Healthcare Pharma & Life Sciences Other Industries
All Services Performance Marketing ChatGPT Ads India · NEW Social Media Marketing SEO & AEO / LLM YouTube Marketing LLM Optimization Brand & Growth Consulting AI Solutions Industries We Serve
Enterprise Hub · All Solutions + Services Growth Transformation AI Transformation Revenue Operations Fractional CGO Growth Operating System Executive Growth Advisory
Clinic Launch Programme (Hub) NABH Consulting India Healthcare Brand Launch Clinic SOP Creation Logo Design (Healthcare) Brand Book Creation Clinic Launch Marketing D2C Brand Launch Clinic Interior Design
Workforce Hub For Employers — post a requirement For Professionals — register Public Openings Training Academy AI Training Flagship
Hawk · CRM Intelligence (NEW) YODA · YouTube Intelligence Angryturtle · GBP Intelligence (NEW) Prism Pulse · Instagram Analytics (NEW) Beacon · Attribution Agency OS · Dashboards Phoenix · Clinic Revenue HealthPro 360 · PMS/HMS AI Patient Lifecycle Bots AI Lead Management System Smart Appointment System Healthcare CRM Patient Feedback System AI, Analytics & Automation Digital Transformation Calculators Free Digital Health Audit →
All 13 calculators → 🎯 Business Exploration Matrix (New) Dental Clinic Setup IVF Clinic + Lab Setup Multi-Specialty Hospital Setup Aesthetic / Cosmetology Clinic Dermatology Clinic Setup Generic Clinic Setup Physiotherapy Clinic Setup Diagnostic Centre Setup CAC Calculator CPQL Calculator Franchise ROI Calculator Revenue Leakage Calculator CRM ROI Calculator
All Events Workshop 1 · Jun 13 · AI in Clinical Practice Workshop 2 · Jun 27–28 · AI in Growth & Governance Hospital Ops Workshop · Jul 12 Pre-Summit Seminar · Aug 16 Grand Summit 2.0 · Oct 10–11 Bihar AI Summit · Recap AI Innovation Awards · Aug 22 Grand Summit 2.0 · Oct 2026 Aarambh 2026 Recap
Case Studies Insights & Blog Research Reports Calculators AI in Healthcare Digest
Our Story Leaders @ Ichelon · IN · US · AU Ichelon India · Gurgaon Ichelon Consulting US · Dallas, TX Ichelon Australia · Sydney Speakers & Panelists Client Elevation Programme 🤝 Partner Connect 🇦🇪 ICG UAE Careers
Book a Growth Diagnostic →
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
US compliance pillar · TCPA · SMS · 2026

Medspa TCPA SMS compliance — the 2024 FCC update, revocation of consent, quiet hours and statutory damages

A working field guide for medspa owners, growth heads and agency practice leads who run SMS programmes on 10-digit long codes, short codes and toll-free numbers. Written against the Telephone Consumer Protection Act, the 2024 Federal Communications Commission rulemakings on one-to-one consent and revocation, and the enforcement patterns established across two decades of TCPA private litigation and class-action settlements in the aesthetic and cosmetic-medicine vertical.

Direct answer
  • The TCPA at 47 USC 227 restricts calls and texts placed using an automatic telephone dialling system or an artificial or prerecorded voice, and separately restricts telephone solicitations to residential lines and Do Not Call registered numbers. SMS from any commercial medspa platform is squarely inside scope.
  • The FCC's December 2023 order closed the lead-generator loophole. From January 2025 onward, prior express written consent must be to receive calls and texts from a single, clearly identified seller. A shared consent that authorises "our marketing partners" is not valid TCPA consent for the medspa named in that partner list.
  • The FCC's February 2024 revocation-of-consent order requires that any reasonable method of opt-out be honoured — reply STOP, inbound call, email, website form, in-person — within 10 business days. Silence, buried terms, or a "reply UNSUBSCRIBE only" narrow channel are not compliant.
  • Statutory damages are USD 500 per violation, trebled to USD 1,500 for knowing or wilful violations. Every unlawful message is a separate violation. Class-action settlements in aesthetic-vertical TCPA cases have typical enforcement patterns of seven- and eight-figure common funds plus injunctive relief.
  • The defensible posture is: named-seller one-to-one written consent, 8AM-9PM local quiet hours, honour STOP within seconds not days, appointment reminder templates strictly separated from promotional templates, and a four-year rolling consent audit log.
The ICG engagement model
Every practice welcome — retainers starting from $499/mo.
Goals-Driven engagements · Performance-Linked Payout Models available. Read the full engagement model →
🎯 Ichelon Agency OS See your goals live · client-facing dashboard, updated in real time. Click any screenshot to zoom. Open the full engagement model →
Trusted by US practices · case studies → 8 live practices · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Foundation

What the TCPA actually covers — and why SMS is not a lighter version of a phone call

The Telephone Consumer Protection Act of 1991 was written before commercial SMS existed. Congress and the FCC have spent the better part of thirty years extending it to text messages through a chain of declaratory rulings — most importantly the 2003 FCC order that classified SMS to a wireless number as a "call" under section 227, and the Supreme Court's 2021 Facebook v. Duguid decision that narrowed the definition of an automatic telephone dialling system but left the broader statutory framework intact. For a medspa marketing operator, the practical outcome is that every commercial SMS you send is subject to the TCPA even though the statute never uses the word "text."

The two operative sections for a medspa SMS programme are 47 USC 227(b), which restricts calls and texts made using an automatic telephone dialling system, an artificial voice, or a prerecorded voice, and 47 USC 227(c), which authorises the Do Not Call registry and the residential-telemarketing rules that flow from it. A well-run programme satisfies both — not one or the other. Confusing 227(b) consent with 227(c) DNC compliance is the single most common structural error in aesthetic-vertical TCPA claims.

Prior express written consent — the 2012 uplift that never went away

The FCC's 2012 order raised the consent standard for telemarketing calls and texts from prior express consent to prior express written consent. The written consent must be a written agreement bearing the signature (electronic signatures under E-SIGN qualify) of the person called or texted, identifying the specific seller who may make the calls or texts, and containing a clear and conspicuous disclosure that the person is not required to sign as a condition of purchasing any property, goods or services. Buried terms in a booking form, a pre-checked box, or a scroll-past ToS line do not satisfy this. Aesthetic-vertical plaintiffs' firms have built entire practice areas on exactly this failure mode.

Citation: 47 USC 227(a)(3), (b), (c); 47 CFR 64.1200(a)(2), (a)(3), (f)(9); FCC 12-21 (2012); FCC 23-107 (Dec 2023); FCC 24-24 (Feb 2024).
The 2024 rulemakings

One-to-one consent — the end of the lead-generator loophole

In December 2023 the FCC adopted an order — FCC 23-107 — that closes what the Commission called the lead-generator loophole. Under the old regime, a single web form could obtain the consumer's consent to be contacted by "our marketing partners" and then sell that consent onward to hundreds or thousands of sellers, each of whom could then treat the shared submission as valid prior express written consent for TCPA-restricted outreach. The FCC concluded that this practice does not meet the "clear and conspicuous" bar and does not identify a specific seller as the statute requires.

The remedy, phased in through 2024 and 2025 (effective January 27 2025 for the one-to-one provisions before an eleventh-circuit ruling further shaped the timeline), is a rule that consent must be to receive calls or texts from a single seller — one form, one seller, one consent — and only on topics logically and topically associated with the interaction that prompted the consent. A medspa cannot rely on a submission harvested by a comparison-shopping affiliate to text an unrelated laser service the consumer never enquired about.

Operational implication. Every lead source feeding a medspa's SMS list needs to be re-audited against the one-to-one standard. Shared-partner consents collected before January 2025 do not automatically survive. The correct posture is either (a) re-consent every carried-over record on the medspa's own named-seller form, or (b) suppress those records from any SMS or auto-dial campaign and use them for postal or manually-dialled outreach only.

Topical relevance — the second half of the one-to-one rule

A medspa lead who consented to be contacted about laser hair removal has not consented to be contacted about weight-loss injectables, membership plans, aesthetic dermatology or a partner clinic's cosmetic dentistry offer. Topical drift is the second-most-common failure mode after shared consent. Segmentation logic in the CRM should tag each consent with the specific service line it authorises and enforce that at send-time — not rely on marketer judgement.

Revocation of consent

Any reasonable method — the February 2024 revocation order

The companion order — FCC 24-24, adopted February 15 2024 — codifies a rule that recipients may revoke prior express consent through any reasonable means. The core revocation provisions became effective April 11 2025. Callers must treat the revocation as effective as soon as they reasonably can, and in no case later than 10 business days from the request. The order also settled a long-running circuit split by adopting the recipient-favourable reading that consent revocation extends to all future calls and texts on that topic from that caller, not only to messages of the exact same medium or campaign.

Reasonable methods a medspa must accept

  • Reply STOP, END, QUIT, CANCEL, UNSUBSCRIBE, REVOKE or OPT-OUT to the originating short code, toll-free number or 10DLC number.
  • An inbound voice call to any phone number the medspa uses in commerce — including a listed booking line, a Google Business Profile phone number, or a call-tracking DID.
  • An email to any address listed in the medspa's privacy notice, contact page, or footer.
  • A website form submission on any generic contact form or a dedicated preferences centre.
  • A verbal or written request made in person during a treatment visit.

The 10-business-day maximum is not a target — it is a ceiling. The safe operational rule is that STOP replies suppress within seconds through the SMS platform's native STOP handler, other channels flow into the CRM within one business day, and a nightly suppression sync ensures no queued campaign can send to a revoked record.

Safe pattern. Multiple redundant intake channels for revocations, all writing to a single canonical suppression table keyed on E.164 phone number. Every campaign platform reads that suppression table at build-time and at send-time, so a revocation that lands after a campaign is scheduled still stops the send.
Quiet hours

8AM to 9PM local — the rule marketing teams routinely break

47 CFR 64.1200(c)(1) prohibits telephone solicitations to residential telephone subscribers before 8AM or after 9PM in the recipient's local time. The rule applies to SMS to wireless numbers by extension of the 2003 declaratory ruling and has been enforced in text-message class actions. The two failure modes are (a) a national medspa chain scheduling a 7:30AM Eastern send that reaches West Coast recipients at 4:30AM, and (b) a boutique medspa scheduling an "end of day" send at 9:30PM local that violates the ceiling on its own home turf.

The FCC counts quiet-hour violations on a per-message basis. A single mis-scheduled campaign of 40,000 messages sent one hour after the local ceiling is not one violation — it is potentially 40,000 violations. Statutory damages at USD 500 per violation, before any wilfulness enhancement, produce a face-value exposure of USD 20 million on a single campaign of that size.

Time-zone logic in the campaign platform

Every credible aesthetic-vertical SMS platform — including HIPAA-safe options that medspas use for combined appointment and marketing traffic — supports per-recipient time-zone gating. Turning that gate on is a one-time configuration, not a per-campaign decision. The area code is not a reliable time-zone proxy for a mobile number; the correct field is the recipient's stated residence time zone captured at consent, or a downstream lookup keyed on ZIP code or self-selected timezone.

State overlays. Several states — Florida, Oklahoma, Washington and Maryland among them — have enacted mini-TCPA statutes with narrower windows, additional consent requirements, and their own private rights of action. Florida's FTSA in particular has been amended (2023 SB 1308) but continues to attract text-message class filings. A medspa marketing in these states should apply the tighter of federal or state rule at campaign scheduling.
The distinction that matters most

Appointment reminder vs marketing — where informational content crosses the line

The FCC has repeatedly recognised that appointment reminders, prescription refill notifications, and other purely informational communications occupy a different regulatory posture from marketing under the TCPA. The 2015 healthcare declaratory ruling (FCC 15-72) carved out a narrow exemption for certain healthcare messages, though its interaction with the 2013 HIPAA Omnibus Rule and the 2024 rulemakings has evolved. For a medspa the practical distinction is content, not intent.

  • Informational (no PEWC required, still subject to consent-in-fact and STOP). "Reminder: your Botox follow-up with Dr. Patel is tomorrow at 2:15 PM at our Uptown Dallas location. Reply C to confirm or R to reschedule."
  • Marketing (PEWC required). "It's been three months since your last visit — 20% off your next filler treatment this week. Reply BOOK to schedule."
  • Marketing (PEWC required). "Reminder: your Botox follow-up with Dr. Patel is tomorrow at 2:15 PM. Ask about our new membership plan when you check in."

The third example is the trap. Adding a single promotional line to an otherwise informational reminder converts the entire message to marketing under the FCC's treatment. The correct architecture is two templates, two send-time gates, two consent scopes — never a single template that mixes both.

Where HIPAA and TCPA intersect

An appointment reminder that discloses treatment type, provider name, or condition is a PHI disclosure under HIPAA. The SMS platform must be under a Business Associate Agreement — HIPAA-safe options include CallRail Healthcare for call and text tracking, PatientEngage, JaneApp, Zenoti and Boulevard for combined booking and reminder traffic, and Retreaver HIPAA for enterprise conversion routing. The intersection matters because a "one platform for everything" decision made by a growth team without compliance review often lands the practice on a consumer SMS platform that will not sign a BAA, forcing either a costly migration or a defensible information-minimisation posture on every send.

Fix these first

The four highest-risk surfaces on a medspa SMS programme

1. Lead-form consent copy

Named seller, single seller, clear disclosure that consent is not required for booking. Any older shared-partner text needs to be replaced site-wide, and legacy leads captured under the old copy need to be re-consented or suppressed.

2. STOP handling latency

Reply STOP must suppress across every campaign platform in seconds, not days. Multiple intake channels — inbound call, email, website form — must flow into the same canonical suppression table within one business day.

3. Time-zone gate on campaign send

Recipient-local 8AM-9PM enforced at send time. Area-code proxy is not sufficient; capture the timezone at consent or use ZIP-based lookup. State overlays (FL, OK, WA, MD) applied where tighter.

4. Informational vs marketing separation

Appointment reminders never carry a promotional line. Two templates, two consent scopes, two send-time gates. Content review at the template layer, not per-campaign, so a well-meaning coordinator cannot mix them.

Damages and enforcement

USD 500 to USD 1,500 per message — how the arithmetic actually runs

The TCPA private right of action under 47 USC 227(b)(3) allows a recipient to sue in state or federal court to recover the greater of actual monetary loss or USD 500 per violation. Where the court finds that the violation was knowing or wilful, the court may in its discretion increase the amount up to three times — the widely cited USD 1,500 ceiling. Actual monetary loss is rarely proven; the statutory floor is the operative number.

Every unlawful message is a separate violation. Class actions aggregate. A representative plaintiff who received four unlawful messages does not stand in a USD 2,000 case — she stands in a case that, if certified as a class of everyone in a similarly situated position, may involve hundreds of thousands or millions of messages. The typical enforcement pattern in aesthetic-vertical TCPA cases has been common-fund class settlements in the seven- and eight-figure range, plus injunctive relief that reshapes the defendant's SMS infrastructure for years afterward.

FCC enforcement in parallel

Separately from the private right of action, the FCC can impose civil penalties under 47 USC 503 and forfeitures under 47 USC 227(e) for unlawful spoofing. The 2024 FCC one-to-one order specifically emphasised that the Commission will use its enforcement bureau to pursue lead-generator abuse. A medspa insulated from private class exposure by a robust arbitration clause is not insulated from an FCC forfeiture on the same underlying conduct.

Insurance posture. General liability and cyber policies typically do not cover TCPA statutory damages. Some markets have written narrow TCPA endorsements at high premiums with low sublimits — often USD 100,000 to USD 500,000 aggregate — which does not meaningfully cover an eight-figure class exposure. The cheaper defence is a compliant programme, not an insurance rider.
Documentation

The four-year consent audit log — what to capture and why

The TCPA federal statute of limitations is four years under 28 USC 1658. The practical documentation floor is therefore four years of rolling audit records, per recipient, retained in a form that can be produced under a subpoena without prompting a spoliation motion. The minimum record set for each opt-in is:

  • Exact, verbatim consent copy displayed at the time of opt-in — not the current version of the copy, but the historical version the recipient actually saw. A screenshot or a versioned HTML archive is the standard evidence.
  • Timestamp with time zone.
  • Channel and identifier — website form URL, in-clinic tablet form ID, verbal consent captured in the EHR by staff member name.
  • IP address if web-collected. Device information optional.
  • Named seller listed in the consent copy.
  • Topical scope authorised (which service lines, membership tier, offer categories).
  • Every subsequent revocation event with channel, timestamp, and the campaign or list from which the record was suppressed.

Store the full record set inside the medspa's CRM or EHR (JaneApp, Nextech, Modernizing Medicine, Zenoti, Boulevard and Aesthetic Record all support versions of this pattern). Do not rely on the SMS platform alone — SMS platforms rotate features and vendors change; the practice needs a durable record independent of any one dependency.

Federal envelope

Where TCPA sits in the medspa marketing stack

A defensible medspa outreach programme lives inside a federal-plus-state compliance envelope. Every SMS decision is scored against six overlapping rule sets — miss any one and the programme is exposed on the axis you did not check.

TCPA HIPAA CAN-SPAM ADA FTC FDA State medical boards State mini-TCPA (FL, OK, WA, MD)
Our research · State of Med Spa Google Presence 2026

What we found when we studied 555 US med spas on Google

Patients praise the care almost without exception. The one area where complaints outnumber praise is booking and communication, and that is where most med spas can win.

4.87★
average Google rating. Near-perfect ratings are table stakes.
5.83
median new reviews per month. Most profiles grow slowly.
~54%
of booking and communication reviews are negative, the one weak theme.

Full study · 555 US med spas across 20 metros · roughly ±4% nationally · review velocity and themes from a 115-spa subsample · verified against raw data.

Leadership

Backed by Ichelon Consulting US leadership

Every TCPA-scoped medspa engagement is reviewed by a senior member of the Leadership Team with direct experience of the 2024 FCC rulemakings, aesthetic-vertical class litigation patterns, and the intersection with state medical board advertising codes.

The ICG technology stack

Nine tools. One compounding system. HealthApex OS
Built in-house. Deployed in every engagement.

ICG's results are reproducible because they are built on proprietary infrastructure — not agency intuition or generic tools. These nine HealthApex OS platforms are what power every ICG engagement.

WhatsApp AI

LynxFlow

WhatsApp AI Lead Qualifier

An AI assistant that holds a short WhatsApp conversation with every enquiry, decides whether it fits your criteria, and posts qualified leads to your CRM labelled Qualified. Team inbox, campaigns and consent handling included. $40/mo for US practices.

Explore LynxFlow →
Business Layer

Hawk

CRM Intelligence & Lead-Ops MIS

Sits as the business intelligence layer above your CRM — AtomCRM or any other CRM you run, including custom builds. Shows where leads are leaking, which effort is wasted, and which good leads were quietly downgraded by automation — not by a human decision.

  • Sits above your existing LMS — no replacement
  • 83% of effort goes to dead leads — surfaced Day 1
  • ~75% qualified-lead downgrades by automation
  • Free Lead-Leak Audit in 48 hours
Explore Hawk + free audit →
Attribution Core

Beacon

Attribution Engine & CAPI Middleware

Sits at the centre of every ICG attribution architecture. CAPI middleware connecting Meta Ads, Google Ads, WhatsApp and IVR to your CRM. Lifts Event Match Quality from 2.5 to 6+, reducing CPM 30–40% from the same budget.

  • Server-side CAPI — bypasses iOS privacy changes
  • EMQ 2.5 → 6+ across portfolio
  • 30–40% CPM reduction from EMQ lift alone
  • Multi-touch: ad → consultation → revenue
Explore Beacon →
Practice Management

HealthPro 360

PMS with built-in revenue intelligence layer

A PMS built to track cross-sell and up-sell opportunities within your existing patient base. 12 modules covering OPD, IPD, Pharmacy, Labs, Billing, Inventory, Patient Portal, Smart Scheduling, RBAC, AES-256 encrypted storage.

  • Only PMS with built-in Revenue Intelligence
  • Cross-sell signal tracking within existing patients
  • 12 modules: OPD, IPD, Pharmacy, Labs, Billing+
  • Audit trails + RBAC + AES-256 encryption
Explore HealthPro 360 →
Revenue Layer

Phoenix

Revenue intelligence built over your existing PMS

If you already have a PMS, whichever one it is, Phoenix builds the business intelligence layer on top of it without replacement. Built for single clinics and multi-centre chains alike.

  • Works over your existing PMS — no migration
  • Daily action queue: Prevent Loss / Maintain / Grow
  • Catches unbilled services, collection gaps, lapsing patients
  • CPQL variance ₹620–₹3,800 → ₹680–₹1,420
Explore Phoenix →
YouTube Intelligence

YODA

YouTube analytics that measures patients, not views

A YouTube intelligence platform built for healthcare business outcomes. Connects video performance to actual consultation bookings — not views, not subscribers. Patient testimonial videos generate 6.9× more consultations per view than condition explainers.

  • Consultation attribution per video — not views
  • Demand-gap: what patients search that your channel misses
  • 50+ doctor channels tracked across India
  • AIO readiness scoring: which videos AI tools cite
Explore YODA →
Governance & Transparency

Agency OS

Full transparency. Instant diagnosis. Zero surprises.

ICG's centralised governance platform — every client sees everything in real time, and ICG's team sees every problem the moment it surfaces. 30+ real-time alert systems fire the moment a metric drifts outside its performance envelope.

  • GSC, GA4, Google Ads, Meta Ads, IVR — one live view
  • 30+ real-time alert systems per account
  • CPQL drift alert at >15% week-on-week change
  • Client login: full transparency on your account
Explore Agency OS →
AEO & LLM Intelligence

AIO Intel

AI Overview + LLM citation tracking, healthcare-tuned

Knows the moment ChatGPT, Perplexity, Google AI Overviews and Gemini cite your brand in patient answers — and which content drove the citation. Bot-aware dashboard with GA4-registered custom dims (AIO source, AIO referrer) and IndexNow + GSC API integration.

  • Live tracking across ChatGPT / Perplexity / Google AIO / Gemini
  • Bot-aware: knows human vs scraper traffic
  • Custom GA4 dims register AIO source + referrer
  • IndexNow + GSC API: content surfaced to LLMs within hours
View AIO Intel dashboard →
Competitor Intelligence

Prism Spy

Every Meta + Google ad your competitors run, watched daily

Tracks 75+ Indian healthcare brands, 2,150+ active ads, ₹50Cr+ aggregate ad spend visibility per month. Surfaces what's working, what's been killed, what offers are emerging. Powers every ICG Meta Ads brief, Performance Marketing diagnostic, and IVF / derm / dental specialty campaign with real competitive intelligence.

  • 75+ brands tracked across 30+ healthcare specialties
  • 2,150+ active ads · daily refresh
  • Activity Feed: every spend / hook / pause logged
  • Offers Intelligence: 250+ offers in market tracked
Explore Prism Spy →
GBP Intelligence Platform

Angryturtle

Every Google Business Profile scored, tracked, protected, and grown from one command centre

ICG's proprietary Google Business Profile intelligence platform. Scores every listing across 7 dimensions, tracks rank on a live geo-grid across your actual service area, audits NAP + citations, monitors 531 suspension-risk factors continuously, and drafts Google Posts on cadence. Currently managing 143 healthcare listings with 0 suspensions and 4.76★ portfolio average across 28,137 reviews.

  • 143 listings under management · 0 suspensions · 4.76★
  • 7-dimension Health Score + 5-factor Rank OS per listing
  • Geo-grid rank tracking + NAP + Citation audit + Profile Shield
  • NMC + NABH + ART Act + DPDP compliance built into every content + review workflow
Explore Angryturtle →

Every ICG engagement runs on some combination of these ten HealthApex OS tools. The diagnostic determines which combination is right for your practice.

Explore HealthApex OS → See the full stack live on your account — free 30-min audit →
FAQ

Medspa TCPA SMS — common questions

What is the 2024 FCC one-to-one consent rule?

In December 2023 the FCC closed the lead-generator loophole under the TCPA. Prior express written consent must now identify a single, clearly identified seller — one form, one seller, one consent. Bulk-consent flows that authorise dozens of sellers at once no longer meet the standard for medspa call or text outreach.

When did the FCC revocation-of-consent rule take effect?

FCC 24-24 was adopted February 15 2024, with core revocation provisions effective April 11 2025. Callers must honour opt-out through any reasonable method — reply STOP, inbound call, email, website form, in-person — within a maximum of 10 business days.

Do TCPA quiet hours apply to medspa marketing texts?

Yes. Under 47 CFR 64.1200(c) telephone solicitations to residential lines cannot be initiated before 8AM or after 9PM in the recipient's local time. The rule extends to SMS by declaratory ruling. Post-consent messages are not automatically exempt; the safe posture is a hard time-zone gate at send.

Is an appointment reminder text a marketing message?

An appointment reminder that is strictly about a scheduled visit is treated as informational. The moment the same message adds a promotion, package or rebooking offer, it becomes marketing and prior express written consent applies.

What are TCPA statutory damages per violation?

USD 500 per violation under 47 USC 227(b)(3), or actual monetary loss if greater. Knowing or wilful violations may be trebled to USD 1,500. Each unlawful message is a separate violation and class actions aggregate rapidly.

Does DNC apply if the recipient has consented to marketing texts?

Prior express written consent is a defence to a DNC claim for the specific named seller. It does not survive revocation, does not extend to other sellers, and does not authorise messages outside the topical scope of the original consent.

How long must consent records be retained?

The federal statute of limitations is four years under 28 USC 1658, so a four-year rolling audit log is the practical minimum. Capture the verbatim consent copy shown at opt-in, timestamp, channel, named seller and topical scope.

Is a STOP-confirmation autoresponder itself a violation?

Under the 2012 SoundBite declaratory ruling, a one-time confirmation that contains no promotional content and is sent within five minutes of STOP is not a new marketing message and does not violate the TCPA.

Do medspas need to register with 10DLC?

US carriers require every A2P sender on a 10-digit long code to be brand-registered and campaign-registered through The Campaign Registry. Unregistered traffic is filtered and pass-through fees apply. Registration is a carrier requirement, not a TCPA rule.

Can we use a call-tracking number for medspa marketing SMS?

Yes — with a HIPAA-safe provider that will sign a BAA (CallRail Healthcare, Retreaver HIPAA), a named-seller consent that identifies the medspa (not the number provider), and the same TCPA gates that apply to any other originating number.

Scope your TCPA-safe medspa SMS programme

Book a 30-minute call with a senior member of the Leadership Team, email the US practice lead, or call the Dallas office. Retainers are custom-scoped per engagement · from USD 250 per month equivalent, with SMS compliance audits priced on scope.

Selected ICG clients

Healthcare brands ICG
has worked with.

A representative slice of the 150+ healthcare brands ICG has delivered for across India. Full client list available under NDA during a Brand and Growth Diagnostic.

Read full client case studies →

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership