Your patient portal is a secure inbox that patients log into roughly never. Ask any front-desk staffer how many people actually check it between visits and you'll get a laugh. The rough industry pattern I keep seeing: portal messages sit unread for days — often close to a week — because opening one means remembering a password, digging through a login flow, and choosing to check. A text, by contrast, gets glanced at within a few minutes for most people. That's not a marketing stat; it's just how phones work versus how portals work.

Full disclosure: I work for Ready, an SMS platform. So I'm obviously biased toward "send the text." But the honest answer for a healthcare practice is not "text everything." It's a routing decision — some messages belong in the portal, some belong in a text, and getting the split wrong either buries urgent info or leaks protected health information into an insecure channel. This is a guide to making that call cleanly.

The two variables that decide the channel

Forget gut feel. Route on two axes:

  1. Read latency you need. Does this message need to be seen in minutes, hours, or is "sometime this week" fine?
  2. PHI in the body. Does the actual message text contain protected health information, or can it be written as a content-free nudge?

Everything else — appointment reminders, recall nudges, balance-due notices, lab-result alerts — sorts itself once you answer those two questions for each message type.

MessageRead latency neededPHI in body?Route
Appointment reminderHoursNo (if written right)SMS
Recall nudge ("you're due")Days–hoursNoSMS
Lab results, actual valuesDays OKYesPortal
Diagnosis / treatment detailDays OKYesPortal
Balance-due noticeDaysSometimesPortal or careful SMS
Same-day cancellation / weather closureMinutesNoSMS
"New message in your portal" alertHoursNoSMS (pointing to portal)

The pattern: SMS carries the urgency and the nudge; the portal carries the content. The best flows use SMS as the doorbell and the portal as the room.

What can legally sit in a text body

This is where practices get nervous and either over-restrict (portal everything, tank engagement) or over-share (text the lab value, breach HIPAA). Neither is necessary.

You can text a patient legally and still breach in the message body — the two questions are separate. A text can name an appointment without naming why. The safe pattern is content-free identification:

  • ✅ "Hi Sarah, this is Cedar Dental confirming your visit Tue 3/12 at 2pm. Reply C to confirm or call 555-0100."
  • ✅ "Hi Sarah, it's been a while — you're due for a checkup. Call 555-0100 to book."
  • ❌ "Hi Sarah, your A1C came back at 7.9, let's discuss your diabetes management."

The last one puts a diagnosis and a lab value in an unencrypted SMS. That's the breach. For a fuller list of exactly which fields never belong in the body, we wrote a whole piece on the four fields to never include in a patient text. The short version: no results, no conditions, no medications, no procedure names.

So the routing rule for PHI is simple — if you can't write the message without a clinical detail, it goes to the portal, and you send an SMS that says "you have a new secure message, log in to view."

When the portal is actually the right call

I'm not going to pretend everything should be a text. The portal wins whenever:

  • The message contains PHI you can't strip out. Results, imaging notes, care-plan detail. The portal is the encrypted, authenticated channel built for exactly this.
  • **The patient needs to do something involved** — fill out intake forms, review a treatment estimate, sign a document. Texting a 20-line consent form is absurd; a portal link is right.
  • You want a durable, auditable record the patient acknowledged. Portals log reads and actions in a way SMS doesn't.

The mistake isn't using the portal. It's using the portal as the delivery mechanism for time-sensitive nudges and then wondering why recall response is flat. A "you're overdue for your cleaning" message sitting unread in a portal for six days is a lost appointment.

Use SMS as the portal's doorbell

The highest-leverage move for most practices isn't picking one channel — it's chaining them. Send the PHI-heavy content to the portal, then fire a content-free SMS that drives the login:

"Hi Sarah, you have a new secure message from Cedar Health. Log in at [portal link] to view. Questions? Call 555-0100."

That text contains zero PHI. It just moves the read latency from "six days" to "three minutes" for the notification, while the sensitive content stays behind authentication. You get the speed of SMS and the security of the portal, and you never have to choose.

This is also where consent lines matter. A reminder text and a "book your flu shot" text sit on opposite sides of your consent wall, and a portal-alert text is a treatment communication, not marketing — so it rides on treatment permission, not your marketing opt-in. If that distinction is fuzzy, the piece on recall vs. marketing consent is worth ten minutes.

The two compliance traps that bite even correct routing

Getting the channel right doesn't finish the job. Two things quietly break otherwise-compliant recall flows.

Quiet hours. TCPA restricts messaging to permitted local hours — generally 8am to 9pm in the recipient's timezone. A recall batch scheduled for 9am on your server can hit a patient at 6am if they've moved across the country and their number didn't. On Ready, quiet-hours enforcement holds sends outside the permitted window based on the recipient's area, so a batch queued overnight doesn't fire at 6:40am for a third of your list. If you run multi-timezone panels, the multi-timezone quiet-hours trap walks through exactly how this goes wrong.

Consent decay. The permission a patient gave in 2022 may not cover a 2026 recall — the relationship it was tied to can lapse, and treatment consent for one visit isn't blanket permission to text forever. Ready records opt-in attestation and honors STOP automatically, propagating the opt-out so a patient who unsubscribes can't be messaged again across any campaign. That's the audit trail you want when someone asks who agreed to what and when. For more on how long text permission actually lasts, see the consent window piece.

Neither of these makes you lawsuit-proof — compliance is ultimately the sender's responsibility, and the exposure on a bad text runs $500–$1,500 per message. But quiet-hours holds, automatic STOP handling, and captured attestation remove the most common self-inflicted mistakes.

A quick routing checklist for your team

Print this and tape it to the scheduling monitor:

  1. Does the message contain a clinical detail (result, diagnosis, medication, procedure)? → Portal. Send an SMS alert pointing to it.
  2. Is it a content-free reminder or nudge (confirm, reschedule, you're due)? → SMS.
  3. Does the patient need to complete a form or review a document? → Portal, with an SMS doorbell.
  4. Is it same-day urgent (closure, cancellation)? → SMS, always.
  5. Before any batch send: timezone-aware quiet hours on, opt-out honored, consent current.

If a message passes step 1 as "no PHI," write it as a nudge and text it. The whole point of SMS in a recall flow is speed — burying a due-date reminder in the portal defeats it.

The practical takeaway

Portals aren't broken; they're just slow-read, high-security channels, and treating them like a notification system is why recall numbers sag. SMS isn't a replacement for the portal — it's the fast, unsecured layer that carries urgency and drives patients to the portal when the content needs protection. Route on read latency and PHI, use the text as the doorbell, and let quiet-hours and consent enforcement handle the parts that are easy to get wrong at scale.

If you want to see how the compliance side works in practice — quiet-hours holds, automatic STOP propagation, consent attestation — the SMS product page lays it out, and you can start with 2,500 free credits without a card to test a small recall batch before you commit. Route it right first, then send.