A patient checks in, hands over their phone number, and taps a box that says "Yes, text me appointment reminders." Three weeks later your front desk fires off a blast: "Flu shots are here — book yours today, walk-ins welcome!" to that same number.

You just crossed a line most clinics don't know exists. The reminder was transactional. The flu-shot text was marketing. And the consent the patient gave you covers exactly one of them.

Full disclosure: I work for ReadySMS, an SMS platform that a lot of clinics use for this exact stack. I'll show you where our tooling helps, but the consent-scope problem is real no matter what you send with, so I'm going to be straight about where the responsibility actually sits (spoiler: with you, the sender).

Two texts, two legal categories

The word "consent" gets used like it's one thing. It isn't. Under the TCPA, texts split into two buckets, and each bucket needs its own kind of permission.

  • Transactional / informational — appointment reminders, recall notices, "your results are ready," post-visit care instructions, rescheduling. These support the care relationship the patient already has with you. The consent bar is lower: the patient gave you their number for the purpose of getting these.
  • Marketing / promotional — anything designed to sell, upsell, fill capacity, or promote a service. "Book your flu shot," "20% off teeth whitening this month," "we now offer Botox." These need prior express written consent — a separate, affirmative, marketing-specific opt-in.

The flu-shot text is the trap because it feels clinical. It's health-adjacent, it's arguably good for the patient, and it's coming from their doctor. But the intent is to fill appointment slots and drive revenue. That's marketing. Feeling helpful doesn't move it across the line.

We wrote a longer breakdown of exactly this on the recall-vs-promo side — a recall text and a promo text need different consent — because the same failure shows up in dental recalls, optometry, derm, everywhere.

Why a single opt-in can't cover both

Consent is scoped to purpose. When a patient taps "text me reminders," the reasonable reading of that permission is: reminders. Not offers. Not campaigns. A court doesn't read a narrow opt-in generously in your favor — it reads it against the party who drafted it.

Here's the exposure that makes this worth caring about. TCPA statutory damages run $500 per text, up to $1,500 for willful violations. A single promo blast to 4,000 patients who only consented to reminders isn't one violation — it's potentially 4,000. Even at the floor, that's $2M in theoretical exposure from one Tuesday-morning send.

Nobody's saying you'll get hit for the full number. But litigator plaintiffs seed lists, class actions aggregate, and "I thought it was fine because it's healthcare" is not a defense that has aged well. The three lists compliance teams keep confusing — DNC, litigator, and TCPA complainers — are all quietly on your patient roster somewhere.

The 10DLC angle nobody warns you about

There's a second, quieter failure mode that has nothing to do with lawsuits: your texts just stop arriving.

When you register a 10DLC campaign, you declare a use case — is this messaging transactional or marketing? Carriers filter against that declaration. If you registered a lean, transactional "appointment notifications" campaign to get fast approval and clean throughput, and then you push marketing content through it, the carrier's content filters can silently drop the promos. No bounce, no error you'll notice — just delivery quietly falling off.

This is the same mismatch we've seen wreck delivery for tons of senders: registering the wrong use case for the traffic you actually send. The fix mirrors the consent fix — run the two message types as two registered campaigns.

With ReadySMS you handle brand + campaign registration in-app. Rough carrier costs are ~$10/mo per brand and ~$20/mo per campaign, approval typically 1–3 days. So running a separate marketing campaign alongside your transactional one costs about $20/mo extra. That's the price of keeping your promos from getting filtered and keeping the consent tracks legally distinct. Cheap.

Running two consent tracks without annoying patients

The fear I hear from practice managers: "If I ask twice, patients will feel nagged and half won't opt into anything." Fair. Here's how to keep it painless.

1. Split the opt-in at intake — but keep it one form

On your intake form or check-in flow, use two checkboxes, not one:

  • ☐ Text me appointment reminders and health notices (transactional)
  • ☐ Text me occasional offers, seasonal services, and news (marketing)

The patient sees them together, taps once or twice, done. You've now captured two distinct consent records from a single interaction. Most patients tick both. The ones who only tick the first told you exactly where the line is — respect it.

2. Store the two consents separately

Don't collapse them into one "opted in: yes" flag. You want a record that says this number consented to marketing on this date via this form, distinct from the reminder consent. When ReadySMS captures opt-in attestation for bulk and API sends, that record is your audit trail if anyone ever asks. Reminders draw from the transactional list; promos only ever draw from the marketing list.

3. Never let a workflow blur the lists

This is where GHL users get burned. A workflow that triggers off a trigger-link click, or a tag applied for one purpose and reused for another, quietly pulls reminder-only patients into a promo send. We've catalogued the workflow mistakes that double-text and mis-target contacts, and separately why trigger-link clicks aren't consent in the first place. Audit your sends: does the marketing blast pull only from the marketing-consent segment? If you can't prove it, fix it before the next campaign.

4. Honor STOP once, everywhere

If a patient replies STOP to a flu-shot promo, that opt-out has to stick — and it has to stick across every campaign, not just the one that got the STOP. ReadySMS handles inbound STOP/UNSUBSCRIBE automatically and propagates the opt-out so the contact can't be messaged again. That matters double when you're running two campaigns: a patient who quits marketing shouldn't have to quit reminders too, and a patient who fully opts out shouldn't slip through because the opt-out only registered on one campaign.

A quick before/after

ScenarioOne opt-in (the gap)Two consent tracks
Appointment reminder✅ Covered✅ Transactional list
"Book your flu shot"❌ Marketing sent on transactional consent✅ Marketing list only
Carrier delivery⚠️ Promos filtered on transactional campaign✅ Registered marketing campaign
Patient replies STOP to promoRisk of blanket opt-out losing reminders tooScoped opt-out, reminders continue
Audit request"We had a checkbox" (vague)Dated, purpose-specific consent record

What to do this week

You don't need a compliance overhaul. You need three things:

  1. Add the second checkbox to intake or check-in, worded plainly for marketing. Start capturing scoped consent today so the list grows clean going forward.
  2. Register a second 10DLC campaign for marketing use case, distinct from your transactional one. ~$20/mo, 1–3 days, done in-app.
  3. Audit your next promo blast's audience — confirm it pulls only from the marketing-consent segment, not "everyone with a phone number."

For the fuller picture on what you can and can't put in the message body itself, SMS for healthcare: HIPAA, consent, and what you can actually send is the companion piece to this one.

The reminder and the flu-shot promo look like the same text to your front desk. They're two different legal objects wearing the same 160 characters. Treat them that way — separate consent, separate list, separate campaign — and the whole thing stops being a liability and goes back to being what it should be: patients getting texts they actually agreed to receive.

If you want to see how the consent capture, per-campaign registration, and automatic STOP handling fit together, our 10DLC explainer walks the registration side, and you can start on the free 2,500 credits — no card — to test a clean two-track setup before you commit.