Compliance

The Patient Texting Rules Change in January 2027

By Velaire Health · September 8, 2026 · 10 min read

ShareXLinkedIn
Compliance

A patient texts STOP to your appointment reminders. Today that stops the reminders. From 31 January 2027 it is scheduled to stop everything you ever send that person, including the recall you had not thought of yet.

the patient replies STOP

Understood.Removed.

the reminder system

the other two systems

The rule is about opt-outs. The problem is that nothing tells the other systems.

Key takeaways

  • A revocation must already be honoured within 10 business days, and that rule is in force now.
  • From 31 January 2027, an opt-out in response to one message type is scheduled to apply to all of them.
  • The exposure is architectural: practices texting from several systems have no shared opt-out list.
  • HIPAA and the TCPA answer different questions, and being right on one says nothing about the other.
  • The useful first step is an inventory of every system that can text a patient, which usually finds more than expected.

There is a piece of American telecoms rulemaking that most practice owners have never heard of and that will land squarely on how they text patients. It has been delayed twice, which is exactly why nobody is watching it, and it is currently scheduled to take effect on 31 January 2027.

The short version is that a patient's opt-out is about to become much broader than most practices assume. Today, a STOP in reply to your reminders stops your reminders. Under the new rule, a request to revoke consent in response to one kind of message has to be treated as revoking consent for every kind of message you send that person.

This is not a HIPAA question, which is the first thing to get straight. It is a Telephone Consumer Protection Act question, it is enforced very differently, and a practice can be perfectly correct on HIPAA and still be exposed here. None of what follows is legal advice, and a practice actually sending patient texts at volume should have its own counsel read the rule.

What the rule actually says#

The current requirement is narrow and already in force. A request to revoke consent, made in any reasonable manner, must be honoured within a reasonable time, capped at 10 business days from receipt. It applies now, it reaches appointment reminders as much as promotions, and the cap is an outer limit rather than a target.

The exact wording matters, because two phrases in it are doing work. "In any reasonable manner" means a patient does not have to reply with the magic word: a spoken request to your receptionist counts, and so does a reply that says "please stop texting me" in ordinary English [1]. "Within a reasonable time not to exceed ten business days" means 10 days is the ceiling, not the standard you should be aiming at.

What is scheduled for 2027 is broader. The delayed provision requires that a revocation received in response to one type of message be applied to all future regulated calls and texts from that caller, including ones about entirely unrelated subjects. That is the part practices are not built for.

The reason it has slipped twice is that the FCC accepted that healthcare and financial firms could not cleanly build for it in the original window. The date moved from April 2025 to April 2026, and then on 6 January 2026 the Commission moved it again, to 31 January 2027 [2].

A rule delayed twice is not a rule that went away. It is a rule with a longer runway and the same destination.

Why "one opt-out ends everything" is harder than it sounds#

For a practice running a single messaging system, this is close to trivial: one opt-out list, one flag, done. For the majority of practices, which are not running a single system, it is genuinely difficult, and the difficulty is architectural rather than legal.

Consider a fairly ordinary setup. Appointment reminders go out of the practice management system. Recall and reactivation campaigns go out of a marketing tool. Review requests go out of a third product a vendor installed 2 years ago. A patient replies STOP to a reminder, and only the first system ever learns about it.

How an opt-out gets lost
  1. 1
    Reminders, from the practice management system
    Receives the STOP reply, suppresses the patient, and tells nothing else.
  2. 2
    Recall, from the marketing tool
    Holds its own list. Never sees the reply. Sends on schedule 6 weeks later.
  3. 3
    Review requests, from a third product
    Triggered by a visit. Nobody has looked at its settings since it was installed.
  4. 4
    The patient
    Asked once, in the obvious way, and is still receiving 2 of the 3.
Three systems installed 18 months apart, and only one of them heard the STOP.

Nothing about that arrangement is unusual and nothing about it is careless. It is what happens when three good decisions get made 18 months apart. But under the new rule it produces exactly the failure the rule is aimed at, and it produces it silently, because the marketing tool has no idea it is now sending to someone who opted out.

The fix is not a policy document. A policy that says "honour all opt-outs everywhere" does nothing if the systems have no way to tell each other. What is needed is one place where opt-out status lives and which every sender checks before it sends.

Where practices are actually exposed#

The exposure is not evenly distributed, and it is worth being specific about who should care rather than telling every practice to worry. Four situations account for most of the real risk here, and a practice that recognises none of them in its own setup can reasonably put this near the bottom of the list.

SituationWhy it is exposed
Texting from more than one systemAn opt-out in one is invisible to the others
Opt-outs handled by staff manuallyA person on holiday is a 10 business day clock still running
Marketing and clinical texts on one numberRecipients cannot distinguish them, so a STOP is ambiguous
Consent recorded on paper onlyNothing machine-readable for a sender to check

The third row deserves particular attention in aesthetics and dentistry, where the line between a clinical reminder and a promotion is genuinely blurry. A message about a treatment a patient is already receiving sits in a different category from an offer, and the practice sending both from one number has made that distinction invisible to the person receiving them.

Row four is more common than practices admit. Consent captured on an intake form in a filing cabinet is real consent and it is useless to an automated sender, which cannot read it, cannot check it, and will happily send anyway.

Row two is the one that catches otherwise careful practices. A manual process is not automatically a bad process, and a small single-location practice handling 3 or 4 opt-outs a month by hand is doing something entirely reasonable. What makes it fragile is that the clock does not pause: a request arriving on the Friday before someone takes 2 weeks off has consumed most of its 10 business days before anyone reads it. The test is not whether the process works on a normal Tuesday, it is whether it works on the worst Tuesday of the year.

HIPAA is a separate question with a different answer#

It is worth separating these cleanly, because conflating them causes practices to over-restrict useful communication and under-restrict the risky kind. HIPAA governs what you may say and to whom. The TCPA governs whether you were allowed to send an automated message at all.

Under HIPAA, marketing means a communication about a product or service that encourages the recipient to buy or use it, and several things are carved out of that definition. Communications for the treatment of an individual, including case management and care coordination, are excluded, as are refill reminders, provided there is no third-party payment behind them [3].

An appointment reminder sits comfortably inside treatment. A message telling a patient their annual review is due sits inside care coordination for most practices. A message offering 20% off a treatment package does not sit in either, and no amount of arguing that it is health-related moves it.

Two frameworks, two questions
HIPAATCPA
Question it answersWhat may you say, and to whomWere you allowed to send at all
Appointment reminderTreatment, not marketingRegulated, consent still applies
Discount offerMarketing, needs authorisationRegulated, stricter consent
Who enforces itHHS Office for Civil RightsFCC, and private lawsuits
Being right on one says nothing about the other. Both have to be satisfied.

There is a further HIPAA point practices routinely miss. A patient has the right to request that you communicate with them by alternative means or at alternative locations, and a provider must accommodate reasonable requests [4]. "Do not text me, call the landline" is a reasonable request, and it needs somewhere to live in your systems too.

What the timeline has actually looked like#

The date has moved twice, and knowing why is more useful than knowing that it did, because the reasons say something about where the rule is heading. Both delays were granted on the basis that regulated firms could not build the systems in time, not on the basis that the requirement itself was wrong.

The original compliance date was 11 April 2025. A limited waiver moved the cross-subject part of it to 11 April 2026, specifically citing the difficulty healthcare and financial firms described in designing systems that could apply a broad revocation without over-applying it. On 6 January 2026 the Commission moved it again, to 31 January 2027 [2].

How the date has moved
  1. Feb 2024
    Rule adopted
    The Commission adopts the revocation requirements.
  2. 11 Apr 2025
    Original date
    The first compliance date for the full rule.
  3. 11 Apr 2026
    First waiver
    The cross-subject part is waived for 12 months.
  4. 31 Jan 2027
    Current date
    Moved again by order DA-26-12 on 6 January 2026.
Two delays, both granted on build difficulty rather than on the merits of the rule.

Read that sequence as 21 months of extra runway rather than as a signal the rule is dying. Nothing in either order suggests the Commission has changed its mind about the destination, and a practice reading two delays as two reprieves is making a bet on a third one.

What to fix in the next 12 months#

The work here is unglamorous and mostly a matter of consolidation. None of it requires new software, and a practice that does the four things below is in a defensible position regardless of what the final rule looks like when it lands.

  1. Inventory every system that can send a patient a text. Practice management, marketing tool, review tool, forms tool, anything a vendor set up. Most practices find more than they expected.
  2. Pick one place where opt-out status lives, and make every sender check it before sending. If two systems cannot share a list, that is the finding, and it is better found now.
  3. Separate consent by purpose and record it. Reminders, recall, and promotions are different permissions. Recording them as one flag means you cannot honour a narrow opt-out even if the rule eventually permits one.
  4. Time the response, not just the outcome. The current 10 business day limit is a clock that starts on receipt, and a manual process that depends on one person is not a process that survives a holiday.

The one thing worth doing immediately, before any of the above, is the inventory. It takes an afternoon and it frequently changes the shape of the problem, because the answer to "how many systems text our patients" is more often 3 or 4 than 1.

There is a fifth item that is not compliance work but belongs on the same list. Check what your systems do when a patient replies with something that is not STOP. Real people write "stop texting me", "remove me", "wrong number", and "please don't send these", and a keyword matcher looking for 1 exact word will miss all 4 of those while the 10 business day clock runs.

The rule is about opt-outs. The work is about consolidation, and the consolidation is worth doing anyway.

What we do about it, and why we went further#

We built to the stricter version rather than the current one, which is a deliberate choice and worth explaining rather than asserting. One opt-out ends everything in our system today, ahead of the deadline and beyond what the current rule requires.

Two reasons. Building to the waiver would mean rebuilding when the waiver lapses, and a rule that has moved twice can move again in either direction. More importantly, a patient who asked once should not have to ask twice, and a system that requires a second STOP for the second channel is one that failed the person rather than the regulator.

The rule enforcement lives in the database rather than in application code, which matters more than it sounds. A rule in TypeScript is one refactor away from being lost, and it does not apply at all to a stray script or a hand-run query. A constraint the database enforces applies to everything, including the things nobody remembered to route through the application.

If you want the operational version of this rather than the regulatory one, the patient texting guide walks through the inventory, the consent model, and the opt-out plumbing in order. If you are earlier than that and still sizing whether any of this is worth doing, start with what a front desk actually costs.

ShareXLinkedIn
Good questions. Clear answers.

Questions about this

Does this apply to appointment reminders, or only to marketing texts?

The consent and revocation rules reach regulated calls and texts generally, not only promotional ones, which is why treating reminders as exempt is risky. HIPAA takes a different view and treats reminders as treatment communications rather than marketing. The two frameworks answer different questions and you have to satisfy both.

We only use one system. Do we still need to do anything?

Less, but not nothing. Check that opt-outs are processed automatically rather than by a person, since the 10 business day limit runs from receipt and a manual queue does not pause for holidays. Also check whether that one system is genuinely the only thing that can send, because forms and review tools often can.

Can we send a confirmation text after someone opts out?

The rule permits a single confirmation message, provided it only confirms the revocation, carries no marketing or promotional content, and is the only further message sent. A confirmation sent within 5 minutes of receipt is presumed to fall inside the existing consent. Anything beyond that one message is not covered.

Is this the same as A2P 10DLC registration?

No, though practices meet both at the same time. 10DLC registration is a carrier requirement about identifying who is sending business messages over standard numbers, and unregistered traffic gets filtered. Consent and revocation are legal obligations about whether you were permitted to send. Registration does not grant consent.

The date moved twice already. Why act on it now?

Because the work is consolidation rather than compliance theatre, and it is worth doing whether or not the date holds. An inventory of your senders and one shared opt-out list improves your messaging regardless. Practices that wait will be doing the same work later under a deadline instead of at their own pace.

Keep reading

More from the blog

Start here

What is an AI front office?

The plain-language explainer: what it does, what it deliberately doesn't, and how it compares with voicemail, an answering service, a phone tree, and hiring.

Read the guide
Let’s make room for better care

Your next caller
could be your
next patient.

See how Velaire would handle the calls your practice misses. A personal walkthrough, built around your questions.

Let’s talk about your practice
Illustrative warm, quiet practice reception at the end of the day