorization actually buys you
HIPAA's treatment/payment/operations (TPO) allowance already lets you contact a patient about their own care without a separate signed authorization — that's why an appointment reminder is fine under HIPAA even without a special form. The catch is the content and the channel.
Two things HIPAA cares about that TCPA never mentions:
- The message body. SMS is not encrypted end to end, and the patient's lock screen, spouse, coworker, or a lost phone are all foreseeable exposures. Even a permitted disclosure has to be the minimum necessary. "Reminder: your appointment is Tuesday at 3" is minimum necessary. "Reminder: your oncology chemo infusion is Tuesday at 3" is not.
- Signed HIPAA authorization is a separate, higher document required when you want to disclose PHI for a purpose outside TPO — most relevantly, marketing. If you're sending a promo that references a condition ("time for your diabetes supply refill — and check out our new glucose monitors!"), you're now stacking a marketing disclosure of PHI, which needs authorization on top of TCPA written consent.
We broke down the specific fields that turn a legal text into a HIPAA breach in the 4 fields to never include in a message body. Worth reading alongside this — it's the "you can text legally and still breach in the body" companion.
The worked example: one message, two failure modes
Say you run a dermatology clinic and want to send this to 3,000 patients:
"Hi [Name], results from your recent skin biopsy are in — and we're running 15% off all cosmetic consults this month. Reply to book."
Walk it through both gates:
- TCPA: These patients gave you numbers at intake for appointment reminders. That's express consent for the "results are in" half. The "15% off cosmetic consults" half is marketing — it needs prior express written consent, which you don't have. Fail one.
- HIPAA: "Results from your skin biopsy" is PHI, sent over an unencrypted channel to a lock screen. Referencing the biopsy inside a message that's partly promotional also drags PHI into a marketing context. Fail two.
One message, sued twice. TCPA statutory damages run $500–$1,500 per text. At 3,000 recipients, the TCPA math alone is a $1.5M–$4.5M exposure ceiling before a single HIPAA penalty stacks on top.
The fix is boring and effective: split it. Send "results are in, please call the office" (treatment, minimum-necessary, TPO-covered) to everyone. Send the cosmetic promo only to the subset who gave written marketing consent, and strip every clinical reference out of the promo body.
How the two permissions fail on different clocks
They don't even expire together. TCPA consent is tied to the number and the relationship; HIPAA authorization for a specific marketing disclosure can be revoked independently, and consent given years ago may not cover what you're sending now. We've got a couple of pieces on the timing traps:
- The consent a patient gave in 2022 may not cover your 2026 recall text — how long text permission actually lasts.
- Patient SMS consent doesn't expire, but the relationship it's tied to does — the re-consent trigger.
The practical takeaway: track what each patient consented to and when, as separate fields, not one master flag. A patient can be TCPA-valid for reminders, TCPA-invalid for marketing, and have revoked a marketing authorization — all at once. Your system needs to represent that.
Where a texting platform helps — and where it can't
A platform can't manufacture consent you never collected, and it can't decide for you whether a message body is minimum-necessary. That judgment is yours. What tooling can do is enforce the boundaries once you've drawn them. Here's what we actually built at Ready for this:
- Automatic STOP/opt-out handling — inbound STOP propagates across campaigns so a patient who opts out can't be re-messaged from a different list. Revocation is a legal event under both regimes; you don't want it depending on someone remembering to update a spreadsheet.
- Quiet-hours enforcement — sends held outside the recipient's permitted local hours, which matters when a recall batch spans time zones. (The 6 PM recall blast that's illegal for a third of your list is a real trap.)
- Consent/attestation capture — an audit trail of who opted in, for what, and when, recorded on bulk and API sends. If you ever have to prove consent existed, "we have a record" beats "we're pretty sure."
- 10DLC registration handled in-app — separate registered campaigns for treatment vs marketing traffic, so the two consent tiers map to two campaigns instead of one blurry one.
One thing to insist on with any vendor: a signed BAA before PHI ever touches the platform. No BAA, and you're limited to messages that contain no PHI at all — we cover exactly which ones in the vendor BAA checklist.
The one-paragraph version to tape to the front desk
TCPA consent decides whether you can text the number and what category (reminder vs promo). HIPAA decides whether the content is a legal disclosure over an unencrypted channel. Collect both, track them as separate fields, and never let a marketing offer share a message with clinical detail. A reminder to a patient who agreed to reminders, with no diagnosis in the body, is clean on both fronts. Anything that adds a promo or adds PHI needs you to re-check both gates before it sends.
If you want a deeper single reference on the whole picture, our healthcare SMS HIPAA guide walks through what you can actually send. And if you're setting up texting and want the compliance tooling to enforce these lines rather than trusting memory, you can look at Ready or start with 2,500 free credits — no card required — and register a treatment campaign and a marketing campaign as two separate things from day one. That separation is the whole game.