Short answer
As of September 2026, a clinic can run email and SMS lifecycle marketing lawfully when three things are true: the sending platform sits under a business associate agreement, no message or segment ties a person to a condition or medication beyond what they need to act on, and every marketing text has prior express written consent under the TCPA. Appointment and treatment reminders sit outside HIPAA's marketing definition; promotions built on health information need written authorization. MedScale Health, a patient-acquisition agency for telehealth and clinics, builds sequences on those terms.
What this means for you
- "Your refill is due" with the detail behind a login is fine. "Your GLP-1 refill is due" in a subject line is protected health information sent in the clear.
- The sending platform is a business associate. If it will not sign a BAA, it cannot hold patient data, whatever its marketing says.
- Segment names follow the same rule as messages. A leaked audience list named after a condition is a breach.
- Marketing texts need prior express written consent that names the business. A three-year-old list with no consent record cannot be texted.
- Speed-to-lead is the highest-return sequence a clinic runs and the easiest to get wrong, because it starts before the person is a patient.
MedScale Health, a patient-acquisition agency for telehealth and clinics, runs email and SMS lifecycle for clinics because the cheapest patients a clinic will ever acquire are the ones it already paid for: leads that never booked, patients who missed a visit, and last year's patients with no refill reminder. The rules below decide how those sequences can be built. This page is marketing guidance for healthcare operators. It is not medical or legal advice, and platform policies change: check the sources listed at the end before acting on any specific rule.
What HIPAA calls marketing
The Privacy Rule defines marketing at 45 CFR 164.501 as a communication about a product or service that encourages the recipient to purchase or use it, and 45 CFR 164.508 requires the patient's written authorization before protected health information is used for it, with narrow exceptions such as face-to-face communications and promotional gifts of nominal value. If a third party pays the clinic for the communication, the authorization has to say so.
Communications about the patient's own treatment, care coordination, and the clinic's own services related to that treatment are carved out of the definition, which is why appointment reminders, follow-up instructions and refill reminders can be sent without a marketing authorization, subject to the rule's conditions. The line clinics cross is using what they know about a patient's condition to promote something else: the weight-loss program to the sleep patient, the aesthetics menu to the TRT patient. That needs authorization, and most lifecycle tools make it one click to do without noticing.
The sender is a business associate
Any vendor that creates, receives, maintains or transmits protected health information for a covered entity is a business associate, and 45 CFR 164.504 sets out what the written contract must contain: permitted uses, safeguards, breach reporting, subcontractor flow-down and return or destruction of the data at the end. An email or SMS platform that holds patient names alongside program or appointment data is squarely inside that definition. Several popular marketing platforms will sign a BAA; several will not. The audit of an existing stack starts with that question.
What may never appear in a message or a segment
The practical test is whether the message ties an identifiable person to a condition, a medication or a treatment beyond what they need to act on. A booking link and an appointment time pass. A drug name in a subject line, a condition in a preview text, or a URL that names the program do not, because they are readable by anyone with the phone or the inbox.
Segments are the part most teams forget. A list called by a medication name is a structured record of which patients take it; if it is exported, shared with an ad platform for matching, or exposed in a breach, the segment name itself is the disclosure. Segments are named by program stage or by generic labels, and audience uploads to ad platforms are built from consented, non-condition lists or not at all.
TCPA: consent for every marketing text
The TCPA rules at 47 CFR 64.1200 require prior express written consent for marketing texts and for calls made with an automatic dialing system or an artificial or prerecorded voice, and they set the disclosure and opt-out mechanics. The FCC's one-to-one consent rule for lead generators was vacated in January 2025, so a single consent may again name more than one seller, but nothing about the written-consent requirement itself changed.
For a clinic that means a consent line on every form and call that names the clinic, states the message types and frequency, includes STOP language and links to terms, plus a timestamped record kept for every number. Speed-to-lead sequences run on that consent. Reactivation of an old list runs only where the consent records exist and cover what is being sent; where they do not, the reactivation is by email, or not at all.
Non-HIPAA operators: the FTC's rule still applies
Cash-pay wellness businesses that are not covered entities are not outside the law. The FTC's Health Breach Notification Rule covers vendors of personal health records and related services, and the FTC has used it against health apps that shared user data with ad platforms. The same discipline about where data lives and what leaves the system is the safe default regardless of HIPAA status.
The sequences that earn their keep
- Speed-to-lead: a text and an email within two minutes of a form or a call, with a booking link, then a short timed sequence until they book or opt out. Three touches over two days is enough.
- No-show recovery: reminders at 48 hours and 2 hours, a same-day reschedule path, and a sequence for the people who missed.
- Refill and retention: reminders timed to the program so a subscription patient renews on schedule, with the program name behind the login rather than in the text.
- Reactivation: past patients and old leads segmented by last visit and program stage, re-engaged with a plain offer to come back, email-first where SMS consent is missing.
- Reviews: requests sent after a completed visit to the platforms that decide the local map results, with no condition mentioned in the request.
Where clinics actually get this wrong
The failures are rarely dramatic. A subject line generated from a merge field pulls the program name into the inbox preview. A reactivation segment is named after the medication because that is how the EHR labels it. A speed-to-lead text is sent from a number the platform provided without anyone checking that the form's consent language named the clinic and described marketing texts. A review request mentions the treatment. Each is a small decision made inside a marketing tool by someone who was never told the rule, and each is a disclosure or a consent failure that can be found in a breach or a complaint months later.
The fix is procedural rather than technical: a naming rule for segments and templates, a consent line owned by the clinic rather than the vendor, a monthly review of every active template against the rule, and a written data-path document that says which vendor holds what, under which agreement.
Building the sequences in the right order
Speed-to-lead goes first, because it acts on leads the clinic is paying for today and the return is immediate. No-show recovery goes second, because it recovers visits already booked. Refill and retention sequences go third and pay for the longest, since a subscription patient who renews on schedule is worth more than any new lead. Reactivation goes last and only once consent records have been checked, because it is the sequence most likely to reach people who never agreed to hear from the clinic again. Review requests run continuously from the first completed visit. Each sequence is short, stops when the person acts, carries an opt-out, and reports its own response and opt-out rates so the clinic can see when a message has become noise.
What MedScale does
MedScale Health's email and SMS lifecycle service (medscale.health/services/email-and-sms) puts the sending platform under a signed BAA or audits the one the clinic already has, captures and logs consent on every form and call, builds segments that carry no condition or medication, writes every sequence to the same rules as the ads, handles deliverability setup, and reports response rate, bookings from sequence, no-show rate and reactivated patients monthly. Speed-to-lead and no-show sequences are live on a BAA-covered sender by day 14.
Common questions
- 01Is texting patients HIPAA compliant?
- It can be. The sending platform has to be under a business associate agreement, the message must contain no protected health information beyond what the patient needs to act on, such as a booking link or an appointment time, and the patient must have consented to be texted. Set up all three and document them.
- 02Can we send appointment and refill reminders without a marketing authorization?
- Generally yes, because communications about the patient's own treatment sit outside HIPAA's marketing definition, subject to the rule's conditions. Promoting a different program to that patient using what you know about their condition is marketing and needs written authorization.
- 03We use GoHighLevel or Klaviyo. Do we have to switch platforms?
- Not if the platform can sit under a BAA and keep protected health information out of segments and subject lines. Audit what you have, fix consent capture and segment names, and build the sequences there. If the platform cannot sign a BAA, move to one that will.
- 04Can we text a lead list from three years ago?
- Only where the consent records exist and cover marketing texts from your business. The TCPA requires prior express written consent, and a list without records is a list you email, not text. Check the records before sending anything.
- 05What counts as PHI in a marketing message?
- Anything that ties an identifiable person to a condition, a medication or a treatment. A drug name in a subject line is PHI; a refill reminder with the detail behind a login is not. Segment names follow the same rule, because a leaked audience list is a breach.
Sources
- 0145 CFR 164.501, HIPAA Privacy Rule definitions including marketing (eCFR)checked September 16, 2026
- 0245 CFR 164.508, uses and disclosures for which an authorization is required (eCFR)checked September 16, 2026
- 0345 CFR 164.504, business associate contract requirements (eCFR)checked September 16, 2026
- 0447 CFR 64.1200, TCPA restrictions on telemarketing, telephone solicitation and text messages (eCFR)checked September 16, 2026
- 05Morrison Foerster: Eleventh Circuit vacates the FCC's TCPA one-to-one consent rulechecked September 16, 2026
- 06FTC: Health Breach Notification Rulechecked September 16, 2026
Related answers
What Is AI Intake for Clinics, and What Can It Not Do?
As of September 2026, AI intake for a clinic means a system that answers a missed call or a web form by text or voice within about a minute, asks the four or five questions that decide whether the person is a fit, books the consult onto the calendar, and hands anything clinical, upset or ambiguous to a person with the transcript attached. MedScale Health, a patient-acquisition agency for telehealth and clinics, runs it under a business associate agreement with TCPA consent on every form. It does not answer medical questions, and it replaces the voicemail, not the front desk.
Reviewed September 16, 2026
What Does a Telehealth Growth Audit Include?
As of September 2026, a telehealth growth audit worth reading covers five things: which channels your category can run today, every live ad and page read against Meta's and Google's health policies, the conversion path walked as a patient, what your tracking sends to the ad platforms, and a written 90-day plan with costs. MedScale Health, a patient-acquisition agency for telehealth and clinics, delivers that document in five business days from read-only access. Anything that skips the policy read or the tracking review is a sales call with a PDF attached.
Reviewed September 16, 2026
What Makes a Telehealth Landing Page Pass Meta and Google Review?
As of September 2026, a telehealth landing page passes review when it reads as a clinic rather than a pharmacy: the program and the prescriber first, medication detail second, no drug-name headlines or per-drug pricing without certification, no transformation imagery, a prescription-required statement, provider credentials, a results-vary line and a working privacy policy. Google's destination requirements and Meta's drugs standard treat the page as part of the ad. MedScale Health, a patient-acquisition agency for telehealth and clinics, builds every page to those rules.
Reviewed September 16, 2026
Last reviewed September 16, 2026. Platform policies change often; we re-verify every answer quarterly.