Three laws, three questions
A practice that emails or texts patients is dealing with three separate sets of rules, and each asks a different question.
- CAN-SPAM, enforced by the FTC, asks whether a commercial email is truthful and easy to leave.1
- The Telephone Consumer Protection Act, enforced through FCC rules, asks whether you had the right kind of consent before an automated call or text.23
- HIPAA, for covered practices, asks whether a message is marketing and whether patient information travels safely.45
Health coaches and other practices outside HIPAA still have to follow CAN-SPAM and the TCPA. Those two apply to everyone.
Email: what CAN-SPAM requires
CAN-SPAM is an opt-out law, not an opt-in law. You may email someone who has not asked for it, but every commercial email has to meet the FTC’s requirements.1
- Accurate "From", "To" and "Reply-To" details, and a subject line that reflects the content.
- A clear disclosure that the message is an advertisement.
- Your valid physical postal address.
- A clear explanation of how to opt out, honored within 10 business days.
The FTC also states that hiring an email platform or agency does not move the responsibility: "you can’t contract away your legal responsibility". Each separate email in violation can bring penalties of up to $53,088.1
Transactional or relationship messages, such as confirming a booking or delivering something the patient already agreed to, are exempt from most of these requirements, as long as they stay transactional. The FTC judges a mixed message by its primary purpose, and a subject line that reads like an advertisement can make the whole message commercial.1
Texts: consent under the TCPA
The FCC treats a text message as a call. Its consumer guide says the rules "ban text messages sent to a mobile phone using an autodialer unless the phone owner previously gave consent", and adds: "Commercial texts require written consent; for informational texts, your consent may be oral."2
The regulation defines prior express written consent as a signed written agreement, which can be electronic, that clearly authorizes the sender to deliver advertisements or telemarketing messages to a stated number.3 A phone number written on an intake form is not that. A checkbox with its own sentence, such as "I agree to receive marketing texts from Smith Chiropractic at the number above", is much closer.
Practices get a narrow exception. The FCC rules exempt calls that deliver a "health care" message made by, or on behalf of, a HIPAA covered entity from the written consent requirement for telemarketing to many lines.3 Separately, free-to-the-patient appointment and exam reminders, lab result notices and similar messages can be sent to a patient’s mobile number under tight conditions.3
| Condition | What the rule says |
|---|---|
| Number | Only the wireless number the patient provided |
| Purpose | Appointment and exam confirmations and reminders, wellness checkups, lab results, prescription notices and similar care messages |
| Content | No telemarketing, solicitation, advertising or billing content |
| Length | Generally 160 characters or less for texts |
| Frequency | One message per day, up to three per week, per patient |
| Identity | Name and contact information of the provider in each message |
| Opt-out | Tell recipients they can reply STOP, and honor it immediately |
| Cost | The message must not be charged to the patient |
Read the content row twice. A reminder that ends with "Ask about our new IV therapy package" is no longer a reminder under this exemption.3 It is a marketing text, and it needs written consent.
Opt-outs: faster and broader than most platforms assume
Under the current rule, a patient may revoke consent "by using any reasonable method". Replies of "stop", "quit", "end", "revoke", "opt out", "cancel" or "unsubscribe" count automatically, and so does any other reply a reasonable person would read as a request to stop. You may not require one exclusive method, and a revocation must be honored "within a reasonable time not to exceed ten business days".3
In practice, "please stop texting me" typed by a patient is an opt-out, even if your platform only listens for the word STOP. Someone at the front desk has to watch replies and remove numbers by hand when the software misses them.
Where HIPAA fits
For a covered practice, HIPAA defines marketing as a communication that "encourages recipients of the communication to purchase or use the product or service", then excludes communications for treatment and for describing the practice’s own health-related services, unless someone pays the practice to send them.4 Appointment reminders sit comfortably inside treatment.
Security is the other half. HHS guidance on patient access recognizes that a patient can ask to receive information by unencrypted email, and that a covered entity is not responsible for a breach in transit when the patient "was warned of and accepted the security risks".5 Ask each patient which channel they prefer, warn them in plain words if it is not secure, and write their choice in the record.
A consent setup that holds up
- On the intake form, add two separate checkboxes: one for appointment reminders, one for news and offers. Neither should be pre-ticked.
- Store the date, the wording the patient agreed to and the number or email, in the same system that sends the messages.
- Keep reminders and marketing in separate lists or campaigns, so an opt-out from one is not confused with the other.
- Put your postal address and an unsubscribe link in every marketing email, and test the link monthly.
- Have a named person check text replies each business day for opt-outs the software missed.
Patient emails with a testimonial or a result in them raise a separate set of FTC rules, covered in testimonials and social proof. If you want your forms, reminders and marketing flows checked together, that is part of a technical and compliance rebuild. This post explains the rules as published. It is not legal advice, and a practice with a specific TCPA question should speak to a lawyer.