SMS and Email to Patients under GDPR - Appointment Reminders Without Breaches
Does an SMS appointment reminder require patient consent? When a message becomes marketing, what may go into an SMS body and how to email medical records safely.
An SMS reminder about tomorrow's visit is standard today - patients expect it, and it cuts your no-shows. But between "appointment reminder" and "SMS with a massage package promo" runs a legal line many practice owners do not see. On one side sits communication related to the service the patient booked; on the other, marketing that requires separate consent. Then there is a third issue: what may go into the message body at all, given that an SMS can pop up on a locked phone lying on a desk at work. We covered informing patients about data processing in the article on the GDPR privacy notice - here we deal with the communication itself.
This article explains which messages you can send without extra consent, when consent is required, what may go into an SMS and how to safely email documents to a patient.
Appointment reminders - no separate marketing consent needed
Let's start with the most common doubt. A reminder about a booked visit is part of delivering the service the patient signed up for - not marketing. The basis for processing the phone number here is the performance of the service agreement (and, for the health-data layer, the healthcare purpose), not marketing consent.
What this means in practice:
- You may send a reminder to a patient who gave their phone number at registration - without collecting a separate "SMS consent".
- Mention it in the privacy notice - the patient should know their number will be used for confirmations and reminders.
- Allow opting out - if a patient does not want reminders, note it and stop sending them. That is good practice and data minimization.
- Stick to the purpose - a number given for appointment matters serves appointment matters. Not holiday wishes with a discount code.
When a message becomes marketing
The line is simpler than it seems: if the message encourages the patient to use something they have not booked yet, it is marketing. And electronic marketing requires consent - both under the GDPR (processing basis) and under electronic communication rules, which require consent for commercial information.
| Message type | Nature | Marketing consent required |
|---|---|---|
| Reminder of a booked visit | Service delivery | No |
| Request to confirm or cancel a slot | Service delivery | No |
| Change of opening hours, practice closure notice | Organizational information | No |
| "A slot opened up - would you like to come earlier?" | Service delivery (ongoing therapy) | No |
| "New massage package, 20% off" | Marketing | Yes |
| Newsletter with tips and the practice's offer | Marketing | Yes |
| Holiday wishes with a discount code | Marketing | Yes |
| Request for a Google review | Grey area - safer with consent | Recommended |
Marketing consent must be freely given, specific and revocable at any time. It cannot be a condition of booking a visit and must not be buried in the treatment consent form - we cover separating forms in the article on first-visit documents. Also remember that the content of a practice's marketing messages is separately restricted by the rules on advertising healthcare entities - more in the article on practice marketing and the law.
What may go into the SMS body
Even a permitted reminder can become a breach if it says too much. SMS is not a confidential channel: it shows on the lock screen, phones are shared with family, and a number can be typed with a typo. So the minimization principle applies.
A safe reminder
A good reminder contains only the essentials: the practice name, date and time, possibly a confirmation request. Example: "XYZ practice reminds you of your visit on 12 Sep at 3:00 pm. To cancel, please call 600 000 000".
What to avoid in SMS and email subject lines
- Diagnoses and therapy types - "reminder about your post-surgery spinal rehab" reveals health data to anyone glancing at the screen.
- Results and recommendations - clinical details should not travel in a plain SMS.
- Financial data - leave outstanding amounts for a call or a secure channel.
- Full personal data - a first name is enough; there is no reason to include an ID number or address.
The same logic applies to email subjects - "Results and therapy plan - L5/S1 discopathy" in the subject line is a bad idea, because subjects show up in notifications.
Emailing medical records - how to do it safely
The patient has the right to receive their medical records, including electronically - the full request-handling procedure is described in the article on releasing records. From the GDPR angle the key part is "how", because sending records to a wrong address is a ready-made data breach.
A safe sending routine looks like this:
- Verify the address - send only to the address the patient gave in their records or request, not one "dictated over the phone" by someone whose identity you cannot confirm.
- Encrypt the attachment - a PDF in an encrypted archive or a password-protected file. Pass the password through another channel, e.g. an SMS to the patient's number on file.
- Keep medical data out of the body and subject line - everything sensitive travels in the encrypted attachment.
- Record the disclosure - an entry in the records disclosure log: to whom, when, in what scope.
- Double-check before hitting send - recipient autocomplete is one of the most common causes of misdirected email.
Example: Karolina's receptionist emailed a scanned patient card to an autocompleted address - a different patient with the same first name. The file had no password. That is a classic data breach: the data reached an unauthorized person and included health data, so the practice had to assess the risk, record the event and notify UODO. Had the attachment been encrypted with the password sent separately, the same mistake would most likely have ended as an entry in the breach register - because the outsider could not have accessed the content.
Messaging apps - WhatsApp, Messenger and friends
Patients write on Messenger or WhatsApp because it is convenient for them. You may reply on organizational matters (slots, cancellations), but do not discuss health there and do not send records. The reasons are practical: no control over who accesses the patient's account, the messaging provider processing data on its own terms, and no integration with the practice's records. If you use a messenger for business, include it in the records of processing activities and set rules in the data protection policy: what this channel may handle and what requires a call or a visit.
Rolling it out at your practice - a short checklist
- Update the privacy notice to say the phone number and email are used for confirmations and appointment reminders.
- Separate the consents - an optional, standalone marketing consent, outside the treatment consent form.
- Set message templates - ready-made reminder texts without health data, identical for the whole team.
- Describe email record-sending rules in the data protection policy: address verification, encryption, disclosure log entry.
- Check your SMS provider - a company sending SMS on your behalf processes patient data, so you need a data processing agreement with them.
- Train the team - most communication breaches are human error: wrong recipient, too much content, no verification.
Frequently asked questions
Does an SMS appointment reminder require the patient's consent?
It does not require separate marketing consent. A reminder about a booked visit is part of service delivery and rests on the performance of the agreement, not consent. The patient should, however, learn about this use of their number from the privacy notice and be able to opt out of reminders.
Can I text a patient about the practice's promotions?
Only if the patient has previously given voluntary marketing consent. A message encouraging the use of a new service or a discount is commercial information, which requires consent to electronic communication. That consent must not be bundled into the treatment consent form or made a condition of booking. Also mind the restrictions on advertising by healthcare entities.
Can I send medical records by email?
Yes, at the patient's request records may be released electronically. Send them only to a verified address from the records or the request, as an encrypted attachment with the password delivered through another channel, and keep medical data out of the body and subject line. Record every disclosure in the records disclosure log.
What if a message with patient data reaches the wrong person?
Treat it as a potential personal data breach. Assess the risk to the patient's rights and freedoms, record the event in the breach register, and if the risk is not unlikely - notify UODO within 72 hours of becoming aware of the breach. If the risk is high, inform the patient as well. Safeguards such as encrypted attachments significantly lower the risk and affect how the event is assessed.
CTA: Want ready-made patient communication rules, privacy notices and marketing consent templates in one package? The FizjoReady TARCZA package contains a complete set of GDPR documents tailored to the daily work of a physiotherapy practice. See FizjoReady packages →
Related articles:
- The patient privacy notice - what it must contain and where to place it
- A data breach at your practice - you have 72 hours
- Physiotherapy practice marketing and the law
- A patient requests their medical records - step-by-step procedure