The Dual Challenge: HIPAA & 10DLC
Telehealth providers face a unique compliance environment. You must satisfy mobile carrier requirements (10DLC) to ensure message delivery while strictly adhering to federal patient privacy laws (HIPAA). Failure in either area can lead to communication blackouts or significant fines.
HIPAA Privacy
Protecting PHI. SMS is generally not secure for sensitive diagnosis or treatment details.
10DLC Rules
Carrier mandates for brand verification and explicit opt-in for business messaging.
TCPA Consent
Prior express written consent required for marketing messages, distinct from treatment consent.
Core Compliance Requirements
To successfully register your telehealth SMS campaign, you must meet these specific criteria:
-
1
Specific Use Case
Register under the "Healthcare" use case. Be specific in your description (e.g., "Appointment reminders and secure portal notifications for [Clinic Name]").
-
2
No PHI in Texts
Sample messages must NOT contain Protected Health Information. Use generic notifications (e.g., "You have a new message in your portal") rather than specific medical info.
-
3
Secure Link Practices
If sending links to patient portals, use a branded domain (e.g., `portal.yourclinic.com`). Avoid generic public shorteners like bit.ly.
Patient Consent: The Critical Link
A general "Consent to Treat" form is not sufficient for SMS consent under 10DLC or TCPA rules.
Privacy Policy for Healthcare
Your website's privacy policy must include the standard carrier disclosure: "No mobile information will be shared with third parties/affiliates for marketing/promotional purposes." This is distinct from your HIPAA Notice of Privacy Practices.
Implementation Roadmap
Get your telehealth practice compliant in 3 phases.
Review Intake Forms
Update digital and paper forms to capture explicit SMS consent.
Register Brand
Submit your legal entity details to TCR. Ensure exact match with tax records.
Configure Messaging
Set up your system to send generic notifications that link to your secure portal.
Streamline Healthcare Compliance
MyTCRPlus offers specialized compliance kits for healthcare providers, including HIPAA-aware consent templates and registration guides.
View Healthcare SolutionFrequently Asked Questions
Is 2FA required for patient portals?
What if a patient opts out?
Can I use a shared short code?
Legal Disclaimer: This content provides general information about Telehealth SMS compliance requirements and does not constitute legal or medical advice. Compliance obligations vary based on business model, message content, and applicable federal/state regulations (HIPAA, TCPA). Organizations should consult qualified legal counsel for guidance specific to their messaging programs. MyTCRPlus does not provide legal advisory services.