KLYR Media Logo
HomeBlogU.S. Clinics: 7 Step HIPAA SMS Marketing Plan That Clears TCPA & 10DLC
Healthcare Marketing
September 16, 2026
11 min read

U.S. Clinics: 7 Step HIPAA SMS Marketing Plan That Clears TCPA & 10DLC

A U.S. clinic playbook: a 7 step HIPAA SMS marketing plan tying 45 CFR 164.508 to TCPA and A2P 10DLC, with templates, vendor diligence questions, and an...

U.S. Clinics: 7 Step HIPAA SMS Marketing Plan That Clears TCPA & 10DLC

U.S. Clinics: 7 Step HIPAA SMS Marketing Plan That Clears TCPA & 10DLC

Clinic coordinator drafting compliant patient text

Yes, you can run HIPAA SMS marketing programs, but only inside a narrow lane: any text that uses protected health information to promote a product or service needs written HIPAA authorization, plus separate TCPA consent, plus carrier registration through A2P 10DLC. Treatment and operations texts (appointment reminders, refill alerts) don’t need that authorization. Before you send another promotional blast, pause bulk marketing sends, confirm your vendor will sign a Business Associate Agreement, and run a short risk analysis on your texting workflow.


TL;DR:

  • Sending promotional texts using protected health information requires explicit HIPAA authorization, separate TCPA consent, and carrier registration through A2P 10DLC.
  • Standard SMS lacks encryption and audit trails, so sensitive content must be routed through secure messaging apps or patient portals to remain compliant.
  • Vendors must sign a Business Associate Agreement, ensure data encryption, maintain audit logs, and support remote device management to meet HIPAA security standards.
  • TCPA mandates prior express written consent for marketing texts, while A2P 10DLC registration is essential to prevent filtering or blocking of messages by carriers.
  • Automating consent capture, revocations, and compliance documentation is crucial for ongoing SMS marketing compliance and readiness for audits.

Klyrmedia
Build A Compliant Healthcare Marketing System
Klyrmedia helps healthcare providers combine HIPAA-compliant websites, local SEO, and marketing automation into a tailored digital strategy.

Table of Contents

What HIPAA Requires for SMS Marketing Programs

The Privacy Rule doesn’t ban marketing texts. It draws a hard line between communications that promote a product or service and those tied to treatment or operations. Send a refill reminder and you’re on safe ground. Send a text nudging a patient toward a cosmetic procedure or a new supplement line using their diagnosis history, and you’ve crossed into marketing territory, which triggers 45 CFR 164.508.

That authorization can’t be a checkbox buried in your new-patient paperwork. It has to spell out specifics: what information gets used, who’s using it, what it’s for, and an expiration. If a pharmaceutical company or device maker is paying you to send that message, the authorization must disclose that remuneration in plain language.

Here’s the trap most clinics fall into: pulling a patient list segmented by diagnosis or medication, then texting that segment a promotional offer. That’s PHI driving a marketing decision, and it needs authorization even if the message itself sounds harmless.

A valid HIPAA marketing authorization generally needs:

  • A specific, meaningful description of the information being used (not a blanket “your health data”)
  • The name of who’s authorized to send and receive
  • A clear expiration date or event
  • Disclosure of third-party remuneration, when it applies
  • The patient’s signature and date

One narrow exception exists: patients can ask you to text them through unencrypted channels after you’ve warned them of the risk, but that’s a convenience carve-out for patient-initiated requests, not a green light for broad unsecured marketing.

Store every authorization where you can pull it fast. Most EHRs let you tag a consent field with a timestamp and expiration; if yours doesn’t, a CRM note with the same metadata works, as long as it’s auditable.

Why Standard SMS Fails Your Compliance Requirements

Regular carrier SMS wasn’t built for healthcare. It has no end-to-end encryption, no reliable audit trail, and no way to enforce who can view a message after it lands on a patient’s lock screen. The Security Rule treats texting like any other electronic transmission, which means access control and transmission security apply whether you’re emailing or texting. Standard SMS usually can’t meet that bar on its own.

That’s why most compliant programs route sensitive content through secure messaging apps or push a patient to a portal link instead of putting details in the text body itself. The message becomes the doorbell, not the delivery.

Before you approve any texting vendor, get answers on these points:

  • Will they sign a Business Associate Agreement, in writing, before any PHI touches their system?
  • Is data encrypted both in transit and at rest?
  • Do they maintain audit logs you can pull during an OCR inquiry?
  • Is access role based, so front-desk staff can’t see clinical notes?
  • Does the platform support MDM integration, message expiration, and remote wipe on lost devices?
  • Do their own subcontractors flow down the same BAA terms?

Ask for evidence, not just a sales page claim. A SOC 2 summary, a recent penetration test report, and the actual BAA language tell you more than a “HIPAA compliant” badge ever will. Vendor diligence is where most compliance programs quietly fail, because staff default back to their personal phone’s messaging app when the “compliant” system feels slower.

Pro Tip: Configure your platform so unsecured SMS simply can’t carry PHI, at the system level. Don’t rely on staff remembering a policy when they’re rushed between patients. A secure messaging setup should make the compliant path the only path.

Secure messaging system blocks unsecured PHI

How Do TCPA and A2P 10DLC Rules Apply to Healthcare Texting?

HIPAA and the Telephone Consumer Protection Act solve different problems, and mixing them up is how clinics end up compliant on one front and exposed on the other.

  1. TCPA governs the phone call itself. Under 47 U.S.C. 227, sending marketing texts to a cell phone generally requires the recipient’s prior express written consent, separate from anything HIPAA requires about PHI. A patient can consent to receive texts under TCPA while still never authorizing you to use their diagnosis in that message under HIPAA.
  2. A2P 10DLC governs whether the message even arrives. Application-to-person traffic sent over standard 10-digit long codes now has to go through brand and campaign registration with the carriers. Unregistered traffic risks getting filtered or blocked outright, which means even a fully authorized, fully consented message never reaches the patient.
  3. Build one enrollment flow that captures both. When a patient opts in, log the HIPAA authorization (if the message will use PHI for marketing), the TCPA consent, a timestamp, and the source (web form, in-office tablet, IVR). Sync all of it to your EHR or CRM the same day.
  4. Handle revocation as two separate events. A patient who texts STOP has revoked TCPA consent, not necessarily their HIPAA authorization, and the two records must be tracked independently. Update both systems, and don’t assume one revocation clears the other.

Skipping A2P 10DLC registration is one of the more common, and more avoidable, mistakes independent practices make. It’s not a legal violation in the same way as skipping a HIPAA authorization, but it quietly kills your entire campaign at the carrier level.

Templates and Content Rules for Compliant Text Campaigns

Most clinics don’t need clever copy. They need language that stays inside the treatment/operations lane and never forces a HIPAA authorization they haven’t collected.

A safe appointment reminder reads something like: “Reminder: you have an appointment with [Practice Name] on [date] at [time]. Reply C to confirm or call [phone] to reschedule.” A refill nudge works the same way: “Your prescription refill is ready for pickup at [Pharmacy Name]. Questions? Call [phone].” Neither mentions a diagnosis, a drug name tied to a condition, or anything that requires a patient to have signed a marketing authorization first.

Now compare that to a message that crosses the line: “Managing your diabetes? Ask about our new CGM program today!” That references a health condition to sell a service, which puts it squarely in marketing territory and requires authorization on file. Rework it as: “New patient program available at [Practice Name]. Text INFO to learn more or visit [secure portal link].” Generic language plus a secure link keeps the sensitive detail off the SMS body entirely.

Keep every template inside these guardrails:

  • No diagnoses, test results, or medication names tied to a condition in the message body
  • Mandatory opt-out language (“Reply STOP to unsubscribe”) on every promotional send
  • Frequency disclosure at opt-in (“You’ll receive up to 4 messages per month”)
  • Minimal personalization, first name at most, no clinical detail

One industry guide on healthcare SMS practices recommends automating STOP and HELP replies and syncing opt-outs across every connected system in real time, rather than relying on a staff member to manually update a spreadsheet after the fact. That single automation step prevents a huge share of the accidental sends that trigger patient complaints.

How Do You Document and Train Staff for Texting Compliance?

Your risk analysis for texting doesn’t need to be an epic. Scope it around three failure points: messages sent to the wrong number, a lost or stolen staff device with message history intact, and a vendor-side breach or outage.

  1. Write down your approved use cases (appointment reminders, refill alerts) and your prohibited content list (diagnoses, test results, billing details) in one policy document.
  2. Set device management rules: PINs, remote wipe capability, and a ban on personal phones for anything touching PHI.
  3. Document how consent revocations get processed and how fast they sync across EHR, CRM, and the texting platform itself.
  4. Set a logging and retention schedule that matches your other PHI retention policies, not a shorter one just because it’s “just texting.”
  5. Train every staff member who touches patient communication, at onboarding and at least annually, and keep signed training records.
  6. Define sanctions for policy violations, and actually enforce them once.
  7. Write an incident response checklist specific to texting: what to capture, who to notify, and how fast, if a message goes to the wrong patient or a device goes missing.

Pro Tip: During an OCR inquiry, the practices that fare best are the ones that can produce a dated training log and a documented risk analysis on request, not the ones that simply claim they “have a policy.” Paper trail beats memory every time.

Your 7-Step Action Plan for Compliant SMS Marketing

Don’t try to fix everything the same week. Triage by urgency.

  • Within 48 to 72 hours: Pause any broad promotional SMS sends, confirm every vendor’s BAA is signed and current, and check your A2P 10DLC registration status with your carrier or platform.
  • Within 1 to 4 weeks: Audit existing consent records for gaps, add or fix EHR authorization fields, configure automated STOP and HELP handling, and standardize your message templates against the content rules above.
  • Ongoing, monthly or quarterly: Review audit logs for anomalies, retrain staff on any policy updates, and rehearse your incident response plan before you actually need it.
Timeframe Priority action Why it matters
48 to 72 hours Pause bulk marketing sends, verify BAA, confirm A2P status Stops active exposure and blocked traffic immediately
1 to 4 weeks Audit consent, fix EHR fields, standardize templates Closes documentation gaps before an audit finds them
Monthly/quarterly Review logs, retrain staff, test incident response Keeps compliance current as staff and vendors change

Compliance Isn’t the Enemy of Good Marketing

Most practices treat HIPAA SMS marketing as a legal hurdle standing between them and patient volume. That framing gets it backward. Klyrmedia builds texting programs where compliance is baked into the message flow from day one, not bolted on after a scare. A practice that texts fewer, cleaner, better-targeted messages tends to see lower no-show rates and stronger retention than one blasting generic promos to an unverified list, with far less breach exposure hanging over it.

— Opinly

Let Klyrmedia Handle the Compliance Plumbing So You Don’t Have To

Some retention automation services build workflows including consent capture for HIPAA authorization and TCPA opt-in with timestamps, EHR and CRM synchronization for revocation updates, and vendor integrations with signed BAAs.

Klyrmedia

You don’t need to piece this together from vendor sales calls and a risk analysis template you found online. Klyrmedia works exclusively with pharmacies, clinics, and healthcare practices, which means the messaging automation, the HIPAA-compliant web design for your patient portal, and the consent workflows are built to talk to each other from the start, instead of stitched together from three unrelated tools. If you’re not sure whether your current texting setup would survive an OCR inquiry, request a review of your patient retention automation setup and get a straight answer on where the gaps are.

Where This Guidance Comes From

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

Is SMS Texting HIPAA Compliant?

SMS texting can be HIPAA compliant, but standard carrier SMS usually isn’t secure enough on its own for PHI because it lacks end-to-end encryption and audit logging. Providers typically need a secure messaging vendor with a signed BAA, or should route sensitive content through a patient portal link instead.

Yes, SMS marketing is legal in the U.S., but it requires prior express written consent under the TCPA, and if the message uses PHI to promote a product or service, it also needs a separate written HIPAA authorization under 45 CFR 164.508.

What Is the New HIPAA Rule for 2026?

There’s no single new nationwide HIPAA rule specific to texting for 2026. The core marketing authorization requirement under 45 CFR 164.508 and the Security Rule’s transmission safeguards still govern how PHI can be used in SMS campaigns, so the priority stays the same: authorization, a signed BAA, and TCPA consent.

Which Text Messaging Platforms Are HIPAA Compliant?

No platform is automatically HIPAA compliant out of the box. A platform becomes part of a compliant program only when the vendor signs a BAA, provides encryption and audit logging, and your practice pairs it with proper consent capture and staff training, which is the workflow services like Klyrmedia’s Retention Automation Service are built to manage.

Share this article: