AURA

SMS reminders for patients: what you can write without breaching confidentiality

You send an SMS reminder about an appointment — and a coworker or family member sees it. A short message can reveal the diagnosis, procedure, or doctor's specialization. Learn what you can write without violating confidentiality and GDPR.

Published
13 min read2682 words

AURA — a virtual business manager. Management on facts, not impressions. Who we are

Key takeaways

  • Article 14 of the Patient Rights Act prohibits disclosing health information — this applies to SMS and emails too
  • Medical data is special category data under Article 9 of GDPR — it requires special protection
  • You can write in messages: date, time, address, contact phone — without diagnoses or procedure names
  • Third-person test: if a stranger reads the message, will they learn about the patient's health condition?
  • Message templates should be approved by a DPO or lawyer, not an external service provider
  • Automated reminders don't need to contain any medical data — date and phone are enough

You send a patient an SMS reminder about their appointment — but their phone is sitting on a desk at work, visible to a coworker, partner, or child. From that short message, someone can learn far more than the clinic intended to convey. The name of the procedure, the doctor's specialization, the diagnosis — all of this is covered by professional confidentiality, and at the same time constitutes sensitive data that could harm the patient if it falls into the wrong hands. As a clinic owner, you need to know how to communicate with patients without violating regulations or exposing them to consequences.

This article covers the rules governing what you can include in patient messages, concrete examples of what is allowed and what must be avoided, and neutral message templates that meet legal requirements.

Dental clinic reception with a plant, service bell, and green indicator light
The clinic reception — where patient messages originate

Article 14 of the Patient Rights Act clearly states that persons practicing medical professions are obligated to keep patient information confidential, particularly information relating to their health condition — according to the Patient Rights Act. The same applies to physicians under the Act on the Professions of Physician and Dentist.

Shadow of a raised index finger on a plain wall
Professional confidentiality — a principle worth knowing

Who can see messages sent to a patient

SMS or email lands on a mobile device that is rarely used by only one person. For medical clinic patients, this is particularly relevant — the phone may be on a desk at work, within view of household members, or passing between hands. From a brief message like "Reminder: appointment on Monday at 9:00 with the dentist," a coworker immediately knows three things: the patient is getting dental treatment, they visit regularly, and they have a specific problem requiring a specialist.

The same issue applies to emails and messenger messages. WhatsApp, SMS, or Messenger may be open on a tablet in the living room, a laptop at work, or a smartphone on a desk. Anyone with access to that screen automatically becomes a recipient of information about the patient's health. In practice, this means the clinic must assume that every message could be read by a third party — and design communication with this assumption in mind.

Worse still, information about a medical appointment itself says something about health status. The fact that someone scheduled an appointment with an oral surgeon, orthodontist, or psychiatrist is enough to draw conclusions. This is why regulations require the clinic to exercise particular caution in every element of patient communication, including automated messages.

Polish law clearly defines what information is protected by confidentiality and who is responsible for maintaining it. Article 13 of the Patient Rights Act states that patients have the right to have information relating to them kept confidential. Article 14(1) of the same act specifies that persons practicing medical professions are obligated to keep patient information confidential, particularly information relating to their health condition. Exceptions to this rule are listed in paragraph 2 and include patient consent, among other situations.

Parallel to this, Article 40 of the Act on the Professions of Physician and Dentist imposes an obligation on physicians to keep patient information confidential obtained in connection with practicing their profession. Exceptions, similarly to the Patient Rights Act, include patient consent given after being informed about the consequences, and situations where maintaining confidentiality could endanger the patient or others. The key point is that this obligation applies to any information that could link a patient with their health condition — therefore the doctor's specialization and type of procedure. The appointment date alone at a general clinic doesn't yet reveal that, as the table below shows.

The rule is simple: if the content of a message allows a third party to draw conclusions about the patient's health status, then that message violates confidentiality. It doesn't matter whether the clinic intentionally meant to disclose a diagnosis — what counts is the effect the message could have on an incidental reader.

Medical data as special category data

The Polish Data Protection Office (UODO) in its statement to the Minister of Health clearly indicated that medical data contains personal data of a special category within the meaning of Article 9 of GDPR — according to the UODO position. Moreover, this data often reveals many other pieces of information about an individual, beyond just their health status.

From the clinic's perspective, this means double risk. First, violating professional confidentiality is subject to professional liability and can result in consequences from the medical association. Second, processing sensitive data without appropriate legal basis constitutes a GDPR violation, which carries high financial penalties. This is why every message sent to patients must be designed with both requirements in mind.

The exception is when the patient themselves explicitly consents to receiving messages containing detailed appointment information. In practice, however, this is rarely used because it requires conscious, voluntary, and specific consent, and the patient must be informed about all consequences of such a choice. In most cases, the safer path is neutral communication that requires no decision from the patient.

What you can and cannot write in patient messages

The rule is: only organizational information that doesn't allow conclusions about health status can be included in patient messages. In practice, this means a narrower range of permissible content than one might expect. The table below presents a breakdown of elements that can and cannot be included in SMS and email messages to patients.

Message elementCan you write itNotes
Date and time of appointmentYesOrganizational information, doesn't reveal the reason for the visit
Clinic addressYesNeutral contact information
Phone number for reschedulingYesWorks on a "please contact us" basis without stating the reason
Clinic nameYesUnless the name indicates a medical specialization
Reason for visit, diagnosisNoClearly indicates health condition
Name of procedure, treatmentNoMedical information covered by confidentiality
Doctor's specializationOnly if it doesn't reveal the problem"Doctor" is safe, "orthodontist" or "oral surgeon" are not
Reminder to bring documentsYesGeneral organizational information
Link to patient portalYesSafer alternative to details in the message

The key is the third-person test: if someone who isn't the patient reads the message, can they draw conclusions about that person's health status? If yes — the message is too detailed and should be simplified.

This is why the safest approach is to limit content to the absolute organizational minimum from the table above — without adding anything "just in case."

Different communication channels and their specifics

The choice of communication channel matters for information security. SMS messages appear on the phone's lock screen and are visible even without unlocking the device. A coworker, partner, or child passing by the patient's phone will automatically see: "Dental Clinic — appointment tomorrow at 10:00." The very name of a dental clinic says it all.

Emails are somewhat safer because most email accounts require login. However, message content can still be visible in previews on tablets or computers, in notifications on other devices synced with the same account, and in search history if the patient uses autocomplete.

Messengers like WhatsApp or Messenger offer end-to-end encryption, meaning message content is protected during transmission. However, on the recipient's device, the message is stored unencrypted and can be visible on screen at any time. Additionally, many people use WhatsApp on computers or tablets where the screen is larger and content more conspicuous. If the clinic team already works in a messenger app, Telegram / WhatsApp Integrations can route team notifications there instead of adding yet another channel nobody checks.

The safest solution is to limit message content to the absolute organizational minimum, and to convey detailed appointment information, health status, or recommendations through a secure patient portal that requires login. The patient decides for themselves when and where they want to view private information. More about customer communication automation can be found in the article Query handling automation, and about confirmation effectiveness in the restaurant industry in No-show in restaurants.

Do automated reminders actually reduce no-shows?

Microsoft, in its documentation for Bookings — its appointment management tool — states that "email and SMS text notifications reduce no-shows and enhance customer satisfaction" — according to the Microsoft Bookings documentation. However, this is the manufacturer's declaration, not a scientifically verified conclusion.

For a clinic owner, this means automated reminders may help, but there's no guarantee. the actual impact on patient attendance depends on many factors: punctuality culture in the region, the nature of the service (checkup vs. surgical procedure), whether the patient is new or returning, and how easy it is to reschedule. The only reliable way to verify the effectiveness of reminders in a specific clinic is to analyze the own calendar: compare the number of no-shows before and after implementing automated messages.

It's worth noting that even if reminders don't significantly affect attendance, they still serve another important function — they build a professional image of the clinic and show the patient that the clinic cares about contact. This is an element of customer experience that has value regardless of specific attendance metrics. About how much missed calls cost can be found in the article How much do missed calls cost in a company.

Who should create patient message templates

This may seem obvious, but is often overlooked in practice: patient message templates should be created or at least approved by the person responsible for data protection in the clinic or by a lawyer specializing in GDPR and medical law. Sending mass messages through an external marketing service provider who doesn't know the clinic's legal specifics poses significant risk.

The DPO or lawyer should analyze each template for compliance with Article 13 and 14 of the Patient Rights Act, Article 40 of the Act on the Professions of Physician and Dentist, and GDPR. They should also consider the specifics of the particular clinic: whether the clinic name reveals specialization, what patient information is stored in the CRM system, who has access to this data, and what the message sending process looks like.

It's also important to remember that templates must be flexible. A different message works for a checkup, another before a procedure, and another after completed treatment. Each of these message types requires separate analysis regarding what information can be included and what must be excluded.

Neutral patient message templates

Below are three message templates that meet legal requirements while being informative enough for the patient. They can be adapted to the needs of a specific clinic while maintaining the principle of content minimization.

Appointment reminder

"Good morning, we remind you of your appointment on [date] at [time] at our clinic. Please contact us at [phone] if you need to reschedule. See you soon."

This template contains no medical information. The patient knows when and where to be, and knows who to call if something doesn't work for them. Everything else — what kind of appointment, with whom, and why — is omitted.

Rescheduling at patient's request

"Good morning, we confirm the change of your appointment. The new date is [date] at [time]. Should you need further changes, please contact us by phone at [phone]. See you soon."

Like the previous template, this one is completely neutral. It doesn't say why the appointment was rescheduled or what caused it.

Thank you after the visit

"Thank you for visiting our clinic. Please feel free to contact us by phone at [phone] if you have any questions. Warm regards."

This is the shortest possible template and is perfect for automatic sending after a completed visit. It contains no details that could reveal the nature of the visit or treatment.

What these templates are based on: they were created based on analysis of the legal requirements described in Article 13 and 14 of the Patient Rights Act, Article 40 of the Act on the Professions of Physician and Dentist, and UODO guidelines on special category data. Each template was checked against the third-person test — whether an incidental reader could draw conclusions about the patient's health status.

15.5%
Among 259 Warsaw dental clinics whose websites we analysed (July 2026), 226 pages opened; 35 of them (15.5%) had no clickable phone number, and 102 (45.1%) had no contact form.

This shows that many clinics don't even offer patients the basic way to communicate — yet every patient should have the ability to easily contact the clinic to reschedule or get information.

Automating reminders without breaching confidentiality

The clinic management system can send neutral reminders automatically. How it works:

  1. appointment in calendar
  2. neutral template
  3. SMS with date and phone
  4. phone call for changes
  5. record in CRM
The diagram shows the same process step by step — from the first link to the last.

For clinics wanting to implement such a solution, Aura offers Automatic messages with neutral templates, Booking Systems with a calendar that manages appointments automatically, and CRM and automations that records all patient interactions in one place. More details on how this works can be found on the AI reception and telephony page, where the system answers calls and qualifies inquiries. More about patient communication automation can be found in the article Follow-up automation, and about data protection in Automation and GDPR.

Frequently asked questions

Can I send SMS messages with the treatment name?

No. The name of a medical procedure, treatment, or diagnosis is information covered by professional confidentiality. Including it in a text message that could be read by third parties violates Article 14 of the Patient Rights Act and Article 40 of the Act on the Professions of Physician and Dentist.

Is email safer than SMS?

Email requires login, so message content isn't visible on the lock screen. However, in message previews on computers or tablets, content can also be visible. Safer than email is directing the patient to a login portal where detailed appointment information is available only after authentication.

The legal basis for a neutral organizational reminder can be the provision of the health service itself, not only patient consent — which basis under GDPR fits your clinic's specific situation is for a lawyer or your DPO to assess. If a message were to contain any medical information, it's safer to assume upfront that separate, explicit, informed consent would be needed — which is exactly why it's simpler not to put such information in the message at all.

What if the patient themselves asks for appointment details in a message?

The patient can ask for details, but the clinic shouldn't provide them via SMS or email. The safer option is to inform the patient that detailed information is available in the patient portal or will be provided during a phone call.

Can I use the specialist's name in the message?

Only if the specialist's name doesn't reveal the health problem. General terms like "doctor" or "specialist" are safe. However, "orthodontist," "oral surgeon," "periodontist," or "endodontist" immediately indicate a specific problem that may be sensitive for the patient.

Does the automated reminder system need to be GDPR compliant?

Yes. Every tool for sending patient messages must process data in accordance with GDPR. This includes data minimization (no more than necessary), appropriate technical security, legal basis for processing, and the ability to fulfill patient rights (access, correction, deletion).

How often should I send reminders?

Sending reminders 24 hours before the appointment and a few hours before the appointment usually works best. More reminders may be perceived as spam and irritate the patient. It's worth testing different frequencies and checking what works best in a specific clinic.

Who writes this

See your business as a system.

Aura is a virtual business manager: management on facts, not impressions. For a company that wants a system running its processes instead of the owner’s memory.

The website, CRM, admin panel and automations are modules of the same system. We are not a website agency.

Look at my business

You will land on the home page. Give a company name — Aura looks at it in public data and shows what a client sees before calling you. No promises of a result.

See what we do

Related services

Read next Scroll for more

Let us look at your numbers

Tell us how enquiries are handled today — how many there are, who picks them up, where they get lost. Aura walks the process with you and shows what can be taken off a person, and what is better left alone.

Talk to Aura

The home page with Aura opens. Give a company name — she looks at it in public data and shows what a client sees. No promises of a result.

Prefer to write? marketing@auraglobal-merchants.com

Next step

Let us check whether Aura fits your place

We do not take everyone: first we look at your processes, sales and current systems and tell you honestly whether it makes sense for us to come in. A few questions, about five minutes.

Take the assessment →