Skip to main content
    ← Blog

    TCPA SMS Compliance: Your 2026 Practical Playbook

    August 10, 2026 · Cannatract Team

    To stay TCPA-compliant with SMS marketing right now, you need to do five things before sending a single message: obtain documented prior express written consent (PEWC) for every marketing text, honor opt-out requests within seconds, register your brand and campaign through A2P 10DLC carrier registration, store timestamped consent records with IP addresses and form copies, and never send messages outside the 8 AM–9 PM quiet-hours window in the recipient’s local time zone. These are not optional best practices. They are the minimum floor under 47 CFR § 64.1200, and violations carry statutory damages per message, with higher penalties for willful violations, and no aggregate cap.

    Quick-action triage checklist for operations teams:

    • Consent language audit: Pull every opt-in form, landing page, and point-of-sale script. Confirm each one names your company specifically, describes the message type, estimates frequency, and includes a “Msg & data rates may apply. Reply STOP to cancel” disclosure.
    • Suppression sync: Verify your CRM, SMS platform, and any third-party vendors share a single, real-time suppression list. A contact who opted out in your CRM but not in your ESP is a lawsuit waiting to happen.
    • Lead list review: Any list sourced from a third-party lead generator with generic “you may be contacted by our partners” language is high-risk. The FCC has closed the lead-generator loophole, and that consent no longer protects you.
    • A2P 10DLC registration: Confirm your brand and every active campaign are registered with The Campaign Registry (TCR). Unregistered traffic is filtered by carriers regardless of your TCPA posture.
    • Recordkeeping check: Confirm your system logs phone number, consent text, timestamp, IP address, source URL, form ID, and campaign ID for every opt-in. If you cannot produce that record in 24 hours, you are not ready for litigation.

    The three items that generate the most class-action exposure: consent language that is buried in terms-of-service links rather than displayed at the point of collection, purchased lead lists carrying generic partner consent, and failure to suppress opted-out contacts across every sending system simultaneously.


    Key Takeaways

    TCPA SMS compliance requires documented prior express written consent, real-time suppression management, A2P 10DLC registration, and defensible recordkeeping to withstand litigation and carrier enforcement.

    Point Details
    PEWC is the baseline for marketing texts Every promotional SMS sent via an autodialer requires a signed, seller-specific prior express written consent record before sending.
    Suppression must be real-time Opt-outs processed in batch cycles create liability; sync your CRM, SMS platform, and vendors to a single suppression list immediately after each opt-out.
    Recordkeeping must survive litigation Log phone number, consent text, timestamp, IP address, source URL, form ID, and campaign ID for every opt-in and retain records for at least four years.
    Carrier rules are independent of TCPA A2P 10DLC registration and CTIA compliance are enforced by carriers through filtering and blocking, separate from any FCC or court action.
    Cannatract automates the hard parts Cannatract builds consent capture, suppression sync, and audit export systems with fixed quotes and 2–4 week delivery timelines.

    Table of Contents

    Does the TCPA apply to your texts? Scope, exemptions, and key definitions

    The short answer is yes, with very few exceptions. The Telephone Consumer Protection Act of 1991 covers “calls” to mobile phones, and the FCC has consistently held that text messages are calls under that definition. The FCC’s Enforcement Bureau has made clear that TCPA restrictions apply to autodialed text messages and that senders carry the burden of proving consent. That burden-shifting matters: in litigation, you do not get to say “we assumed they consented.” You have to show the record.

    The law’s scope turns on two variables: the technology used to send the message and the content of the message. Marketing messages sent using an automatic telephone dialing system (ATDS) to a mobile number require prior express written consent. Non-marketing, transactional messages sent using an ATDS may qualify for a lower consent tier. Messages sent without any automated dialing technology occupy a different risk profile entirely, though most commercial SMS platforms involve some degree of automation.

    Key definitions you need to know:

    • ATDS (Autodialer): A system with the capacity to store or produce telephone numbers to be called using a random or sequential number generator, and to dial those numbers. Courts have debated the word “capacity” extensively since the Supreme Court’s 2021 Facebook v. Duguid decision, which narrowed the definition. The practical risk remains high for any platform that sends bulk messages without individual human initiation.
    • Prior express consent: Consent to receive non-marketing informational texts, which can be given orally or through a clear affirmative action.
    • Prior express written consent (PEWC): Required for marketing messages sent via ATDS. Must be a signed written agreement (electronic signatures qualify) that clearly authorizes the specific sender to send advertising or telemarketing messages.
    • Marketing vs. transactional: A message promoting a product, service, or sale is marketing. A message confirming an order, sending a shipping update, or reminding a patient of an appointment is transactional, provided it contains no promotional content.

    U.S. SMS compliance sits on three overlapping layers: federal TCPA law, carrier and CTIA Messaging Principles (which carriers enforce independently through filtering and suspension), and A2P 10DLC registration. Being legally compliant does not protect you from carrier filtering if you violate CTIA principles, and carrier registration does not substitute for TCPA consent.

    Message Type Example PEWC Required? Notes
    Promotional offer “promotional offer” Yes Classic marketing; PEWC required
    Order confirmation “order confirmation message” No Transactional; prior express consent sufficient
    Appointment reminder “Your appointment is tomorrow at 2 PM” No Transactional; no promotional content
    Appointment reminder + upsell “Reminder: 2 PM appt. Also, try our new service!” Yes Mixed content triggers marketing rules
    Debt collection notice “You have a balance due of $X” Contested Additional FDCPA rules apply; consult counsel
    Political/campaign message “Vote for Candidate X on Tuesday” No PEWC required But prior express consent still needed for ATDS
    Emergency alert “Evacuation order for your area” No Emergency exemption applies

    Does the TCPA apply to your texts? Scope, exemptions, and key definitions — overview diagram

    The consent framework under TCPA is not binary. There are two distinct tiers, and using the wrong one for the wrong message type is one of the most common compliance failures.

    Prior express consent covers informational, non-advertising messages. A customer who gives you their phone number on a purchase form and checks a box saying “I agree to receive order updates” has given prior express consent. You can send them shipping notifications. You cannot send them a promotional coupon.

    Prior express written consent is required the moment your message promotes a product, service, or sale. Under 47 CFR § 64.1200, PEWC must be a signed written agreement (electronic signatures qualify under the E-SIGN Act) that clearly and conspicuously discloses that the consumer authorizes the specific company to send autodialed marketing texts. The FCC’s Second Report & Order tightened this further, requiring seller-specific consent rather than broad partner-style consent language.

    What “clear and conspicuous” actually requires

    The FCC does not define “clear and conspicuous” with a pixel count, but enforcement actions and CTIA guidance make the standard concrete. Your consent disclosure must:

    • Name your company specifically (not “our partners” or “affiliated brands”)
    • Describe the type of messages the consumer will receive (e.g., “promotional offers and new product announcements”)
    • Estimate message frequency (e.g., “up to 4 messages per month”)
    • Include “Msg & data rates may apply”
    • Include opt-out instructions (“Reply STOP to cancel, HELP for help”)
    • Appear at the point of consent collection, not buried in a linked terms-of-service page

    Web form (checkbox, not pre-checked): Point-of-sale (verbal or paper): Phone intake (read aloud, then confirm via text): Dos and don’ts for consent prompts:

    • Do: Display the disclosure at the same visual level as the phone number field.
    • Do: Use a standalone checkbox for SMS consent, separate from email or general terms.
    • Don’t: Use language like “I agree to be contacted by [Company] or its partners” without naming every specific sender.
    • Don’t: Rely on a hyperlinked “Terms & Conditions” page to carry the disclosure. Courts have rejected this repeatedly.
    • Don’t: Collect consent once and reuse it for a different brand, product line, or campaign type without re-obtaining consent.

    Twilio’s SMS compliance guide recommends sending a confirmation message immediately after opt-in that restates the consent summary. This serves two purposes: it improves deliverability by confirming the number is active, and it creates a contemporaneous record of what the consumer agreed to receive.


    Consent you cannot prove in court is consent that does not exist. The operational question is not just whether you collected it, but whether you can produce it on demand within 24 hours of a subpoena or demand letter.

    1. Build consent capture at the point of entry. Every web form, point-of-sale terminal, and phone intake script must log consent at the moment it is given. Do not rely on a downstream CRM sync to capture the record. The capture must happen at the source system.
    2. Send a confirmation text immediately. The first message a new subscriber receives should confirm what they signed up for: “You’re now subscribed to [Company] alerts. Msg & data rates may apply. Reply STOP to cancel.” This message is both a deliverability check and a consent record.
    3. Log the full consent record. Every opt-in event should write a record to a dedicated consent database with these fields at minimum:
    Field Description Why It Matters
    phone_number E.164 format Ties record to the subscriber
    consent_text Exact disclosure shown at opt-in Proves what was disclosed
    timestamp UTC, millisecond precision Establishes when consent was given
    ip_address IPv4 or IPv6 of submitting device Corroborates the submission
    source_url Full URL of the opt-in page Identifies which form was used
    form_id Unique identifier for the form version Tracks consent language versions
    campaign_id Campaign or program identifier Scopes consent to a specific use
    opt_in_method Web, POS, phone, SMS keyword Documents the collection channel
    1. Implement SMS double opt-in for high-risk campaigns. After the initial web form submission, send a text asking the subscriber to reply “YES” to confirm. This adds a second layer of verification and is particularly valuable when list quality is uncertain.
    2. Use a vendor like ActiveProspect for third-party lead verification. ActiveProspect’s TrustedForm product captures a certificate of the web session at the moment of consent, including a video replay of the form interaction. This is the closest thing to litigation-proof consent documentation available for web-based opt-ins.

    Pro Tip: Set a minimum retention period of four years for all consent records. The TCPA’s statute of limitations is four years under 28 U.S.C. § 1658. Store records in an exportable format (CSV or JSON) so your legal team can pull them without engineering support. When a subscriber deletes their account, archive the consent record rather than deleting it.


    How do opt-outs, suppression lists, and reassigned numbers work?

    Opt-out handling is where many otherwise-compliant programs fall apart. The rule is simple: when someone opts out, they stop receiving messages. The execution is harder than it sounds.

    Under 47 CFR § 64.1200 and the FCC’s updated rules, you must honor opt-outs via “any reasonable method.” STOP is the standard keyword, but a consumer who replies “unsubscribe,” “cancel,” “quit,” or even sends a clear written request through another channel has exercised their right to opt out. Your system must recognize all of these.

    Operational steps for suppression list management:

    • Maintain a single master suppression list that is the source of truth across your CRM, SMS platform, email platform, and any third-party vendors.
    • Sync opt-outs in real time or near-real time. A 24-hour batch sync is not acceptable if you send campaigns daily.
    • Confirm opt-outs with a single final message: “You’ve been unsubscribed from [Company] texts. No further messages will be sent.” Do not send any additional marketing after this point.
    • Audit your suppression list against every vendor’s send list before each campaign. A vendor who does not accept suppression file uploads is a liability.

    Reassigned numbers: a specific and underappreciated risk

    When a consumer gives up a phone number, the carrier reassigns it to a new subscriber. If you keep texting that number, you are now messaging someone who never consented. The FCC’s Second Report & Order addressed this directly.

    The practical safeguard is the FCC’s Reassigned Numbers Database (RND), which carriers report disconnected numbers to. Before sending to any number that has not engaged in 30 or more days, check it against the RND. The safe harbor for the first message to a reassigned number is limited: you may have a defense if you had no reason to know the number was reassigned, but continuing to message after a new subscriber signals they did not consent eliminates that defense immediately.

    Reassignment and opt-out process checklist:

    1. Check all numbers inactive for 30+ days against the Reassigned Numbers Database before each send.
    2. Remove any number flagged as reassigned from your active list immediately.
    3. Process STOP replies within one business day at the absolute latest, ideally in real time.
    4. Accept opt-outs through email, web form, or phone call when a consumer uses those channels.
    5. Log every opt-out event with timestamp, method, and the agent or system that processed it.
    6. Run a monthly suppression audit comparing your master list against each vendor’s active list.

    Which technologies trigger ATDS risk, and how do you evaluate your vendor?

    The autodialer definition is the most litigated question in TCPA history. The Supreme Court’s 2021 Facebook v. Duguid decision narrowed the statutory definition, holding that an ATDS must use a random or sequential number generator to store or produce numbers. But the practical risk for bulk SMS senders remains significant, because most commercial platforms store lists of numbers and dial them without individual human initiation per message.

    The FCC continues to interpret “capacity” broadly in some contexts, and plaintiffs’ attorneys argue that platforms with the technical ability to function as autodialers carry ATDS risk even when that mode is not actively used. Courts remain split on this question.

    Technical features that increase ATDS risk:

    • Stored number lists dialed without per-message human initiation
    • Predictive or progressive dialing modes
    • API-based bulk send triggered by a single command
    • Automated campaign scheduling without human review of each recipient
    • Platforms marketed explicitly as “mass texting” or “bulk SMS” tools

    Vendor questionnaire: 8 questions to ask before you sign

    1. Does your platform store phone numbers and initiate messages without individual human action per message?
    2. Does your system have the technical capacity to generate or dial numbers randomly or sequentially, even if that mode is not currently enabled?
    3. What documentation do you provide confirming the platform’s ATDS status or non-ATDS architecture?
    4. Do you indemnify customers for TCPA violations arising from your platform’s technical design?
    5. How do you process and log opt-out requests, and what is your SLA for suppression updates?
    6. Are you registered with The Campaign Registry for A2P 10DLC, and do you support brand and campaign registration for customers?
    7. What carrier filtering or blocking events have you experienced in the past 12 months, and how were they resolved?
    8. Can you provide a sample compliance report or audit log showing consent records and opt-out processing?

    Risk mitigation checklist for ATDS exposure:

    • Set human-trigger thresholds: require a human to initiate each campaign send, not just schedule it.
    • Throttle send rates to avoid patterns that resemble random-number dialing.
    • Document your reliance on vendor representations about ATDS status in writing.
    • Include indemnification and TCPA-specific liability clauses in every vendor contract.
    • Review your platform’s technical architecture with outside counsel at least annually.

    Special cases: healthcare, debt collection, political messages, and transactional texts

    Some industries carry compliance obligations that stack on top of TCPA. Getting one layer right while ignoring the other is not a defense.

    Healthcare: TCPA plus HIPAA

    Texting in a healthcare context triggers two separate legal frameworks. TCPA governs the consent and autodialer rules. HIPAA governs what information can be transmitted and how. When a text message contains Protected Health Information (PHI), such as a diagnosis, test result, medication name, or appointment detail that reveals a condition, standard consumer SMS is not sufficient.

    HIPAA Journal’s 2026 analysis confirms that non-secure SMS generally risks violating HIPAA when PHI is transmitted without appropriate controls. Covered entities and their business associates must use secure texting platforms that support Business Associate Agreements (BAAs) and implement technical safeguards including encryption in transit and at rest.

    The CMS memorandum on texting patient information for hospitals and critical access hospitals states that texting patient orders is permissible only through HIPAA-compliant secure texting platforms with Conditions of Participation compliance. CPOE remains the preferred method for orders. For appointment reminders that do not include clinical details, standard SMS with TCPA-compliant consent may be acceptable, but the safer path is a secure platform regardless.

    For healthcare teams combining HIPAA-compliant texting with practice management workflows, the medical billing automation guide covers how to integrate secure messaging with CPOE-adjacent processes.

    Debt collection and political messages

    Debt collection texts carry TCPA risk plus Federal Debt Collection Practices Act (FDCPA) constraints. Consent obtained at the time of the original transaction may or may not transfer to a debt collector, depending on the assignment. Consult counsel before texting consumers about outstanding balances.

    Political and campaign messages are not exempt from TCPA. Prior express consent is still required for autodialed texts to mobile phones. The exemption that applies to political calls to landlines does not extend to mobile numbers.

    Compliance matrix for common use cases


    What happens when you violate TCPA for SMS?

    What happens when you violate TCPA for SMS? — overview diagram

    The financial exposure is not theoretical. TCPA statutory damages are $500 per message for standard violations and $1,500 per message for willful violations. There is no statutory cap on aggregate damages, which means a campaign sent to 100,000 recipients without proper consent carries a potential exposure of $50 million to $150 million before any legal fees.

    Class actions are the primary enforcement mechanism. Plaintiffs’ attorneys file on behalf of all recipients of a non-compliant campaign, and because each message is a separate violation, the math compounds quickly. A single misconfigured suppression sync that sends one message to 10,000 opted-out contacts is a $5 million to $15 million exposure event.

    Exposure scenario: A retailer sends a promotional text to 50,000 contacts using a purchased list with generic partner consent language. Under the FCC’s lead-generator loophole closure, that consent is insufficient. At $500 per message, the statutory exposure is $25 million. At $1,500 per message for willful violation (the plaintiff argues the company knew the consent was deficient), the exposure reaches $75 million.

    The FCC also has direct enforcement authority. The Second Report & Order requires terminating mobile wireless providers to block text messages from numbers after FCC notification, and the Federal Register publication of that order confirms the effective dates and procedural requirements. Carrier blocking is independent of litigation: your messages can be filtered or suspended by carriers for CTIA violations even when no lawsuit has been filed.

    The FCC’s Second Report & Order also codified that the National Do-Not-Call Registry’s protections extend to text messages. Texting a number on the DNC Registry without an established business relationship or express invitation is a separate violation.

    Practical mitigation steps:

    • Document every consent record with the fields listed in Section 4 above.
    • Process opt-outs in real time and confirm them with a final message.
    • Audit vendor contracts for indemnification clauses and TCPA representations.
    • Run a pre-campaign suppression sync within one hour of send time.
    • Never send to a purchased list without re-obtaining brand-specific consent.

    Step-by-step workflow for sending a compliant marketing SMS campaign

    This is the operational sequence your team should run for every marketing campaign. Treat it as a checklist, not a guideline.

    Pre-send checklist

    1. Verify consent records. Pull the send list and confirm every number has a logged PEWC record with timestamp, consent text, IP address, and source URL. Remove any number without a complete record.
    2. Check against the Reassigned Numbers Database. Flag and remove any number that has been disconnected since consent was collected.
    3. Sync suppression list. Pull the current master suppression list from your CRM and apply it to the send list. Do this within one hour of send time.
    4. Confirm A2P 10DLC registration. Verify your brand and this specific campaign are registered with The Campaign Registry. Unregistered campaigns are filtered by major carriers.
    5. Review message content against CTIA guidelines. Confirm the message identifies the sender, includes opt-out instructions (“Reply STOP to cancel”), and contains no prohibited content (cannabis, firearms, adult content on standard short codes).
    6. Check quiet hours. Confirm the send time falls between 8 AM and 9 PM in the recipient’s local time zone. For national campaigns, segment by time zone.

    Send-time checklist

    1. Confirm sender identification appears in the message body or is clear from the short code/long code registration.
    2. Include “Reply STOP to cancel” in every marketing message.
    3. Monitor delivery reports in real time for anomalous failure rates that may indicate carrier filtering.
    4. Watch for complaint spikes in the first 30 minutes after send.

    Post-send checklist

    1. Log delivery receipts and opt-out events within 24 hours.
    2. Process all STOP replies immediately and update the master suppression list.
    3. Run a compliance audit comparing messages sent against consent records on file.
    4. Archive the campaign record including send list, message content, delivery report, and opt-out log.
    Phase Key Action System Responsible
    Pre-send Consent verification Consent database + CRM
    Pre-send Suppression sync CRM + SMS platform
    Pre-send RND check Reassigned Numbers Database API
    Pre-send A2P 10DLC confirmation Campaign Registry portal
    Send-time Quiet-hours enforcement SMS platform scheduler
    Send-time Delivery monitoring SMS platform analytics
    Post-send Opt-out processing CRM + suppression list
    Post-send Compliance audit log Consent database + archive

    Why permission-first SMS programs outperform the alternatives

    The conventional wisdom in SMS marketing is that list size drives revenue. Build the biggest list you can, send frequently, and optimize from there. That logic is wrong, and the data from real programs bears it out.

    Permission-first programs, built on explicit PEWC with clear opt-in language and confirmed double opt-in flows, grow more slowly. There is no getting around that tradeoff. But the contacts on those lists convert at higher rates because they actively chose to hear from you. Deliverability is better because carriers and spam filters score engagement signals, and a list of genuinely interested subscribers generates fewer complaints per send. Legal exposure is lower because every contact has a documented, defensible consent record.

    The alternative, buying lists or using broad partner consent, generates short-term volume and long-term liability. The FCC’s closure of the lead-generator loophole was not a surprise to anyone paying attention. The enforcement trend has moved consistently toward stricter, more specific consent requirements since 2012. Businesses that built permission-first programs before the rule changes were not disrupted. Businesses that relied on aggregated or partner consent had to rebuild their lists from scratch or face litigation.

    The operational tradeoff is real: slower list growth, more friction at the opt-in point, and more infrastructure to maintain consent records. But the conversion rates on a clean, permission-first list typically justify the investment, and the litigation risk reduction is not a soft benefit. It is a hard dollar figure you can calculate against the exposure scenarios in Section 8.


    Cannatract builds the compliance infrastructure your SMS program needs

    Consent capture, suppression syncs, and audit-ready recordkeeping are not marketing problems. They are engineering problems, and most marketing teams do not have the technical resources to build them correctly. Cannatract designs and builds the backend systems that make TCPA SMS compliance operational rather than aspirational.

    Cannatract

    Specifically, Cannatract builds consent capture forms with real-time database logging (phone, consent text, timestamp, IP, form ID, campaign ID), integrates suppression lists across your CRM and SMS platform so opt-outs propagate in real time, and creates automated audit export workflows so your legal team can pull consent records without engineering support. For healthcare clients, Cannatract integrates secure texting workflows with HIPAA-compliant platforms and BAA documentation. Every project ships with a fixed quote and a 2–4 week delivery timeline, so you know exactly what you are getting and when.

    If your current consent capture is a checkbox in a form builder with no backend logging, or your suppression sync runs on a nightly batch job, those are the gaps that generate litigation. Cannatract and get a clear scope of what it takes to fix them.


    Useful primary sources and further reading

    The following primary sources were used throughout this article. Verify current rules directly with these sources before making compliance decisions.

    • 47 CFR § 64.1200: The FCC’s primary regulatory text for consent and delivery restrictions governing autodialed calls and texts.
    • FCC Second Report & Order (FCC-23-107A1): The order requiring carrier blocking, codifying DNC Registry protections for texts, and tightening consent language requirements.
    • Federal Register Publication of FCC Order (FR-2024-01-26): Official public notice with effective dates and procedural details for the blocking and consent rule changes.
    • FCC Enforcement Bureau Advisory (DA-16-1299): FCC position that TCPA restrictions apply to autodialed text messages and that senders bear the burden of proving consent.
    • Twilio U.S. SMS Compliance Guide: Vendor-facing best-practice guidance on opt-in flows, confirmation messages, and opt-out handling.
    • HIPAA Journal: Is Texting in Violation of HIPAA?: Analysis of when healthcare texting triggers HIPAA obligations and platform requirements.
    • CMS Memo: Texting of Patient Information and Orders: Federal health guidance on permissible texting in hospital and CAH settings.
    • BCLP Law: TCPA Opt-Out Rules Effective April 11, 2025: Legal commentary on the operational impact of the FCC’s updated opt-out and blocking rules.

    This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

    Sources

    FAQ

    What are the main U.S. regulations governing SMS marketing?

    The primary federal law is the Telephone Consumer Protection Act (TCPA), enforced by the FCC under 47 CFR § 64.1200, which requires prior express written consent for autodialed marketing texts and mandates immediate opt-out compliance. Carrier-level rules from the CTIA and A2P 10DLC registration requirements operate independently and can result in filtering or blocking regardless of TCPA compliance.

    What are the new TCPA rules taking effect in 2025 and 2026?

    The FCC’s Second Report & Order, published in the Federal Register on January 26, 2024, requires mobile wireless providers to block texts from numbers after FCC notification, codifies National Do-Not-Call Registry protections for text messages, and tightens consent requirements to mandate seller-specific rather than generic partner consent. The updated opt-out rules took effect April 11, 2025.

    What does it take to comply with the TCPA for SMS campaigns?

    At minimum, you need documented prior express written consent for every marketing text, a real-time suppression system that honors opt-outs immediately, A2P 10DLC brand and campaign registration, timestamped consent records retained for at least four years, and messages sent only between 8 AM and 9 PM in the recipient’s local time zone.

    Are iMessages subject to TCPA?

    iMessages sent from a business platform using an ATDS to a mobile number are subject to TCPA in the same way standard SMS messages are. The FCC’s position is that texts are “calls” under the statute regardless of the underlying messaging protocol, so the consent and opt-out requirements apply.

    When does texting a patient violate HIPAA?

    Texting a patient violates HIPAA when the message contains Protected Health Information and is sent over a non-secure channel without appropriate technical safeguards. Per HIPAA Journal’s analysis, covered entities must use secure texting platforms that support Business Associate Agreements when PHI is transmitted, and the CMS memo confirms this requirement for hospitals and critical access hospitals.

    Want this working in your business?

    Book a free automation audit and we'll map the highest-ROI opportunity in your operation.