Skip to main content
Guide

SMS & Text Message Marketing for Healthcare: HIPAA, TCPA & State Rules in 2026

Between January 1 and November 30, 2025, plaintiffs filed [1]thousands of TCPA lawsuits, with healthcare organizations a recurring target. At the same time, HHS Office for Civil Rights (OCR) closed...

13 min read

SMS & Text Message Marketing for Healthcare: HIPAA, TCPA & State Rules in 2026

Between January 1 and November 30, 2025, plaintiffs filed [1]thousands of TCPA lawsuits, with healthcare organizations a recurring target. At the same time, HHS Office for Civil Rights (OCR) closed one of its busiest enforcement years on record. For healthcare marketers, this is the operating reality of healthcare SMS HIPAA TCPA compliance in 2026: a single misconfigured text campaign can simultaneously trigger an OCR investigation, a class action under the federal TCPA, and parallel claims under state "mini-TCPA" statutes like Florida's FTSA and Texas's SB 140.

This guide explains how text message marketing healthcare programs are regulated under HIPAA, the TCPA, and the rapidly growing patchwork of state laws, what penalties look like in 2026, how violations actually happen, and concrete steps practices can take this week, this month, and over the long term to reduce risk.

The Current Enforcement Landscape

OCR Enforcement Trends Shaping Healthcare SMS HIPAA TCPA Risk

OCR enforcement has accelerated meaningfully. [2]In 2022, OCR resolved 22 HIPAA violation cases with financial penalties; enforcement dipped to 13 in 2023, then rose to 16 in 2024 and 21 in 2025. Through the cumulative life of the program, [3]OCR has settled or imposed civil money penalties in 152 cases, with total collections of approximately $144.9 million.

OCR's most-cited violation category in recent matters has been inadequate risk analysis, which prompted increased OCR focus on Security Rule risk-analysis enforcement. A representative result: [4]a $1.19 million civil monetary penalty against Gulf Coast Pain Consultants for alleged HIPAA Security Rule violations after a breach notification triggered the investigation.

FTC and OCR Tracking-Technology Focus

The intersection of marketing technology and HIPAA is now a dedicated enforcement lane. OCR's bulletin on online tracking technologies, originally published December 1, 2022 and updated March 18, 2024, makes clear that [5]regulated entities may not impermissibly disclose PHI to tracking technology vendors and that OCR is prioritizing HIPAA Security Rule compliance in investigations into the use of online tracking technologies. In July 2023, OCR and the FTC sent joint warning letters to approximately 130 hospitals and telehealth providers about the risks of these technologies and the potential for impermissible PHI disclosures. Many healthcare marketers send promotional texts through vendors that handle phone numbers, click data, and conversion identifiers, exposing them to dual FTC and OCR jurisdiction when something goes wrong.

Class-Action Lawsuit Explosion

Private litigation is now the dominant financial risk. Under 47 U.S.C. § 227, the TCPA provides for statutory damages of [11]$500 per violation, which a court may in its discretion increase up to three times that amount if the defendant willfully or knowingly violated the statute, with no aggregate cap. A single SMS campaign sent to thousands of patients without valid consent can therefore expose a provider to substantial statutory damages before defense costs. Pixel-based healthcare class actions piggyback on this pattern: following widely reported journalism in 2022 showing that the Meta Pixel was deployed on a substantial share of top hospital websites, multiple class actions were filed against named providers under privacy tort, state privacy, and federal wiretap theories (because HIPAA itself has no private right of action).

State-Level Actions Driving New Healthcare SMS HIPAA TCPA Exposure

State mini-TCPA statutes now create independent exposure on top of federal law. [6]Florida's FTSA (Fla. Stat. § 501.059) requires consent for auto-dialed calls and texts and provides a private right of action: claimants may obtain $500 per violation or actual damages (whichever is greater), trebled for willful or knowing violations.

Texas joined the mini-TCPA states in 2025. [7]Texas SB 140, effective September 1, 2025, extends the telephone-solicitation law to text marketing, adds registration requirements, and expands private suits with penalties reaching $1,500 per text (trebled for willful violations); state AG enforcement can seek up to $5,000 per violation. SB 140 also explicitly allows consumers to recover multiple times from the same defendant.

For broader analysis of state-level data and AI rules that interact with SMS programs, see our coverage of the Texas TDPSA and healthcare data collection rules and state AI disclosure rules in Colorado, Texas, and Utah.

Specific Risks & Consequences

Financial Penalties

HIPAA penalties are tiered and inflation-adjusted annually, with per-violation amounts running from low-tier minimums into seven figures at the highest culpability tier under OCR's enforcement discretion. Layered TCPA and state mini-TCPA damages compound the exposure:

  • OCR civil monetary penalties: Tiered per-violation amounts with annual caps that have risen significantly through annual inflation adjustments
  • TCPA statutory damages: $500 per violation, trebled up to $1,500 for willful or knowing violations, with no aggregate cap
  • Florida FTSA: $500 per call/text, trebled for willful or knowing violations
  • Texas SB 140: Private actions up to $1,500 per text (treble for willful); AG enforcement up to $5,000 per violation; recovery is not limited by prior recoveries
  • Criminal HIPAA penalties: Up to 10 years' imprisonment for knowing violations involving intent to sell, transfer, or use PHI for commercial advantage or malicious harm

Reputational Damage

OCR maintains a public-facing breach portal (commonly called the "Wall of Shame") that lists every breach affecting 500 or more individuals. For SMS-related disclosures involving sensitive conditions (mental health, reproductive health, substance use), the reputational consequences can outlast the financial ones. Cases involving reproductive health information disclosed without consent, for example, draw disproportionate media coverage and patient-trust impact.

Operational Disruption

OCR investigations are long-running and resource-intensive. OCR often prefers settlements because it can negotiate ongoing monitoring and Corrective Action Plans, an option unavailable when it imposes a civil monetary penalty. A typical CAP imposes multi-year reporting, vendor audits, policy rewrites, and outside-monitor obligations that consume compliance bandwidth long after the press release.

Personal Liability

Criminal HIPAA penalties exist for knowing violations, and OCR refers appropriate cases to the Department of Justice for criminal investigation. Executives can face personal exposure where they had decision-making authority over the practices that led to the violation, and cyber/E&O insurance policies frequently exclude or sub-limit regulatory penalties and intentional acts.

How Violations Happen

The TCPA Trap: Treatment vs. Marketing

The healthcare exemption under the TCPA is narrower than most marketers realize. [8]To qualify, a call or text must not include telemarketing, solicitation, or advertising content; must not pertain to accounting, debt collection, or financial information; must comply with HIPAA privacy rules; must be 160 characters or less; providers may send only one message per day, up to a maximum of three combined calls or texts per week; and each message must offer an easy opt-out (such as replying STOP), with all opt-out requests honored immediately.

A "wellness reminder" text that promotes a new service, recommends an upsell, or includes financial language can lose exemption status and convert into a marketing message that requires prior express written consent.

Revocation Rule Changes Effective April 11, 2025

The FCC's revocation rules dramatically expanded patient opt-out rights. [9]A consumer can now withdraw consent in "any reasonable manner that clearly expresses his or her desire not to receive further calls," and the FCC has identified standardized keywords that must be honored as explicit revocation requests, including "stop," "quit," "revoke," "opt out," "cancel," "unsubscribe," and "end." Consumers may respond in the language in which they received the communication.

Days before the April 11, 2025 effective date, the FCC issued a limited waiver delaying the so-called "revoke all" provision of 47 CFR § 64.1200(a)(10), which would require callers to treat a revocation made in response to one type of message as applicable to all future communications on unrelated matters. [10]The FCC found good cause to delay the effective date of that requirement until April 11, 2026, to allow affected parties (including healthcare organizations) a reasonable opportunity to implement modifications to communications systems in a cost-effective manner. Healthcare organizations should not interpret the waiver as a holiday: the other revocation requirements, including the 10-business-day opt-out processing rule, took effect on schedule.

One-to-One Consent: Vacated but Not Dead

On January 24, 2025, the Eleventh Circuit issued its decision in Insurance Marketing Coalition v. FCC, vacating the FCC's one-to-one consent rule and remanding it to the agency after finding that the rule exceeded the FCC's statutory authority under the TCPA. However, healthcare marketers should not treat the vacatur as a green light to bundle consents: state mini-TCPAs (notably Florida's FTSA, with its prior-express-written-consent requirement) and CMS rules for Medicare marketing impose stricter consent expectations independent of the vacated federal rule.

HIPAA Marketing Triggers in SMS

Under the HIPAA Privacy Rule, "marketing" means a communication about a product or service that encourages recipients to purchase or use it; generally, if the communication is "marketing," the covered entity must first obtain the individual's authorization. If the marketing involves direct or indirect remuneration to the covered entity from a third party, the authorization must state that such remuneration is involved.

SMS programs commonly cross the line by:

  • Including a patient's condition, medication, or diagnosis in the message body, converting routine reminders into impermissible PHI disclosures over unencrypted SMS
  • Sending cross-sell promotions (cosmetic add-ons, supplement sales, partner offers) using lists derived from PHI without authorization
  • Sharing phone numbers and click data with SMS vendors that lack a signed Business Associate Agreement
  • Using URL parameters or short links that transmit patient identifiers to ad networks when the recipient taps the message

Vendor and BAA Gaps

OCR's tracking technologies guidance is unambiguous: regulated entities must have BAAs with vendors that receive PHI through trackers, including those embedded in SMS landing pages, link-shorteners, and analytics tools. Many SMS platforms offer BAAs only on enterprise tiers, and subcontractor chains (carriers, link-shorteners, analytics pixels embedded in landing pages) are often unaccounted for in the regulated entity's BAA inventory.

Protection Strategies

Immediate Actions (This Week)

  1. Inventory every SMS campaign and template. Classify each as treatment, healthcare operations, or marketing under HIPAA, and as informational or telemarketing under the TCPA.
  2. Pull every BAA. Confirm signed agreements with your SMS platform, CRM, scheduling system, and any URL-shortening or analytics vendor that touches the message flow.
  3. Audit message content for PHI. Remove diagnoses, medications, and specialty references from any non-encrypted SMS template.
  4. Test your opt-out. Send STOP, "unsubscribe," "remove me," and a non-English variant. Confirm each is honored within the FCC's 10-business-day window.

Short-Term Fixes (This Month) for Healthcare SMS HIPAA TCPA Compliance

  1. Rebuild consent capture. Use a clear, standalone opt-in that names your practice, identifies the message types, discloses frequency, and states "Msg & data rates may apply."
  2. Document remuneration. If any third party is paying for the message, build a HIPAA-compliant authorization that includes the required Remuneration Disclosure.
  3. Map state residency. Tag every contact record by state and apply the strictest applicable rule for Florida, Texas, and other mini-TCPA jurisdictions.
  4. Train staff. Marketing, front-desk, and clinical teams should know what content triggers marketing classification and what to do when a patient opts out.

Long-Term Compliance Infrastructure

  • Consent and preference management: A centralized system that records opt-ins, opt-outs, revocation method, timestamps, and channel scope, retained for the TCPA's four-year statute of limitations period
  • Server-side, BAA-covered tracking: Replace pixel-based attribution on SMS landing pages with server-side tracking that strips PHI before data reaches ad platforms
  • Quarterly audits: Sample messages, consent records, opt-out timing, and vendor subcontractor lists
  • Documented risk analysis: Given OCR's increased focus on risk analysis, ensure SMS systems are explicitly covered in your annual security risk analysis

Vendor Evaluation Criteria

  • BAA availability: Signed, no-exception BAA on the tier you actually use, not an enterprise upcharge
  • Encryption and access controls: End-to-end encryption, role-based access, audit logging, and remote wipe capability
  • Healthcare-specific controls: PHI scrubbing on outbound messages and inbound replies, quiet-hours enforcement by recipient time zone, frequency caps
  • SOC 2 Type II or HITRUST: Independent third-party attestation

For specialty-specific guidance, see our analysis of psychiatric medication management marketing and Texas HB 300 healthcare marketing requirements.

How Curve Addresses Each SMS Compliance Risk

Curve was built for the exact intersection of risks described above: HIPAA-regulated PHI flowing through marketing systems designed for retail, not healthcare.

  • Automated PHI stripping: Curve removes the 18 HIPAA identifiers from data before it reaches ad platforms or analytics destinations, addressing the technical risk that turns routine SMS attribution into an impermissible disclosure.
  • Server-side tracking: Conversion events from SMS landing pages are processed server-side and de-identified, so platform-level pixels never see raw patient data.
  • Signed BAAs included: Every Curve deployment includes a signed Business Associate Agreement, eliminating the most common vendor compliance gap in SMS marketing stacks.
  • Audit trails: Curve maintains detailed logs of what data was collected, what was stripped, and what was transmitted, providing the documentation OCR and state AGs expect during investigations.
  • Healthcare-specific design: Curve is configured for healthcare conversion events, intake flows, and the specific patterns that create HIPAA exposure in SMS programs.
  • Rapid implementation: Healthcare organizations typically move from contract to compliant tracking in days, not the months associated with custom server-side builds.

Frequently Asked Questions

What are the penalties for HIPAA marketing violations?

HIPAA civil monetary penalties in 2026 are tiered and inflation-adjusted, with per-violation amounts ranging from low-tier minimums into seven figures at the highest culpability tier. TCPA statutory damages add $500 per violation, trebled up to $1,500 for willful or knowing violations, with no aggregate cap. State laws can stack additional penalties: Florida's FTSA awards $500 per call/text (trebled for willful), and Texas SB 140 reaches $1,500 per text under private actions and $5,000 per violation under AG enforcement. Criminal penalties for knowing violations can include up to 10 years' imprisonment.

Can healthcare practices be sued for sending non-compliant texts?

Yes. Florida's FTSA and Texas's SB 140 grant private rights of action, meaning patients can sue directly. TCPA class actions also routinely seek aggregate damages in the millions. While HIPAA itself has no private right of action, plaintiffs in pixel and tracking cases have pleaded state privacy, wiretap, and common-law tort claims to reach healthcare providers whose SMS landing pages transmitted PHI to ad platforms.

How do I know if my healthcare SMS program is compliant?

Compliance requires simultaneous alignment with (1) HIPAA's marketing authorization and Security Rule requirements, (2) the TCPA's consent, content, and frequency rules including the healthcare exemption conditions, (3) FCC revocation rules effective April 11, 2025, and (4) every applicable state mini-TCPA. A practical test: can you produce, for any patient who received a text in the last four years, a documented consent record, the message content sent, and proof that any opt-out was honored within 10 business days?

What should I do if I discover a compliance violation?

Stop the offending campaign immediately, preserve all logs and consent records, and engage healthcare privacy counsel before any external communication. If PHI was disclosed impermissibly to 500 or more individuals, breach notification timelines under HIPAA and the FTC Health Breach Notification Rule apply (generally without unreasonable delay and within 60 days). Voluntary disclosure with a credible corrective action plan typically results in better outcomes than waiting for an OCR investigation triggered by a patient complaint.

Does the TCPA healthcare exemption mean I don't need consent for appointment reminders?

The exemption is narrow. The message must come from a HIPAA-covered entity or business associate, be sent only to the number the patient provided, contain no marketing or financial content, stay within 160 characters, and respect frequency limits of one per day and three per week. After the April 11, 2025 FCC revocation rules, any STOP request must be honored within 10 business days, and once the delayed cross-channel provision takes effect, an opt-out on one program will apply across the organization's automated communications.

Self-Assessment Compliance Checklist

  • Consent records: We can produce written, time-stamped opt-in records for every SMS recipient, retained at least four years
  • Message classification: Every template is documented as treatment, operations, or marketing under HIPAA and as informational or telemarketing under TCPA
  • BAAs in place: Signed BAAs with SMS platform, CRM, URL shortener, analytics, and any subcontractor touching message data
  • PHI scrubbed: No diagnoses, medications, or specialty identifiers appear in unencrypted SMS
  • Opt-out tested: STOP, alternative phrases, and non-English opt-outs are honored across channels within 10 business days
  • Quiet hours enforced: Messages sent within permitted hours under federal and applicable state law (with stricter local windows applied where state law requires)
  • Frequency caps: Maximum one message per day, three per week, per provider for TCPA-exempt healthcare messages
  • State tagging: Contact records tagged by state with strictest applicable rule applied, including FTSA and Texas SB 140
  • Risk analysis updated: SMS systems explicitly included in annual HIPAA Security Rule risk analysis
  • Marketing authorization: Written, HIPAA-compliant authorizations on file for any SMS that promotes a product or service using PHI
  • Remuneration disclosed: Third-party payment for any promotional message is disclosed in the authorization
  • Audit trail: Logs capture what was sent, when, to whom, and what data was transmitted to downstream platforms

Don't Wait for Enforcement

Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve to map your current SMS and tracking stack against HIPAA, TCPA, and 2026 state rules, identify the gaps that create the largest exposure, and implement PHI-stripped, BAA-backed infrastructure before regulators or plaintiffs find them first.

Sources

  1. Goodwin: CFS 2025 Year-in-Review TCPA and Mini TCPAs
  2. HIPAA Journal: HIPAA Violation Cases (Updated 2026)
  3. HHS OCR: Enforcement Highlights
  4. HHS OCR: Gulf Coast Pain Consultants Notice of Proposed Determination
  5. HHS OCR: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
  6. Morrison Foerster: Uptick in Florida Telephone Solicitation Act Litigation
  7. Morgan Lewis: Texas Telephone Solicitation Law Now Covers Texts (SB 140)
  8. Bass, Berry & Sims: TCPA Exemptions for Healthcare Companies
  9. Nixon Peabody: FCC Partially Delays New TCPA Consent Revocation Rules
  10. FCC Order DA 25-312 (April 7, 2025): Limited Waiver of TCPA Consent Revocation Rule
  11. Cornell Law: 47 U.S.C. § 227 (Telephone Consumer Protection Act)

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit