TCPA Compliance for Patient Texting: The Rule HIPAA Misses
HIPAA protects health information. TCPA governs whether you had the right to text a number at all. Here is what the narrow healthcare exemption actually covers.
Muhammad Qasim HammadAugust 8, 202610 min read
On this page
- Why "HIPAA-compliant" does not mean TCPA-compliant
- The healthcare exemption, and exactly how narrow it is
- TCPA versus HIPAA: 2 separate rules that both apply
- What actually triggers a violation, in plain terms
- Where automated texting fits a practice, and where it needs a real compliance check
- Audit your own texting compliance before you send another campaign
- Match your texting program to the actual rule
Your texting platform's homepage says "HIPAA-compliant" somewhere near the top. That is true, and it answers a different question than the one that actually gets practices sued. HIPAA governs whether patient health information is protected. It says nothing about whether you had the legal right to text that number in the first place, and that second question belongs to a completely separate federal law.
That law is the Telephone Consumer Protection Act, TCPA, and it carries its own penalties, $500 to $1,500 per violation, with every individual message counted separately and no cap on the total. A healthcare payer recently agreed to pay up to $10.5 million to settle a case built on exactly this: automated texts that kept going out after patients had already replied to opt out.
This post explains the actual, narrow healthcare exemption correctly, keeps TCPA and HIPAA clearly separate rather than blurring them the way most vendor pages do, and gives you a 30-minute way to check your own texting setup before your next campaign, not after a complaint.
None of this is legal advice, and it is not meant to be. It is meant to give you the specific, checkable questions to bring to whoever actually reviews your texting program, whether that is a healthcare attorney or a genuinely knowledgeable vendor, so the conversation starts from real terms instead of a reassuring but vague "don't worry, we're compliant."
Why "HIPAA-compliant" does not mean TCPA-compliant
TCPA consent and HIPAA authorization are separate legal requirements, and both apply to the same automated text message at the same time. A signed HIPAA authorization does not satisfy TCPA's consent requirement, and TCPA violations carry penalties of $500 to $1,500 per message, with no cap on total damages.
The per-message structure is what makes this expensive in a way a single fine never would be. A campaign that sends the same non-compliant message to 200 patients is not one violation, it is potentially 200, each carrying its own $500 to $1,500 exposure, which is how a single bad campaign can turn into a genuinely large number quickly.
3,200 TCPA cases were filed in 2025, and healthcare is consistently named among the top industries involved. That is not a niche risk confined to telemarketers and robocallers; it is an active area of litigation that a practice's own patient-communication system can walk straight into without anyone realizing it until a demand letter arrives.
Average settlements in recent cases ran roughly $5,000 to $12,000 per claim, which sounds modest next to the headline-grabbing multimillion-dollar cases until you remember those are per-claim figures, not per-campaign ones. A single flawed campaign that reaches a few dozen patients who each file separately does not need a class action to become expensive; it can get there through ordinary, individual claims alone.
The healthcare exemption, and exactly how narrow it is
A healthcare provider can text a patient's mobile number using automated methods when that number was provided directly by the patient and the message is healthcare-related rather than promotional. That exemption is real, but it is narrower than most compliance summaries make it sound, and it disappears the moment any of those conditions stop being true.
| Message type | Exemption status | Consent actually required |
|---|---|---|
| Appointment or exam confirmation | Exempt, if sent to a patient-provided number | Providing the number is generally sufficient |
| Wellness checkup or pre-registration instructions | Exempt, if sent to a patient-provided number | Providing the number is generally sufficient |
| Promotional or marketing message | Not exempt | Prior express written consent required |
| Billing or debt-collection message | Not exempt | Prior express written consent required |
Messages under this exemption also carry their own content rules: keep texts concise, offer an easy opt-out, and honor that opt-out immediately, not at the end of a campaign or a billing cycle. None of these are optional extras layered on top of the exemption, they are the conditions the exemption depends on.
It helps to think of the exemption as a narrow lane rather than a broad shield. It was built for a specific, low-risk kind of message, a reminder the patient would reasonably expect given the number they handed over at check-in, and it was never meant to cover the full range of things a practice might eventually want to text about once the technical capability exists.
TCPA versus HIPAA: 2 separate rules that both apply
TCPA governs whether a practice had the right to contact a number with an automated message at all. HIPAA governs whether patient health information is protected wherever it travels. Neither law substitutes for the other, and a text message can cleanly satisfy one while quietly violating the other at the same time.
For the HIPAA side of this, what a HIPAA-aware setup requires covers the BAA and configuration questions that matter regardless of how a message gets sent. TCPA sits alongside that, not underneath it, and a vendor that only talks about one of the 2 is only answering half the question a compliance-cautious practice should be asking.
Real settlements make the stakes concrete rather than theoretical. Beyond the healthcare payer's $10.5 million settlement over ignored opt-outs, a separate insurer agreed to a $2.5 million settlement over non-emergency prerecorded calls to cell phones, a reminder that voice campaigns carry the same exposure as text ones under this law.
Neither of those settlements involved a small, obscure vendor. They involved large, well-resourced healthcare organizations with presumably real compliance functions in place, which is worth remembering the next time "we already have compliance covered" is offered as a reason to skip a closer look at a specific texting program.
What actually triggers a violation, in plain terms
Continuing to text a number after a patient has already opted out is the single most common, most expensive mistake, and it shows up repeatedly in real settlements. Using a number the patient did not provide directly, a referral list, a purchased list, a family member's number entered by mistake, forfeits the exemption entirely.
State-level rules are also getting stricter on top of the federal baseline. Virginia's SB 1339, effective January 1, 2026, requires businesses to honor a text opt-out for a full 10 years, which is a meaningfully longer memory than many systems are built to keep by default.
That kind of state-level rule is likely the direction this area keeps moving, not an isolated exception. A texting platform that only tracks opt-outs for a year or 2, or that quietly resets the record when a phone number gets reassigned to a new patient in the system, may already be out of step with where individual states are heading, independent of what federal TCPA requires today.
Where automated texting fits a practice, and where it needs a real compliance check
Automated texting fits appointment reminders, wellness checkup nudges, and pre-registration instructions, all healthcare-related, all short, all sent only to numbers the patient provided directly, with a working opt-out on every message. It needs a real compliance review, not just automation, the moment a message turns promotional or reactivation-focused.
If you have never evaluated an automated texting setup against this standard before, treat it the same way you would any other vendor claim: ask specifically how the platform verifies that a number was patient-provided, not just collected somewhere along the way, and how quickly an opt-out actually takes effect once a patient sends one.
This is the same evaluation discipline covered in what an AI receptionist does and where it stops, applied to text instead of voice. A vendor confident enough to explain its safeguards in specific, checkable detail is a very different proposition than one that simply asserts "we're compliant" and moves on to the next feature.
Audit your own texting compliance before you send another campaign
Before sending another campaign, spend 30 minutes checking your own setup. Confirm every number came directly from the patient, check message content for anything promotional, test your own opt-out by replying STOP, and review whether you can actually show when and how each number's consent was recorded.
Do this audit even if a vendor has already told you their platform is compliant. A platform can be technically capable of TCPA-compliant behavior, honoring opt-outs, limiting content, restricting sends to verified numbers, and still be misconfigured or misused in ways that undo all of that capability in practice.
Match your texting program to the actual rule
This is general compliance information, not legal advice, and the right setup depends on your own message types and consent records, not a vendor's assurance. A practice sending only appointment reminders to patient-provided numbers is in a very different position than one running promotional or reactivation campaigns by text.
Walk the flow once: anything promotional or billing-related needs full prior written consent, no exemption available. A number not provided directly by the patient means no automated message goes out under the exemption. An opt-out that has already been used means the messages stop, permanently, on that number. Everything else, sent to a patient-provided number with a working opt-out, generally falls within the healthcare exemption.
Have a healthcare attorney review your specific texting program before scaling it, especially anything beyond simple appointment and care reminders. If you would rather have your broader front-desk communication setup reviewed first, the free Growth Leak Audit looks at the practice's numbers before anyone talks tools.
Fair questions.
Does being HIPAA-compliant mean my texting system is also TCPA-compliant?
No. TCPA and HIPAA are separate federal requirements that both apply to the same automated text message. HIPAA governs whether patient health information is protected; TCPA governs whether you had the legal right to contact that number with an automated message at all. A signed HIPAA authorization does not satisfy TCPA consent requirements.
What is the TCPA healthcare exemption, and what does it actually cover?
It allows automated calls or texts to a patient's mobile number when the patient provided that number directly and the message is healthcare-related, such as an appointment reminder or wellness checkup, rather than promotional. It does not cover marketing messages or billing/debt-collection texts, which require full prior express written consent regardless of the healthcare context.
How much can a TCPA violation actually cost a practice?
Statutory damages run $500 to $1,500 per violation, and each individual message counts as a separate violation with no cap on total damages. A real healthcare payer settled for up to $10.5 million over texts sent after patients had already opted out, and average settlements in recent individual claims have run roughly $5,000 to $12,000 per claim.
What is the most common mistake that triggers a TCPA violation?
Continuing to text a number after a patient has already opted out is the most common and most expensive mistake, and it appears repeatedly in real settlements. Using a number the patient did not provide directly, such as one pulled from a referral list or entered by a family member, also forfeits the healthcare exemption entirely.
How quickly must a patient text opt-out be honored?
Immediately, not at the end of a campaign or billing cycle. Continuing to message a number after an opt-out is one of the clearest ways to trigger a violation. Virginia's SB 1339, effective January 1, 2026, also requires businesses to honor a text opt-out for a full 10 years, signaling that state rules are getting stricter on top of federal requirements.
Sources
- [1]TCPA compliance for text messaging: healthcare organizations 2026 (Fransis)
- [2]Using automated services to reach patients? Know the rules (AOA)
- [3]Comprehensive guide to TCPA compliance for healthcare organizations
- [4]Guide to TCPA regulation for healthcare providers (GoIcon)
- [5]TCPA lawsuit statistics 2026 (Claim Supply)
- [6]What is a TCPA settlement and how to control exposure in 2026 (Tratta)
- [7]Kaiser Foundation Health Plan settles unwanted text message lawsuit (HIPAA Journal)
Written by
Muhammad Qasim Hammad
Founder, Cart Gaze
Qasim builds AI receptionists and front-office automation for medical and dental practices at Cart Gaze. Posts here start from published sources and real call data, not vendor claims, and every number links back to where it came from.