Calls, texts and the law: a compliance guide for vet clinics
By the Tilly editorial team · Updated
What changed: First edition. We review this guide every six months and whenever a US federal or state rule it covers changes.
This is general information, not legal advice.

Jurisdiction: United States. This guide explains, in plain language, the main rules that apply when a vet clinic texts, calls or records its clients: the Telephone Consumer Protection Act (TCPA) and the FCC's rules under it, carrier texting rules, call recording consent, AI disclosure, WhatsApp consent, HIPAA and state privacy laws. It is written for practice managers and owners. It covers federal rules in detail and describes state rules in general terms, because they differ and they change. Where a state rule matters, check your own state's statute or ask a lawyer licensed in your state.
Most clinics are not trying to bend these rules. They text reminders because clients like them, and they record calls to train the team. The risk comes from small gaps: a reminder list that includes someone who said stop, a "we miss you" text sent to clients who only agreed to appointment messages, a recording with no notice. This guide is about closing those gaps with a few clear habits.
What is vet clinic texting compliance?
Vet clinic texting compliance means sending texts and making automated calls to clients only in ways the law and the carriers allow. In practice that means the right consent for each kind of message, a record of that consent, sending only at permitted hours, honoring opt-outs quickly and identifying your clinic in every message.
The main federal law is the Telephone Consumer Protection Act, usually called the TCPA. The FCC enforces it through rules in 47 CFR 64.1200. The FCC's TCPA overview is the best plain-language starting point from the regulator itself. On top of the federal rules sit three more layers:
- State laws. Several states have their own telemarketing laws, sometimes called "mini-TCPAs", with stricter hours, frequency limits or consent rules.
- Carrier rules. US mobile carriers require businesses that text from ordinary phone numbers to register and to follow industry guidelines, set out in the CTIA Messaging Principles and Best Practices. A carrier can filter or block messages that break them, whatever the law says.
- Platform rules. WhatsApp has its own business messaging policy, covered below.
You do not need to memorize every rule. You need a process that answers four questions before any message goes out: what kind of message is this, does this client agree to it on this channel, is it a permitted time where they are, and have they asked us to stop?
Informational or marketing: why the difference matters
The single most useful habit is to sort every message you send into one of two kinds, because the consent you need depends on it.
Informational messages are about something the client already has with you. Appointment confirmations, appointment reminders, a note that a prescription refill is ready to collect, a link to an intake form for a booked visit, or a reply to a question the client asked are all informational. They do not try to sell anything new.
Marketing messages encourage the client to buy something or come back for something they have not booked. A "we haven't seen Max in a while, book a check-up" message, a dental-month promotion, a new-service announcement or a discount offer are marketing. The FCC's rules call these "advertisements" or "telemarketing".
Some messages sit in between. A vaccine or wellness recall drawn from your practice software is tied to an existing client relationship, but it also asks the client to book a new visit. Clinics and their advisers treat recalls differently. A cautious approach is to ask clients specifically whether they want reminders and recalls, and to keep that consent separate from both appointment messages and marketing.
When you are not sure which kind a message is, treat it as marketing. That costs you a little reach. Guessing wrong in the other direction can cost far more.
What consent does a vet clinic need to text clients?
Vet clinics need prior express consent for informational automated texts and calls to a client's mobile number, and prior express written consent for marketing texts and AI or prerecorded marketing calls. Carrier rules also expect clear opt-in for texting. Collect consent for each channel and purpose separately, and keep a record you can produce later.
Under 47 CFR 64.1200(a)(1), a call to a mobile number made with an autodialer or an artificial or prerecorded voice needs the called party's prior express consent, unless it is made for emergency purposes. The FCC treats text messages as calls for this purpose. For marketing, 64.1200(a)(2) goes further and requires prior express written consent.
Prior express consent
Prior express consent is the basic level. It can be given orally or in writing. In many cases the FCC has treated a person who gives their number for a purpose as agreeing to be contacted about that purpose. A client who gives you their mobile number when booking an appointment is likely agreeing to be contacted about that appointment. Do not stretch that further than it goes. Giving a number at the desk is not agreement to recall campaigns, surveys or promotions.
Prior express written consent
Prior express written consent is the higher level, required for marketing sent with an autodialer or an artificial or prerecorded voice. The regulation defines it as a written agreement, signed by the client, that clearly authorizes the business to send them advertisements or telemarketing messages at a specific number. The agreement must disclose clearly that the client is authorizing those messages, and that they do not have to agree in order to buy anything. An electronic signature counts where federal or state law recognizes it, so a web form or a texted keyword reply can work when it is set up properly.
Does the law apply to every texting tool?
The TCPA's autodialer definition has been narrowed by the courts over the years, and whether a particular texting system counts as one is a legal question. That does not mean you can skip consent. Carrier rules expect opt-in for business texting regardless, several state laws have their own broader definitions, and an AI or prerecorded voice call needs consent whatever dialing system places it. The practical answer is the same everywhere: get consent, and get the right kind.
A note on the health-care exemption
The FCC rules contain some exemptions for "health care" messages. Read them carefully before you rely on them. In 64.1200 they apply to messages made by or on behalf of a "covered entity" or its "business associate" as those terms are defined in the HIPAA Privacy Rule. As the HIPAA section below explains, veterinary clinics are generally not HIPAA covered entities, so a vet clinic should not assume those exemptions apply to it.
How should you record consent?
Record consent as a dated entry per client, per phone number, per channel and per purpose. Store the exact wording the client agreed to, how they agreed, when, and who or what captured it. Record refusals and opt-outs the same way, and keep the records long enough to answer a complaint years later.
Consent you cannot show is consent you may not be able to rely on. A tick box in your practice software that says "OK to contact" tells you very little: contact by what channel, for what, since when, and in what words? If a client complains, you want to point to a specific record.
A good consent record holds:
- Who: the client, and the specific phone number or email address the consent covers.
- Channel: text, WhatsApp, voice call or email. Consent for one channel is not consent for another.
- Purpose: appointment messages, reminders and recalls, or marketing. Keep each separate.
- Wording: the exact question or form text the client agreed to.
- How: in person at the desk, on a phone call, on a signed or e-signed form, or by a keyword reply.
- When: the date and time.
- Who captured it: the staff member or system.
- Refusals and changes: a "no" is worth recording too, so nobody asks again tomorrow or sends anyway.
Two practical points. First, numbers change hands. The FCC maintains a Reassigned Numbers Database that lets callers check whether a number has been permanently disconnected since consent was given; consider using it, or a service that does, before campaigns to older contacts. Second, migrate carefully when you change software. Consent records should travel with the client, with their dates and wording intact.
What are the quiet hours for texting clients?
Federal rules bar telephone solicitations before 8 a.m. or after 9 p.m. in the recipient's local time. Several states set narrower windows or limit Sunday and holiday contact. A safe default is to send non-urgent messages only between 8 a.m. and 8 p.m. in the client's time zone, then adjust for state rules.
The federal rule in 64.1200(c)(1) says no one may make a telephone solicitation to a residential subscriber before 8 a.m. or after 9 p.m., local time at the called party's location. Strictly, that rule is about telemarketing. Many clinics apply the same window to all automated reminders anyway, because clients do not want a reminder at 10 p.m. either, and because some state rules apply more broadly.
State rules vary. Some states, including Florida and Oklahoma under their telephone solicitation laws, use a narrower evening cut-off and limit how many messages a business can send on the same subject in a day. Others restrict contact on Sundays or state holidays. Check the current text of the law in each state where your clients live, not only the state where your clinic is.
Three habits make quiet hours easy:
- Use the client's time zone, not yours. A clinic near a state line, or one with clients who winter elsewhere, will have clients in more than one time zone.
- Move reminders earlier, not later. If a two-hour reminder would land before 8 a.m., send it the previous evening within the window instead of breaking the window.
- Keep conversations separate from campaigns. If a client texts you at 9:30 p.m. asking to rebook, replying in that conversation is different from starting a campaign message at that hour.
For more on timing and wording, see our reminder text templates and the TCPA texting guide for vet clinics.
How should a clinic handle opt-outs?
A clinic should treat any reasonable request to stop as an opt-out, including STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, UNSUBSCRIBE and plain sentences like "please stop texting me." Federal rules require honoring requests within ten business days at most. Stopping at once, and confirming with one short message, is better practice.
The FCC tightened the opt-out rules recently. Under 64.1200(a)(10), a person can revoke consent "by using any reasonable method". Replying with "stop", "quit", "end", "revoke", "opt out", "cancel" or "unsubscribe" counts automatically. If a client replies with other words that a reasonable person would understand as a request to stop, you must treat it as one too. You may not insist on a single exclusive way to opt out, and the request must be honored within a reasonable time, not more than ten business days.
The rules also allow one confirmation text after an opt-out, as long as it only confirms the request, contains no marketing, and is the only message sent. A confirmation sent within five minutes is presumed to be within the client's consent.
Good opt-out handling at a clinic looks like this:
- Stop means stop, on every list. An opt-out received by the reminder system must also reach whoever sends recalls, promotions and surveys.
- Plain language counts. "No more texts please" in reply to a reminder is an opt-out. So is a client telling the receptionist on the phone.
- Respect scope when the client gives one. If a client says "stop the recall messages but keep appointment reminders", record exactly that. If they do not say, stop everything on that channel except what they have clearly asked to keep.
- Opt back in only on the client's request. If a client who opted out wants messages again, record that new consent the same way you recorded the first.
AI and prerecorded voice calls

More clinics now use AI to answer calls, and some use it to make reminder calls. The rules for calls you receive and calls you make are different.
Outbound calls: AI voices are "artificial"
In February 2024 the FCC issued a declaratory ruling, FCC 24-17, confirming that the TCPA's restrictions on calls using an "artificial or prerecorded voice" cover current AI technologies that generate human-sounding voices. In plain terms, a reminder call placed by an AI voice is treated like a robocall. It needs the same prior express consent as a prerecorded call, and prior express written consent if it is marketing.
The rules also set what an artificial or prerecorded voice message must say. Under 64.1200(b), the message must state clearly, at the beginning, the identity of the business responsible for the call, and during or after the message state a telephone number for that business. Telemarketing calls must also offer an automated way to opt out. A good AI reminder call therefore:
- Says who is calling, for which clinic, and that it is an automated AI assistant, in the first sentence.
- Checks it is speaking with the right person before mentioning a pet or an appointment.
- Gives the clinic's phone number.
- Accepts "stop calling" or a key press as an opt-out and confirms it.
- Leaves a voicemail that names the clinic and gives a callback number, without appointment or health details.
Inbound calls: the TCPA rarely applies, disclosure still matters
When a client calls you and an AI assistant answers, the TCPA's consent rules for outgoing calls generally do not apply, because your clinic did not place the call. Other rules do: recording consent if the call is recorded, and AI disclosure, both covered below.
Do you need consent to record client calls?
Recording consent depends on state law. Federal law and most states allow recording when one party to the call consents. A minority of states require every party to consent. Because callers can be anywhere, the safest practice is to give every caller a clear recording notice at the start and let them say no.
The federal wiretap law uses a one-party consent rule: a call can be recorded if one participant agrees, and your clinic counts as a participant. Most states follow the same approach. A smaller group of states require the consent of everyone on the call, sometimes called "all-party" or "two-party" consent. California, Florida, Maryland, Massachusetts, Pennsylvania and Washington are among them. Lists of all-party states vary in how they classify a few states with unusual rules, so check your own state's statute rather than relying on any list, including this one.
Three points cause most of the confusion:
- Calls cross state lines. A clinic in a one-party state can receive calls from clients in an all-party state. When the two states' rules differ, the cautious approach is to follow the stricter one.
- Notice is how consent usually works. In all-party states, a clear notice at the start of the call, such as "this call is recorded", followed by the caller choosing to continue, is the common way to get consent. The notice should come before anything that matters is said.
- Vendors may count as a party. Some recent lawsuits have argued that a technology vendor that records or processes a call can be a third party to the conversation. A clear notice that names why the call is recorded, and a way to decline, reduces that risk.
Good recording practice at a clinic:
- Play a short notice at the start of every recorded call, in every state.
- Let callers say they would rather not be recorded, and stop recording when they do.
- Keep recordings only as long as you need them, and limit who can play them.
- Record the fact that the notice was played, so you can show it later.
Our glossary entry on call recording consent explains the terms in more detail.
Do you have to tell callers they are talking to an AI?
No single US law requires every AI phone assistant to say it is an AI, but some states require bots or generative AI to disclose themselves in certain situations, and the FCC treats AI voices as artificial voices for outbound calls. Telling every caller at the start is the simplest way to satisfy all of them.
AI disclosure means telling people plainly that they are dealing with an AI, not a person. The legal picture is patchy and moving. California's bot disclosure law covers bots used to influence a purchase or a vote online. Utah requires disclosure of generative AI in some interactions, including when a person asks. Other states have passed or proposed rules, and the list grows each year.
Rather than tracking which rule applies to which call, many clinics adopt a simple policy:
- Disclose at the start. The first words of every call or message say the assistant is an AI and name the clinic.
- Never pretend to be human. The assistant does not use a human name as its own, does not claim to be a receptionist, and answers truthfully if asked "am I talking to a real person?"
- Always offer a person. A caller who would rather talk to someone on your team can ask at any time and be offered a transfer or a callback.
Disclosure is also good service. Clients who know they are talking to an AI ask simpler questions, and they trust the clinic more when the path to a person is clear.
Texting from your clinic number: carrier rules
Even when the law is satisfied, carriers decide whether your messages arrive. US carriers require businesses texting from ordinary ten-digit numbers to register under the A2P 10DLC system: the business registers its brand, describes each texting use case, gives sample messages and explains how people opt in and opt out. Unregistered or poorly described traffic can be filtered or blocked.
The CTIA Messaging Principles and Best Practices set the expectations carriers apply. In practice:
- Clear opt-in. Tell clients what kind of messages they will get, from whom, and how to stop.
- Identify yourself. Name the clinic in the first message of a conversation.
- Support STOP and HELP. STOP ends messages; HELP returns your clinic name and a way to reach you.
- Avoid content that triggers filters. Public link shorteners, all-caps promotions and unexpected links can get messages blocked.
If you use a texting platform or an AI front desk, ask how it handles registration and whether your sample messages and opt-in description match what you actually send.
WhatsApp consent

Many clients, especially Spanish-speaking families, prefer WhatsApp. It has its own rules on top of the law. The WhatsApp Business Messaging Policy says a business may contact people on WhatsApp only if they have given the business their phone number and the business has received opt-in permission confirming they wish to receive messages from it. The policy also requires businesses to respect any request, on or off WhatsApp, to block, stop or opt out of messages, and it recommends that the opt-in covers the categories of messages the business will send.
WhatsApp also limits when a business can start a conversation. Outside a 24-hour window after the client's last message, a business can only send pre-approved message templates, and Meta classifies each template, for example as utility or marketing.
Whether the TCPA applies to app-based messages is less settled than for ordinary texts. The simplest approach is to treat WhatsApp like texting: ask specifically for WhatsApp consent, record it the same way, keep reminders and marketing separate, and honor opt-outs the same way.
Does HIPAA apply to veterinary records?
HIPAA generally does not apply to veterinary records. HIPAA covers health plans, health care clearinghouses and human health care providers that conduct certain electronic transactions. Many states have their own rules on the confidentiality of veterinary records, usually in the veterinary practice act or board regulations, and those rules can limit what you share and with whom.
The myth that vet clinics are bound by HIPAA is common, and it cuts both ways. Some clinics refuse reasonable requests because "HIPAA won't let us". Others assume that, since HIPAA does not apply, client and patient information has no special protection. Neither is right.
What to know:
- HIPAA is about human health information. Its rules apply to "covered entities" and their "business associates", and veterinary clinics generally are neither. That is also why the HIPAA-linked exemptions in the FCC rules, mentioned above, should not be assumed to help a vet clinic.
- State veterinary confidentiality rules may apply. Many states require veterinarians to keep patient records and client information confidential, with listed exceptions such as the owner's consent, a court order or public-health reporting. The details vary, so read your state's veterinary practice act and board rules.
- Client information is personal information. Names, phone numbers, addresses, payment details and call recordings are personal information about your clients, whoever's health they relate to. State privacy and data-breach laws can apply to them.
A practical rule for the front desk: share pet and appointment details only with the client or someone they have authorized, and confirm who you are talking to before you do. That habit satisfies most state confidentiality rules and protects clients from simple mistakes.
What do state privacy laws like the CCPA mean for vet clinics?
State privacy laws such as California's CCPA, as amended by the CPRA, give residents rights over their personal information, including the rights to know, delete, correct and opt out of the sale or sharing of it. They apply only to businesses that meet thresholds, so many independent clinics may fall outside them. Check before assuming.
The CCPA/CPRA is California's consumer privacy law. According to the California Attorney General's CCPA page, it applies to for-profit businesses that do business in California and meet at least one threshold: annual gross revenue above a set amount, buying, selling or sharing the personal information of a large number of California residents or households, or earning most of their revenue from selling or sharing personal information. California voters approved the CPRA in 2020, which amended the CCPA and added the rights to correct and to limit the use of sensitive personal information.
Many single-location independent clinics will not meet these thresholds. Larger groups, and clinics owned by bigger companies, may. Several other states, including Virginia, Colorado and Connecticut, have passed comprehensive privacy laws of their own, each with its own thresholds and exemptions.
Even where these laws do not apply, they are a useful guide to what clients now expect:
- Know what you collect. List the personal information your phones, texts, forms and recordings capture.
- Keep it no longer than you need. Set retention periods for recordings and transcripts, and delete on schedule.
- Know where it is stored. Ask vendors where your data is hosted and processed. Our glossary entry on data residency explains why that matters.
- Choose vendors carefully. Your phone, texting and AI vendors handle client data on your behalf. Ask whether they use it to train models, who can access it and how they handle deletion requests.
- Have a way to answer requests. If a client asks what you hold about them, or asks you to delete it, know who handles that and how.
A compliance checklist for your clinic
Use this list to check your current setup. It is a starting point, not a substitute for advice on your state's rules.
Texting and automated calls
- Every message type is sorted into informational, reminders and recalls, or marketing.
- Consent is recorded per client, number, channel and purpose, with wording, date and time.
- Marketing texts and AI or prerecorded marketing calls go only to clients with prior express written consent.
- An "OK to contact" flag is not treated as consent for recalls or marketing.
- Messages are sent only within the permitted hours of the client's state, in the client's time zone.
- STOP, other standard keywords and plain-language requests end messages promptly, on every list.
- Marketing lists are checked against the National Do Not Call Registry and any state lists that apply.
- Your texting numbers are registered with carriers, and the registration matches what you send.
- Older numbers are checked against the Reassigned Numbers Database before campaigns.
Calls and recordings
- Every recorded call starts with a recording notice, in every state.
- Callers can decline recording, and the recording stops when they do.
- Recordings have a set retention period and limited access.
- AI assistants say they are an AI at the start of every call and message, and offer a person.
- AI reminder calls identify the clinic, give a callback number and accept "stop calling".
Privacy
- The team knows HIPAA generally does not apply, and knows your state's veterinary confidentiality rules.
- Pet and appointment details are shared only after confirming who you are talking to.
- You know which state privacy laws, if any, apply to your clinic.
- You know where your vendors store your data and whether they use it to train models.
Review the checklist every six months, and whenever you add a new channel, a new vendor or a new kind of campaign.
How Tilly handles consent, recording and disclosure
Tilly is the AI front desk built for independent vet clinics in the US. It was designed around the practices in this guide. This section describes how it works; it does not make your clinic compliant on its own, and you remain responsible for how you contact your clients.
- AI disclosure in every conversation. Every call and message starts with Tilly saying it is the clinic's AI assistant, followed by the person line: callers can say "person" at any time to reach the team, and they are offered a transfer or a callback.
- A recording notice wherever recording is on. When your clinic records calls, every caller hears a recording notice, in every state, and can say they would rather not be recorded. Tilly stops recording and deletes what it already captured. Tilly applies the stricter rule of your clinic's state and the caller's state. Set recordings to 0 days and Tilly won't record or play a notice.
- Consent with fixed wording and stored evidence. Tilly asks for consent only with approved wording that names the channel and the purpose, and stores the wording, the answer, the number and the time. Appointment messages, reminders and marketing are separate, and Tilly never asks for marketing consent on a call.
- Reminders only to clients who agreed. Reminders and recalls go only to clients with recorded consent for that channel and kind of message. Consent you already hold in your practice software is used only where it is recorded as a clear opt-in; a general "OK to contact" flag counts for appointment messages only.
- Quiet hours, opt-outs and Do Not Call checks. Messages are sent within the allowed hours of the client's state. STOP and plain-language opt-outs take effect immediately, and marketing lists are checked against Do Not Call registers before sending.
- WhatsApp by the rules. Messages outside WhatsApp's 24-hour window use approved templates only.
- US hosting. Your calls, transcripts, recordings, backups and exports are stored and processed in the United States.
Read more on our security and privacy page, see how reminders work on the reminders page, and read the rules Tilly follows on every call on our safety page. The quickest way to hear the disclosure and the person line is to call our demo line.
Keep it simple and keep records
Compliance at a vet clinic comes down to a short list of habits: know what kind of message you are sending, ask for the right consent and write it down, send at sensible hours, stop when asked, tell callers when they are recorded and when they are talking to an AI, and protect client information as if HIPAA applied even though it usually does not. Put those habits into your tools and your team's routine, check them twice a year, and ask a lawyer licensed in your state when a question goes beyond this guide.
If you want to see how much your phones are missing before you change anything, start with an audit.
Get your free missed-call auditSources
- fcc.gov/general/telemarketing-and-robocalls
- docs.fcc.gov/public/attachments/FCC-24-17A1.pdf
- ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200
- ctia.org/the-wireless-industry/industry-commitments/messaging-interoperability-sms-mms
- business.whatsapp.com/policy
- oag.ca.gov/privacy/ccpa