TCPA Compliance Dental Practice Guide: Calls and Texts

TCPA compliance dental practice rules decide which automated calls and texts you may send. See consent standards, opt-out timing, and risk by campaign.
Share:
Table of contents
TCPA compliance dental practice questions almost always start the same way. Your office buys a reminder system. Someone asks whether it is actually legal to text patients, and nobody in the building knows. The federal law behind that question is the Telephone Consumer Protection Act, passed by Congress in 1991 and reshaped repeatedly by the FCC since.
The reason it matters is arithmetic. Exposure is counted per message, not per campaign. Send one automated reminder to 400 patients on the wrong consent footing and you have 400 separate problems, or up to $200,000 in statutory exposure at $500 each.
This guide covers the consent you need before the first automated call or text goes out, how the healthcare carve-out works, how quickly an opt-out has to be honored, and which outbound campaigns carry the most exposure. Treat it as general education rather than legal advice, and read it alongside the rest of our compliance and legal coverage for dental teams.
What does TCPA compliance dental practice law actually cover?
The TCPA governs how businesses reach consumers by phone using automated technology. For a dental office, that means any prerecorded voice call, artificial voice call, autodialed call, or text message sent to a patient. Live calls dialed by hand from your front desk sit largely outside it.
Two federal layers matter. The statute itself, 47 U.S.C. section 227, creates the private right of action patients use to sue. The FCC implementing rules at 47 CFR 64.1200 fill in what consent means and how opt-outs work. Plaintiffs' firms read both closely, because the statute allows recovery per message.
What the statute puts at stake
Under the statutory text, a person who receives a violating call may recover actual monetary loss or $500 per violation, whichever is greater. A court may award up to 3 times that amount, so $1,500 per message, if the violation was willful or knowing. That treble provision is why a single sloppy campaign can become a real number.
What sits outside the TCPA
- Manually dialed live calls. A team member picking up the handset and dialing a patient one number at a time is not automated dialing. This is the fallback most practices lean on when consent status is unclear.
- Emergency purposes. Calls made for emergency purposes are carved out entirely.
- Email and patient portal messages. Different rules apply. HIPAA still does.
State law adds another layer. Florida, Oklahoma, and Maryland are among the states that have passed their own mini-TCPA statutes, with tighter calling windows and separate damages. Your state dental board or counsel is the right place to check that.
Does the HIPAA exemption cover dental appointment reminders?
Partly, and the nuance is where practices get caught. A health care message from a HIPAA covered entity or its business associate is exempt from the stricter written consent standard that applies to marketing. It is not exempt from consent altogether, and it is not exempt from opt-out duties.
Those terms come from the HIPAA Privacy Rule at 45 CFR 160.103. The rule text at 47 CFR 64.1200 draws the line around content, not intent. A reminder that confirms a date, a time, and a provider is a treatment communication. The moment that same message mentions a whitening special or a membership plan, it stops being a treatment message and becomes telemarketing.
Where the carve-out quietly disappears
- Bundled offers. A confirmation text with a promotional line appended is treated as an advertisement. Split them into separate sends.
- Reactivation framed as a deal. "We miss you, here is $50 off a cleaning" is marketing, even to a former patient of record.
- Third-party sends. If a marketing vendor sends on your behalf without a business associate agreement, the carve-out is on shaky ground.
The practical test we give office managers is blunt. Read the message out loud. If it would still make sense in a chart note, it is clinical. If it would only make sense in an ad, treat it as marketing and get written consent. Your HIPAA posture for automated patient communication should be documented before any of this goes live.
Not sure which of your messages count as marketing?
Content decides the consent standard, not the channel. Auditing your message templates before launch is faster than untangling it later.
See how DentiVoice handles patient messaging →What counts as prior express consent for a dental text or call?
Prior express consent means the patient gave you the number knowingly, for the purpose you are now using it for. A phone number written on an intake form for treatment communication generally supports treatment reminders. It does not, on its own, support promotional texting.
There are two standards, and the gap between them is the whole compliance question.

Prior express consent
This is the lower bar. It covers non-telemarketing automated contact, including the treatment reminders most practices care about. It can be oral or written. It has to be traceable back to a moment the patient actually provided the number.
Prior express written consent
This is the higher bar for anything promotional. It requires a signed written agreement, which can be electronic, that clearly authorizes automated marketing calls or texts to a specific number. It cannot be a condition of receiving treatment. Burying it in a paragraph of intake boilerplate is exactly the fact pattern plaintiffs like.
- Name the technology. Say the messages may be automated or prerecorded.
- Name the number. Tie consent to the mobile number the patient wrote down.
- Say it is optional. Treatment cannot hinge on agreeing to marketing texts.
- Timestamp it. Consent without a date is hard to defend two years later.
Most practices already collect the number. Very few capture the language, the checkbox state, and the timestamp in a way anyone could produce on request. Structured digital intake forms close that gap without adding front desk work.
How many automated reminders can a dental practice send?
There is a hard numeric cap on one channel and no fixed number on the other. For residential landlines, the health care exemption in the federal rules allows no more than 1 call per day to a patient, up to a maximum of 3 combined calls per week, and the caller must honor opt-out requests.
Wireless numbers work differently. There is no published per-week ceiling for consented treatment messages to a mobile phone. That sounds permissive until you remember that consent is the ceiling. Consent given for appointment reminders does not stretch to cover a weekly newsletter.
A frequency pattern that stays defensible
- Confirmation at booking, sent immediately.
- Reminder roughly one week out.
- Final reminder the day before, with a reply option to reschedule.
- One follow-up after a missed visit, then stop unless the patient responds.
That is 4 touches tied to a single appointment. Each one is clearly connected to the treatment relationship, which is the argument you want to be able to make. Anything beyond that starts to look like a campaign rather than a reminder.
| Message type | Consent standard | Opt-out requirement | Risk level |
|---|---|---|---|
| Appointment reminder (confirm, reschedule) | Prior express consent. Treatment message from a covered entity. | Must honor any reasonable opt-out request | Low |
| Recall or hygiene due notice | Prior express consent, as long as no offer or price is attached | Must honor any reasonable opt-out request | Low to moderate |
| Unscheduled treatment follow-up | Prior express consent. Stays clinical, never a pitch | Must honor any reasonable opt-out request | Moderate |
| No-show or reactivation outreach | Prior express consent. Written consent once wording turns promotional | Opt-out plus internal do-not-call list | Moderate to high |
| Promotional or membership offer | Prior express written consent, signed and specific | Opt-out in every message plus do-not-call scrub | High |
The table above is a planning tool, not a legal opinion. Risk levels reflect how often each message type shows up in TCPA litigation, and your own counsel may read a given campaign differently.
How should you collect and store consent at intake?
A TCPA compliance dental practice record starts at intake. Capture consent at the moment the number is given, store it as a structured field, and keep the exact wording the patient saw. Consent is only useful if you can reproduce it later. A note in a chart that says "OK to text" will not carry much weight on its own.
The American Dental Association practice resources on legal and regulatory topics are a reasonable starting point for building intake documentation, though they are not a substitute for advice from your own attorney.
Fields worth capturing
- The number itself, flagged as mobile or landline. The rules diverge by line type.
- Consent scope, separated into treatment communication and marketing.
- Method and timestamp, so you can show when and how it was obtained.
- Version of the disclosure text the patient actually agreed to.
- Revocation events, with the same timestamp discipline.
Keep records for as long as you could plausibly be sued. According to 28 U.S.C. 1658, the federal catch-all statute of limitations is 4 years, so many practices retain consent records for at least 4 years after the last contact. Storage is cheap. Reconstruction is not.
One more operational point. Whoever holds this data on your behalf should be able to show their security posture, which is why vendor SOC 2 documentation is worth asking for before you sign.
Consent records should be a field, not a sticky note.
Structured capture at intake gives you a defensible record without adding steps for your front desk team.
Explore DentiVoice →What happens when a patient asks you to stop calling?
You have to stop, and you have a deadline. Federal rules require that a revocation request made by any reasonable means be honored within a reasonable time, not to exceed 10 business days from receipt. You also cannot force patients into one specific opt-out channel.
The FCC rulemaking record on revocation of consent spells out what counts. Replying to a text with stop, quit, end, revoke, opt out, cancel, or unsubscribe is treated as a reasonable revocation on its face. So is using an interactive opt-out on a call, or a website or phone number you designated for that purpose.

The parts practices miss
- Other wording still counts. If a reasonable person would read the reply as a request to stop, you have to treat it that way. "Please quit texting me" is not a technicality.
- Voicemail and email create a presumption. A revocation left through another channel raises a rebuttable presumption that consent was withdrawn.
- Confirmation texts are allowed, once. A single message confirming the opt-out is permitted as long as it carries no marketing content and is the only further message sent.
- Verbal opt-outs on the phone are real. A patient telling your receptionist to stop calling is a revocation, whether or not anyone logs it.
That last one is where manual workflows break. Someone says "take me off your list" during a Tuesday afternoon call, the note never reaches the reminder system, and the next campaign goes out anyway. Consistent call quality review is how most offices catch it.
Related: Automated text-back workflows need the same opt-out handling as any other outbound message. See how missed call text back works →
Which outbound campaigns carry the most TCPA risk?
Promotional campaigns to cold or stale numbers carry the most TCPA compliance dental practice risk. Treatment reminders to active patients carry the least. Everything else falls on a spectrum defined by two variables: how promotional the wording is, and how recently the patient gave you the number.
Ranked by exposure
- Purchased or scraped lists. No consent exists. Do not send automated messages to them, full stop.
- Membership plan or whitening offers to the full patient base. This is textbook telemarketing and needs written consent.
- Reactivation of patients last seen years ago. The number may be reassigned to a different person entirely.
- No-show recovery with an incentive attached. The incentive is what pushes it across the line.
- Recall reminders to active patients. Low risk when the wording stays clinical.
Reassigned numbers deserve their own mention. Mobile numbers get recycled constantly, so a number that was validly consented in 2019 may belong to a stranger today. The FCC operates a Reassigned Numbers Database for exactly this reason, and scrubbing against it before large reactivation sends is standard practice. Separately, the FTC Telemarketing Sales Rule imposes its own obligations on telemarketing calls, and it is enforced independently of the TCPA.
If a campaign is genuinely promotional and you are not confident in the consent record, dial it manually or send it by mail. The lift is real, but so is the alternative. Message wording is also worth locking down at the template level, which is what script customization is for.
How does an AI receptionist handle consent and opt-outs?
A well-configured AI receptionist treats consent as a data field and an opt-out as a system event. It captures consent language during booking, writes it to the patient record in Dentrix, Open Dental, or whichever system you run, with a timestamp, and recognizes stop requests in natural speech rather than waiting for a keyword.
That matters because the failure mode in most practices is not bad intent. It is a note that never made it from a phone call into the reminder queue.

What to ask a vendor before you sign
- Where is consent stored, and can you export it as a report?
- How are verbal opt-outs captured during a live call, and how fast do they propagate to outbound queues?
- Does the system distinguish treatment messages from promotional ones, with separate consent flags for each?
- Is there an internal do-not-call list, and does every outbound channel check it before sending?
- Will the vendor sign a business associate agreement? Without one, the health care carve-out gets harder to argue.
None of this replaces your team. It gives them a record they can actually produce, and it removes the human handoff that quietly causes most violations. A TCPA compliance dental practice program lives or dies on whether the opt-out someone heard on Tuesday reaches the system before Friday.
What should you read next on dental privacy and communication law?
Consent to contact is one piece of a larger obligation. The articles below cover the rules that sit next to the TCPA in a dental practice: what you can say, what you can record, who you can say it to, and where the records live.
- HIPAA-Compliant Dental Communication with AI. TCPA decides whether you may send the message. HIPAA decides what the message is allowed to say.
- Call Recording Laws Dental Practice: State-by-State Guide. Consent to be called and consent to be recorded are separate obligations, and recording law is set by your state.
- Dental Patient Phone Verification: Confirm Without Friction. Before you disclose anything on an outbound call, you have to know the person answering is the patient.
- AI Dental Receptionist HIPAA Compliance: A Dentist Guide. The covered entity status that makes the health care carve-out work depends on getting HIPAA right first.
- Evaluating AI Vendors for Dental HIPAA Compliance. Business associate agreements, subprocessors, and the diligence questions to ask before a vendor touches patient data.
- AI Receptionist SOC 2 Dental Guide: Compliance and Security. Where your consent records live, who can reach them, and what a SOC 2 report actually proves.
- AI Dental Intake Forms: How Digital Patient Paperwork Works. Consent language, checkbox state, and timestamps captured as structured data at the point the number is given.
Start with an inventory. List every automated message your practice sends, mark each one as treatment or promotional, then check whether you can produce the consent behind it. Most offices find the gap in the same place: verbal opt-outs and old numbers.
TCPA compliance dental practice work is mostly documentation, not legal wizardry. The offices that stay out of trouble are the ones that capture consent as structured data, honor stop requests fast, and keep promotional wording out of clinical reminders.
This article is general education and not legal advice. Bring your specific campaigns to your own attorney or state dental board before you launch them.
Build outbound reminders on a consent record you can defend.
DentiVoice captures consent at booking, recognizes verbal opt-outs on live calls, and keeps treatment and promotional messaging separate.
Book a DentiVoice demo →Want to review your current phone and messaging workflow first?
Talk to the DentiVoice team →Frequently Asked Questions
No. Appointment reminders from a HIPAA covered entity qualify as health care messages, so prior express consent is enough. Written consent becomes necessary once the message includes an offer, a price, or any other promotional content alongside the reminder.
Usually for treatment reminders, rarely for marketing. Giving the number supports automated contact for the purpose it was collected. Promotional texting needs a separate signed authorization that names automated messaging and is not a condition of treatment.
Cautiously, and only with clinical wording. Old consent may still stand, but the number may have been reassigned to someone else. Scrub against a reassigned number database first, and avoid attaching any promotional offer to reactivation messages.
The statute allows recovery of actual loss or five hundred dollars per violating call or text, whichever is greater. Courts may award up to three times that amount, so fifteen hundred dollars per message, when the violation was willful or knowing.
Yes. An AI voice agent placing outbound calls uses an artificial voice, which falls squarely inside the rules. Consent, calling limits, and opt-out obligations apply exactly as they would to any prerecorded or autodialed campaign.
Long enough to defend a claim. Federal TCPA claims commonly run on a four-year limitations period, so many practices retain consent and revocation records for at least four years after the last contact with that patient.
Within a reasonable time, not to exceed ten business days from receipt of the request. You also cannot require patients to use one specific opt-out channel, since any reasonable method of revoking consent must be accepted.
Sources & References
- 1
- 2
- 3
- 4
- 5
- 6
Topics
Was this article helpful?
Written by
DentalBase Team
Expert dental industry content from the DentalBase team. We provide insights on practice management, marketing, compliance, and growth strategies for dental professionals.
