A patient texts STOP to your appointment reminders. Today that stops the reminders. From 31 January 2027 it is scheduled to stop everything you ever send that person, including the recall you had not thought of yet.
the patient replies STOP
the reminder system
the other two systems
Key takeaways
- •A revocation must already be honoured within 10 business days, and that rule is in force now.
- •From 31 January 2027, an opt-out in response to one message type is scheduled to apply to all of them.
- •The exposure is architectural: practices texting from several systems have no shared opt-out list.
- •HIPAA and the TCPA answer different questions, and being right on one says nothing about the other.
- •The useful first step is an inventory of every system that can text a patient, which usually finds more than expected.
There is a piece of American telecoms rulemaking that most practice owners have never heard of and that will land squarely on how they text patients. It has been delayed twice, which is exactly why nobody is watching it, and it is currently scheduled to take effect on 31 January 2027.
The short version is that a patient's opt-out is about to become much broader than most practices assume. Today, a STOP in reply to your reminders stops your reminders. Under the new rule, a request to revoke consent in response to one kind of message has to be treated as revoking consent for every kind of message you send that person.
This is not a HIPAA question, which is the first thing to get straight. It is a Telephone Consumer Protection Act question, it is enforced very differently, and a practice can be perfectly correct on HIPAA and still be exposed here. None of what follows is legal advice, and a practice actually sending patient texts at volume should have its own counsel read the rule.
What the rule actually says#
The current requirement is narrow and already in force. A request to revoke consent, made in any reasonable manner, must be honoured within a reasonable time, capped at 10 business days from receipt. It applies now, it reaches appointment reminders as much as promotions, and the cap is an outer limit rather than a target.
The exact wording matters, because two phrases in it are doing work. "In any reasonable manner" means a patient does not have to reply with the magic word: a spoken request to your receptionist counts, and so does a reply that says "please stop texting me" in ordinary English [1]. "Within a reasonable time not to exceed ten business days" means 10 days is the ceiling, not the standard you should be aiming at.
What is scheduled for 2027 is broader. The delayed provision requires that a revocation received in response to one type of message be applied to all future regulated calls and texts from that caller, including ones about entirely unrelated subjects. That is the part practices are not built for.
The reason it has slipped twice is that the FCC accepted that healthcare and financial firms could not cleanly build for it in the original window. The date moved from April 2025 to April 2026, and then on 6 January 2026 the Commission moved it again, to 31 January 2027 [2].
A rule delayed twice is not a rule that went away. It is a rule with a longer runway and the same destination.
Why "one opt-out ends everything" is harder than it sounds#
For a practice running a single messaging system, this is close to trivial: one opt-out list, one flag, done. For the majority of practices, which are not running a single system, it is genuinely difficult, and the difficulty is architectural rather than legal.
Consider a fairly ordinary setup. Appointment reminders go out of the practice management system. Recall and reactivation campaigns go out of a marketing tool. Review requests go out of a third product a vendor installed 2 years ago. A patient replies STOP to a reminder, and only the first system ever learns about it.
- 1Reminders, from the practice management systemReceives the STOP reply, suppresses the patient, and tells nothing else.
- 2Recall, from the marketing toolHolds its own list. Never sees the reply. Sends on schedule 6 weeks later.
- 3Review requests, from a third productTriggered by a visit. Nobody has looked at its settings since it was installed.
- 4The patientAsked once, in the obvious way, and is still receiving 2 of the 3.
Nothing about that arrangement is unusual and nothing about it is careless. It is what happens when three good decisions get made 18 months apart. But under the new rule it produces exactly the failure the rule is aimed at, and it produces it silently, because the marketing tool has no idea it is now sending to someone who opted out.
The fix is not a policy document. A policy that says "honour all opt-outs everywhere" does nothing if the systems have no way to tell each other. What is needed is one place where opt-out status lives and which every sender checks before it sends.
Where practices are actually exposed#
The exposure is not evenly distributed, and it is worth being specific about who should care rather than telling every practice to worry. Four situations account for most of the real risk here, and a practice that recognises none of them in its own setup can reasonably put this near the bottom of the list.
| Situation | Why it is exposed |
|---|---|
| Texting from more than one system | An opt-out in one is invisible to the others |
| Opt-outs handled by staff manually | A person on holiday is a 10 business day clock still running |
| Marketing and clinical texts on one number | Recipients cannot distinguish them, so a STOP is ambiguous |
| Consent recorded on paper only | Nothing machine-readable for a sender to check |
The third row deserves particular attention in aesthetics and dentistry, where the line between a clinical reminder and a promotion is genuinely blurry. A message about a treatment a patient is already receiving sits in a different category from an offer, and the practice sending both from one number has made that distinction invisible to the person receiving them.
Row four is more common than practices admit. Consent captured on an intake form in a filing cabinet is real consent and it is useless to an automated sender, which cannot read it, cannot check it, and will happily send anyway.
Row two is the one that catches otherwise careful practices. A manual process is not automatically a bad process, and a small single-location practice handling 3 or 4 opt-outs a month by hand is doing something entirely reasonable. What makes it fragile is that the clock does not pause: a request arriving on the Friday before someone takes 2 weeks off has consumed most of its 10 business days before anyone reads it. The test is not whether the process works on a normal Tuesday, it is whether it works on the worst Tuesday of the year.
HIPAA is a separate question with a different answer#
It is worth separating these cleanly, because conflating them causes practices to over-restrict useful communication and under-restrict the risky kind. HIPAA governs what you may say and to whom. The TCPA governs whether you were allowed to send an automated message at all.
Under HIPAA, marketing means a communication about a product or service that encourages the recipient to buy or use it, and several things are carved out of that definition. Communications for the treatment of an individual, including case management and care coordination, are excluded, as are refill reminders, provided there is no third-party payment behind them [3].
An appointment reminder sits comfortably inside treatment. A message telling a patient their annual review is due sits inside care coordination for most practices. A message offering 20% off a treatment package does not sit in either, and no amount of arguing that it is health-related moves it.
| HIPAA | TCPA | |
|---|---|---|
| Question it answers | What may you say, and to whom | Were you allowed to send at all |
| Appointment reminder | Treatment, not marketing | Regulated, consent still applies |
| Discount offer | Marketing, needs authorisation | Regulated, stricter consent |
| Who enforces it | HHS Office for Civil Rights | FCC, and private lawsuits |
There is a further HIPAA point practices routinely miss. A patient has the right to request that you communicate with them by alternative means or at alternative locations, and a provider must accommodate reasonable requests [4]. "Do not text me, call the landline" is a reasonable request, and it needs somewhere to live in your systems too.
What the timeline has actually looked like#
The date has moved twice, and knowing why is more useful than knowing that it did, because the reasons say something about where the rule is heading. Both delays were granted on the basis that regulated firms could not build the systems in time, not on the basis that the requirement itself was wrong.
The original compliance date was 11 April 2025. A limited waiver moved the cross-subject part of it to 11 April 2026, specifically citing the difficulty healthcare and financial firms described in designing systems that could apply a broad revocation without over-applying it. On 6 January 2026 the Commission moved it again, to 31 January 2027 [2].
- Feb 2024Rule adoptedThe Commission adopts the revocation requirements.
- 11 Apr 2025Original dateThe first compliance date for the full rule.
- 11 Apr 2026First waiverThe cross-subject part is waived for 12 months.
- 31 Jan 2027Current dateMoved again by order DA-26-12 on 6 January 2026.
Read that sequence as 21 months of extra runway rather than as a signal the rule is dying. Nothing in either order suggests the Commission has changed its mind about the destination, and a practice reading two delays as two reprieves is making a bet on a third one.
What to fix in the next 12 months#
The work here is unglamorous and mostly a matter of consolidation. None of it requires new software, and a practice that does the four things below is in a defensible position regardless of what the final rule looks like when it lands.
- Inventory every system that can send a patient a text. Practice management, marketing tool, review tool, forms tool, anything a vendor set up. Most practices find more than they expected.
- Pick one place where opt-out status lives, and make every sender check it before sending. If two systems cannot share a list, that is the finding, and it is better found now.
- Separate consent by purpose and record it. Reminders, recall, and promotions are different permissions. Recording them as one flag means you cannot honour a narrow opt-out even if the rule eventually permits one.
- Time the response, not just the outcome. The current 10 business day limit is a clock that starts on receipt, and a manual process that depends on one person is not a process that survives a holiday.
The one thing worth doing immediately, before any of the above, is the inventory. It takes an afternoon and it frequently changes the shape of the problem, because the answer to "how many systems text our patients" is more often 3 or 4 than 1.
There is a fifth item that is not compliance work but belongs on the same list. Check what your systems do when a patient replies with something that is not STOP. Real people write "stop texting me", "remove me", "wrong number", and "please don't send these", and a keyword matcher looking for 1 exact word will miss all 4 of those while the 10 business day clock runs.
The rule is about opt-outs. The work is about consolidation, and the consolidation is worth doing anyway.
What we do about it, and why we went further#
We built to the stricter version rather than the current one, which is a deliberate choice and worth explaining rather than asserting. One opt-out ends everything in our system today, ahead of the deadline and beyond what the current rule requires.
Two reasons. Building to the waiver would mean rebuilding when the waiver lapses, and a rule that has moved twice can move again in either direction. More importantly, a patient who asked once should not have to ask twice, and a system that requires a second STOP for the second channel is one that failed the person rather than the regulator.
The rule enforcement lives in the database rather than in application code, which matters more than it sounds. A rule in TypeScript is one refactor away from being lost, and it does not apply at all to a stray script or a hand-run query. A constraint the database enforces applies to everything, including the things nobody remembered to route through the application.
If you want the operational version of this rather than the regulatory one, the patient texting guide walks through the inventory, the consent model, and the opt-out plumbing in order. If you are earlier than that and still sizing whether any of this is worth doing, start with what a front desk actually costs.



