In a Cochrane review of eight randomised trials, patients who got a text message reminder attended 78.6% of their appointments, against 67.8% for patients who got no reminder at all. That gap is the cheapest argument for healthcare marketing automation, and it comes from a message nobody at your front desk had to type.
The same logic applies to every repetitive message a practice sends. The catch is that patient data raises the stakes in a way it doesn't for most other businesses, so the order you build things in matters.
What healthcare marketing automation covers
It's software that sends the right message when something happens: a patient books, an enquiry arrives, a visit ends, a recall date comes up. A person writes the message and the rules once, and the system handles every repeat.
In a practice that usually means appointment reminders and confirmations, instant replies to new enquiries, post-visit review requests, and recall or education emails to existing patients. Each one removes a task that someone currently does by hand, or, more often, doesn't do at all because the front desk is busy.
Under the surface sits a connected setup: forms, a CRM, messaging and a way to see what happened. Our AI and automation work is built around exactly that wiring, where the tools you already use pass data to each other instead of relying on someone to copy it across.
Start with appointment reminders
Reminders are the best-evidenced automation in healthcare, so build them first. The Cochrane review of mobile phone messaging reminders pooled seven trials with 5,841 participants and found attendance of 78.6% with text reminders versus 67.8% with none, a risk ratio of 1.14.
Against phone calls, texts did about as well, with calls only slightly ahead on raw attendance. Where costs were reported, a text per attendance cost 55% and 65% less than a call in the two studies that measured it.
Two caveats come with that. The review searched studies only up to August 2012 and was published in December 2013, so it says nothing about today's inbox habits. And its authors rated the evidence low to moderate quality, with little reporting on harms or on how patients felt about the messages.
Even so, the direction is clear enough to act on. A confirmation text that costs almost nothing to send and removes a call from someone's afternoon is an easy first workflow.
Reply to new enquiries before they go cold
Someone who fills in a contact form on a Tuesday evening is comparing you with two other practices. If the first reply arrives the next afternoon, the decision may already be made.
An automatic acknowledgement that names the next step, offers a booking link and tells the patient when a human will call fixes the gap without pretending a person wrote it. We looked at how fast replies change outcomes in a healthcare AI case study on response times.
Keep the first message free of clinical detail. Say you received the request and what happens next. Anything about a condition belongs in a secure channel, a point the compliance section below returns to.
Where HIPAA draws the line on marketing messages
The rule is short. Under 45 CFR 164.508(a)(3), a covered entity needs the patient's authorisation before using or disclosing protected health information for marketing. Two communications are exempt: a face-to-face conversation, and a promotional gift of nominal value.
If a third party pays you for the communication, the authorisation has to say so.
The practical question is which of your messages count as marketing. A compliance guide from AccountableHQ puts it this way: written authorisation is needed for marketing that isn't part of treatment, payment or operations. A reminder for a booked visit sits on one side of that line, and a promotion for a cosmetic service sent to your whole patient list sits on the other.
Edge cases exist, and your compliance officer or counsel should settle them before a workflow goes live, not after a complaint.
Choose tools and settings that can prove consent
A message platform is part of your compliance footprint. AccountableHQ's guide to HIPAA-compliant marketing automation says vendors must sign business associate agreements and that responsibilities should be documented when you onboard them and again each year.
Consent is the second test. The guide recommends channel-specific preferences, automatic suppression the moment an authorisation is revoked, and a central consent service so that one opt-out reaches every tool at once. If your reminder tool and your newsletter tool each keep their own list, a patient who opted out of one can keep hearing from the other.
Audit logs are the third. The same guide lists the events to record: sign-ins, data views, exports, edits to workflows and content, consent changes and message deliveries. When a regulator or a patient asks what was sent and why, that log is the answer.
Keep patient details out of subject lines and analytics

Photo by Vitaly Gariev on Pexels
Automation makes small mistakes large. A subject line that names a procedure goes to every recipient on the list, and a tracking parameter that carries a diagnosis ends up in a third-party dashboard.
AccountableHQ advises keeping PHI out of subject lines, URLs and analytics parameters, collecting data server-side where you can, and reporting in aggregate. It also suggests segmenting audiences on criteria that aren't PHI.
That limits personalisation, and it should. A first name and an appointment time carry most of the value of a reminder. The condition behind the visit adds little, and it's exactly the part that creates risk.
The order to build it in
Sequence the work so each step is safe before the next one adds volume.
- Sign business associate agreements with every vendor that touches patient data, and write down who is responsible for what.
- Set up one consent record and make every messaging tool read from it.
- Turn on appointment confirmations and reminders, with no clinical detail in the message.
- Add the instant acknowledgement for new enquiries, with a booking link and a stated callback time.
- Add review requests and recall messages once consent and logging are working.
- Review the logs and the analytics setup for PHI leaks before you add campaigns.
Resist the urge to launch everything in one week. A broken reminder flow is visible within days, whereas a consent gap can stay quiet for months.
Measuring whether it's working
Count outcomes that a front desk would recognise: appointments kept, enquiries answered within a set time, bookings that started from an automated message, and reviews collected. Dashboards full of open rates tell you little about patients.
Compare the months before and after each workflow goes live, and change one thing at a time. If attendance moves after you add reminders, you know why.
Reviews and local visibility compound the effect of faster follow-up. Our guides to healthcare reputation management and to optimising a healthcare Google Business Profile cover the pieces that decide whether a new patient finds you before they ever see a reminder, and our digital marketing and growth service ties them to the follow-up flows above.
For a worked example of the email side, dental practice email marketing basics shows what a simple, consent-based programme looks like.
Frequently asked questions
Are text reminders as effective as phone calls?
In the Cochrane review, three trials found texts and calls had a similar effect on attendance, and the two studies that reported costs found texts were much cheaper per attendance.
Do I need patient authorisation to send marketing messages?
Yes, for marketing that uses protected health information, with narrow exceptions for face-to-face communication and gifts of nominal value. Whether a given message counts as marketing is a question for your compliance officer or counsel.
Is it safe to put a patient's name or procedure in an email subject line?
AccountableHQ's guidance is to keep PHI out of subject lines, URLs and analytics parameters. A generic subject such as a reminder to confirm an appointment carries the value without the exposure.
Do my messaging vendors need to sign anything?
AccountableHQ's guide says platforms must execute business associate agreements, with shared responsibilities documented at onboarding and reviewed annually.
Cover photo by Tara Winstead on Pexels
Sources
- Mobile phone messaging reminders for attendance at healthcare appointments — Cochrane
- 45 CFR 164.508 Uses and disclosures for which an authorization is required — Legal Information Institute, Cornell Law School





























