10 Reasons Why Healthcare Practices Should Offer Online Scheduling
Online scheduling software allows patients to book appointments with only a few simple clicks from a computer or mobile device, and it’s a critical...
11 min read
Joshua Inciso
:
Updated on August 11, 2026
Most practices treat TCPA compliance as a question they answered years ago. The intake form has a phone number field, reminders go out, nobody has been sued. That reading was defensible until 2025. It no longer is.
Two things changed. District courts stopped being bound by the FCC's reading of the law, so the healthcare exemption your vendor cited in a sales deck is now something a judge weighs fresh. The opt-out rules that took effect in April 2025 also put a hard clock on every stop request: 10 business days, whichever system caught it.
The gap that opens up is operational. Your reminder platform catches a STOP reply. Your recall campaign runs off a list exported three weeks ago. Both look compliant on paper.
Then a patient who opted out gets a text anyway, and the record showing what happened sits in two systems that never talk. That is where TCPA claims start for small practices. Not from a blast to a purchased list, but from a suppression request that reached one tool and not the other.
The rules themselves are manageable. Keep automated messages clinical, send them to the number the patient gave you, stay inside one message a day and three a week, and clear opt-outs fast. The TRACED Act adds a second layer most offices never examine, which is why their calls show up as Spam Likely on a patient's screen.
This guide covers both laws, the healthcare carve-outs that apply to your practice, and where compliance tends to fail once message volume climbs.
Congress passed the Telephone Consumer Protection Act (TCPA) in 1991. The goal was to stop telemarketers from reaching people by phone and fax without permission.
It limits the use of automated dialing systems and prerecorded voice messages on certain calls and texts. Debt collection calls by phone fall under it too.
Patients can file a complaint with the Federal Communications Commission (FCC) when a healthcare organization breaks the rules.
They can also sue, and the TCPA sets a floor of $500 in damages for every violation. That figure counts per message. A single reminder blast to 400 patients is 400 potential violations.
Three FCC actions built the framework most practices deal with today.
| Year | What Changed |
|---|---|
| 1992 | Telephone marketers had to keep their own do-not-call lists |
| 2003 | FCC and FTC launched the national Do Not Call Registry, with nonprofits exempt |
| 2012 | Marketing robocalls to mobile phones needed written consent, plus an automated way to opt out |
That written consent doesn't need a pen. An electronic signature counts under the E-SIGN Act. The 2012 rule also applies to marketing content only. Reminder and treatment messages sit under a different set of rules.
One more shift matters. In 2021, the Supreme Court decided Facebook, Inc. v. Duguid, narrowing what counts as an automatic telephone dialing system. Equipment now qualifies only if it uses a random or sequential number generator.
Most appointment reminder platforms don't work that way, so they fall outside that definition. Prerecorded and artificial voice calls stay covered no matter what dials them.
Healthcare providers get their own carve-outs from these rules.
The FCC treats medical messages differently from sales calls. A reminder about tomorrow's visit isn't a pitch, and the rules reflect that. Three carve-outs let practices reach patients by automated call or text with lighter consent requirements than a marketer would face.
Each one has its own limits on who you can contact, what the message can say, and how often it can go out. Miss those conditions and the exemption drops away, leaving the standard consent rules in place.
Two things decide the rule here: what the message says, and what kind of phone it goes to.
| Message Goes To | Consent Needed |
|---|---|
| Home landline, prerecorded medical message | None |
| Mobile phone, medical message by autodialer or prerecorded voice | Prior express consent |
Landline calls carry the lighter burden. A HIPAA covered entity or its business associate can send a prerecorded medical message to a residential line without asking first.
Mobile numbers still fall under the TCPA. The bar is lower than it looks, though. These messages need prior express consent, not the written consent a marketer would have to collect.
The FCC has treated a patient handing over a phone number as consent for healthcare messages within that scope — the number on an intake form usually does the work.
That distinction saves your front desk from chasing signatures for every appointment reminder.
This carve-out covers messages tied to care. A HIPAA covered entity, or a vendor working on its behalf, can send autodialed texts and prerecorded voice calls to a patient's mobile phone without collecting separate consent first.
The FCC built the exemption around a healthcare treatment purpose, which covers appointment and exam reminders, wellness checkups, hospital pre-registration instructions, prescription notifications, and home healthcare instructions.
Scope is what keeps it valid. The message has to go to the number the patient gave you, and it has to stay clinical. Add a promotion for a new service line and the exemption disappears for that message.
Four conditions travel with it:
Billing reminders and payment notices sit outside this exemption. Those follow the marketing consent rules instead.
Some calls aren't emergencies but can't wait either. The 2015 Order (FCC-15-72) covers that middle ground.
Six message types qualify:
Appointment reminders
Wellness checkups
Prescription notifications
Pre-registration instructions
Lab results
Exam confirmations
The FCC drew the line at money and paperwork. Account communications, payment notifications, and Social Security disability eligibility fall outside the exemption.
The FCC reaffirmed this exemption in 2020 under the TRACED Act, keeping the limits on who can call, who can be called, and how often. Those conditions now sit in the rules themselves, so they're what a court would measure your messages against.
Every message needs an easy way to stop future ones. Honor those requests right away, not at the end of the week.
Send only to the number the patient gave you. Name your practice and include contact information. Keep the content medical under HIPAA, with no promotions and no requests for payment. Patients can't be charged for the message.
| Limit | Cap |
|---|---|
| Voice message length | Under 1 minute |
| Text message length | Under 160 characters |
| Messages per patient, per day | 1 |
| Messages per patient, per week | 3 |
That weekly cap is per provider. A patient seeing two doctors in your group can receive messages from both without either one breaking the limit.

Congress passed the Telephone Robocall Abuse Criminal Enforcement and Deterrence Act in December 2019. It targets illegal robocalls, and it changed how every outbound call from your office gets treated on the way to a patient.
Caller ID authentication is the mechanism. Your carrier checks whether the number showing on a call actually belongs to the caller. That check follows the call across networks. The receiving carrier uses the result to decide whether to connect it, block it, or stamp it with a warning label.
Spoofers lose ground when that check is in place. Investigators can trace bad traffic to its source, and carriers can stop illegal calls before a patient's phone ever rings.
There's a side effect practices feel every day. The same system that grades scam calls also grades yours. A clinic calling from an unauthenticated line can land under a spam label, and patients stop answering.
The TRACED Act told the FCC to require a caller ID authentication framework. That framework is STIR/SHAKEN, short for Secure Telephone Identity Revisited and Signature-based Handling of Asserted Information Using toKENs.
The FCC adopted rules in 2020 requiring voice service providers to implement it across the IP portions of their networks by June 30, 2021.
Your carrier signs each outbound call with a grade. That grade travels with the call and tells the receiving carrier how much to trust the number on screen.
| Grade | What Your Carrier Confirmed | What Patients Often See |
|---|---|---|
| A | You own the number and are authorized to use it | Verified checkmark |
| B | Your identity checks out, the number doesn't | Number only |
| C | The call entered the network, nothing more | Spam Likely |
C-level calls are the ones that get flagged. Practices routing calls through older phone systems or unregistered numbers tend to land there. Ask your phone vendor which attestation level your outbound calls carry, then ask what it takes to reach A.
Assess Barriers to Implementing STIR/SHAKENThe TRACED Act required the commission to assess the burdens and barriers providers may face in implementing the STIR/SHAKEN framework on their networks and permitted the commission to grant extensions for phone companies that face undue hardship in implementation, so long as those companies perform robocall mitigation to ensure they are not the source of illegal robocalls. |
Both laws limit who can reach a patient's phone and how. The TCPA controls the message: who may send automated calls and texts, what those messages can say, and how a patient stops them. The TRACED Act controls the line itself, so a scammer can't fake a local number to get picked up.
Patients gain three protections a front desk sees in practice:
A patient can opt out by replying with any of seven words the FCC treats as reasonable: stop, quit, end, revoke, opt out, cancel, or unsubscribe. Once that request lands, you have 10 business days to process it.
Volume stays capped. One message per day, three per week, per provider. A patient with three appointments in one week doesn't get buried.
Caller ID stays honest. Authentication makes it harder for a fraudster to imitate your clinic's number, which is a real risk for practices whose numbers appear on public directories.
Two rules decide whether your practice stays on the right side of both laws.
Clearing TCPA doesn't clear HIPAA. A reminder can satisfy every FCC condition and still leak protected health information.
The Privacy Rule and Security Rule require covered entities to protect PHI wherever it travels. Standard SMS travels unencrypted. That makes the message body your compliance decision, made fresh every time someone on your team types one.
Take a real reminder.
"Hi John, you have an appointment on January 25 at 2 PM. Reply YES to confirm or contact us at [PHONE NUMBER]."
A first name and a time slot. Nothing about why he's coming in.
Now add the reason:
"John Smith, your cardiology appointment to address your coronary artery disease is scheduled for January 25 at 2 PM with Dr. Williams."
Same appointment, same patient. This version ties a full name to a diagnosis, and that pairing is PHI. It needs encrypted messaging.
Based on our internal guidance to Curogram clients, three additions turn a safe text into a risky one:
When a message needs any of those, send a link instead of the content. "You have received a secure document from XYZ Family Practice" routes the patient to an encrypted page that verifies identity first. The reminder still lands. The diagnosis stays off the carrier network.
Under the TCPA’s healthcare exemption, individuals who provide a mobile number express consent to receive phone calls or text messages for communications related to their health.
Entities using automated dialers or prerecorded messages may distribute medical information to patients’ provided mobile phone numbers. Medical information is also limited to that which addresses a patient’s health information, such as:
It’s vital to note that any healthcare organization or medical practice that wants to distribute financial information or promotional marketing via automated dialers or prerecorded messages must gather prior written consent.
All promotional or financial communications require prior express written consent, regardless of whether you’re calling a cell phone or residential landline.

Compliance breaks at the edges, not the center. Most practices know they can send appointment reminders. Fewer know what happens when a patient replies STOP to a billing text, whether that opt-out reaches the reminder system, and whether anyone can prove it did.
That's the gap Curogram is built around. Our platform handles secure, HIPAA-compliant patient communication through 2-way text messaging, with the consent and opt-out mechanics running underneath every message your team sends.
Here's what that covers in practice:
| Requirement | How It Works in Curogram |
|---|---|
| Opt-out keywords | Stop, cancel, unsubscribe and the other recognized replies are caught automatically |
| 10-business-day processing | Suppression applies on receipt, not on a batch cycle |
| PHI protection | Sensitive content routes to an encrypted link instead of plain SMS |
| Message records | Every send and every opt-out is logged and retrievable |
Volume is where manual tracking fails. Based on our internal data, Covina Arthritic Clinic runs over 1,100 patient confirmations a month through the platform. Nobody keeps a suppression list clean at that scale on a spreadsheet.
Compliance isn't a vendor's job alone. Your intake forms, your staff training, and your message templates carry real weight. What we handle is the machinery: the keyword catching, the encryption, the audit trail, the volume caps. What stays with you is deciding what goes in the message.
The other half is the outcome. Atlas Medical Center cut no-shows from 14.20% to 4.91% in three months on our platform, based on our internal data. Compliant messaging and effective messaging aren't in tension.
Both laws come down to one idea. Patients decide what reaches their phone.
The rules that follow are narrow enough to post on a wall. Keep automated messages clinical. Send them to the number the patient gave you.
Stay inside one message a day and three a week. Honor a stop request within 10 business days and keep a record showing you did.
What has shifted is where the risk sits. District courts no longer have to follow the FCC's reading of the TCPA, so an exemption your practice leaned on in 2019 is now something a judge can weigh fresh. The revoke-all rule sits at January 31, 2027, and the FCC has signaled it may not take effect as written.
That churn argues for building around the parts holding still. Consent captured at intake. Opt-outs that reach every system at once. A log you can pull in an afternoon.
Most practices lose ground on the third one. The reminder platform catches a STOP reply, the recall campaign runs from a different list, and nobody notices until a patient who opted out twice files a complaint. Volume makes it worse. At 1,100 confirmations a month, a manual suppression list falls behind in weeks.
Compliance and results are not competing goals here. Atlas Medical Center cut no-shows from 14.20% to 4.91% in three months on our platform, based on our internal data. That came from messages patients wanted, sent inside the limits.
Book a demo to see how Curogram handles consent, opt-outs, and secure messaging for your practice.
Treat the two message streams as separate today, and document that choice. The revoke-all rule that would collapse them is delayed to January 31, 2027, and the FCC has signaled it may not take effect as written. Until then, confirm with the patient which messages they want stopped rather than guessing. Log the confirmation.
Carriers grade every outbound call and text before it reaches the handset. Consent has no effect on that grade. Calls from older phone systems or unregistered numbers get a C-level mark, which sets off Spam Likely labels. Ask your phone vendor what level your calls carry now. Then ask what it takes to reach A.
Before 2025, courts had to follow the FCC's reading of the TCPA. Pointing at the healthcare exemption usually ended the argument. Judges now read the law themselves. Your defense shifts to what you can show: consent records, message content, and how fast you cleared each opt-out request.
The two rules measure different things. TCPA asks whether you had permission to send. HIPAA asks what you put in the message body. A reminder can sit well inside the volume caps and still pair a full name with a diagnosis, which is protected health information moving over unencrypted SMS. Route that content through a secure link.
The cap runs per provider, per patient. A patient seeing a cardiologist and a family doctor in your group can get messages from both. Neither one breaks the limit. Trouble starts when a single platform sends for several providers and nobody tracks which provider owns each message.
Online scheduling software allows patients to book appointments with only a few simple clicks from a computer or mobile device, and it’s a critical...
Technology is one of the greatest allies of efficiency in the healthcare industry. It has reduced the number of daily manual processes, from patient...
💡Electronic patient communication means reaching patients through text, email, portals, and video instead of paper and phone tag. The advantages...