SMS compliance guide: Telehealth, weight management & prescription drug programs

If your business operates in a regulated industry, such as telehealth, weight management, prescription drugs, or healthcare-adjacent programs, this guide is for you. SMS in these categories receives elevated review from wireless carriers, aggregators, and messaging providers, and the requirements can be more involved than what you may be used to in other channels. We have put this guide together to help you navigate those requirements and set your program up for success. We do recommend reading it in full before you launch, because approval decisions rest with the carriers, aggregators, and providers, and even a fully compliant program is not guaranteed approval.

Requirements in this space change constantly. Everything on this page reflects our current understanding of carrier, aggregator, and provider requirements and is subject to change without notice. We recommend re-checking with us before launching anything new.

We do not recommend pursuing marketing SMS for these programs in any form. We are not aware of any viable marketing use case for telehealth, weight management, or prescription drug programs. Transactional messaging is the only path we would recommend. See the Marketing use cases section below for the full detail.

How SMS regulation works in this space

The following sections explain the regulatory landscape, Customer.io’s role, and how carrier and provider requirements apply to your program.

Customer.io is a messaging platform. We use Twilio as our service provider and subprocessor for Customer.io-provided SMS, as described in our SMS Feature Terms. We do not set the carrier, aggregator, or provider requirements described here, and we cannot approve, guarantee, or override their decisions. Everything on this page is a recommendation based on our reading of current carrier, aggregator, and provider requirements, including Twilio’s own policies, and on what we have seen work and not work in practice. You are responsible for determining what your program needs in order to comply.

SMS messaging in the United States is subject to federal requirements, including the Telephone Consumer Protection Act (TCPA) and related FCC requirements, as well as FTC consumer-protection requirements. In addition to these legal requirements, Twilio and the mobile carriers establish and enforce their own requirements governing permitted SMS content and use cases. As reflected in Twilio’s U.S. SMS Guidelines and Forbidden Message Categories, these requirements and restrictions can evolve as laws, regulatory guidance, industry standards, and carrier policies change. Twilio’s restrictions can also apply based on the nature of the use case or business, rather than solely on the content of an individual message. That is why a message that looks compliant on its face can still be rejected or filtered if it is associated with a restricted use case category.

Before you build

Before you start building or submitting a campaign, there are a few things worth knowing about use case viability and number type selection.

Talk to us first: If you have questions about whether a specific use case is viable, we recommend reaching out to your Customer.io contact before you build or submit anything. It is usually far faster to talk through a use case up front than to recover a rejected campaign or a suspended number. We are happy to help you think through your use case and the requirements that may apply to your program, though we want to be upfront that Twilio maintains its own registration and compliance requirements that are outside of our control. We will do our best to set you up for success, but we cannot guarantee any particular outcome.

Transactional messaging only: In general, we can support eligible transactional messaging for programs in this space, but we will not submit a marketing use case or request a marketing-enabled number for accounts operating in these program categories. This is not a Customer.io policy choice. Carriers, aggregators, and providers currently prohibit most marketing SMS for these programs, and their restrictions apply based on the nature of the use case and business category, not solely on the content of any individual message. Marketing use cases covers this in detail.

If you were expecting to send marketing or promotional messages as part of your SMS program, we recommend discussing alternative channels with your Customer.io contact. Email and other channels may offer more flexibility for the messaging goals that SMS cannot support in this space.

Number type recommendations: We recommend against using short codes for any use case in this space. Based on current carrier and provider guidance as we understand it, we recommend 10DLC long codes or toll-free numbers (TFN) for telehealth, weight management, and prescription drug programs. We would not suggest planning a short code program around these use cases. If you currently have a short code in place for one of these programs, we recommend reaching out to your Customer.io contact to discuss transitioning to a supported number type.

Everything else on this page applies equally to 10DLC and toll-free numbers. As we understand it, carriers and providers hold both to the same standard for these programs. Choosing one over the other does not change the consent, content, or website requirements described below, and we are not aware of any exemptions for either number type.

We recommend reviewing the following resources for additional context on the current requirements and restrictions that apply in this space:

This page is carrier- and provider-focused guidance. It does not replace your responsibility to comply with applicable SMS laws and regulations, including the Telephone Consumer Protection Act (TCPA) and related FCC requirements, FTC consumer-protection requirements, applicable state laws, industry rules, carrier requirements, and the Customer.io Feature Terms. This guidance is focused on SMS/MMS programs sent to recipients in the United States and Canada. Other countries may have additional or different requirements.

Use case recommendations at a glance

Use case typeOur recommendation
Transactional (account notifications, OTP, appointment alerts, shipping and delivery updates, care coordination)✅ Supported. Use 10DLC or toll-free with proper consent and compliant content.
Healthcare quizzes / assessments that connect a person to a provider✅ Supported. Typically treated as transactional, provided messaging stays focused on connecting the person to care.
Any marketing or promotional messaging🚫 Not supported. Carriers and providers prohibit marketing SMS for these programs. We will not submit a marketing use case.
Any use case sent from a short code🚫 Not supported. Use 10DLC or toll-free instead. Contact us if you need to transition an existing short code.

Transactional use cases

Transactional messaging is the path we recommend for programs in this space, and it covers a wide range of use cases:

  • Account notifications and account status updates
  • One-time passcodes (OTP) and authentication codes
  • Appointment reminders, confirmations, reschedules, and cancellations
  • Order, shipping, and delivery notifications
  • Billing, payment, and subscription notices
  • Care coordination and provider follow-up logistics

As we understand it, it also covers one case that customers often assume is marketing:

  • Healthcare quizzes and assessments used to connect a person to a provider. Sending a recipient into an intake quiz, health assessment, or eligibility questionnaire whose purpose is to match them with a licensed provider is typically treated as a transactional use case, provided the messaging stays focused on the process of connecting them to care and does not promote a specific medication, treatment, or outcome.

We recommend applying all of the content guidance below to transactional messaging too. In our experience, transactional classification does not create room to name a drug, make a medical claim, or include a promotional offer.

Marketing use cases

Carriers, aggregators, and messaging providers currently prohibit marketing SMS for telehealth, weight management, and prescription drug programs. These restrictions apply based on the nature of the use case and business category, not solely on the content of any individual message. We are not aware of any viable marketing use case in this space, and we strongly recommend against pursuing one. For that reason, Customer.io will not submit a marketing use case or request a marketing-enabled number for accounts operating in these program categories at this time.

This covers promotional messaging of any kind, including offers, incentives, and program enrollment pushes. We would not recommend building any messaging program in this space around a promotional offer.

In our experience this is not something careful copywriting solves. Because restrictions can apply at the use case and business category level, promotional messaging tied to these programs tends to be rejected at registration or filtered in flight regardless of how the copy is worded, and it can put your brand, your number, and your remaining campaigns at risk. If your goal is to reach existing customers with something other than a transactional message, we recommend talking to your Customer.io contact about email or another channel before you build anything in SMS.

Three things we strongly recommend

Based on current Twilio and carrier guidance as we understand it, we recommend treating all three of the following as effectively required for your program to stay in good standing.

1. Keep content focused on your business, not products or treatments

We recommend keeping every message focused on your business and service. That means:

  • Driving users who have properly opted in to your own branded sign-up, account, intake, or scheduling flow
  • Helping people connect with a provider, including through a healthcare quiz or assessment
  • Driving traffic to your website using branded links, not public URL shorteners
  • Sharing service updates, account information, and reminders tied to your business

We recommend against positioning your messages around a specific medication or medical outcome.

2. No medication names and no medical or pharmaceutical language

Keep all content focused on your service. We recommend avoiding:

  • Offers, promotions, or calls to action for prescription drugs, even if your provider network is licensed
  • Any medication by brand or generic name, including GLP-1 and other prescription weight management drugs
  • Clinical or pharmaceutical terms, dosing, or drug class references
  • Diagnoses, condition names, treatment references, or medical claims, for example promises about weight loss results or treating a condition

If a reader could not tell what specific drug or condition you are referring to from your message, you are on the right track.

3. Add a date-of-birth age gate to your website

Where required, we recommend that your website verify age before or at consent capture using a month / day / year date-of-birth entry. This can live wherever makes sense for your flow: a site entry gate, the checkout form, or the intake form.

  • We don’t consider a simple “I am over 18” checkbox sufficient.
  • We recommend requiring the visitor to actively enter their date of birth.

Any breach can trigger immediate suspension

Carriers and Twilio can suspend your number and campaign instantly for any violation of the guidance above. This often happens with no warning, and reinstatement is not guaranteed. We recommend treating every message and every change to your site as something that must stay compliant.

  • “Welcome to [Brand]. Your account is ready. Get started here: [link]”
  • “[Brand]: Your consultation is confirmed. Reply STOP to opt out.”
  • “[Brand]: Your verification code is 123456.”
  • “Ready to take the next step with [Brand]? Answer a few questions to get matched with a provider: [link]”
  • General service reminders, appointment confirmations, and account notifications tied to your business

What we recommend avoiding

  • Any drug name, brand or generic, including GLP-1 medications
  • Dosing, prescriptions, or pharmacy references
  • Condition names, diagnoses, or treatment and outcome claims
  • Any marketing or promotional messaging for these programs
  • Any short code program for these use cases
  • SHAFT content (Sex, Hate, Alcohol, Firearms, Tobacco), cannabis, or CBD
  • Anything that reads as a third-party or affiliate offer

Standard SMS rules

We recommend treating the following as required for all A2P programs, alongside the points above. Many of these are also verified by Twilio during the campaign registration process that Customer.io manages on your behalf:

  • Consent: Only message people who have actively opted in. You cannot buy, sell, share, or transfer consent. Keep records of the opt-in date, method, language shown, and message program consented to. Twilio requires evidence of valid consent as part of campaign registration, and Customer.io may need to review your consent documentation before we can submit your campaign.
  • Opt-in flow review: Before you submit or send, we recommend confirming that your phone number collection flow clearly identifies the sender, message purpose, whether messages are recurring, message frequency, that message and data rates may apply, how to get help, how to opt out, and links to your SMS terms and privacy policy. Twilio reviews your opt-in flow as part of campaign registration, so we recommend having your flow finalized and live on your site before Customer.io submits your campaign.
  • Opt-out: Honor STOP and other standard opt-out keywords (QUIT, END, CANCEL, UNSUBSCRIBE), as well as opt-out requests made by other reasonable methods, and include opt-out language in your messages.
  • HELP: Respond to HELP with your brand name and a support contact number or email. Your HELP response is reviewed during campaign registration, so we recommend having it configured before Customer.io submits your campaign.
  • Privacy policy and SMS terms: Your site needs both a privacy policy and SMS-specific terms. The privacy policy should confirm that mobile numbers and SMS opt-in consents are not sold, shared, or transferred to third parties for their marketing. Your SMS terms should outline your STOP and HELP instructions, support contact information, and program description, as well as any other required disclosures. Twilio checks for these pages during campaign registration, and missing or incomplete policies are a common reason for rejection.
  • Brand match: Your registered brand, your website, and your message content must all line up. Twilio verifies brand consistency during registration, and mismatches are one of the most common reasons campaigns get rejected. We recommend using branded links only, and not using public URL shorteners like bit.ly or tinyurl.

Opt-out and HELP

  • STOP and HELP must always work on your number.
  • Include opt-out language, for example “Reply STOP to opt out,” in your opt-in confirmation and your first message. We recommend treating this as required.
  • Best practice: add “Reply STOP to opt out” to your recurring messages too. It is not strictly required, but in our experience it protects deliverability in this closely watched space.
  • Honor any STOP request promptly.

Questions about whether a specific use case, a specific piece of copy, or a specific site setup will pass? Reach out to your Customer.io contact before you build or send. We cannot guarantee carrier approval in this category, but it is usually much faster to talk something through in advance than to recover a rejected campaign or a suspended number. We are happy to partner with you on the transactional use cases that can be supported and to discuss any questions about these requirements. For additional context regarding current requirements and restrictions, we also recommend reviewing Twilio’s U.S. SMS Guidelines and Forbidden Message Categories directly.

Updated August 27, 2026