Healthcare is full of acronyms: EHR, SDOH and FQHC just to name a few. HIPAA often tops the list because a lack of compliance with it has the potential to result in costly fines and penalties.

Although independent from HIPAA, the Telephone Consumer Protection Act (TCPA) includes an exemption from the Federal Communications Commission (FCC) if healthcare-covered entities comply with regulations and certain conditions of the Health Insurance Portability and Accountability Act. Enacted by Congress in 1991 to protect consumers from unsolicited telemarketing calls and messages, TCPA regulations prohibit businesses from using auto-dialers to contact individuals who have not provided consent.

TCPA also specifies that these entities are not to use prerecorded messages to communicate with these consumers. They must follow procedures for maintaining a do-not-call list and providing an “opt-out” option for each call.

What Changes Have Been Made to the Telephone Consumer Protection Act?

Earlier this year, the FCC adopted new consent revocation rules for robocalls and robotexts. The rules are designed to make it simpler for consumers to revoke consent. They also require that callers and texters implement such requests in a timely manner.

More TCPA rules for some exempt calls went into effect in July 2023. The new guidelines added call limits and opt-out requirements for the following types of artificial or prerecorded voice calls:

  • Non-commercial calls to a residence
  • Commercial calls to a residence that do not include an advertisement or constitute telemarketing
  • Tax-exempt nonprofit organization calls to a residence
  • HIPAA-related calls to a residence

What are the TCPA Exemption Rules?

All marketers, common carriers and businesses are subject to the TCPA rules. Healthcare marketing is subject to TCPA compliance, but there are slightly different rules based on the Federal Communications Commission’s TCPA healthcare exemption. An established business relationship, as defined by the TCPA, allows for certain telemarketing communications without violating the law if there is prior express invitation or permission from the recipient.

This exemption encourages healthcare providers and payers to promote public health using reasonable and fair communication channels while still protecting patients and consumers from unwanted marketing calls and text messages. It enables healthcare-covered entities to deliver health-related messages to patients and consumers — as long as they comply with HIPAA regulations and certain conditions, including:

  • Messages must be healthcare-related under HIPAA and may not include any promotional or financial solicitation (i.e., accounting, billing or debt collection).
  • Messages can only be sent to the cell phone number provided by the patient.
  • Messages must explicitly state the name and contact information of the healthcare entity.
  • Messages must be concise, with voice messages under one minute and text messages with fewer than 160 characters.
  • Calls must be free to the end user.
  • Callers may contact residential consumers only between 8:00 AM and 9:00 PM (recipient’s time zone).
  • All communications must offer an easy opt-out.
  • Opt-out requests must be honored immediately.

Also, under the new rule, to be exempt from the TCPA’s consent requirements, callers are limited to three calls per week (one per day) for healthcare-related calls. They must include an opportunity to opt out of prerecorded calls as part of the message.

Penalties for TCPA Non-Compliance

Violations of the TCPA aren’t as expensive as those for the Do Not Call (DNC) provision of the Telemarketing Sales Rule (TSR), the maximum for which has increased to $46,517. However, fines for TCPA non-compliance range from $500 to $1500 per individual violation, with willful action being higher. Plus, penalties can be assessed multiple times per phone call if it violates more than one aspect of the TCPA’s regulations.

Protecting Healthcare Providers from Non-Compliance

There are four primary points you should know about both the TCPA and TRACED Act to ensure you keep compliant with them. In addition to following these best practices, adopting an agentic AI solution helps healthcare practices of any size mitigate risks associated with a lack of TCPA compliance. 

Note: it is crucial to consult legal counsel to navigate TCPA rules and ensure full compliance with regulations.

1. All patient communications must comply with HIPAA.

HIPAA includes multiple rules for protecting patient privacy and security. Both the Privacy and the Security Rules offer provisions for covered entities to implement safeguards that minimize unauthorized use, exposure or access of protected health information (PHI) as it is created, communicated and maintained. 

2. Healthcare entities must obtain prior express consent if they use an automated dialer system to communicate with patients.

Under the TCPA’s healthcare exemption, individuals who provide a cell phone number are expressing consent to receive calls or texts for communication related to their health. For entities using automated dialers or prerecorded messages, healthcare information may be distributed to landlines and cell phones for patients and consumers who have provided their phone numbers. Information is limited to that which addresses an individual’s health and wellness, such as:

It is also essential to honor ‘do not call requests’ to maintain compliance with the National Do Not Call Registry. Telemarketers must respect these requests to avoid legal issues and ensure consumer preferences are managed effectively.

3. Health-related patient communications using autodialers must comply with messaging frequency and length regulations.

When communicating with patients who have provided prior express consent for health-related information via text or voice channels, TCPA compliance requires entities to limit how often they can text or call. Telemarketing messages, in particular, require explicit consent and must adhere to specific regulations, differentiating them from other non-marketing calls such as debt collection or informational messages. Agentic AI directly supports TCPA compliance by personalizing communication within these guidelines.

4. Healthcare communications must enable and honor opt-out requests.

Patients must have a clear opportunity to opt out of automated voice and text communications in compliance with both the TCPA and TRACED Acts, especially regarding telephone solicitation. Healthcare entities need to consider how their communication workflows allow recipients to revoke any express consent for receiving healthcare information via autodialers and prerecorded messages.

Opt-out requests must be honored immediately, so it’s important to implement policies and procedures for managing and responding to patient opt-outs. Utilizing TCPA-compliant conversational AI to handle opt-out requests not only saves time for medical practice staff but also ensures such requests are completed within the necessary timeframe to avoid hefty penalties.

Ensure TCPA Compliance Through Agentic AI from Providertech

Agentic AI automates compliance checks and manages patient preferences to ensure provider communications meet TCPA regulations. The technology also can be employed to answer common patient questions, automate appointment scheduling, disseminate patient education, increase medication support and expand multilingual support. Additionally, agentic AI helps prevent unsolicited sales calls by ensuring that communications are compliant with the TCPA and the National Do Not Call Registry.

To learn how healthcare automation can enhance patient engagement while ensuring strict adherence to TCPA regulations, give Providertech.ai a try today by listening to a sample recording.