regulation and compliance
Texting Patients About Overdue Cleanings: HIPAA and TCPA Rules
Two separate rulebooks govern a recall text: HIPAA decides what the message may say, and the TCPA decides whether you may send it at all. Here is what each one requires of a dental office.
Two Rulebooks: HIPAA Governs Content, the TCPA Governs Consent
Texting patients about overdue cleanings is not just a courtesy. It is an act governed by two main federal regulations: HIPAA and the TCPA. Each sets different expectations. HIPAA, the Health Insurance Portability and Accountability Act, dictates what information may be included in a patient communication and who can see it. The Telephone Consumer Protection Act (TCPA) controls who you can contact by text, when, and what permissions are needed first.
For every hygiene recall message, both sets of rules apply. It does not matter if a message is sent one at a time or in bulk. Even if you hand-type a reminder, HIPAA and the TCPA still cover what you say and how you reach out. Ignoring either rulebook can bring fines, patient complaints, and possible state-level enforcement.
Many dental practices use texting because it is fast and patients respond. But the law does not treat text messages like postcards. What is said, how it gets to the patient, and whether the patient agreed to receive it, all of these are closely watched by regulators.
Keep reading: Replacing Recall Postcards With a Texted Overdue List: A Case
Why Recall and Appointment Texts Count as Treatment Communications
HIPAA splits patient communications into treatment, payment, and healthcare operations. Recall reminders and appointment confirmations fall under the "treatment" category, because they directly relate to care the patient has received or should receive. This is not considered marketing by default. A routine message saying "You are due for a cleaning. Call to schedule an appointment." qualifies as a treatment communication.
This matters because, under HIPAA, treatment communications do not require written authorization from the patient. Regular business conduct covers them. As long as personal health information is handled correctly, you can send reminders about upcoming or overdue cleanings, follow-up appointments, and other direct care needs.
However, once a message contains anything outside this narrow scope, such as promoting a whitening special or a new product, it may slip into marketing territory. That changes the rules, as explained later in this article.
State Variations
Most states mirror the federal distinction, but some add extra layers. For example, a few states require specific consent wording on new patient forms, even for simple reminders. Always check local law before relying only on federal categories.
What Prior Express Consent Looks Like on an Intake Form
The TCPA requires "prior express consent" before a business may text a patient. For dental practices, the intake form is the usual place to obtain it. This consent must be clear, and the patient must provide a valid mobile number. Implied consent, such as the patient giving a phone number without a signature, can be risky if challenged.
A compliant intake form has a statement like: "I authorize [Practice Name] to send me text message reminders about my appointments and care." The patient signs or initials this section. If you collect phone numbers digitally, electronic signatures are valid, as long as the consent is stored and retrievable.
Consent is specific to the type of message. For recall and appointment texts, the language must mention reminders or communications related to treatment. If you wish to send marketing messages later, that requires a separate consent.
Updating and Withdrawing Consent
Patients may change their minds. You must honor a request to stop texts if the patient tells you in person, by phone, or by replying STOP. Document every opt-out. If a patient gives a new number, repeat the consent process.
Keep reading: Where Hygiene Capacity Is Going: Hiring, Pay, and Scope Rules
The Healthcare Message Exemption and the Limits Attached to It
The TCPA offers a healthcare exemption for certain informational texts, including appointment reminders and recall notices. This allows dental practices to send these messages without the written consent otherwise required for marketing texts. However, the exemption is not a free pass. The content, timing, and frequency must still follow strict rules.
The exemption only covers messages that are necessary for the patient's care, such as reminders to schedule a cleaning or follow up on a recent procedure. It does not include messages that cross into sales or promotion. The exemption also requires that practices identify themselves in every message, provide a way to opt out, and keep messages brief and infrequent.
Boundaries of the Exemption
The Federal Communications Commission (FCC) has clarified that healthcare messages under the exemption must be concise, generally one per event, and sent only to the number provided by the patient. You may not send repeated messages in a short period, nor may you text family members or alternate contacts without separate consent. If a patient replies STOP, you must stop immediately, even if the message was exempt.
Opt Out Language, Message Frequency, and Honoring STOP Immediately
Every recall or appointment text must include clear instructions for opting out. "Reply STOP to unsubscribe" is the standard. This is not optional. The TCPA and most messaging carriers require that opt out language appears in the initial message and at reasonable intervals afterward for ongoing campaigns.
If a patient replies STOP, the practice must cease all non-emergency texts to that number right away. There can be no delays or further messages asking the patient to confirm. Automated systems should process opt outs instantly. Manual systems require extra attention, staff must be trained to honor requests the same day.
Message frequency is also limited. The FCC expects healthcare reminders to be infrequent, typically one per recall cycle or upcoming appointment. Daily or weekly texts may look like harassment and invite complaints. Many practices set recall reminders to once every six months, with a single follow-up if the patient does not respond.
Tracking and Documenting Opt Outs
Keep a record of all opt out requests. This protects the practice if there is ever a dispute. Software can automate this, but even a paper log is better than nothing. Never add a number back into a texting list unless the patient gives new consent.
See how ChairGap handles this for dental practices
Minimum Necessary: What Never Belongs in the Body of a Text
HIPAA's "minimum necessary" rule means you may only include information in a text that is required for the purpose of the message. For a recall, this means basic details only: the patient's first name, the practice name, and a neutral reminder to schedule a cleaning. Do not include diagnosis codes, insurance status, or specific treatment details.
Avoid texting anything that would identify the patient's condition or imply sensitive health information. "You are due for your six-month checkup" is sufficient. "Your periodontal disease requires another deep cleaning" is not. Never mention test results, medication, or referrals in a text, even if the patient asks you to.
Do not include financial information, Social Security numbers, or links that require login. If a patient requests details that are too sensitive for text, call them or direct them to your secure patient portal.
Family Members and Shared Phones
Many patients share phones with family. If a message might compromise privacy, choose a more discreet channel. Assume anyone who picks up the device could read the text. Only send recall reminders to the number the patient gave for this purpose, not to numbers on file for other contacts.
Business Associate Agreements With a Messaging Vendor
If you use any third-party service to send texts containing protected health information, HIPAA requires a Business Associate Agreement (BAA) with the vendor. This contract spells out how your vendor will safeguard patient data, limit use and disclosure, and report breaches. Without a BAA, your practice is exposed to liability if the vendor mishandles information.
Many popular texting platforms are not HIPAA compliant by default. Always ask the vendor if they will sign a BAA. If not, do not send patient information through their system. Some health-specific vendors build HIPAA compliance into their platform and offer a standard BAA as part of the contract. Review the document before signing, and make sure it covers text messaging specifically.
Keep a signed BAA on file for every platform that accesses your patient list, whether for bulk reminders or one-off texts. If you change vendors, archive the old agreement and review security practices during the transition.
Staff Training and Platform Audits
Staff must know which platforms are approved and which are not. Regularly audit your vendor list and communications channels. Remove any app or service that is not covered by a current BAA. If your staff uses personal phones for texts, use a secure app with audit trails and remote wipe capability.
Where Marketing Begins and Authorization Becomes Required
The line between treatment communications and marketing is not always clear. Under HIPAA, a message is marketing if it encourages patients to buy or use a product or service that is not part of their current care. For example, if you text "Schedule your overdue cleaning," this is a treatment reminder. If you text "Get 10 percent off our new whitening package," this is marketing, even if sent to an existing patient.
Marketing messages require written authorization from the patient, separate from the consent for recall and appointment reminders. The authorization must describe the specific message content, who is sending it, and who will see the patient's information. You may not condition treatment on receiving marketing texts. Patients must be free to decline without penalty.
Combining recall reminders with promotional language is a common mistake. Do not add coupons, endorsements, or links to commercial products to your hygiene recall texts. If you want to send promotions, get explicit written authorization first, and keep it on file. Honor opt outs immediately for all marketing texts as well.
Enforcement Examples and Practical Steps
Regulators have fined practices for blurring the line between reminders and promotions. Protect your practice by keeping recall texts neutral and strictly related to care needs. Train staff to recognize the difference, and review all text templates before sending. If in doubt, leave the promotional content out of the recall message.
Dental practices must balance patient engagement with regulatory demands. HIPAA and the TCPA both expect careful consent management, secure platforms, and disciplined messaging. For most small offices, the burden is in the details: tracking opt outs, storing consents, and keeping texts brief and private. A tool that manages the overdue hygiene recall list, sends HIPAA-compliant texts with one tap, and fills same-week gaps, while honoring all consent and opt out rules, removes much of the risk and workload for independent practices.