Skip to the main content.

11 min read

How TCPA and TRACED Rules Apply to the Healthcare Industry

How TCPA and TRACED Rules Apply to the Healthcare Industry
 💡 The TCPA and TRACED Act both govern how medical practices reach patients by phone and text. They control different things. The TCPA, passed in 1991, limits automated calls and sets consent rules. Healthcare providers get carve-outs.

Treatment messages such as appointment reminders, lab result notices, and prescription alerts can go to a patient's mobile number without written consent. Those messages must stay clinical, cap at one a day and three a week, and carry an easy opt-out.

Marketing and billing texts need prior express written consent. The TRACED Act, signed in December 2019, targets fake caller ID through the STIR/SHAKEN framework.

That system grades every outbound call before it reaches a phone, so practices calling from unregistered numbers can land under Spam Likely labels. Current FCC rules give you 10 business days to process a stop request.

Most practices treat TCPA compliance as a question they answered years ago. The intake form has a phone number field, reminders go out, nobody has been sued. That reading was defensible until 2025. It no longer is.

Two things changed. District courts stopped being bound by the FCC's reading of the law, so the healthcare exemption your vendor cited in a sales deck is now something a judge weighs fresh. The opt-out rules that took effect in April 2025 also put a hard clock on every stop request: 10 business days, whichever system caught it.

The gap that opens up is operational. Your reminder platform catches a STOP reply. Your recall campaign runs off a list exported three weeks ago. Both look compliant on paper.

Then a patient who opted out gets a text anyway, and the record showing what happened sits in two systems that never talk. That is where TCPA claims start for small practices. Not from a blast to a purchased list, but from a suppression request that reached one tool and not the other.

The rules themselves are manageable. Keep automated messages clinical, send them to the number the patient gave you, stay inside one message a day and three a week, and clear opt-outs fast. The TRACED Act adds a second layer most offices never examine, which is why their calls show up as Spam Likely on a patient's screen.

This guide covers both laws, the healthcare carve-outs that apply to your practice, and where compliance tends to fail once message volume climbs.

What is TCPA?

Congress passed the Telephone Consumer Protection Act (TCPA) in 1991. The goal was to stop telemarketers from reaching people by phone and fax without permission.

It limits the use of automated dialing systems and prerecorded voice messages on certain calls and texts. Debt collection calls by phone fall under it too.

Patients can file a complaint with the Federal Communications Commission (FCC) when a healthcare organization breaks the rules.

They can also sue, and the TCPA sets a floor of $500 in damages for every violation. That figure counts per message. A single reminder blast to 400 patients is 400 potential violations.

Three FCC actions built the framework most practices deal with today.

Year What Changed
1992 Telephone marketers had to keep their own do-not-call lists
2003 FCC and FTC launched the national Do Not Call Registry, with nonprofits exempt
2012 Marketing robocalls to mobile phones needed written consent, plus an automated way to opt out

 

That written consent doesn't need a pen. An electronic signature counts under the E-SIGN Act. The 2012 rule also applies to marketing content only. Reminder and treatment messages sit under a different set of rules.

One more shift matters. In 2021, the Supreme Court decided Facebook, Inc. v. Duguid, narrowing what counts as an automatic telephone dialing system. Equipment now qualifies only if it uses a random or sequential number generator.

Most appointment reminder platforms don't work that way, so they fall outside that definition. Prerecorded and artificial voice calls stay covered no matter what dials them.

Healthcare providers get their own carve-outs from these rules.

What are the TCPA Exemptions for Healthcare Providers?

The FCC treats medical messages differently from sales calls. A reminder about tomorrow's visit isn't a pitch, and the rules reflect that. Three carve-outs let practices reach patients by automated call or text with lighter consent requirements than a marketer would face.

Each one has its own limits on who you can contact, what the message can say, and how often it can go out. Miss those conditions and the exemption drops away, leaving the standard consent rules in place.

1. Healthcare Messages

Two things decide the rule here: what the message says, and what kind of phone it goes to.

Message Goes To Consent Needed
Home landline, prerecorded medical message None
Mobile phone, medical message by autodialer or prerecorded voice Prior express consent

 

Landline calls carry the lighter burden. A HIPAA covered entity or its business associate can send a prerecorded medical message to a residential line without asking first.

Mobile numbers still fall under the TCPA. The bar is lower than it looks, though. These messages need prior express consent, not the written consent a marketer would have to collect.

The FCC has treated a patient handing over a phone number as consent for healthcare messages within that scope — the number on an intake form usually does the work.

That distinction saves your front desk from chasing signatures for every appointment reminder.

2. Healthcare Treatment Purpose Exemption

This carve-out covers messages tied to care. A HIPAA covered entity, or a vendor working on its behalf, can send autodialed texts and prerecorded voice calls to a patient's mobile phone without collecting separate consent first.

The FCC built the exemption around a healthcare treatment purpose, which covers appointment and exam reminders, wellness checkups, hospital pre-registration instructions, prescription notifications, and home healthcare instructions.

Scope is what keeps it valid. The message has to go to the number the patient gave you, and it has to stay clinical. Add a promotion for a new service line and the exemption disappears for that message.

Four conditions travel with it:

  1. The patient can't be charged for the call or text.
  2. Every message carries a simple way to opt out.
  3. Opt-out requests get honored right away.
  4. Volume stays at one message per day, three per week.

Billing reminders and payment notices sit outside this exemption. Those follow the marketing consent rules instead.

3. Urgent Healthcare Messages via the 2015 Order

Some calls aren't emergencies but can't wait either. The 2015 Order (FCC-15-72) covers that middle ground.

Six message types qualify:

  • Appointment reminders

  • Wellness checkups

  • Prescription notifications

  • Pre-registration instructions

  • Lab results

  • Exam confirmations

The FCC drew the line at money and paperwork. Account communications, payment notifications, and Social Security disability eligibility fall outside the exemption.

The FCC reaffirmed this exemption in 2020 under the TRACED Act, keeping the limits on who can call, who can be called, and how often. Those conditions now sit in the rules themselves, so they're what a court would measure your messages against.

Opt-outs

Every message needs an easy way to stop future ones. Honor those requests right away, not at the end of the week.

Delivery and content

Send only to the number the patient gave you. Name your practice and include contact information. Keep the content medical under HIPAA, with no promotions and no requests for payment. Patients can't be charged for the message.

Length and volume

Limit Cap
Voice message length Under 1 minute
Text message length Under 160 characters
Messages per patient, per day 1
Messages per patient, per week 3

 

That weekly cap is per provider. A patient seeing two doctors in your group can receive messages from both without either one breaking the limit.

Infographic showing whether appointment reminders need patient consent under TCPA rules by message type and phone

What is the TRACED Act?

Congress passed the Telephone Robocall Abuse Criminal Enforcement and Deterrence Act in December 2019. It targets illegal robocalls, and it changed how every outbound call from your office gets treated on the way to a patient.

Caller ID authentication is the mechanism. Your carrier checks whether the number showing on a call actually belongs to the caller. That check follows the call across networks. The receiving carrier uses the result to decide whether to connect it, block it, or stamp it with a warning label.

Spoofers lose ground when that check is in place. Investigators can trace bad traffic to its source, and carriers can stop illegal calls before a patient's phone ever rings.

There's a side effect practices feel every day. The same system that grades scam calls also grades yours. A clinic calling from an unauthenticated line can land under a spam label, and patients stop answering.

The Implementation of STIR/SHAKEN

The TRACED Act told the FCC to require a caller ID authentication framework. That framework is STIR/SHAKEN, short for Secure Telephone Identity Revisited and Signature-based Handling of Asserted Information Using toKENs.

The FCC adopted rules in 2020 requiring voice service providers to implement it across the IP portions of their networks by June 30, 2021.

Your carrier signs each outbound call with a grade. That grade travels with the call and tells the receiving carrier how much to trust the number on screen.

Grade What Your Carrier Confirmed What Patients Often See
A You own the number and are authorized to use it Verified checkmark
B Your identity checks out, the number doesn't Number only
C The call entered the network, nothing more Spam Likely

 

C-level calls are the ones that get flagged. Practices routing calls through older phone systems or unregistered numbers tend to land there. Ask your phone vendor which attestation level your outbound calls carry, then ask what it takes to reach A.

Assess Barriers to Implementing STIR/SHAKEN

The TRACED Act required the commission to assess the burdens and barriers providers may face in implementing the STIR/SHAKEN framework on their networks and permitted the commission to grant extensions for phone companies that face undue hardship in implementation, so long as those companies perform robocall mitigation to ensure they are not the source of illegal robocalls.

How Do TCPA and the TRACED ACT Protect Patients?

Both laws limit who can reach a patient's phone and how. The TCPA controls the message: who may send automated calls and texts, what those messages can say, and how a patient stops them. The TRACED Act controls the line itself, so a scammer can't fake a local number to get picked up.

Patients gain three protections a front desk sees in practice:

  • A patient can opt out by replying with any of seven words the FCC treats as reasonable: stop, quit, end, revoke, opt out, cancel, or unsubscribe. Once that request lands, you have 10 business days to process it.

  • Volume stays capped. One message per day, three per week, per provider. A patient with three appointments in one week doesn't get buried.

  • Caller ID stays honest. Authentication makes it harder for a fraudster to imitate your clinic's number, which is a real risk for practices whose numbers appear on public directories.

Two rules decide whether your practice stays on the right side of both laws.

Patient Communications Must, At Any Cost, Comply with HIPAA

Clearing TCPA doesn't clear HIPAA. A reminder can satisfy every FCC condition and still leak protected health information.

The Privacy Rule and Security Rule require covered entities to protect PHI wherever it travels. Standard SMS travels unencrypted. That makes the message body your compliance decision, made fresh every time someone on your team types one.

Take a real reminder.

"Hi John, you have an appointment on January 25 at 2 PM. Reply YES to confirm or contact us at [PHONE NUMBER]."

A first name and a time slot. Nothing about why he's coming in.

Now add the reason:

"John Smith, your cardiology appointment to address your coronary artery disease is scheduled for January 25 at 2 PM with Dr. Williams."

Same appointment, same patient. This version ties a full name to a diagnosis, and that pairing is PHI. It needs encrypted messaging.

Based on our internal guidance to Curogram clients, three additions turn a safe text into a risky one:

  1. A full name alongside a condition or medication
  2. Test results or specific readings
  3. Billing details tied to a named treatment

When a message needs any of those, send a link instead of the content. "You have received a secure document from XYZ Family Practice" routes the patient to an encrypted page that verifies identity first. The reminder still lands. The diagnosis stays off the carrier network.

Secure Prior Consent from Patients

Under the TCPA’s healthcare exemption, individuals who provide a mobile number express consent to receive phone calls or text messages for communications related to their health.

Entities using automated dialers or prerecorded messages may distribute medical information to patients’ provided mobile phone numbers. Medical information is also limited to that which addresses a patient’s health information, such as:

  • Appointment confirmations and reminders
  • Wellness checkups
  • Hospital pre-registration instructions
  • Home healthcare instructions
  • Preoperative instructions
  • Lab test results
  • Post-discharge follow-up
  • Prescription notifications

It’s vital to note that any healthcare organization or medical practice that wants to distribute financial information or promotional marketing via automated dialers or prerecorded messages must gather prior written consent.

All promotional or financial communications require prior express written consent, regardless of whether you’re calling a cell phone or residential landline.

Medical office manager reviewing a printed patient messaging consent policy for TCPA compliance

TCPA and HIPAA Compliance is Curogram’s Utmost Priority

Compliance breaks at the edges, not the center. Most practices know they can send appointment reminders. Fewer know what happens when a patient replies STOP to a billing text, whether that opt-out reaches the reminder system, and whether anyone can prove it did.

That's the gap Curogram is built around. Our platform handles secure, HIPAA-compliant patient communication through 2-way text messaging, with the consent and opt-out mechanics running underneath every message your team sends.

Here's what that covers in practice:

Requirement How It Works in Curogram
Opt-out keywords Stop, cancel, unsubscribe and the other recognized replies are caught automatically
10-business-day processing Suppression applies on receipt, not on a batch cycle
PHI protection Sensitive content routes to an encrypted link instead of plain SMS
Message records Every send and every opt-out is logged and retrievable

 

Volume is where manual tracking fails. Based on our internal data, Covina Arthritic Clinic runs over 1,100 patient confirmations a month through the platform. Nobody keeps a suppression list clean at that scale on a spreadsheet.

Compliance isn't a vendor's job alone. Your intake forms, your staff training, and your message templates carry real weight. What we handle is the machinery: the keyword catching, the encryption, the audit trail, the volume caps. What stays with you is deciding what goes in the message.

The other half is the outcome. Atlas Medical Center cut no-shows from 14.20% to 4.91% in three months on our platform, based on our internal data. Compliant messaging and effective messaging aren't in tension.

Conclusion: Where TCPA Compliance Actually Breaks Down

Both laws come down to one idea. Patients decide what reaches their phone.

The rules that follow are narrow enough to post on a wall. Keep automated messages clinical. Send them to the number the patient gave you.

Stay inside one message a day and three a week. Honor a stop request within 10 business days and keep a record showing you did.

What has shifted is where the risk sits. District courts no longer have to follow the FCC's reading of the TCPA, so an exemption your practice leaned on in 2019 is now something a judge can weigh fresh. The revoke-all rule sits at January 31, 2027, and the FCC has signaled it may not take effect as written.

That churn argues for building around the parts holding still. Consent captured at intake. Opt-outs that reach every system at once. A log you can pull in an afternoon.

Most practices lose ground on the third one. The reminder platform catches a STOP reply, the recall campaign runs from a different list, and nobody notices until a patient who opted out twice files a complaint. Volume makes it worse. At 1,100 confirmations a month, a manual suppression list falls behind in weeks.

Compliance and results are not competing goals here. Atlas Medical Center cut no-shows from 14.20% to 4.91% in three months on our platform, based on our internal data. That came from messages patients wanted, sent inside the limits.

Book a demo to see how Curogram handles consent, opt-outs, and secure messaging for your practice.

 

Frequently Asked Questions

How should your front desk handle a patient who replies STOP to a billing text but still wants appointment reminders?

Treat the two message streams as separate today, and document that choice. The revoke-all rule that would collapse them is delayed to January 31, 2027, and the FCC has signaled it may not take effect as written. Until then, confirm with the patient which messages they want stopped rather than guessing. Log the confirmation.

Why do appointment reminder texts from your clinic get flagged as spam even when patients consented?

Carriers grade every outbound call and text before it reaches the handset. Consent has no effect on that grade. Calls from older phone systems or unregistered numbers get a C-level mark, which sets off Spam Likely labels. Ask your phone vendor what level your calls carry now. Then ask what it takes to reach A.

How does the McLaughlin ruling change what a practice can rely on when defending a TCPA claim?

Before 2025, courts had to follow the FCC's reading of the TCPA. Pointing at the healthcare exemption usually ended the argument. Judges now read the law themselves. Your defense shifts to what you can show: consent records, message content, and how fast you cleared each opt-out request.

Why does a text that meets every TCPA condition still create HIPAA risk?

The two rules measure different things. TCPA asks whether you had permission to send. HIPAA asks what you put in the message body. A reminder can sit well inside the volume caps and still pair a full name with a diagnosis, which is protected health information moving over unencrypted SMS. Route that content through a secure link.

How should a multi-provider group count the three-messages-per-week limit?

The cap runs per provider, per patient. A patient seeing a cardiologist and a family doctor in your group can get messages from both. Neither one breaks the limit. Trouble starts when a single platform sends for several providers and nobody tracks which provider owns each message.

10 Reasons Why Healthcare Practices Should Offer Online Scheduling

10 Reasons Why Healthcare Practices Should Offer Online Scheduling

Online scheduling software allows patients to book appointments with only a few simple clicks from a computer or mobile device, and it’s a critical...

Read More
7 Ways Technology Can Create Efficiency in Medical Offices

7 Ways Technology Can Create Efficiency in Medical Offices

Technology is one of the greatest allies of efficiency in the healthcare industry. It has reduced the number of daily manual processes, from patient...

Read More
Advantages and Disadvantages of Electronic Patient Communications

Advantages and Disadvantages of Electronic Patient Communications

💡Electronic patient communication means reaching patients through text, email, portals, and video instead of paper and phone tag. The advantages...

Read More