Most practices texting patients are doing it from three systems that cannot see each other's opt-outs. That is survivable today. It stops being survivable on 31 January 2027, and the fix takes weeks rather than days.
the patient replies, once
the senders, none of them told
Before you start
- •Admin access to your practice management system and any marketing or review tool
- •Your business Tax ID, legal entity name, and registered address
- •Whoever owns the relationship with your phone or messaging provider
- •About 3 hours spread over 2 weeks, since registration involves waiting
What you will end up with
- •A written inventory of every system that can text a patient, which is usually more than you expected.
- •One system named as the authority on consent, with every other sender reading from it.
- •Consent recorded per purpose and against the phone number, with 5 fields a machine can check.
- •One opt-out list, tested by opting out in one channel and attempting to send from every other.
- •An approved 10DLC Brand and Campaign whose description matches what you actually send.
This guide exists because patient texting is three separate problems wearing one name, and practices usually discover that in the wrong order. There is a legal question about consent, a carrier question about registration, and an architectural question about whether your systems can tell each other anything. Most practices meet the carrier one first, because it is the one that blocks messages.
The nine lessons below run in the order that saves the most rework. Inventory before consent, consent before opt-out plumbing, and registration in parallel with all of it, because registration involves waiting on other people and you may as well start the clock.
None of this is legal advice, and a practice sending patient messages at any volume should have its own counsel read the underlying rules. What this is instead is the operational work: the parts you have to build regardless of how your lawyer reads the finer points.
What this guide covers, and what it deliberately does not#
This covers outbound text messages to patients from a US practice: reminders, recall, follow-up, and promotions. It covers consent, revocation, carrier registration, and the plumbing that connects them. It is written to the stricter reading of a rule currently under a waiver.
It does not cover voice calls, which have overlapping but distinct rules, nor email, which sits under different law again. It does not cover practices outside the US, where Canada's CASL and the UK and Irish regimes impose different and sometimes stricter obligations on the same message.
It also does not attempt to tell you whether a particular message is marketing. That determination is genuinely fact-specific, it depends on who paid for the message, and it is exactly the question worth paying a lawyer 1 hour for.
Registration decides whether your message is delivered. Consent decides whether you were allowed to send it. They are unrelated and you need both.
01Inventory every system that can send a patient a message#
The first lesson is the one that most often changes the shape of the problem, and it is deliberately boring. You cannot build one opt-out list until you know how many senders it has to serve.
- List your practice management or EHR system, and check whether its reminder module sends text as well as email.
- List any marketing or CRM tool, including anything a previous vendor set up and nobody has opened since.
- List review-request tools, which very often text and are very often forgotten.
- List online forms, intake tools, and booking widgets, several of which send confirmations.
- List anything a staff member does from a personal phone, which is a real category and a separate problem.
- For each, write down: what it sends, what number it sends from, and where it stores its opt-outs.
The last column is the one that matters and it is the one people cannot fill in. A sender whose opt-out storage you cannot name is a sender that will keep messaging someone who asked it to stop.
Expect the list to be longer than you assumed. A single-location practice commonly finds 3 or 4 systems capable of texting a patient, and a multi-location group frequently finds more than 6 systems doing it.
Two hiding places are worth checking explicitly, because neither shows up when you go looking system by system. The first is your own phone bill: an unfamiliar messaging line item usually has a tool attached to it that somebody forgot. The second is your outbound message logs for the last 30 days, sorted by sending number, which will surface any sender nobody remembered to mention.
Line 5 of the list, staff texting from personal phones, is not a compliance problem you can solve with plumbing, and it is worth separating for that reason. It is a policy and training problem, and it also carries a records issue: a message about a patient's care sitting on a personal handset is part of the practice's communication record and is not under the practice's control.
- 1Practice management systemAppointment reminders. Opt-outs stored in the patient record.
- 2Marketing or CRM toolRecall and promotions. Keeps its own separate suppression list.
- 3Review-request toolTriggered after a visit. Nobody has opened its settings in 2 years.
- 4Forms or booking widgetSends confirmations. Opt-out storage frequently unknown.
02Classify each stream by purpose, not by system#
Consent is not one permission. A patient who agreed to appointment reminders has not thereby agreed to promotions, and a system that records one flag called "SMS OK" cannot tell the difference between them.
Classify every message stream you found in lesson 1 against this:
| Purpose | Example | Where it sits |
|---|---|---|
| Treatment | Appointment reminder, pre-visit instructions | Outside HIPAA's marketing definition |
| Care coordination | Recall due, follow-up after a procedure | Outside marketing, per the same carve-out |
| Operational | Practice closed for weather, number changed | Neither treatment nor marketing |
| Marketing | Package offer, seasonal promotion | Marketing, and needs authorisation |
The HIPAA line here is narrower than people assume. Marketing means a communication about a product or service that encourages the recipient to buy or use it, and communications for the treatment of an individual, including case management and care coordination, are carved out of that definition [1].
That carve-out does most of the work for a normal practice. Reminders and recall are not marketing under HIPAA. A discount on a treatment package is, and calling it "patient education" does not move it.
Record the classification. You will need it in lesson 4, and you will need it again if a carrier ever asks what your campaign actually sends.
03Decide where consent lives before you record any#
There is one architectural decision in this whole guide and this is it. Every downstream problem follows from getting it wrong, and it is much cheaper to make now than after 18 months of records exist.
- Pick one system as the authority on consent and opt-out. Usually the practice management system, because it already holds the patient record.
- Confirm it can store consent per purpose rather than as a single boolean.
- Confirm every other sender can read from it, by API or by a scheduled sync you actually verify.
- If a sender cannot read from it, that sender is now a liability and you have found the real finding of this guide.
- Write down which system is the authority, and tell the staff who administer the others.
Step 4 is the one people skip past, and it is the whole point of doing this in lesson 3 rather than lesson 8. A marketing tool that cannot check your consent record is a tool that will eventually message someone who opted out, and no policy document prevents it.
A policy that says "honour all opt-outs" does nothing if the systems have no way to tell each other. Plumbing beats policy here.
The uncomfortable version of step 4 is that the answer is sometimes to retire a tool. That is a real cost and it is smaller than the alternative, which is discovering the gap after somebody complains.
There is a middle option worth considering before retiring anything. If a tool cannot read your consent record automatically but can accept an imported suppression list, a scheduled push every 24 hours is materially better than nothing, and it is honest to write down that the window exists. What it cannot do is satisfy a same-day revocation, so treat it as a stopgap with a stated gap rather than a solution.
A daily sync is not a shared list. It is a shared list with a 24 hour hole in it, and the hole belongs in the written record.
04Record consent so a machine can check it#
Consent on paper is real consent and it is useless to an automated sender, which cannot read a filing cabinet. The record has to carry enough for a system to answer "may I send this specific message to this specific person right now".
Five fields do it. Anything less and you will be reconstructing intent from a timestamp:
| Field | Why it is needed |
|---|---|
| Phone number | The thing consent attaches to, not the patient, since numbers move |
| Purpose | Which of the four categories from lesson 2 this covers |
| Captured at | The timestamp, since consent has to predate the send |
| Method | Web form, intake paperwork, verbal at the desk, inbound text |
| Evidence | The form submission, the recording reference, or the staff member |
Attaching consent to the number rather than to the patient is the field practices most often get wrong, and it matters because numbers get reassigned. A patient who changes carrier and gives up a number leaves that number with someone who never consented to anything.
Record method honestly. A verbal "yes, texting is fine" at the desk is legitimate consent and it is weaker evidence than a signed form, and knowing which you have is the difference between defending a complaint and guessing.
Two operational details follow from attaching consent to the number. First, when a patient updates their phone number, the old consent does not travel with them: capture it again against the new number rather than copying the flag across. Second, a number that has been unreachable for 6 months or more is worth flagging for re-confirmation, since carrier reassignment is invisible to you and the person now holding it never agreed to anything.
Neither of these is required by a rule you can point at. Both are the difference between a consent record that describes the world and one that describes the world as it was 3 years ago.
- ✓Phone number, because consent attaches to the number and numbers get reassigned
- ✓Purpose, one of treatment, care coordination, operational, or marketing
- ✓Captured at, since consent has to predate the send
- ✓Method, whether web form, paperwork, verbal, or inbound text
- ✓Evidence, the submission, recording reference, or staff member
05Build one opt-out list every sender checks#
This is the lesson the 2027 rule is actually about. The requirement heading toward you is that a revocation received in response to one type of message applies to every regulated message you send that person, and a practice with per-system opt-out lists cannot satisfy it.
- Create one opt-out table in the system you named in lesson 3, keyed on phone number.
- Make every sender check it immediately before sending, not on a nightly sync.
- Make every inbound reply channel write to it, including replies to numbers you rarely think about.
- Test it by opting a test number out through one channel and attempting a send from each of the others.
- Record the test result and the date, because an untested opt-out list is an assumption.
Step 4 is not optional and it is the step that finds the bugs. Practices that run it routinely discover one sender that never checks, usually the one installed longest ago by a vendor who is no longer engaged.
There is an argument for going further than the rule requires, and it is the position we took in our own product. One opt-out ending everything is stricter than today's requirement, and building to today's requirement means rebuilding when the waiver lapses. It also means a patient who asked once does not have to ask twice.
Where the rule is enforced matters as much as what it says. A check written in application code applies to the application and to nothing else: not to a script somebody runs by hand, not to an automation node a vendor added, not to a bulk import. A constraint enforced in the database applies to all of them, including the paths nobody remembered. That is the reason our own consent and opt-out rules live in the database rather than in TypeScript, and it is a reasonable question to put to any vendor.
| Per system | One shared list | |
|---|---|---|
| Patient opts out of reminders | Reminders stop | Everything stops |
| Marketing tool learns about it | Never | On its next send check |
| Meets the 2027 provision | No | Yes |
| Cost to build | Nothing, it is the default | Days, plus retiring anything that cannot read it |
06Handle the replies that are not the word STOP#
Every messaging platform recognises STOP. Real patients write "stop texting me", "remove me please", "wrong number", and "who is this", and a keyword matcher looking for 1 exact word misses all 4 while the clock runs.
The clock is real. A request to revoke consent, made in any reasonable manner, must be honoured within a reasonable time not to exceed 10 business days from receipt [2]. "Any reasonable manner" is the operative phrase: a patient does not have to use the magic word, and a request made to your receptionist counts.
- Expand keyword matching well beyond STOP, including misspellings and multi-word phrases
- Route anything ambiguous to a human within 1 business day rather than guessing
- Give front-desk staff a documented way to record a verbal opt-out in the authority system
- Treat "wrong number" as an opt-out, because the consent on file belongs to someone else
- Check what your platform does with a reply it does not recognise, since silence is the dangerous default
The rule does permit one confirmation. A single message confirming the revocation is allowed provided it only confirms, carries no marketing content, and is the only further message sent, and a confirmation sent within 5 minutes of receipt is presumed to fall inside the existing consent [2].
The "wrong number" row deserves emphasis. It is the one staff most often deprioritise and it is the one where continuing to send is least defensible, because by definition the person receiving the messages never consented.
07Register for A2P 10DLC before you need it#
This is the carrier layer and it is entirely separate from consent. Registration decides whether your messages get delivered at all, and it involves waiting on third parties, which is why it belongs in parallel with everything above rather than at the end.
- Determine your customer type. A practice sending its own messages is a Direct Brand, which needs a business Tax ID rather than a Social Security Number [3].
- Register the Brand, which tells carriers who is sending.
- Register a Campaign, which describes your message purpose and how patients opt in, opt out, and get help [3].
- Attach your sending numbers to the messaging service linked to the approved campaign.
- Wait. New campaign registrations go through manual vetting, carry a $15 verification fee at external vetting, and the process can take up to 1 week [3].
Unregistered traffic does not fail loudly in a way anyone notices. Messages sent to US numbers from an unregistered 10DLC number are blocked, and the practice discovers it when patients mention they stopped getting reminders [3].
Your campaign description has to match what you actually send, and this is where the lesson 2 classification pays for itself. Traffic that does not match the registered use case is a documented cause of brand suspension, alongside inaccurate descriptions of purpose, opt-in, and opt-out [3].
That mismatch is easy to create without meaning to. A practice registering a campaign described as appointment reminders, then adding a seasonal promotion 6 months later, has changed what it sends without changing what it declared. The promotion is the message most likely to draw a complaint, and a complaint against a brand whose declared use case does not cover it is the worst version of that conversation.
The practical rule is to register the broadest accurate description of what you send, not the narrowest one that sounds most benign. A campaign covering reminders, recall, and occasional practice promotions is honest and approvable. One covering only reminders is neither, if you also promote.
Volume matters too, and it is worth knowing before you pick a campaign type. Lower-volume campaign types exist with lower monthly fees and lower throughput, bounded at fewer than 2,000 message segments per day on at least one major carrier [3]. A practice sending 200 messages a day is comfortably inside that. One sending recall blasts to 5,000 patients in an afternoon is not, and will find out through filtering rather than through a warning.
- Day 1Register the BrandWho is sending. Needs a business Tax ID for a Direct Brand.
- Day 1Register the CampaignPurpose, opt-in, opt-out and help language.
- Up to 1 weekManual vettingA $15 verification fee applies at external vetting.
- On approvalAttach numbersNumbers join the messaging service linked to the campaign.
08Time the clock, not just the outcome#
Most practices measure whether an opt-out was honoured. The rule measures how long it took, and a process that always gets there eventually can still be non-compliant.
- Timestamp receipt of every revocation, however it arrived.
- Timestamp the moment the last sender stopped being able to message that number.
- Report the gap in business days, and alert on anything over 2.
- Test the process against your worst case, not your normal one.
Step 4 is the one that matters. A manual process handled by one person is entirely reasonable at 3 or 4 opt-outs a month, and it is fragile in a specific way: a request arriving the Friday before someone takes 2 weeks off has consumed most of its 10 business days before anyone reads it.
The test is not whether the process works on a normal Tuesday. It is whether it works during the worst week of the year, when the person who normally handles it is away and the practice is short-staffed.
Alerting at 2 business days rather than at 10 is deliberate. The rule caps the honour time at 10 business days, which in a normal calendar is 2 full weeks, and a process that only alarms at the deadline gives you no room to fix anything. An alert at 2 days is a process problem you can still solve; an alert at 9 days is an incident.
If you want the same measurement discipline applied to the rest of your front office rather than only to opt-outs, size your missed-call gap applies the same evidence-first approach to your call records.
09Write the one-page record#
The last lesson makes the previous 8 durable. Everything above is invisible unless it is written down, and the value of the written version is that someone who was not there can check it.
- Every system that can send a patient a message, with what it sends and where its opt-outs live
- Which system is the authority on consent, decided in lesson 3
- The purpose classification for each stream
- The 5 consent fields, and where they are stored
- The date you tested the cross-sender opt-out, and the result
- Your Brand and Campaign registration status and use case
- Your measured opt-out honour time over the last 3 months
- The date of this page and who wrote it
Review it every 6 months, and immediately whenever a new tool is added. New tools are how this decays: a practice that did all 9 lessons correctly in March and installed a review-request tool in August is back where it started and does not know it.
- Which system is the authority on consent
- The 5 consent fields
- Your Brand registration
- The purpose classification
- The sender inventory, the moment a tool is added
- The cross-sender opt-out test result
- Campaign use case, if what you send changes
- Opt-out honour time, whenever staffing changes
What changes on 31 January 2027#
The specific provision heading for that date requires a revocation made in response to one message type to be applied to all future regulated calls and texts from you, including on unrelated subjects. That is the requirement per-system opt-out lists cannot meet, and it is why lessons 3 and 5 sit where they do.
It has moved twice, from April 2025 to April 2026, and then again on 6 January 2026 to 31 January 2027 [4]. Both delays were granted because regulated firms could not build in time, not because the requirement was reconsidered, which is a meaningfully different thing from a rule being abandoned.
The practical reading is that a practice which completes these 9 lessons is compliant with the current rule, ready for the delayed one, and has better messaging hygiene either way. Nothing here is wasted if the date moves a third time. How Velaire itself handles consent, opt-out and the send window is on patient messaging, and what a front desk actually costs covers the economics of the systems doing the sending.


