The patient should agree, on a form or page, to one clear statement that names the practice, describes the messages, states how often they come and that message and data rates may apply, explains STOP and HELP, links the privacy policy and terms, and, for a medical practice, warns that texts are not encrypted and are not for emergencies. GoHighLevel stores the form submission as the record. The bottom line: carrier registration, the federal texting rules, and HIPAA each ask for something slightly different, and one well written consent line can satisfy all three.

What carriers and registries require

Guides to A2P 10DLC registration list the same elements: a specific program description, a frequency disclosure, the line message and data rates may apply, both keywords STOP and HELP called out before the patient consents, links to the privacy policy and terms of service, and a privacy policy that states opt in data is not shared with third parties. One guide notes the consent checkbox must not be pre checked and the phone number field must not be required if consent is optional. Another advises that consent is not a condition of any purchase. A registration platform's guide says carriers reject campaigns with missing or incomplete terms, and the wording on your website must match what you submit.

What HIPAA adds

HHS's Omnibus Rule commentary, as quoted by Holland and Hart, says covered entities may send unencrypted messages if they warned the individual of the risk and the individual still prefers that channel, so the consent should state the risk and be documented. A patient can also ask for communication by other means under 45 CFR 164.522(b).

What the FCC adds

The FCC's 2015 healthcare exemption lets HIPAA covered entities and their business associates send certain treatment messages, such as appointment and exam reminders, without prior express consent, but only under conditions. Law firm summaries list them: the message goes only to the number the patient provided, states the provider's name and contact information, has no marketing, billing, or debt collection content, complies with HIPAA, is concise (160 characters or less for a text), is limited to one message a day and three a week per provider, offers an easy opt out, and every opt out is honored immediately. The FCC also said the calls must be free to the end user, not charged against the patient's plan, which many practices cannot guarantee. Because of that, many practices also collect consent and treat reminders as informational messages.

Outside the healthcare exemption, the FCC's 2024 order lets people revoke consent by any reasonable means, with stop, quit, end, revoke, opt out, cancel, and unsubscribe counting automatically, and requires honoring a request within a reasonable time not to exceed 10 business days. The FCC released a revised order on September 9, 2026, so confirm which version applies when you launch.

Sample consent wording

This is a starting point to adapt with counsel, not legal advice.

ElementSample wording
Who and whatI agree to receive appointment reminders, scheduling messages, and forms links from [Practice name] at the mobile number I provided.
How oftenMessage frequency varies with my appointments.
CostMessage and data rates may apply.
Stop and helpReply STOP to stop messages and HELP for help.
HIPAA warningI understand text messages are not encrypted and are not for medical emergencies or questions about my care.
Not a conditionAgreeing is not a condition of receiving care.
LinksPrivacy Policy [link] and Terms [link].

Build it in GoHighLevel

  1. Write the consent text in the table, and have counsel and the privacy officer approve it.
  2. Add it as a checkbox, not pre checked, on the new patient form, the booking page, and the chat widget.
  3. Publish a privacy policy and terms that match, and use the same wording in your A2P campaign registration.
  4. Complete A2P brand and campaign registration in your GoHighLevel account, following the help portal steps.
  5. Store the submission as the consent record, and add the tag Text consent with the date.
  6. Build an opt out workflow that adds Opted out for the stop words, removes the contact from all messaging workflows, and logs the time.
  7. Test STOP and HELP replies before launching.

Worked example

For example, a practice that registers 2,000 patients for text reminders holds 2,000 consent records. If 3 percent opt out in the first year, that is 60 patients (2,000 times 0.03), each of whom must be removed immediately under the exemption's standard.

Mistakes to avoid

How this was handled before

Practices recorded phone numbers on registration forms and called with reminders. Texting added carrier registration and the federal consent and opt out rules, so one consent statement now has to do more than a phone number field did.

What to measure after launch

Track consent records, opt outs, opt outs honored immediately, and registration rejections. Test STOP and HELP replies monthly.

Check before you switch it on

US text messages sent from a standard 10 digit number need A2P 10DLC registration. The HighLevel support portal says registration is required for texts to US recipients from 10 digit long code numbers and that toll free numbers do not require it. HighLevel's opt in guidelines also say a person cannot be forced to agree to text messages in order to submit a form, so keep the consent box optional. One compliance guide separates informational texts, which need documented consent, from marketing texts, which need prior express written consent. Ask your attorney which category your reminders fall into. Have counsel review the wording against federal rules, your state's rules, and your registration, and keep every consent record. This is general information, not legal advice.

Questions people ask

What must a text consent say?

Carrier registration guides list the practice's name, a program description, message frequency, message and data rates may apply, STOP and HELP, and links to the privacy policy and terms.

Should it warn about unencrypted texts?

HHS commentary says covered entities may send unencrypted messages after warning the patient of the risk, so the warning belongs in the consent.

How fast must opt outs be honored?

Immediately under the FCC healthcare exemption. The general 2024 rule allows up to 10 business days.

Ready to try it yourself? Start a GoHighLevel account here.

You can also see this in action in our GoHighLevel capabilities demo.