On texting patients: the two rules that actually apply
Practices are often told that texting patients is a compliance minefield, usually by someone selling a product. The real position is narrower than the scare stories and worth knowing before you configure anything. This is a plain summary of two federal sources, not legal advice, and your compliance officer or counsel is the one who signs off.
HIPAA does not require patient authorization for an appointment reminder. The Department of Health and Human Services has answered this directly: "appointment reminders are considered part of treatment of an individual and, therefore, can be made without an authorization." That is HHS guidance, not a vendor's interpretation.
The FCC's rules are where the real conditions live. Federal telecom rules carry a specific carve-out for health care providers contacting a patient's wireless number, and it comes with conditions attached. Messages have to go only to the number the patient gave you, have to identify the practice, cannot contain any marketing or billing content, and are capped at 160 characters for a text or about a minute for a voice call. A provider may send one message per day per patient, up to three per week combined. Every message needs an easy opt-out, replying STOP for texts, and opt-outs have to be honored immediately.
The part almost everyone gets wrong: that three-per-week cap is not a blanket federal limit on talking to your patients. It is a condition of the safe harbor that lets you reach a wireless number without prior express consent. It is widely repeated as a flat rule, and it is not one. The distinction matters, because it changes how a reminder sequence should be built and what you need to have on file.
None of this is complicated to comply with once someone has actually read it. It is mostly a matter of configuring the reminders correctly the first time, which is the part I would handle.
The wider question, whether any of this puts protected health information in front of a vendor, has its own page: how patient data is handled, including where the chatbot sends messages, what a Business Associate Agreement would actually cost, and why "HIPAA compliant website" is not a real certification.