Most healthcare organizations know that HIPAA governs how they store and transmit patient information. Fewer realize that HIPAA also regulates what they are allowed to say to patients, specifically, when a communication counts as "marketing." Send the wrong kind of text without the right paperwork and the communication can be a HIPAA violation even if the message itself was perfectly secure.

Under HIPAA, marketing is any communication about a product or service that encourages the recipient to purchase or use that product or service, and a covered entity must obtain the patient's written authorization before using protected health information to send it, unless a specific exception applies. That definition comes from 45 CFR 164.501, and the authorization requirement lives at 45 CFR 164.508(a)(3). Together they draw the line every healthcare texting program needs to understand.

This article explains where that line sits, which messages are exempt, how financial remuneration changes the analysis, and why HIPAA authorization and TCPA consent are two separate boxes you must check independently.

The Rule: Authorization Before Marketing

45 CFR 164.508(a)(3) states that a covered entity must obtain a valid written authorization from the individual before using or disclosing protected health information (PHI) for marketing purposes. Two details make this rule bite harder than it first appears:

  1. Using PHI to select recipients is a "use." If you pull a list of patients with a particular condition, or even just a list of your patients' phone numbers, and text them a promotional message, you have used PHI for marketing. The phone number itself, held by a covered entity in connection with care, is PHI.
  2. The authorization must be HIPAA-valid. A casual "okay" is not enough. A valid authorization under 45 CFR 164.508 must be in writing, describe the information to be used, identify who may use it and for what purpose, include an expiration date or event, explain the right to revoke, and be signed by the patient. If the covered entity receives financial remuneration from a third party for making the communication, the authorization must say so.

The Office for Civil Rights (OCR) within the Department of Health and Human Services enforces these rules, and marketing violations can trigger the same civil monetary penalty framework as any other HIPAA violation.

What Counts as Marketing Under 45 CFR 164.501

The regulatory definition is a communication about a product or service that encourages recipients to purchase or use the product or service. Applied to texting, these messages are marketing and require prior written authorization:

  • Promoting a cosmetic service line (medspa treatments, elective procedures) to your patient list
  • Texting patients about a third party's product, such as a device manufacturer's new offering, where the third party pays you to send it
  • Cross-selling services unrelated to the patient's current treatment, such as a dental practice promoting teeth whitening packages
  • Announcing a retail product sold by the practice, like supplements or skincare, with a purchase call to action

The Exceptions: Health Texts That Are Not Marketing

The definition of marketing in 45 CFR 164.501 carves out several categories of communication. These may be sent without a marketing authorization (though normal HIPAA privacy and security rules, and TCPA consent rules, still apply):

  • Treatment communications. Messages about the individual's own treatment, including appointment reminders, pre-visit instructions, post-discharge follow-up, and care coordination. This is the exception that makes everyday clinical texting possible.
  • Refill reminders and adherence messages. Communications about a drug or biologic the patient is currently prescribed, including refill reminders and adherence support, remain outside marketing as long as any payment the covered entity receives is reasonably related to its cost of making the communication.
  • Case management and care coordination. Recommending alternative treatments, therapies, providers, or care settings to the individual.
  • Health-care operations communications. Describing the covered entity's own health-related products or services, such as telling patients about a new clinic location, extended flu-shot hours, or a patient portal, provided no third party is paying for the communication.
  • Separately, 45 CFR 164.508(a)(3)(i) exempts two communications from the authorization requirement even though they are marketing: face-to-face communications and promotional gifts of nominal value. Neither arises in texting.

A useful mental test: is this message about this patient's care, or is it trying to sell something? A text that says "Your annual wellness visit is due, tap to schedule" is treatment. A text that says "New year, new you! Special pricing on our aesthetic services this month" is marketing and needs signed authorization first.

The Financial Remuneration Trigger

The HITECH Act tightened the marketing rules around paid communications, and the 2013 Omnibus Rule wrote the change into 45 CFR 164.501 and 164.508. The key concept is financial remuneration: direct or indirect payment from a third party whose product or service is being described.

If a third party pays you to send a communication promoting its product or service, the communication is marketing and requires authorization, even if it would otherwise fit an exception. The main survivor is the refill-reminder carve-out, where payment limited to the reasonable cost of making the communication is permitted. Two practical rules follow:

  1. Treat any sponsored or subsidized patient communication as presumptively requiring authorization, and have counsel review before sending.
  2. If you do obtain authorizations for paid communications, the authorization form must disclose that remuneration is involved.

HIPAA Authorization vs. TCPA Consent: Two Separate Boxes

Healthcare marketers often conflate HIPAA authorization with TCPA consent. They are different legal requirements from different regulators, and satisfying one does nothing for the other.

HIPAA marketing authorizationTCPA consent
Source of law45 CFR 164.508(a)(3), enforced by OCR47 U.S.C. 227 and 47 CFR 64.1200, enforced by the FCC and private lawsuits
What it governsUse of PHI to send the communicationThe act of sending an automated text to a phone number
Standard for marketing textsValid written authorizationPrior express written consent
Standard for treatment textsNo authorization needed (treatment exception)Prior express consent (providing the number for care purposes generally suffices)
Penalty exposureCivil monetary penalties, corrective action plansStatutory damages of $500 to $1,500 per text

A promotional text to patients therefore needs both a HIPAA-valid authorization covering the use of their information for marketing and TCPA prior express written consent to receive automated marketing texts. Many organizations combine both into a single well-drafted enrollment flow, which works if the language satisfies each rule's specific requirements. Our guide to HIPAA compliant text messaging covers the security side of the equation, including encryption, access controls, and the platform safeguards that keep the message channel itself compliant.

Practical Compliance Steps for Healthcare Texting Programs

  1. Classify every message template. Tag each template as treatment, operations, refill reminder, or marketing before it enters your library. The classification determines the consent stack it needs.
  2. Build an authorization workflow for marketing. Collect HIPAA authorizations electronically with the required elements, store them alongside TCPA consent records, and filter marketing sends to authorized patients only.
  3. Sign a BAA with your texting vendor. Any platform that touches PHI on your behalf is a business associate, and HIPAA requires a written business associate agreement before PHI flows. Our explainer on what a business associate agreement is walks through what the contract must contain.
  4. Keep marketing lists separate from clinical lists. Suppression logic should prevent a marketing campaign from ever pulling from the general patient roster.
  5. Honor revocations everywhere. Patients can revoke a HIPAA authorization in writing and can text STOP to revoke TCPA consent. Both must flow through to your send logic.
  6. Watch the remuneration question. Any time money moves from a third party in connection with a patient communication, escalate for review.

FRANSiS supports HIPAA compliance for healthcare texting, with a signed BAA included, role-based access controls, and template-level consent enforcement so treatment messages and marketing messages follow separate rules automatically. The AI Powered Helper drafts and answers within the guardrails you configure, so front-desk teams do not have to make regulatory classification decisions on the fly.

This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.

Frequently Asked Questions

Are appointment reminder texts considered marketing under HIPAA?

No. Communications about an individual's own treatment, including appointment reminders, scheduling messages, and follow-up care instructions, fall under the treatment exception in the marketing definition at 45 CFR 164.501. They do not require a marketing authorization, though TCPA consent rules still apply to the texting channel.

When does a healthcare text require written patient authorization?

A text requires HIPAA authorization when it uses patient information to promote a product or service outside the exceptions, for example promoting elective service lines, retail products, or any communication a third party pays you to send. The authorization must meet the validity requirements of 45 CFR 164.508 and must disclose any financial remuneration.

Can a hospital text patients about its own new services?

Generally yes. Communications about a covered entity's own health-related products or services fall within the health-care operations carve-out from the marketing definition, provided no third party is paying for the communication. The message still needs appropriate TCPA consent for the texting channel.

Do refill reminder texts violate HIPAA marketing rules?

No. Refill reminders and adherence communications about a currently prescribed drug are excluded from the marketing definition, as long as any payment received for sending them is reasonably related to the cost of making the communication. Reminders promoting a different or new drug for payment are treated differently and generally require authorization.

Is TCPA consent the same as HIPAA marketing authorization?

No. TCPA consent (under 47 U.S.C. 227) authorizes the automated text to the phone number; HIPAA authorization (under 45 CFR 164.508) permits the use of protected health information for marketing. A promotional text to patients needs both, and revoking one does not automatically revoke the other.

Send Compliant Patient Texts with FRANSiS

FRANSiS helps healthcare organizations run treatment messaging and marketing campaigns on separate, enforceable rails, with HIPAA compliance supported, a signed BAA included, and an AI Powered Helper that stays inside your configured rules. Contact our team to see how it works for your patient communication program.