It is 8:10 on a Tuesday and your front desk is trying to fill three open slots before lunch. So they text patients who lapsed last month. One reads: “Hi Karen, it’s been 6 weeks since your last adjustment for your L4-L5 disc herniation. Ready to get back on your treatment plan? Reply YES to book.” It feels helpful. It also turns a routine recall into a HIPAA problem, because it dropped a diagnosis and a treatment detail into a plain, unencrypted SMS.
Here is the short answer up front. Chiropractic clinics can text patients, and most patients want them to. What HIPAA regulates is not whether you text, but what you say in the message. Appointment reminders, recall nudges, no-show follow-ups, review requests: all fine. What you cannot do is drop a diagnosis, a condition, a treatment description, or another patient’s information into the message body without the right consent and guardrails. Get it right and texting becomes the most reliable channel you own. Get it wrong and one screenshot from an annoyed patient becomes a complaint to the Office for Civil Rights.
This guide is the content-and-consent half of clinic texting. The TCPA-compliant SMS playbook covers who you may contact; this one covers what you may say once you have permission. Every rule is sourced, and every sample text is one you can copy today.
Table of contents
- Can chiropractors legally text patients?
- What counts as PHI in a text
- The seven texts every clinic sends, made compliant
- The consent and notice language you can steal
- Your texting vendor and the BAA you probably skipped
- Solo, three-doctor, and multi-location
- What happens when you get it wrong
- Common objections
- Frequently asked questions
Can chiropractors legally text patients?
Yes. Nothing in HIPAA bans texting a patient. The confusion comes from mashing two different laws into one worry, so separate them.
The first is the Telephone Consumer Protection Act (TCPA). It governs whether you may contact someone by automated text at all. Informational, care-related messages sit under a lighter consent standard than marketing blasts, and the FCC’s 2015 order exempted certain HIPAA-defined healthcare messages like reminders and confirmations (FCC, 2015). You still need permission to text, and since April 11, 2025 the FCC has required businesses to honor an opt-out sent by any reasonable method, not just the word STOP (FCC).
The second is HIPAA, which governs the privacy of the health information inside the message. The Privacy Rule is explicit that a provider may communicate with patients by email or text about their care. The catch is the Security Rule behind it: it expects you to protect electronic health information, and ordinary SMS is not encrypted. So the Office for Civil Rights guidance is practical: you may use an unencrypted channel if the patient has been warned of the risk and still asks you to use it (HHS OCR). Patients also have a right to request confidential communications, the flip side of the same coin.
So the reality is not “don’t text.” It is “text, with consent, and watch what you put in the message,” and that second clause is where clinics slip.
Patients, meanwhile, are asking for the texts. Appointment reminders are the top reason people opt in to business texts (76% of consumers) (SimpleTexting, 2026), and roughly 90% of patients prefer to hear from their provider by text (Sinch, 2026). Texting is also the one channel where you can be almost certain the message is seen: SMS is opened around 98% of the time, most within minutes (Omnisend, 2025). That read rate is exactly why it fills a schedule that leaks through no-shows and lapsed patients.
What counts as PHI in a text
Protected Health Information (PHI) is any health information that can be tied to a specific person. HIPAA lists 18 identifiers that make information individually identifiable, including name, phone number, email, and even appointment dates (HHS). A text almost always contains one, because it goes to the patient’s own number. That does not make it illegal; it means the content on top of that identifier is what you manage.
The rule doing the heavy lifting is minimum necessary: use only the information needed to get the job done (HHS). For a text, the job is usually “get the patient to show up” or “get them to call back,” and you rarely need clinical detail for that. The practical line: naming the appointment is fine, naming the ailment is not.
| You can safely put in a text | Keep this OUT of the text |
|---|---|
| First name and the clinic name | Diagnosis or condition (“disc herniation,” “sciatica”) |
| Appointment date, time, and location | Treatment or service detail (“your decompression series”) |
| “Confirm, reschedule, or cancel” | Test or imaging results |
| A generic “time for your next visit” | Another patient’s information |
| A payment-due nudge with an amount | Anything a stranger reading the lock screen shouldn’t see |
The test I give front desks: imagine the message on a lock screen while the patient’s coworker glances over. If the glance reveals a health condition, rewrite it. “Reminder: your visit at Summit Chiropractic is Thu 2:30pm” passes. “Reminder: your sciatica treatment is Thu 2:30pm” does not. One word of difference, completely different risk.
The seven texts every clinic sends, made compliant
This is the part to bookmark. Seven message types a clinic actually runs, each with a compliant version you can copy and the way it tends to break. Swap in your clinic name and you have a starter library.
1. Appointment reminder
Send this: “Hi {first name}, this is Summit Chiropractic. Reminder: your visit is Thu 9/25 at 2:30pm. Reply C to confirm or R to reschedule. Reply STOP to opt out.”
How it breaks: staff name the service (“your adjustment for lower back pain”) to feel personal, which puts condition detail on the lock screen. Keep it to the appointment, not the reason.
2. No-show follow-up
Send this: “Hi {first name}, we missed you today at Summit Chiropractic. Want to grab another time this week? Reply here or call {phone}.”
How it breaks: clinics get clinical or scolding (“missing your care plan visits will slow your recovery”), which crosses into treatment detail. A warm, neutral nudge recovers more no-shows and stays clean.
3. Recall and reactivation
Send this: “Hi {first name}, it’s been a while since we saw you at Summit Chiropractic. We’d love to help you get back on track, want us to hold a spot this week? Reply YES.”
How it breaks: this is where PHI leaks most, because staff jog the memory with specifics (“it’s been 6 weeks since your disc treatment”). Cut the clinical hook; “get back on track” does the same work. The reactivation campaign guide sequences these without touching a diagnosis.
4. Missed-call text-back
Send this: “Thanks for calling Summit Chiropractic, sorry we missed you. How can we help? Reply here and we’ll get you booked.”
How it breaks: the outbound line is safe, but the reply thread is not. Once the caller answers “my neck has been killing me since the accident,” your system is storing PHI. The missed-call text-back workflow is worth running, but capture those replies into a compliant system, not a personal phone.
5. Payment and billing
Send this: “Hi {first name}, this is Summit Chiropractic billing. You have a balance of $45. Pay securely here: {link} or call us with questions.”
How it breaks: billing texts stay safe with an amount and a link, not a line item. “Payment due for your 6-visit spinal decompression package” names the treatment. “Balance of $45” does not. Send the number, not the narrative.
6. Review request
Send this: “Hi {first name}, thanks for visiting Summit Chiropractic. Would you share a quick review? It really helps other people find us: {link}.”
How it breaks: never reference why they came in (“hope your headaches are better”). Keep it to gratitude and the link.
7. Two-way conversation
Not a template, a rule. The moment a patient texts back a symptom, condition, or photo, that message is PHI and lives wherever your thread lives. On a personal phone you have no BAA and no way to honor a records request. Keep every patient thread inside a system you control.
The consent and notice language you can steal
Compliance is documented permission, not just careful wording. Two pieces of language do most of the work, and you can add both to your intake in an afternoon.
The opt-in and unencrypted-communication notice. This satisfies the OCR expectation that a patient was warned plain text is not secure and chose it anyway. Put it on the intake form with a checkbox:
“I agree to receive appointment reminders, recall messages, and other communications from {Clinic} by text and email at the number and address I provided. I understand that standard text and email are not encrypted and carry some risk that a message could be seen by someone else, and I accept that risk. Message and data rates may apply. I can opt out at any time by replying STOP.”
That paragraph does three jobs: it collects TCPA consent to contact, documents the HIPAA warning about the unencrypted channel, and sets the opt-out expectation. Capture it with a date and source, not just a yes, because “the patient checked this box on this date” answers a complaint and “they said it was fine” does not.
The confidential-communications option. HIPAA gives patients the right to ask you to reach them a specific way, or not by text at all. Add one line: “Prefer we not text you, or use a different number? Tell the front desk and we’ll note it.” Then flag that contact so no automation ever texts them.
Your texting vendor and the BAA you probably skipped
Here is the gap that catches good clinics. Your texts are clean, your consent is documented, and you still have a hole, because the software you send those texts through handles patient information on your behalf. Under HIPAA, that vendor is a business associate, and you need a signed Business Associate Agreement (BAA) with them (HHS).
A BAA is the contract where the vendor promises to protect the PHI it touches and to report a breach. Without it, if that vendor has an incident, the exposure lands on you, and “I didn’t know” is not a defense. It is also why the personal phone is such a problem: there is no BAA behind a personal number, and there never can be.
What to do:
- List every tool that touches a patient’s number or message: reminder platform, CRM, phone system, review tool. Each that stores or transmits PHI needs a BAA.
- Ask each vendor for their BAA and sign it. Reputable healthcare platforms have one ready. If a vendor cannot produce one, run your patient data elsewhere.
- Consolidate. Fewer systems means fewer BAAs and smaller exposure. Running reminders, recall, missed-call text-back, and reviews through one platform with one BAA beats four disconnected tools, a big reason clinics move to a single patient communication system.
Solo, three-doctor, and multi-location
The rules are the same at every size. What changes is where the risk concentrates.
The solo practice. Your biggest exposure is the personal phone. When you are adjusting and the front desk is slammed, texting from whatever phone is closest is tempting. Kill that habit: get a dedicated business texting number with a BAA, load the seven templates above, and route every patient message through it.
The three-doctor practice. Now the risk is inconsistency. More providers and staff means more ideas of what is okay to text: one writes “your sciatica follow-up,” another writes “your 2:30 visit.” The fix is standardization: a locked template library so nobody free-writes a clinical detail, plus a five-minute training on the lock-screen test. Automation helps because it removes the human urge to personalize with a diagnosis.
The multi-location group. Here you manage BAAs across more vendors, turnover is constant, and one bad habit at one location becomes a pattern. You need centralized template control, onboarding that covers texting rules on day one, and an audit trail. Opt-out and confidential-communications flags must sync across locations, so a patient who opts out at one clinic is not texted by another.
What happens when you get it wrong
The penalties are not theoretical, and they scale with how careless you were. HIPAA civil monetary penalties are tiered by culpability and inflation-adjusted. For 2026, the per-violation minimums run like this (HIPAA Journal, 2026):
An honest mistake starts around $145 per violation. Willful neglect you never fixed runs past $73,000 per violation, and each patient and each message can count separately, with an annual cap above $2.1 million (HIPAA Journal, 2026). The clinic that documents consent, uses locked templates, and holds BAAs can show reasonable safeguards were in place if anything goes wrong. The clinic texting diagnoses off a personal phone with no consent record cannot. And beyond the fine, a patient who feels their privacy was mishandled usually does not complain, they just leave and tell people.
Common objections
“This will slow my front desk down.” The opposite. Locked templates mean staff stop composing texts from scratch, which is faster and safer. Nobody has to decide what is okay to say, because the compliant version is the only one available.
“My patients want the personal touch, not robotic texts.” Personal and compliant are not opposites. “Hi Karen, we’d love to get you back on track, want us to hold a spot this week?” is warm, human, and contains zero PHI.
“I already text patients and nothing has happened.” That is survivorship, not safety. Most PHI slips never get reported because most patients never notice. You are one annoyed patient, one nosy coworker, or one lost phone away from the story changing. Getting compliant costs a couple of afternoons; the one bad day costs far more.
Finish the story
Back to that Tuesday. The compliant version of Karen’s text reads: “Hi Karen, it’s Summit Chiropractic. It’s been a while, we’d love to help you get back on track. Want us to hold a spot this week? Reply YES.” It fills the same slot and gets the same reply. It just does not put her spine on her lock screen, and it went out from a business number with a signed BAA and a consent record.
That is the whole game. Text your patients, because they want you to and it is the channel that fills the schedule. Keep the diagnosis, condition, and treatment out of the message, document consent, hold your BAAs, and route every conversation through a system you control. Do that and texting goes back to being your most reliable way to keep chairs full.
Frequently asked questions
Is it legal for chiropractors to text patients under HIPAA?
Yes. HIPAA permits providers to text patients. You need consent to contact them, the patient must have been warned that SMS is unencrypted and still want it, and you must keep PHI such as diagnosis and treatment out of the message body. Texting the appointment is fine; texting the ailment is not.
What can I include in an appointment reminder text?
The first name, clinic name, date, time, and location, and a way to confirm or reschedule. Leave out the reason for the visit, the condition, and any test or treatment detail. 'Your visit at Summit Chiropractic is Thu 2:30pm' is compliant; naming the condition is not.
Do I need a Business Associate Agreement with my texting software?
Yes. If the platform stores or transmits patient information for you, it is a business associate and needs a signed BAA. Reputable healthcare platforms provide one. A personal cell phone can never have a BAA, which is why patient texting should never run through staff phones.
What consent do I actually need to text patients?
Two layers: TCPA consent to contact by automated text, and a documented HIPAA acknowledgment that the patient understands SMS is unencrypted and accepts the risk. One clear intake checkbox, captured with a date and source, covers both. Keep the signed record.
How much can a HIPAA violation cost a chiropractic clinic?
Penalties are tiered by culpability and adjusted for inflation. For 2026 they run roughly $145 per violation for an honest mistake up to more than $73,000 for uncorrected willful neglect, with an annual cap above $2.1 million. Each patient and message can count separately.
This article is operations and compliance guidance for chiropractic clinics and the agencies that serve them. It is not legal advice. HIPAA and TCPA obligations vary by situation and state, and penalty figures change yearly. Verify current rules with the HHS Office for Civil Rights, the FCC, your state board, and your own counsel before finalizing any patient-communication policy. Every statistic is attributed to the source and year shown.

