Quick answer: TCPA compliance for text messaging comes down to three obligations: obtain express written consent before sending marketing or automated texts, honor every opt-out request immediately, and keep records that prove both. Nonprofits and healthcare organizations are not exempt, and because the TCPA gives individuals a private right of action, senders face per-message statutory liability that multiplies quickly. Below is the complete 2026 rulebook, a copy-ready TCPA compliance checklist, and the consent rules that changed most recently.

The rule, in brief: The governing authorities are the Telephone Consumer Protection Act at 47 U.S.C. 227 and the FCC rules at 47 CFR 64.1200. Under 47 CFR 64.1200(a)(10) a consumer may revoke consent by any reasonable method, and the sender must honor that revocation within a reasonable time not to exceed ten business days.

Current as of August 2026. Primary sources: 47 U.S.C. 227, the Telephone Consumer Protection Act, 47 CFR 64.1200, FCC rules implementing the TCPA (eCFR), FTC, Complying with the Telemarketing Sales Rule.

Book a 15-min walkthrough →

This article is general educational guidance, not legal advice. Consult qualified legal counsel for advice specific to your organization.

What the TCPA is and why it matters in 2026

The Telephone Consumer Protection Act (TCPA) is a federal law that governs how organizations may use automated communications, including SMS text messages, to reach individuals on their mobile phones. Originally passed in 1991, the TCPA has been updated repeatedly through FCC rulemaking, and courts continue to interpret its reach. In 2026, it remains the primary federal framework regulating commercial and informational text messaging in the United States.

The law applies broadly. Whether you are a nonprofit sending fundraising appeals, a hospital system sending appointment reminders, a school district communicating with families, or a government agency notifying constituents, the TCPA likely applies to your outbound SMS program. Assuming your organization is exempt because it is mission-driven or nonprofit is one of the most common, and costly, mistakes organizations make.

Violations can result in significant civil liability, and unlike many regulatory frameworks, the TCPA creates a private right of action, meaning individuals can sue your organization directly, not just file a complaint with a regulator.

What are the TCPA rules for texting in 2026?

If you strip away the case law and the acronyms, the TCPA rules for texting reduce to a short list of operating requirements. Every one of them applies whether you send ten messages a week or ten thousand a day.

  • Consent before contact. Automated marketing and promotional texts require prior express written consent. Purely informational or transactional texts still require prior express consent, which the recipient typically gives by knowingly providing their number for that purpose.
  • Identify yourself. Every message should make clear which organization is sending it. Anonymous or misleading sender identification undermines consent and invites complaints.
  • Respect quiet hours. The federal window at 47 CFR 64.1200(c)(1) runs from 8 a.m. to 9 p.m. local time at the called party's location, and applies to telephone solicitations to residential subscribers. Note that 64.1200(f) excludes calls made by or on behalf of a tax-exempt nonprofit from 'telephone solicitation', so the federal window does not reach nonprofit fundraising texts, but several state mini-TCPA statutes impose their own narrower windows and carriers enforce quiet hours by policy. Schedule campaigns against the recipient's time zone, not your office's.
  • Honor opt-outs immediately. STOP and similar keywords must suppress the number across your program, and FCC rules that took effect in 2025 require senders to honor revocation made through any reasonable means, processed within ten business days at most.
  • Keep proof. The sender carries the burden of demonstrating consent. No record means no defense.

State legislatures have also passed their own mini-TCPA statutes, several of which impose stricter consent and quiet-hour standards than federal law. A compliant program in 2026 accounts for both layers.

Express written consent: the foundation of a compliant program

Before sending any marketing or promotional text message using an automated system, your organization must obtain express written consent from the recipient. This is a higher standard than a simple opt-in, it requires the individual to affirmatively agree to receive messages from your organization, with a clear disclosure of what they are consenting to.

A compliant opt-in should include:

  • The organization's name
  • A clear description of the message type (e.g., fundraising updates, appointment reminders, program alerts)
  • Estimated message frequency or a statement that it may vary
  • A disclosure that message and data rates may apply
  • Instructions for opting out (e.g., "Reply STOP to unsubscribe")
  • A link to your privacy policy and terms of service

Consent obtained for one purpose does not transfer to another. If a donor opts in to receive donation receipts, that consent does not cover sending them fundraising campaigns. Keep consent buckets distinct, and document each one clearly.

For healthcare organizations, it is worth noting that TCPA consent and HIPAA authorization are separate requirements. A patient may have signed a HIPAA-compliant authorization, but that does not satisfy the TCPA's express written consent requirement for automated messaging. Both frameworks apply. See our guide on HIPAA-compliant text messaging for detail on how the two obligations interact.

Opt-out handling: honoring STOP is not optional

When a recipient replies STOP, QUIT, CANCEL, END, or UNSUBSCRIBE to any of your messages, you are required to honor that request immediately. Sending any further marketing or promotional messages to that number, other than a single confirmation of the opt-out, constitutes a TCPA violation.

Your opt-out process should:

  • Remove the number from all active sending lists within seconds of the STOP reply
  • Send a single, brief confirmation message (e.g., "You have been unsubscribed and will receive no further messages from [Org Name].")
  • Suppress the number across all campaigns, not just the one from which they unsubscribed
  • Log the opt-out with a timestamp for your records

Note that under current FCC rules, recipients are not limited to official keywords. A reply like "please stop texting me" or a verbal request through your support line counts as revocation through a reasonable means, and your process needs to capture and honor it just as reliably as a STOP reply.

One area organizations often miss: if a contact re-opts in after previously opting out, you must collect fresh, documented consent before resuming sends. Reactivating a suppressed number without a new consent record puts you back at risk.

Record-keeping: if you cannot prove consent, you do not have it

In a TCPA dispute, the burden falls on the sender to demonstrate that valid consent existed. That means documentation is not a back-office formality, it is your primary legal defense. Every consent record should capture:

  • The phone number that consented
  • The date, time, and method of consent (web form, text keyword, paper form, etc.)
  • The exact language of the opt-in disclosure the individual agreed to
  • The IP address or device identifier where applicable
  • Any subsequent opt-out or re-opt-in events with timestamps

Store these records in a system that is durable, searchable, and backed up. Spreadsheets are not a sufficient long-term solution. FRANSiS™ captures and stores consent and opt-out events automatically, with data protected by encryption in transit (TLS 1.3) and at rest (256-bit AES), so your records remain intact and retrievable when you need them. Our complete guide to SMS for nonprofits covers how to structure your consent workflow from the ground up.

TCPA compliance checklist for text messaging

Use this checklist to audit your current SMS program or stand up a new one. If you cannot check every box, treat the gaps as your priority list.

  • Consent capture: every opt-in flow (web form, keyword, paper, event kiosk) displays your organization name, message type, frequency note, "message and data rates may apply" disclosure, STOP instructions, and privacy policy link.
  • No pre-checked boxes: the SMS opt-in is unchecked by default and separate from other form consents.
  • Purpose separation: consent is tracked per message category, and lists are never cross-used without fresh consent.
  • Opt-out automation: STOP, QUIT, CANCEL, END, UNSUBSCRIBE, and free-text revocation requests suppress the number across every campaign automatically.
  • Revocation window: all revocation requests, in any channel, are processed within ten business days, and ideally within seconds.
  • Quiet hours: sends are scheduled between 8 a.m. and 9 p.m. in each recipient's local time zone.
  • Record retention: consent and opt-out events are logged with timestamps, source, and the exact disclosure language, in a durable searchable system.
  • List hygiene: no purchased or rented lists, and reassigned-number checks run before campaigns.
  • Carrier registration: your brand and use cases are registered under 10DLC, and registered use cases match your actual sends.
  • Staff training: everyone who can hit send understands consent categories, quiet hours, and the opt-out process.
  • Annual review: a yearly audit of opt-in language, suppression logic, and state-law changes, with legal counsel where possible.

SMS compliance checklist: beyond the TCPA

TCPA compliance is necessary but not sufficient. A complete SMS compliance checklist also covers the adjacent frameworks that apply to most mission-driven senders:

  • 10DLC registration: a carrier-level requirement for application-to-person messaging, separate from the TCPA but enforced through filtering and suspensions.
  • CTIA messaging guidelines: industry best practices carriers expect senders to follow, including content restrictions and opt-in standards.
  • HIPAA: if messages contain protected health information, HIPAA compliance supported with a signed BAA is required alongside TCPA consent.
  • FERPA: education institutions texting about student records need FERPA-aware handling of that information.
  • State mini-TCPA laws: states such as Florida, Oklahoma, and Washington have enacted their own telemarketing statutes with independent penalties and, in some cases, tighter quiet hours.

TCPA considerations specific to nonprofits

Nonprofits often assume their mission-driven status puts them outside the TCPA entirely. It does not - but the rules do give them specific, narrow relief that is worth knowing precisely. 47 CFR 64.1200(a)(2) excepts calls made by or on behalf of a tax-exempt nonprofit from the stricter written-consent standard, and 64.1200(f) excludes them from 'telephone solicitation', which is why the national do-not-call registry and the federal 8 a.m. to 9 p.m. window do not by their terms reach nonprofit fundraising. What still applies in full is 64.1200(a)(1), which requires prior express consent for autodialed texts to wireless numbers, and 64.1200(a)(10) on revocation. The law distinguishes between commercial and non-commercial messages in some contexts, but courts have broadly interpreted automated text messaging to fall within the TCPA's scope regardless of the sender's tax status.

Specific areas where nonprofits frequently encounter risk:

  • Fundraising appeals sent by text, treated as marketing messages requiring express written consent
  • Event invitations and volunteer recruitment, if sent via automated system, consent requirements apply
  • Peer-to-peer SMS at scale, where the analysis is unsettled. Automation alone is not the test: under Facebook, Inc. v. Duguid, 592 U.S. 395 (2021), equipment is an autodialer only if it uses a random or sequential number generator, and in DA 20-670 the FCC's Consumer and Governmental Affairs Bureau expressly declined to rule on whether any particular P2P platform qualifies. Even where 227(b) does not attach, state statutes, carrier policy and consent recordkeeping still do
  • Purchased or rented contact lists, consent obtained by a third party for a different purpose does not transfer to your organization

The safest approach is to build consent collection into every touchpoint where a supporter interacts with your organization, donation forms, event registrations, volunteer sign-ups, and to make the SMS opt-in explicit and separate from other form fields. For a look at how compliant two-way texting works in practice for mission-driven teams, see our nonprofit texting solutions page.

TCPA considerations specific to healthcare organizations

Healthcare senders face the most layered compliance picture of any vertical, because TCPA consent rules interact with HIPAA and with carrier requirements at the same time.

Appointment reminders and informational health messages

Texts that are informational rather than promotional, such as appointment reminders, prescription notifications, and care follow-ups, generally require prior express consent rather than the stricter written standard. In most cases a patient who knowingly provides their mobile number to a provider for those communications has given that consent. The safe practice is still to disclose the texting program at intake, record the consent, and give patients an easy way to decline.

Marketing and wellness promotion require the written standard

The moment a message promotes a service, program, or paid offering, it crosses into marketing territory and requires prior express written consent, even when the sender is a healthcare provider and the content is health-related. Flu-shot promotion campaigns, new-service announcements, and wellness program upsells all belong in this bucket. Keep these lists separate from your reminder lists, with separate consent records for each.

Healthcare organizations also need to keep protected health information out of message content unless HIPAA safeguards are in place, which is a content question the TCPA does not address at all. A platform built for regulated senders should handle both: FRANSiS supports TCPA-aware consent management alongside HIPAA compliance supported with a signed BAA. Learn more on our healthcare texting solutions page.

How 10DLC fits into your TCPA compliance strategy

10DLC, 10-digit long code, is the carrier-level infrastructure now required for most application-to-person (A2P) SMS messaging in the United States. While 10DLC registration is a carrier requirement rather than a TCPA requirement, the two are deeply connected in practice.

Carriers require organizations to register their brand and describe the use cases for which they will send messages. The use-case descriptions you submit during 10DLC registration must accurately reflect the consent you obtained. Sending messages for a purpose not covered in your registered use case, even if the recipient consented to something else, can result in filtering, suspension, or carrier penalties that compound your TCPA exposure.

For a detailed walkthrough of the registration process, see our 10DLC registration guide. FRANSiS supports 10DLC registration and helps organizations align their carrier registration with their consent framework so both requirements are satisfied together.

How to choose a TCPA-compliant texting platform

No platform makes an organization compliant on its own, because compliance ultimately depends on how you collect consent and manage your lists. What the right platform can do is make the compliant path the default path. When evaluating vendors, look for:

  • Automatic consent logging that records the timestamp, source, and disclosure language for every opt-in without manual data entry
  • Universal opt-out suppression that honors STOP keywords and free-text revocation across all campaigns instantly
  • Quiet-hours enforcement based on each recipient's local time zone, not the sender's
  • Audit-ready exports so you can produce consent evidence quickly if a dispute arises
  • 10DLC registration support, including help aligning registered use cases with your consent categories
  • A signed BAA if you handle protected health information, plus encryption in transit (TLS 1.3) and at rest (256-bit AES)
  • Two-way conversation handling, because recipients reply with questions, and an AI Powered Helper that routes and answers those replies keeps opt-out and consent signals from slipping through the cracks
  • Predictable cost, so compliance-driven message volume (confirmations, disclosures, reminders) does not create budget pressure to cut corners; FRANSiS pricing is flat, predictable, unlimited messaging

Ask every vendor to walk you through exactly what happens, step by step, when a contact replies STOP and when a contact replies "stop texting me please." The quality of the answer tells you most of what you need to know.

Frequently asked questions

Does the TCPA apply to nonprofit organizations?

Yes, with one important qualification. Nonprofit status is not a blanket TCPA exemption: 47 CFR 64.1200(a)(1) prohibits autodialed calls and texts to wireless numbers without prior express consent regardless of tax status, and revocation must be honored under 64.1200(a)(10). But 64.1200(a)(2) does carve nonprofits out of the stricter WRITTEN-consent standard, excepting 'the prior express consent of the called party when the call is made by or on behalf of a tax-exempt nonprofit organization.' Separately, after Facebook, Inc. v. Duguid, 592 U.S. 395 (2021), equipment only counts as an autodialer if it uses a random or sequential number generator, which most list-based SMS platforms do not. Written consent is still the safer operating baseline, because state mini-TCPA statutes and carrier 10DLC review apply their own standards.

What counts as express written consent under the TCPA?

Express written consent is an affirmative agreement by the recipient to receive automated text messages from your organization. It must include a clear disclosure of the message type, the sender's name, opt-out instructions, and a note that message and data rates may apply. A pre-checked checkbox or implied consent from a prior relationship does not meet this standard.

How quickly must organizations honor a STOP request?

Opt-out requests must be honored immediately. After a recipient replies STOP, you may send a single confirmation message and must then cease all further automated outreach to that number. Organizations that continue sending messages after a STOP reply are exposed to TCPA liability on each subsequent message sent.

Is TCPA consent the same as HIPAA authorization for healthcare text messaging?

No. TCPA consent and HIPAA authorization are separate legal requirements that operate independently. A patient's HIPAA authorization does not satisfy the TCPA's express written consent requirement for automated SMS, and vice versa. Healthcare organizations must meet both standards. Using a platform that supports both HIPAA-compliance workflows (with a BAA) and TCPA-compliant consent management helps address both obligations from a single system.

What is the penalty for violating the TCPA?

Under 47 U.S.C. 227(b)(3) an individual may sue and recover actual monetary loss or $500 for each violation, whichever is greater. The $500 is a floor, not a fixed penalty, and if the court finds the violation willful or knowing it may in its discretion increase the award to not more than three times that amount. These are private statutory damages recoverable by the person who received the message, not fines imposed by a regulator. A separate cause of action at 47 U.S.C. 227(c)(5) covers do-not-call violations, is capped at up to $500 per violation, and requires more than one call within a 12-month period. Because damages accrue message by message, a single non-compliant campaign sent to a large list can create substantial exposure, and the private right of action means class actions are common. The practical takeaway: treat every send as if you will one day need to prove consent for it.

Are there quiet hours for sending text messages?

Yes, with a scope caveat. 47 CFR 64.1200(c)(1) bars telephone solicitations to residential subscribers before 8 a.m. or after 9 p.m. local time at the called party's location. Because 64.1200(f) excludes calls made by or on behalf of a tax-exempt nonprofit from the definition of 'telephone solicitation', that federal window does not by its terms reach nonprofit fundraising texts - but several state mini-TCPA statutes impose narrower windows that do, and carriers enforce quiet hours as policy. Configure your platform to schedule against each recipient's time zone rather than your own, and hold non-urgent informational messages to the same window as a best practice.

Can someone revoke consent without replying STOP?

Yes. Under 47 CFR 64.1200(a)(10), effective April 11, 2025, a consumer may revoke consent by any reasonable method, including free-text replies, emails or phone calls, and the sender must honor it within a reasonable time not to exceed ten business days. The same paragraph provides that a sender 'may not designate an exclusive means to request revocation of consent', so a reply-STOP-only policy is not sufficient. One piece of that rule is still on hold: the FCC's Consumer and Governmental Affairs Bureau has waived the provision that would make a revocation on one message stream cut off unrelated streams from the same sender, extending it to January 31, 2027. Treat that as a compliance target rather than a current obligation, and check the current status before relying on it. Your suppression workflow should capture these signals automatically rather than relying on staff to spot them in an inbox.

Do appointment reminder texts require written consent?

Generally no. Purely informational messages such as appointment reminders require prior express consent, which a patient or client typically provides by knowingly giving their number for that purpose. The stricter express written consent standard applies once messages become promotional. Because the line between informational and marketing content can blur, many organizations apply the written standard across the board to stay safely inside it.

Book a 15-min walkthrough →

Related guides: TCPA Class Action Lawsuits: Lessons for Mission Driven Orgs · TCPA Violations and Penalties: What Fines Actually Look Like · FCC TCPA Revocation Rule: How Opt-Outs Must Work · What Counts as an Autodialer? The TCPA ATDS Rule · What Is a Mini-TCPA? States With Texting Statutes · Does the TCPA Apply to B2B Text Messages? Yes

How to cite this page: FRANSiS™ Team. "TCPA Compliance for Text Messaging: 2026 Guide." FRANSiS, https://www.fransis.ai/blog/tcpa-compliance-for-text-messaging-what-nonprofits-and-healthcare-organizations-must-know-in-2026. Current as of August 2026.

Join The Troop

Sign up for our mailing list for insights, perks, and more!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.