Can you legally text patients and clients?

Yes, with the right consent and the right channel for the content. Standard SMS is not built for protected health information. A reminder with no clinical detail is a different case.

An admin approves every new account by hand. Nothing is created until then. We reply by email; no newsletter, no sequence.

app.salescrew.io/inbox
The unified reply inbox with classified threads

The short answer

  • Texting patients and clients is generally legal with proper consent. The content of the message decides what channel is appropriate. Standard SMS is not built to protect health information. A general appointment reminder with no clinical detail carries less risk.
  • Protected health information sent by text needs a secure, encrypted channel with a signed Business Associate Agreement in place. Standard consumer texting, including plain SMS, lacks the safeguards HIPAA is generally understood to require.
  • TCPA consent rules apply on top of any HIPAA consideration. Sending marketing or automated texts to any client, medical or not, generally requires prior express consent under the TCPA, independent of the HIPAA question.
  • The safer default for anything beyond a basic non-clinical reminder: get documented consent, disclose that standard text is not fully secure, and use a purpose-built secure channel for content that touches health information.

Why the content of the message decides the standard, not only the fact of texting

It is tempting to ask "can I text patients" as a single yes-or-no question. The honest answer splits on what the text says. A reminder that only confirms an appointment time, with no reference to the reason for the visit or any health detail, carries much less risk than a message that mentions a diagnosis, a medication, or treatment specifics. The first kind is commonly handled over standard SMS with patient consent. The second kind generally needs a secure, HIPAA-appropriate channel with a Business Associate Agreement covering the vendor relationship.

Standard SMS is not built with the encryption, access controls and audit trail that HIPAA-covered communication is generally understood to require. That does not make all texting to patients off-limits. It means the content that carries health information needs a different tool than a plain text message. Purely logistical, non-clinical content is treated more leniently in common practice.

What kind of text needs what kind of channel

Message contentTypical channelWhy
Appointment time confirmation, no clinical detailStandard SMS, with consentLower risk, commonly accepted practice
Message referencing diagnosis, treatment, or medicationSecure, HIPAA-appropriate channel with a BAAContains protected health information
General marketing or promotional textStandard SMS, with TCPA-compliant consentNot health information, but still needs consent

This is not legal advice. Confirm your specific obligations with counsel, especially for any message referencing health details.

What to check before texting patients or clients

Separate your message types by content. Which ones are purely logistical, and which could be read as revealing health information? Confirm you have documented consent for texting at all. For anything touching health details, confirm the channel you are using has a signed Business Associate Agreement and the safeguards that arrangement is generally understood to require.

Disclosure: SalesCrew is our product, and SMS features are on our roadmap and not shipped today. This page describes the general framework rather than a SalesCrew feature available now. The distinction between logistical and clinical content applies whichever system eventually sends the message.

Standard SMS is not built for health information

A text confirming an appointment time is a different risk from one referencing a diagnosis or treatment. Use a secure, HIPAA-appropriate channel for anything in the second category. This is not legal advice.

Questions

Is standard SMS ever acceptable for patient communication?
It is commonly used for non-clinical content, like appointment reminders that do not mention specific health details. Content that reveals protected health information generally needs a secure, encrypted channel with a signed Business Associate Agreement in place, not standard SMS.
Does patient consent to texting need to be in writing?
Written or otherwise documented consent, plus a disclosure that standard text is not fully secure, is the commonly recommended pattern. Check the current standard for your own situation rather than assuming verbal consent alone is enough.
Does this apply to non-medical client texting too?
The HIPAA-specific rules apply only to protected health information. TCPA consent rules for marketing or automated texts apply broadly to any business texting clients, medical or not.