The carrier registration system behind every business text message, and what it means when your practice texts patients.
Get started for freeSchedule a demo →10DLC (10-Digit Long Code) is the carrier registration system that governs business texting over standard local phone numbers. When a practice texts patients from a business number, carriers require that number to be registered through the 10DLC program so they can verify who is sending and what the messages are about. Registration is a deliverability requirement, not a formality: unregistered business messages face carrier filtering, throttling, or outright blocking. 10DLC and HIPAA are separate requirements: one governs message delivery, the other is a federal law protecting patient information. Both apply when healthcare organizations text patients.
10DLC stands for 10-Digit Long Code. It is the registration system that U.S. carriers use to identify and authorize business text messages sent from standard local phone numbers. The industry calls these Application-to-Person (A2P) messages — texts sent by a business or its software, as opposed to personal texts between individuals. Before 10DLC, any business could send texts from a regular number with no registration at all. Carriers had no reliable way to tell a legitimate appointment reminder from spam.
The major carriers introduced 10DLC to fix that. Registration creates accountability: each sending business is identified, each messaging use case is declared, and carriers can set sending limits based on the sender's track record. The Campaign Registry (TCR) is the central body that manages the registration ecosystem.
For a healthcare practice, this is straightforward. If your organization sends text messages to patients from a business phone number, those messages are A2P traffic and the number needs to be registered under 10DLC.
Carriers filter, throttle, and block unregistered A2P traffic. Enforcement has tightened steadily since the major carriers adopted 10DLC, and messages that once went through without issue may now fail silently or arrive hours late.
For a healthcare practice, this is a patient communication problem, not a technical one. If appointment reminders stop arriving, patients miss visits. If follow-up instructions do not deliver, care gaps open. The cause is often invisible: no error message, no bounce notification, just messages that never reach the patient's phone.
Registration does not guarantee delivery of every message, but it removes the most common reason messages fail. An unregistered number is the first thing carriers look at, and it is the easiest problem to fix.
Registration happens in two steps. First, the business itself is registered as a brand. This records the organization's legal name, EIN, and contact information in The Campaign Registry. Second, each messaging use case is registered as a campaign. A campaign describes what the messages are about, such as appointment reminders, patient follow-ups, or office closures.
Registration goes through a Campaign Service Provider (CSP) — typically the messaging platform the business uses — rather than directly with TCR. The CSP submits brand and campaign information to TCR on the business's behalf and manages the registration lifecycle.
The two-step structure lets carriers verify the sender separately from the use case. Your practice only registers as a brand once, but you might register separate campaigns for appointment reminders, follow-up instructions, and billing notifications if each serves a different purpose.
This is the most common point of confusion. 10DLC and HIPAA are unrelated requirements that both apply when a healthcare practice texts patients. Mixing them up leads to gaps on both sides.
10DLC is a carrier and industry requirement. It governs whether your messages reach the recipient's phone. It does not address encryption, access controls, or what patient information you can include in a message. It exists to reduce spam and create sender accountability, administered by The Campaign Registry (TCR).
HIPAA is a federal law. It governs how you protect patient information, including information in text messages. It requires a signed Business Associate Agreement with any vendor that handles PHI, encryption, access controls, and audit logs. It says nothing about carrier deliverability.
Registering for 10DLC does not make your texting HIPAA compliant. Signing a BAA does not register your number with the carriers. A practice that texts patients needs both: 10DLC so the messages arrive, and HIPAA safeguards so the messages are protected.
Under 10DLC, every campaign must honor standard opt-out keywords. When a recipient replies STOP, the sender must stop messaging that person. Carriers enforce this, and a campaign that fails to honor opt-outs risks suspension. The FCC's guide to unwanted calls and texts explains the consumer protections that underpin this requirement.
For healthcare teams, opt-out handling overlaps with patient consent under HIPAA but is not the same thing. A patient who opts out of text messages is exercising a carrier-level right. That does not revoke their consent to receive care information through other channels, and it does not change their treatment relationship. Your team should record opt-outs, honor them, and maintain alternative communication paths for patients who have opted out of texting.
BloomText acts as the Campaign Service Provider, so your team does not navigate carrier registration on its own. Patient messages go through registered A2P channels with a signed BAA on every plan, encryption in transit and at rest, access controls, and audit logs. The carrier registration that 10DLC requires and the HIPAA safeguards that patient communication requires are both in place.
Patients receive messages over normal SMS and reply from any phone without downloading an app. Staff manage conversations in a shared inbox with role-based access. The SMS messaging guide walks through the setup.
Last verified August 25, 2026.