August 14, 2026
6 min
Discover how to build, track, and measure a dental referral program that turns patient recommendations into a consistent source of new patients and practice growth.
August 14, 2026
6 min
What dental practices should know about TCPA compliance for bulk SMS, including consent requirements, opt-outs, and recent regulatory changes.

A single non-compliant text message can cost a dental practice between $500 and $1,500 under the Telephone Consumer Protection Act. There is no cap on total exposure. Send a promotional blast to 2,000 patients without proper consent, and the math turns a marketing campaign into a legal liability large enough to threaten the practice itself.
Most practices don't set out to violate the TCPA. They run into trouble because the rules around texting are more layered than they look, and a few common assumptions, like believing a general marketing checkbox covers text messages too, turn out to be wrong at the worst possible moment.
The TCPA regulates marketing texts, calls, and faxes and requires prior express written consent before sending promotional SMS to any patient. Appointment reminders and other transactional messages fall under a lighter standard, but the line between the two categories is easier to cross than most practices realize.
The TCPA treats two categories of text messages very differently, and getting this distinction wrong is where most practices run into trouble.
Transactional or informational messages include appointment reminders, confirmation texts, and account alerts. These require prior express consent, which can be given orally or in writing, and generally carry a lower compliance bar.
Promotional or marketing messages include anything selling a service, offering a discount, or promoting an event. These require prior express written consent, a meaningfully higher standard, documented and specific to text messaging.
Here's where practices get caught: a message that starts as transactional can flip into promotional the moment it includes marketing content. Adding a discount code or a promotional offer to an appointment reminder reclassifies the entire message as promotional, which means it now needs the higher consent standard the original reminder never collected. A practice that's been sending reminder texts for years, under transactional-level consent, cannot simply tack "and mention this code for 10% off" onto that same message thread without a real compliance problem.
Before sending any promotional text, a practice needs documented, written consent that specifically authorizes text message marketing from that practice. This is more particular than it sounds.
A combined checkbox that reads "I agree to receive marketing via email and SMS" does not meet the bar, because it fails to clearly and separately disclose that the patient is agreeing to receive automated marketing text messages specifically. SMS requires its own explicit opt-in, with its own disclosure language, separate from any email consent collected at the same time.
Consent also has to be documented in a way that can be produced later if challenged. A checkbox with a timestamp, an online form submission with a saved consent statement, or a signed intake form all work. A verbal "sure, you can text me" from a patient at the front desk, with nothing recorded, does not hold up as proof of written consent for marketing purposes, even if the patient genuinely agreed.
Before a practice can send a single promotional text at scale in the United States, the sending number and business need to be registered through A2P 10DLC, which stands for Application-to-Person 10-Digit Long Code. This registration process, run through the major carriers, verifies that a business sending bulk texts is legitimate and not a spam operation.
Skipping this step doesn't just risk regulatory exposure. Carriers actively filter and block unregistered bulk messaging traffic, meaning a practice that skips A2P 10DLC registration may find its campaigns simply never arrive, regardless of whether the underlying consent was handled correctly. Most dental marketing platforms handle this registration as part of onboarding, but it's worth confirming directly rather than assuming it's been done.
For years, the safe assumption was that a "STOP" reply covered opt-out compliance. That assumption is now outdated. Current guidance requires businesses to honor opt-out requests made through any reasonable method, not just the STOP keyword. A patient who replies "please don't text me anymore," calls the office to ask to be removed, or leaves a voicemail requesting no further texts has still exercised a valid opt-out, even without using the specific keyword.
This means a practice's texting system needs a process for catching non-standard opt-out language, not just automated STOP handling. Processing must happen within 10 business days at the outside, though real-time or near-real-time processing is the safer practice given how quickly a missed opt-out can compound into repeated violations.
A rule change taking effect in 2026 specifically restricts sharing consent across brands or entities. Each sender must obtain its own consent from each recipient directly. This detail matters far more for multi-location dental groups than it might initially appear.
A DSO that collects marketing text consent under one location's name, then uses that same consent list to send campaigns from a different location or from a central marketing entity, may now be operating outside the rule. If patient consent was originally collected as "Smile Dental Group," it cannot automatically be treated as valid consent for texts sent under a specific location's separate branding, or vice versa, unless the consent language clearly covers the actual sending entity.
This is a meaningful operational shift for any DSO running centralized text marketing across multiple locations, and it's worth confirming with legal counsel exactly how consent language needs to be worded to remain valid across the group's structure. This connects closely to how DSOs handle HIPAA-compliant texting more broadly. HIPAA and TCPA are separate laws covering separate risks, but both require the same kind of entity-specific, well-documented consent tracking to get right.
Before any bulk SMS campaign goes out, a few checks catch most of the common mistakes:
TCPA compliance for dental text marketing isn't complicated once the categories are clear, but the cost of getting it wrong is severe enough that guessing isn't a reasonable option. Separating transactional from promotional messages, documenting SMS-specific consent, registering through A2P 10DLC, and handling opt-outs broadly rather than narrowly covers most of the real risk. For DSOs, the 2026 consent-sharing change adds one more layer worth confirming before any centralized campaign goes out under a shared list.
This is general educational information, not legal advice. Confirm your specific consent language and campaign structure with a qualified attorney before scaling any text marketing program.
If you're trying to run compliant SMS campaigns without building the consent tracking from scratch, Convertlens's lead management tools are built to track consent status alongside every patient record, so compliance doesn't depend on someone remembering to check a spreadsheet before every send.
Do appointment reminders need the same consent as marketing texts?
No. Appointment reminders and other transactional messages need only prior express consent, which can be oral or written. Marketing texts require the higher standard of prior express written consent. The moment a reminder includes promotional content, though, it's treated as marketing and needs the higher standard.
What happens if a patient opts out but keeps getting texts?
This is one of the most common sources of TCPA complaints and potential fines. Every message sent after a valid opt-out, regardless of how the opt-out was communicated, is a separate violation. A reliable, promptly processed suppression list is the single most important safeguard against this.
Can a DSO share opted-in patient lists across locations?
Not automatically under the 2026 rule change. Consent must be tied to the specific sending entity. A DSO wanting to run centralized marketing across locations needs to structure its consent language carefully and should confirm the approach with legal counsel before scaling a shared campaign.
Is email marketing subject to the same rules?
No. Under the TCPA specifically, marketing calls, faxes, and text messages are regulated; email is exempt from this particular law, though other regulations like CAN-SPAM apply to email separately.
Sign Up Now & Someone from Our Team Will Be in Touch Shortly!
Use the form below to send us a message, and we’ll get back to you as soon as we can.