You send a patient an SMS reminder about their appointment — but their phone is sitting on a desk at work, visible to a coworker, partner, or child. From that short message, someone can learn far more than the clinic intended to convey. The name of the procedure, the doctor's specialization, the diagnosis — all of this is covered by professional confidentiality, and at the same time constitutes sensitive data that could harm the patient if it falls into the wrong hands. As a clinic owner, you need to know how to communicate with patients without violating regulations or exposing them to consequences.
This article covers the rules governing what you can include in patient messages, concrete examples of what is allowed and what must be avoided, and neutral message templates that meet legal requirements.

Article 14 of the Patient Rights Act clearly states that persons practicing medical professions are obligated to keep patient information confidential, particularly information relating to their health condition — according to the Patient Rights Act. The same applies to physicians under the Act on the Professions of Physician and Dentist.

Who can see messages sent to a patient
SMS or email lands on a mobile device that is rarely used by only one person. For medical clinic patients, this is particularly relevant — the phone may be on a desk at work, within view of household members, or passing between hands. From a brief message like "Reminder: appointment on Monday at 9:00 with the dentist," a coworker immediately knows three things: the patient is getting dental treatment, they visit regularly, and they have a specific problem requiring a specialist.
The same issue applies to emails and messenger messages. WhatsApp, SMS, or Messenger may be open on a tablet in the living room, a laptop at work, or a smartphone on a desk. Anyone with access to that screen automatically becomes a recipient of information about the patient's health. In practice, this means the clinic must assume that every message could be read by a third party — and design communication with this assumption in mind.
Worse still, information about a medical appointment itself says something about health status. The fact that someone scheduled an appointment with an oral surgeon, orthodontist, or psychiatrist is enough to draw conclusions. This is why regulations require the clinic to exercise particular caution in every element of patient communication, including automated messages.
Legal basis for confidentiality in patient communication
Polish law clearly defines what information is protected by confidentiality and who is responsible for maintaining it. Article 13 of the Patient Rights Act states that patients have the right to have information relating to them kept confidential. Article 14(1) of the same act specifies that persons practicing medical professions are obligated to keep patient information confidential, particularly information relating to their health condition. Exceptions to this rule are listed in paragraph 2 and include patient consent, among other situations.
Parallel to this, Article 40 of the Act on the Professions of Physician and Dentist imposes an obligation on physicians to keep patient information confidential obtained in connection with practicing their profession. Exceptions, similarly to the Patient Rights Act, include patient consent given after being informed about the consequences, and situations where maintaining confidentiality could endanger the patient or others. The key point is that this obligation applies to any information that could link a patient with their health condition — therefore the doctor's specialization and type of procedure. The appointment date alone at a general clinic doesn't yet reveal that, as the table below shows.
The rule is simple: if the content of a message allows a third party to draw conclusions about the patient's health status, then that message violates confidentiality. It doesn't matter whether the clinic intentionally meant to disclose a diagnosis — what counts is the effect the message could have on an incidental reader.
Medical data as special category data
The Polish Data Protection Office (UODO) in its statement to the Minister of Health clearly indicated that medical data contains personal data of a special category within the meaning of Article 9 of GDPR — according to the UODO position. Moreover, this data often reveals many other pieces of information about an individual, beyond just their health status.
From the clinic's perspective, this means double risk. First, violating professional confidentiality is subject to professional liability and can result in consequences from the medical association. Second, processing sensitive data without appropriate legal basis constitutes a GDPR violation, which carries high financial penalties. This is why every message sent to patients must be designed with both requirements in mind.
The exception is when the patient themselves explicitly consents to receiving messages containing detailed appointment information. In practice, however, this is rarely used because it requires conscious, voluntary, and specific consent, and the patient must be informed about all consequences of such a choice. In most cases, the safer path is neutral communication that requires no decision from the patient.
What you can and cannot write in patient messages
The rule is: only organizational information that doesn't allow conclusions about health status can be included in patient messages. In practice, this means a narrower range of permissible content than one might expect. The table below presents a breakdown of elements that can and cannot be included in SMS and email messages to patients.
| Message element | Can you write it | Notes |
|---|---|---|
| Date and time of appointment | Yes | Organizational information, doesn't reveal the reason for the visit |
| Clinic address | Yes | Neutral contact information |
| Phone number for rescheduling | Yes | Works on a "please contact us" basis without stating the reason |
| Clinic name | Yes | Unless the name indicates a medical specialization |
| Reason for visit, diagnosis | No | Clearly indicates health condition |
| Name of procedure, treatment | No | Medical information covered by confidentiality |
| Doctor's specialization | Only if it doesn't reveal the problem | "Doctor" is safe, "orthodontist" or "oral surgeon" are not |
| Reminder to bring documents | Yes | General organizational information |
| Link to patient portal | Yes | Safer alternative to details in the message |
The key is the third-person test: if someone who isn't the patient reads the message, can they draw conclusions about that person's health status? If yes — the message is too detailed and should be simplified.
This is why the safest approach is to limit content to the absolute organizational minimum from the table above — without adding anything "just in case."
Different communication channels and their specifics
The choice of communication channel matters for information security. SMS messages appear on the phone's lock screen and are visible even without unlocking the device. A coworker, partner, or child passing by the patient's phone will automatically see: "Dental Clinic — appointment tomorrow at 10:00." The very name of a dental clinic says it all.
Emails are somewhat safer because most email accounts require login. However, message content can still be visible in previews on tablets or computers, in notifications on other devices synced with the same account, and in search history if the patient uses autocomplete.
Messengers like WhatsApp or Messenger offer end-to-end encryption, meaning message content is protected during transmission. However, on the recipient's device, the message is stored unencrypted and can be visible on screen at any time. Additionally, many people use WhatsApp on computers or tablets where the screen is larger and content more conspicuous. If the clinic team already works in a messenger app, Telegram / WhatsApp Integrations can route team notifications there instead of adding yet another channel nobody checks.
The safest solution is to limit message content to the absolute organizational minimum, and to convey detailed appointment information, health status, or recommendations through a secure patient portal that requires login. The patient decides for themselves when and where they want to view private information. More about customer communication automation can be found in the article Query handling automation, and about confirmation effectiveness in the restaurant industry in No-show in restaurants.
Do automated reminders actually reduce no-shows?
Microsoft, in its documentation for Bookings — its appointment management tool — states that "email and SMS text notifications reduce no-shows and enhance customer satisfaction" — according to the Microsoft Bookings documentation. However, this is the manufacturer's declaration, not a scientifically verified conclusion.
For a clinic owner, this means automated reminders may help, but there's no guarantee. the actual impact on patient attendance depends on many factors: punctuality culture in the region, the nature of the service (checkup vs. surgical procedure), whether the patient is new or returning, and how easy it is to reschedule. The only reliable way to verify the effectiveness of reminders in a specific clinic is to analyze the own calendar: compare the number of no-shows before and after implementing automated messages.
It's worth noting that even if reminders don't significantly affect attendance, they still serve another important function — they build a professional image of the clinic and show the patient that the clinic cares about contact. This is an element of customer experience that has value regardless of specific attendance metrics. About how much missed calls cost can be found in the article How much do missed calls cost in a company.
Who should create patient message templates
This may seem obvious, but is often overlooked in practice: patient message templates should be created or at least approved by the person responsible for data protection in the clinic or by a lawyer specializing in GDPR and medical law. Sending mass messages through an external marketing service provider who doesn't know the clinic's legal specifics poses significant risk.
The DPO or lawyer should analyze each template for compliance with Article 13 and 14 of the Patient Rights Act, Article 40 of the Act on the Professions of Physician and Dentist, and GDPR. They should also consider the specifics of the particular clinic: whether the clinic name reveals specialization, what patient information is stored in the CRM system, who has access to this data, and what the message sending process looks like.
It's also important to remember that templates must be flexible. A different message works for a checkup, another before a procedure, and another after completed treatment. Each of these message types requires separate analysis regarding what information can be included and what must be excluded.
Neutral patient message templates
Below are three message templates that meet legal requirements while being informative enough for the patient. They can be adapted to the needs of a specific clinic while maintaining the principle of content minimization.
Appointment reminder
"Good morning, we remind you of your appointment on [date] at [time] at our clinic. Please contact us at [phone] if you need to reschedule. See you soon."
This template contains no medical information. The patient knows when and where to be, and knows who to call if something doesn't work for them. Everything else — what kind of appointment, with whom, and why — is omitted.
Rescheduling at patient's request
"Good morning, we confirm the change of your appointment. The new date is [date] at [time]. Should you need further changes, please contact us by phone at [phone]. See you soon."
Like the previous template, this one is completely neutral. It doesn't say why the appointment was rescheduled or what caused it.
Thank you after the visit
"Thank you for visiting our clinic. Please feel free to contact us by phone at [phone] if you have any questions. Warm regards."
This is the shortest possible template and is perfect for automatic sending after a completed visit. It contains no details that could reveal the nature of the visit or treatment.
What these templates are based on: they were created based on analysis of the legal requirements described in Article 13 and 14 of the Patient Rights Act, Article 40 of the Act on the Professions of Physician and Dentist, and UODO guidelines on special category data. Each template was checked against the third-person test — whether an incidental reader could draw conclusions about the patient's health status.
This shows that many clinics don't even offer patients the basic way to communicate — yet every patient should have the ability to easily contact the clinic to reschedule or get information.
Automating reminders without breaching confidentiality
The clinic management system can send neutral reminders automatically. How it works:
- 01appointment in calendar
- →02neutral template
- →03SMS with date and phone
- →04phone call for changes
- →05record in CRM
For clinics wanting to implement such a solution, Aura offers Automatic messages with neutral templates, Booking Systems with a calendar that manages appointments automatically, and CRM and automations that records all patient interactions in one place. More details on how this works can be found on the AI reception and telephony page, where the system answers calls and qualifies inquiries. More about patient communication automation can be found in the article Follow-up automation, and about data protection in Automation and GDPR.
Frequently asked questions
Can I send SMS messages with the treatment name?
No. The name of a medical procedure, treatment, or diagnosis is information covered by professional confidentiality. Including it in a text message that could be read by third parties violates Article 14 of the Patient Rights Act and Article 40 of the Act on the Professions of Physician and Dentist.
Is email safer than SMS?
Email requires login, so message content isn't visible on the lock screen. However, in message previews on computers or tablets, content can also be visible. Safer than email is directing the patient to a login portal where detailed appointment information is available only after authentication.
Do I need patient consent for sending SMS messages?
The legal basis for a neutral organizational reminder can be the provision of the health service itself, not only patient consent — which basis under GDPR fits your clinic's specific situation is for a lawyer or your DPO to assess. If a message were to contain any medical information, it's safer to assume upfront that separate, explicit, informed consent would be needed — which is exactly why it's simpler not to put such information in the message at all.
What if the patient themselves asks for appointment details in a message?
The patient can ask for details, but the clinic shouldn't provide them via SMS or email. The safer option is to inform the patient that detailed information is available in the patient portal or will be provided during a phone call.
Can I use the specialist's name in the message?
Only if the specialist's name doesn't reveal the health problem. General terms like "doctor" or "specialist" are safe. However, "orthodontist," "oral surgeon," "periodontist," or "endodontist" immediately indicate a specific problem that may be sensitive for the patient.
Does the automated reminder system need to be GDPR compliant?
Yes. Every tool for sending patient messages must process data in accordance with GDPR. This includes data minimization (no more than necessary), appropriate technical security, legal basis for processing, and the ability to fulfill patient rights (access, correction, deletion).
How often should I send reminders?
Sending reminders 24 hours before the appointment and a few hours before the appointment usually works best. More reminders may be perceived as spam and irritate the patient. It's worth testing different frequencies and checking what works best in a specific clinic.