Send two messages: a short text with the date, time, place, and provider, and an email with the checklist of what to bring, the forms link, the cancellation policy, and the practice's Notice of Privacy Practices. In GoHighLevel the Customer Booked Appointment trigger sends both the moment the booking is made. The bottom line: the confirmation is the first chance to prepare the patient and to meet the privacy notice requirement, so it carries more than a date.
What HHS requires
HHS's guidance says a covered direct treatment provider must give the Notice of Privacy Practices no later than the date of first service delivery, and, except in an emergency, make a good faith effort to obtain the patient's written acknowledgment of receipt, or document why it could not be obtained. The notice must also be posted prominently on any website that provides information about the practice's services. Giving the notice in the booking email means the patient has read it before the first visit, and the acknowledgment can be collected at check in or on the forms.
What each message contains
| Message | Contents |
|---|---|
| Text, immediately | Practice name, date, time, address, provider, and a link to the email |
| Email, immediately | What to bring: photo ID, insurance card, medication list, prior records; a link to new patient forms; parking and directions; the cancellation and late policy; a link to the Notice of Privacy Practices |
| Reminder, 2 days before | Short text with the time and place |
| Reminder, morning of | Short text with the address and a reply option to confirm |
Keep the text free of health information. A visit type such as a new patient visit is fine. The condition or reason for the visit should not be in the text.
Build it in GoHighLevel
HighLevel help center pages describe the Appointment Status trigger as firing when an appointment is created or its status changes, with statuses New, Confirmed, Cancelled, Showed Up, No Show, and Invalid, and with filters for calendar, calendar group, tag, user, and who made the change (customer, user, or API). The Update Appointment Status action can set the same statuses from inside a workflow. A third party agency guide adds that Appointment Status is now the main appointment trigger and the older Customer Booked Appointment trigger is being phased out, so use Appointment Status for new builds.
- Build a workflow with the Customer Booked Appointment trigger, filtered to the new patient calendars.
- Send the short text and the longer email, using custom values for the provider and location.
- Link the forms in the email, and send them by text only if the practice has documented the patient's texting preference.
- Include the Notice of Privacy Practices link, and add a field or form for the acknowledgment.
- Add the reminder workflow from our same day cancellation guide.
- Create a task for the front desk to check that forms and the acknowledgment are complete the day before the visit.
Text, email, and portal compared
| Channel | Strength | Weakness |
|---|---|---|
| Text | Read within minutes | Short, visible on a lock screen, and unencrypted by default |
| Holds the checklist, policies, and links | Often unread, and may land in spam | |
| Patient portal message | Secure, and can hold forms | Requires an account that new patients do not yet have |
For a new patient who has no portal account, the text and email pair is the practical choice. Keep the text generic, and put the forms link in the email. Practices that used to mail a packet found that many patients arrived with the forms unfilled, and sending the link at booking gives the patient days, not minutes in the lobby. Ask the privacy officer whether the forms should open on the practice's own domain or a vendor page, and whether the vendor is covered by an agreement.
Worked example
For example, if a practice books 100 new patient visits a month and each confirmation removes one 5 minute call about what to bring, that saves 500 minutes (100 times 5), about 8 hours for the front desk.
Mistakes to avoid
- Putting the reason for the visit in the text. Keep it generic.
- Forgetting the privacy notice. HHS requires it by first service delivery.
- Skipping the acknowledgment. Collect it or document why not.
- Sending forms by text without a preference. Use a secure link and document consent.
How this was handled before
New patients were mailed a packet of forms and a privacy notice, or handed them on a clipboard at check in. Many practices still do. Sending the notice and forms at booking shortens the wait in the lobby and meets the same rule earlier.
What to measure after launch
Track confirmations sent, forms completed before the visit, acknowledgments collected, and calls about what to bring. If forms are still incomplete at check in, send the link earlier.
Check before you switch it on
US text messages sent from a standard 10 digit number need A2P 10DLC registration. The HighLevel support portal says registration is required for texts to US recipients from 10 digit long code numbers and that toll free numbers do not require it. HighLevel's opt in guidelines also say a person cannot be forced to agree to text messages in order to submit a form, so keep the consent box optional. One compliance guide separates informational texts, which need documented consent, from marketing texts, which need prior express written consent. Ask your attorney which category your reminders fall into. Have your privacy officer approve the confirmation wording and the forms links. This is general information, not legal advice.
Questions people ask
When must a practice give patients its privacy notice?
No later than the date of first service delivery, and it must be posted on the practice's website, according to HHS.
Must the patient acknowledge the notice?
The provider must make a good faith effort to obtain written acknowledgment, or document why it could not.
What should a confirmation text include?
The practice name, date, time, address, and provider, with no health details.
Ready to try it yourself? Start a GoHighLevel account here.
You can also see this in action in our GoHighLevel capabilities demo.
