Limited offer on the Dental GHL Snapshot · Closing in· Closing in00d00h00m00s
Blog

Can You Legally Text Your Dental Patients? The 2026 Rules on HIPAA, Consent, and Reviews

Texting patients fills the schedule, but three separate rulebooks decide whether you are doing it legally. Here are the 2026 HIPAA, TCPA, and FTC rules for a dental front office, with sample consent language and message copy you can steal.

September 21, 2026 · 16 min read · by Devin Okafor

#Tier 4#Compliance#hipaa#tcpa#ftc-review-rule#patient-texting#review-gating#national

It is 7:52am. The coffee is still brewing and you are already thumbing through tomorrow’s schedule, looking at the gaps. Two hygiene slots open, a crown seat that has not confirmed. So you fire off a batch of reminder texts. One, sent by the newest front-desk hire, reads: “Hi Karen, reminder for your crown prep and perio charting tomorrow at 2, balance due $340.”

That single text just broke two federal rules. And the friendly “How was your visit? Tap the thumbs-up for a Google review” flow your last software rep sold you is a liability too.

Here is the short version, so you can breathe: yes, you can absolutely text your patients, and you should. It is one of the cheapest ways to fill the hygiene column and cut no-shows. But three rulebooks govern how, written by three agencies that do not talk to each other, and getting any one wrong is expensive. This is the plain-English version, plus copy you can steal.

Do-and-dont infographic titled What a HIPAA-Compliant Patient Text Can and Cannot Say. OK to send: practice name, date and time, provider first name, reschedule or confirm link. Never send: procedure name, diagnosis, account balance, treatment plan. Footnote: HIPAA minimum necessary standard.

What this article covers

What one mistake actually costs

Front offices treat texting and review requests as marketing chores. The agencies that write the rules treat them as consumer-protection issues with per-message penalties.

$53,088
FTC penalty per review-rule violation (knowing)
$1,500
TCPA damages per unlawful text (willful)
$1,500
Florida FTSA damages per text
1 in 3
Dentists who say they are not busy enough (Q4 2025)

This matters because nobody can afford to just stop texting. In Q4 2025, one in three dentists reported they were not busy enough and could treat more patients, up from one in four a year earlier, per the American Dental Association’s Health Policy Institute State of the U.S. Dental Economy report. When that many practices have open chairs, reminder and recall texts are how you fill them. The answer is never “text less.” It is “text correctly.”

These are not theoretical. The FTC began sending warning letters under the review rule in early 2026, TCPA text lawsuits are a cottage industry, and the state laws below let patients sue you directly, per message.

The three rulebooks, in plain English

A single message clears three checkpoints: HIPAA decides what you can say, the TCPA plus state mini-TCPA laws decide whether you can send it, and the FTC review rule governs how you ask for reviews. Here is each, how it breaks, and the fix.

Rule 1: HIPAA decides what a text can say

Start with the good news, because most people get this backward. HIPAA does not ban texting patients. The Privacy Rule permits using patient information for appointment reminders, and Health and Human Services says so in its guidance on appointment reminders.

What HIPAA controls is the content, through the minimum necessary standard: share only what the patient needs to act on the message. A text shows up on a lock screen, in front of whoever holds the phone.

A compliant text can include: the practice name, the date and time, the provider’s first name, a reschedule or confirmation link, and directions.

A compliant text must never include: the procedure (“crown prep,” “extraction”), any diagnosis, the balance, treatment-plan specifics, or anything that reveals why they are coming in.

“See you tomorrow at 2 with Dr. Lin” is fine. “See you tomorrow for your root canal” discloses health information to whoever picks up the phone.

How it breaks in a real front office:

  • An old reminder template quietly includes the appointment type, so every “hygiene recall” text is a small disclosure.
  • A patient asks for their statement and a team member texts a photo of the ledger. That balance is now on a lock screen.
  • Someone texts from a free app or personal phone because “it was faster,” with no BAA and no audit trail.

The fix: strip every template to who, when, and where; route anything financial or clinical to a portal or a call.

Rule 2: TCPA decides whether you can send it

HIPAA says you can text. The Telephone Consumer Protection Act says only with consent, and splits messages into two buckets.

Informational texts (appointment reminders, recall nudges) need prior express consent: the patient gave you their mobile number for their care. A number written on your intake form for appointments generally clears this bar.

Marketing texts (a whitening promo, a holiday special) need prior express written consent: a clear, affirmative agreement to receive marketing, tied to the number.

There was a recent scare worth clearing up. The FCC tried to add a stricter “one-to-one consent” rule, but in January 2025 the Eleventh Circuit vacated it in Insurance Marketing Coalition v. FCC, and the FCC declined to appeal. The takeaway: a single, well-written consent line on your intake form is still valid. You just need that line and you must honor opt-outs.

How it breaks in a real front office:

  • The intake form has no consent language, so every text technically lacks documented consent.
  • A team member pulls a number off an insurance card or referral and texts it. The patient never gave you that number.
  • A patient replies STOP, then gets a recall text three months later. That single message is a fresh violation.

The fix: one consent line (below), a tool that auto-processes STOP, and a rule that you only text numbers the patient gave you.

Rule 3: State mini-TCPA laws stack on top

Here is the part most software reps skip. Even after you clear the federal TCPA, individual states have tougher laws that follow where the patient is, not where your practice is. A snowbird who winters in Florida can pull your Ohio practice under Florida law. The big four:

  • Florida (FTSA). Requires written consent for automated marketing texts, limits sending to 8am to 8pm local time, and lets patients sue for $500 to $1,500 per text. See the state statute.
  • Oklahoma (OTSA). Closely mirrors Florida, with the same written-consent requirement.
  • Washington (CEMA). Requires consent for commercial texts and pairs with the state Consumer Protection Act for damages.
  • Maryland (Stop the Spam Calls Act). Requires express consent and detailed records, with penalties in the thousands per violation.

A growing patchwork of other states is following. Do not try to memorize all fifty. Hold to the strictest common denominator, written marketing consent, quiet hours of 8am to 8pm in the patient’s time zone, and clean opt-outs, and you are compliant everywhere at once.

How it breaks: a promo blast goes out at 7:15am your time, which is 6:15am two zones west. Or a Florida patient with no written consent gets a whitening text. Either is a per-message claim under state law.

Compliant patient texting, already wired up

Consent capture, automatic STOP handling, quiet-hours scheduling, and reminder templates that never leak PHI, all pre-built into the $997 Dental GHL Snapshot and installed within 24 hours.

Rule 4: A2P 10DLC decides if it even arrives

This one is not a law. It is a carrier requirement, and it is why your texts sometimes just vanish. Business texting over a standard 10-digit number (A2P 10DLC, for “application-to-person”) has to be registered: your practice as a “brand,” your texting program as a “campaign,” approved by the carriers.

Skip it and messages get filtered, throttled, or silently dropped. No bounce, no error, just a reminder that never arrived.

How it breaks: you text from an unregistered number, delivery quietly sinks, and the team assumes patients are ignoring them when they never saw the texts. Our SMS marketing playbook covers registration; the short version is register first, on a platform that handles it.

Rule 5: The FTC review rule and why gating is dead

This is the one that catches almost everyone, because so many dental “reputation” tools were built to do the thing that is now a liability. Two rulebooks apply.

The FTC rule. The Federal Trade Commission’s Rule on the Use of Consumer Reviews and Testimonials took effect on October 21, 2024. It bans fake reviews, paid reviews, and review suppression: using threats to stop negative reviews, or presenting a set of reviews as complete when some were held back by rating. Per the rule’s official Q&A, it applies whether you suppress reviews yourself or hire a tool to. Knowing violations can cost up to $53,088 per violation in 2025.

Google’s policy. Google is more direct about gating. Its prohibited content policy for Business Profiles flatly bars “discouraging or prohibiting negative reviews, or selectively soliciting positive reviews from customers.”

Stats slide titled What one texting or review mistake can cost, showing 53,088 dollars FTC review-rule penalty per violation, 1,500 dollars TCPA damages per unlawful willful text, 1,500 dollars Florida FTSA damages per text, and 1 in 3 dentists not busy enough in Q4 2025. Sources: FTC 2025, TCPA 47 U.S.C. 227, Florida FTSA, ADA Health Policy Institute.

Review gating is the “smart” flow you have almost certainly been pitched: text every patient “How was your visit?” with a thumbs-up and a thumbs-down, route thumbs-up to Google, and route thumbs-down to a private form so it never becomes a public review. It breaks Google’s rules outright, and the harder it hides unhappy patients, the closer it drifts to the FTC’s suppression provision. Either way, you are engineering your public rating.

  1. •
    Aug 2024

    FTC finalizes the review rule

    Bans fake reviews, paid reviews, and review suppression.

  2. •
    Oct 21, 2024

    Rule takes effect

    Knowing violations cost up to $51,744 each, later adjusted to $53,088.

  3. •
    Jan 24, 2025

    Court vacates FCC one-to-one consent rule

    A single well-drafted consent still works.

  4. •
    Apr 2025

    FCC declines to appeal

    The one-to-one rule stays dead.

  5. •
    Early 2026

    FTC sends warning letters

    Review-rule enforcement begins in earnest.

Sources: FTC press release and rule Q&A (2024); Morrison Foerster analysis of Insurance Marketing Coalition v. FCC (2025); Arnold & Porter reporting on FTC warning letters (2026).

03757501,1251,500500TCPA (base)1,500TCPA (willful)1,500Florida FTSA1,500Oklahoma OTSA

Statutory damages per unlawful text ($). Sources: federal TCPA, 47 U.S.C. § 227(b)(3); the Florida and Oklahoma Telephone Solicitation Acts. The FTC review-rule penalty of up to $53,088 per violation is in a different league.

Steal this: compliant copy for the whole patient journey

This is the part to bookmark. Every line below clears HIPAA, TCPA, and the FTC rule. Paste them into your forms and texting tool and most of your exposure is covered.

1. Intake-form consent line (covers TCPA and mini-TCPA):

By providing my mobile number, I agree to receive texts from [Practice Name] about my appointments and care, and occasional practice updates. Message and data rates may apply. Reply STOP to opt out anytime, HELP for help. Consent is not a condition of treatment.

2. Appointment reminder (HIPAA-safe, no PHI):

Hi [First Name], this is [Practice Name]. You have an appointment with Dr. [Last Name] on [Day] at [Time]. Reply C to confirm or call [phone] to reschedule.

No procedure, no reason for the visit, no balance. Who, when, where.

3. Recall / recare nudge (informational, no PHI):

Hi [First Name], it is [Practice Name]. It has been a while. We would love to get you back on the schedule: book here [link] or reply and we will help.

4. Review request (sent to EVERY patient, no gating):

Hi [First Name], thank you for visiting [Practice Name] today. If you have a moment, we would appreciate your honest feedback here: [direct Google review link]. It helps other families find us.

5. When a review is negative, respond publicly and take it offline (never suppress it):

Thank you for the feedback, [First Name]. We are sorry your visit did not meet expectations and we would like to make it right. Please call [name] at [phone] so we can help directly.

How this changes by practice size

The rules are the same for everyone. The exposure and the fix scale with the practice.

Solo or two-operatory practice. Your risk is the DIY setup: a personal phone or free app with no BAA, no consent line, no A2P registration. There is one system to clean up. Add the consent line, move to a platform that signs a BAA and auto-handles STOP, register A2P, and ask every patient for a review.

Mid-size practice (3 to 4 operatories). Now the risk is drift: team members text differently and old templates linger. Standardize on one platform, lock templates so nobody can add a procedure or a balance, keep one shared opt-out list, and kill any gating logic in an old automation.

Multi-location or DSO-affiliated group. Patients across states means multiple mini-TCPA laws at once and more vendors touching data, so you need a BAA with each. Hold every location to the strictest state standard, centralize opt-outs so a STOP at one office applies across the group, and run the same front-desk and insurance automations on one shared consent and audit trail.

The objections you are already thinking

“We have texted patients for years and nothing has happened.” True until it is not. TCPA and state-law claims come from individual patients and plaintiff’s attorneys, not an agency audit, so it stays quiet until one annoyed patient with an ignored STOP sends a demand letter.

“Won’t asking every patient for a review tank our rating?” The data does not support that fear. Most patients who had a normal visit leave no review at all, so you are widening the funnel, not unleashing one-stars: more reviews and a rating that looks human. Our full review playbook covers the “ask everyone” approach.

“Do I need to be technical to fix this?” No. A consent line is a form edit, cleaning a template is copy-and-paste, registering A2P is a guided form, and turning off gating is one switch. The hard part was knowing it needed doing.

FAQ

Can we text appointment reminders without written consent?

Reminders are informational messages, which under the TCPA need prior express consent, not the higher written-consent bar that marketing requires. A mobile number the patient gave you on your intake form for appointments, plus a clear consent line, clears it. Promotions do need written consent.

Is review gating actually illegal, or just against Google's rules?

Google's policies directly prohibit discouraging negative reviews or selectively soliciting positive ones, so a thumbs-up / thumbs-down flow that routes unhappy patients away from Google breaks Google's terms outright. Separately, the FTC's 2024 rule bans review suppression, and aggressively holding negatives back can cross into it, at up to $53,088 per violation. The safe path clears both: ask every patient the same way.

If a vendor sends our texts, do we get fined or do they?

Both can be exposed. HIPAA holds the practice responsible for using a business associate with no signed BAA, and holds the vendor responsible too. Under the TCPA and the FTC rule, the business the messages go out for is on the hook, and both explicitly cover conduct you hire a third party to perform. A vendor contract does not move the risk off you.

Do state mini-TCPA laws apply if our practice is not in Florida or Washington?

Yes, if the patient is there. These laws follow where the person receiving the message sits, so a snowbird or out-of-state patient can pull you under Florida, Oklahoma, Washington, or Maryland law. Hold to the strictest common standard: written marketing consent, quiet hours of 8am to 8pm in the patient's time zone, and instant opt-out handling.

Is a thumbs-up / thumbs-down feedback kiosk in the office legal?

Collecting private feedback is fine. Using it to decide who gets asked for a public Google review, so only happy patients reach Google, is the gating Google prohibits and can drift into the FTC's suppression rule. Ask every patient for a public review the same way, and use private feedback to improve, not to filter your rating.

Back to that 7:52am schedule

The gaps in tomorrow’s book are real, and texting is still the fastest way to fill them. Nothing here says stop. It says clean up the wording, add one consent line, register your number, and ask every patient for a review instead of just the happy ones. That is a morning of work, and it moves you from “quietly at risk” to “doing the smart thing correctly.”

If you would rather not audit all of this by hand, that is fair. It is easy to get 90 percent right and still miss the one template that leaks a procedure name, and that last 10 percent is where the fines live.

Not sure if your current texting and reviews are compliant?

Book a 20-minute walkthrough. We will review your reminder templates, consent capture, and review flow, and show you the gaps and fixes, whether or not you buy anything.

Ready to put this into practice?

Install the Dental GHL Snapshot in 24 Hours

Every workflow above — already built, refined across 80+ U.S. dental practices, installed for you for $997 one-time.

Book DemoGet Snapshot