Here's a scenario that plays out at practices every week. A patient books an appointment. At the front desk they check a box that says "Yes, text me reminders." Three months later that same patient gets a text: "Flu shot season is here — book your visit today, 20% off wellness packages this month."

Both texts came from the same number. Both came from the same opt-in checkbox. And one of them is a violation waiting to happen.

Full disclosure: I work for ReadySMS, and we build the compliance tooling that tracks this kind of thing. But this problem exists no matter whose platform you use, and it's worth understanding before you send another blast.

The two texts aren't the same, even though they feel identical

The reminder text and the flu-shot text look almost the same to a patient. Both are short, both are from the practice, both are arguably "helpful." But under the law they live on opposite sides of a consent wall.

  • The reminder is a treatment communication. It's tied to a specific appointment, a specific clinical relationship, and an action the patient already took. Consent for this is implied by the treatment relationship and usually doesn't require the same express written authorization that marketing does.
  • The flu-shot promo is marketing. It's outreach designed to generate a new visit and, in most framings, sell something. That requires prior express written consent under the TCPA — a distinct, documented "yes I agree to receive promotional/marketing texts."

The line isn't about the topic. A flu-shot text could be a treatment communication if the patient has a standing order or an overdue recall on file. It becomes marketing the moment its purpose shifts to generating business rather than serving an existing care plan. We cover exactly where that line sits in A Recall Text and a Promo Text Need Different Consent — worth reading alongside this one.

Why one checkbox can't cover both

The gap most practices fall into: they collect one opt-in and treat it as blanket permission to send anything.

That single checkbox — "text me about my care" — is a treatment consent. It does not authorize marketing. So when a promo goes out to that list, the practice has express consent for reminders and nothing for the promo, even though the patient is on the list.

The exposure here is real. TCPA statutory damages run $500 to $1,500 per text. A promo blast to 3,000 patients where even a fraction were only opted in for treatment communications is not a rounding-error risk — it's a demand letter.

And the tricky part: the patient often wants the flu-shot reminder. Nobody's angry. But TCPA liability doesn't require an angry patient. It requires a plaintiff's attorney and a number that wasn't authorized for that message type. Litigators buy nothing and complain about everything; a text they can frame as marketing without documented marketing consent is exactly what they're hunting for.

The compliant opt-in flow captures both, separately

The fix isn't complicated. It's two consents, captured at the same moment, tracked as distinct records.

At intake or booking, present two clearly separated choices:

  1. Treatment/operational messaging — "Text me appointment reminders, results-ready notices, and care instructions." (Often pre-checkable or implied by the treatment relationship, depending on your jurisdiction and counsel's read.)
  2. Marketing messaging — "Text me about promotions, health campaigns, new services, and offers." (Must be affirmatively opted into — an unchecked box the patient actively checks, never a pre-checked default.)

The key rules:

  • The marketing box is never pre-checked. Pre-checked marketing consent is not express written consent. Full stop.
  • Marketing consent is not a condition of treatment. The patient must be able to decline the promo consent and still get care and reminders.
  • Both consents are timestamped and stored with the exact language shown, the source, and the patient's action.

That last point is where most practices are exposed even when they did collect two consents — they can't prove it later. A checkbox click that isn't logged with the language, timestamp, and IP/source is an assertion, not evidence.

What "tracking both" actually looks like in practice

This is the part that's hard to do with a spreadsheet and easy to do with the right layer underneath your messaging.

In ReadySMS, consent isn't a single on/off flag. Opt-in attestation is captured and stored per contact for bulk and API sends, building an audit trail you can actually produce. When you segment a list for a marketing blast, you segment on the marketing consent record — not the general "is this person a patient" record. The two never get conflated at send time.

A few mechanics that matter for healthcare senders specifically:

  • Automatic STOP handling propagates across campaigns. If a patient replies STOP to a promo, that opt-out is honored and carries so they can't be messaged again — but you'll want your treatment/operational flow scoped so a marketing STOP doesn't accidentally kill appointment reminders they still want. This is a real design decision, not a default; think it through.
  • Quiet-hours enforcement holds sends outside permitted local hours based on the recipient's area, which reduces TCPA exposure on both message types.
  • Litigator and DNC scrubbing screens known TCPA-litigator and DNC numbers before a marketing send. Our standalone scrub runs $0.005 per contact — cheap insurance against a $500–$1,500 problem.

None of this makes you lawsuit-proof. Compliance is ultimately the sender's responsibility, and I'd rather say that plainly than pretend a feature list absolves you. What the tooling does is make the good practice the default path instead of the thing you forget under deadline.

A worked example: the cost of getting the segment wrong

Say a 3-provider clinic has 8,000 patients. All 8,000 opted into appointment reminders. Only 4,500 affirmatively opted into marketing.

You want to send a flu-shot campaign — a 158-character message, one GSM-7 segment.

The compliant send goes to the 4,500 marketing-consented patients:

  • 4,500 × 1 segment × ($0.02 + $0.0045 carrier) = $110.25

The non-compliant send to all 8,000 saves you nothing worth having — it costs an extra $85.75 in messages and exposes the 3,500 patients who never consented to marketing. If a litigator sits in that untargeted 3,500 and frames it right, the downside dwarfs the entire campaign budget by three orders of magnitude.

The lesson isn't "sending is expensive." It's that segmenting on the right consent field costs you a few hundred fewer messages and removes the only real risk in the whole operation. The math favors compliance.

The re-consent trap most clinics don't see coming

One more wrinkle. Consent doesn't quietly expire, but the relationship it's tied to can. A patient who hasn't been seen in three years and opted into marketing back then is a shakier basis for a promo blast than a patient you saw last month.

If your list has patients who've aged out of the active relationship, that marketing consent is worth revisiting before you lean on it. We break down the trigger in Patient SMS Consent Doesn't Expire — but the Relationship It's Tied To Does. And if you're wiring this into GoHighLevel, be careful that trigger links and clicks aren't standing in for real consent — that's a 10DLC registration risk covered here.

The practical takeaway

Two message types, two consents, tracked separately. That's the whole discipline:

  1. Capture treatment consent and marketing consent as distinct records at intake — marketing never pre-checked, never a condition of care.
  2. Segment marketing blasts on the marketing consent field, not on "is a patient."
  3. Log the language, timestamp, and source so you can prove the consent later.
  4. Scrub before promo sends, respect quiet hours, and honor STOP per message type.

If you're doing this with checkboxes in a form and a spreadsheet, it's technically possible and genuinely fragile. If you want the consent records and the segmentation to line up automatically at send time — plus 10DLC handled in-app, native two-way GoHighLevel sync, and STOP/quiet-hours built in — that's what we built. You can start with 2,500 free credits, no card required, and see whether the flow fits how your front desk actually works: readysms.io/pricing.

Either way, draw the line between the reminder and the promo before the next campaign goes out. That's the gap.