WEO Media
Presents
WEO media recording the Marketing Matters podcast

CAN-SPAM Compliance for Dental Email Marketing: What Practices Need to Know


Posted on 9/1/2026 by WEO Media
CAN-SPAM compliance for dental email marketing with email campaign dashboard, unsubscribe requirements, physical address, and compliance checklistDental practices, DSOs, and their marketing teams achieve CAN-SPAM compliance for dental email marketing by classifying every patient email as commercial or transactional, applying the FTC’s eight requirements to every commercial message, running a separate HIPAA marketing analysis on top of that, and meeting the authentication rules mailbox providers now enforce. Nearly every dental email problem we see traces back to one skipped step: nobody ever decided, in writing, which category each template belongs to.

The rulebooks do not overlap the way most practices assume. CAN-SPAM governs the message as an email — headers, subject line, disclosure, postal address, opt-out. HIPAA governs the same message as a use of protected health information — whether written patient authorization is required before you send it at all. A dental recall email can satisfy HIPAA completely and still violate CAN-SPAM on every single send. It can also satisfy CAN-SPAM and still create a HIPAA problem. Clearing one tells you nothing about the other.

Already have a working unsubscribe link and a compliant footer? Skip ahead to the classification test. That is where most dental email programs actually break. If email is a newer channel for you, start with the fundamentals of dental email marketing for nurture, reactivation, and education first.

Below you will find the commercial-versus-transactional test the FTC actually applies, the eight federal requirements translated into real dental templates, the HIPAA exception that makes most own-service promotions legal without patient authorization, the suppression architecture that survives a practice management system and an email platform disagreeing with each other, and the mailbox provider rules that now reject noncompliant mail outright instead of filtering it.

Written for: dental practice owners, office managers, DSO marketing directors, and agency teams responsible for patient email, recall campaigns, reactivation sends, and newsletters.


TL;DR


If you only do seven things, do these:
1.  Classify every template in writing - commercial or transactional is the decision that drives every other requirement downstream
2.  Treat recall and reactivation emails as commercial - they solicit a new appointment rather than confirm one the patient already booked
3.  Stop assuming HIPAA blocks you - describing health-related services your own practice provides generally falls outside HIPAA’s definition of marketing
4.  Get a signed BAA with your email platform - your patient list is protected health information the moment you upload it
5.  Honor opt-outs in two days, not ten - mailbox providers now enforce a deadline faster than the federal one
6.  Run one suppression list across every system - practice management software, email platform, recall tool, and review platform must all read from the same source
7.  Stop relying on your agency to absorb liability - federal law holds both the promoted practice and the sending company responsible


Table of Contents





The four rulebooks governing dental email


Dental email marketing is regulated in four independent layers. Each one has a different enforcer, a different trigger, and a different remedy. A message can clear three layers and fail the fourth.
•  CAN-SPAM - the federal commercial email statute at 15 U.S.C. 7701 and following, with the FTC’s implementing rule at 16 CFR Part 316; it governs how you send, not whether you may send
•  HIPAA - the Privacy and Security Rules enforced by the HHS Office for Civil Rights; it governs whether using your patient list for this particular message requires written authorization, and how the message must be safeguarded
•  Mailbox provider requirements - Google, Yahoo, and Microsoft sender rules; not law, but functionally binding because failing them means outright rejection rather than a spam folder
•  State law - roughly twenty states have comprehensive consumer privacy laws in effect in 2026, plus consumer health data statutes in Washington, Nevada, and California and state dental board advertising rules

The practical sequencing: in our work with dental practices and multi-location dental groups, the programs that stay clean run the layers in order. Classify the message, apply CAN-SPAM, run the HIPAA check, then confirm the technical sending requirements. Programs that start with the email platform’s default template and work backward almost always have at least one template misclassified.


Who can enforce CAN-SPAM against a dental practice


CAN-SPAM gives enforcement authority to the FTC, to state attorneys general, and to internet access service providers. It does not create a private right of action, so an annoyed patient cannot sue you directly under the statute. That is thinner protection than it sounds, because the same patient can complain to a state attorney general, file with HHS over the underlying HIPAA use, or simply hit the spam button and take your sending domain down with them.


Why dental email and text message rules are not interchangeable


If you also send appointment or promotional text messages, TCPA compliance for dental text marketing runs on a consent-first model rather than CAN-SPAM’s opt-out model. A patient who is fair game for email may not be reachable by text, and one channel’s consent record does not stand in for the other’s.


> Back to Table of Contents


How to classify a dental email as commercial or transactional


CAN-SPAM turns on the primary purpose of the message, a test codified at 16 CFR 316.3. A message whose primary purpose is commercial advertisement or promotion must meet every requirement. A message whose primary purpose is transactional or relationship content must only avoid false or misleading routing information.


The five transactional and relationship categories


The FTC recognizes only content that facilitates, completes, or confirms a transaction the recipient already agreed to; provides warranty, recall, safety, or security information about something the recipient bought; notifies the recipient of a change in terms, features, or standing in an ongoing commercial relationship or provides periodic account balance information; provides employment or benefits information; or delivers goods or services as part of an already agreed transaction. The FTC explicitly warns that an ongoing relationship with the recipient does not by itself make a message transactional.


How mixed commercial and transactional emails are classified


When an email contains both kinds of content, it is commercial if a recipient reasonably interpreting the subject line would conclude it contains an advertisement, or if the transactional content does not appear mainly at the beginning of the message. This is the rule that catches dental practices: a confirmation email with a whitening promotion above the appointment details is a commercial email, no matter what the template is named in your software.


Dental email templates classified one by one


•  Appointment confirmation and reminder for a booked visit - transactional; it confirms a transaction the patient already agreed to
•  Post-operative instructions - transactional; it delivers services as part of an agreed transaction and carries safety information
•  Billing statement or balance notice - transactional; periodic account information
•  Hygiene recall notice - commercial; it solicits an appointment the patient has not yet booked
•  Lapsed patient reactivation campaign - commercial, without exception
•  Insurance benefits expiring campaign - commercial; the purpose is to prompt a new booking
•  New service or technology announcement - commercial
•  Practice newsletter with oral health tips - commercial once it promotes the practice or its services
•  Membership plan renewal notice - transactional if it notifies of terms or standing; commercial the moment it upsells a tier
•  Birthday message with an offer attached - commercial
•  Review request - treat as commercial; it is also governed by the FTC rule on consumer reviews at 16 CFR Part 465
•  Referral program invitation - commercial

Two of these carry the most volume. Hygiene recall systems and patient reactivation campaigns are the highest-frequency commercial sends in most dental practices, and they are also the two most often misfiled as transactional. If either is currently going out without a compliant footer, fix those templates before anything else on this page.

The unscheduled treatment edge case: a follow-up about treatment the patient already accepted and scheduled sits closer to transactional. A follow-up about treatment the patient declined, deferred, or never scheduled is a solicitation. In practice, most unscheduled treatment campaigns re-pitch the case, which makes them commercial. Document which version you are sending.

Write the classification down. Add a field to every template in your email platform recording the classification, the date it was made, and who made it. When a regulator, an attorney, or an incoming agency asks why a template has no unsubscribe link, a documented decision is a defensible position. An undocumented assumption is not. This belongs in your documented marketing SOPs alongside the rest of your recurring campaign workflows.


> Back to Table of Contents


The eight CAN-SPAM requirements in a dental context


The FTC’s current business guidance lays out eight requirements. Older summaries list seven; the guidance was expanded to address subscribers and members separately, which matters directly to practices running in-house membership plans.
1.  Accurate header information - the From, To, Reply-To, and routing information, including the originating domain and email address, must identify the practice that initiated the message
2.  Non-deceptive subject lines - the subject must accurately reflect the content; a promotional message carrying a subject line about the patient’s account or appointment is the exact pattern federal regulators have already penalized
3.  Identification as an advertisement - commercial messages must clearly and conspicuously disclose that they are advertisements, with substantial latitude in how you word it
4.  A valid physical postal address - a current street address, a post office box registered with the U.S. Postal Service, or a private mailbox registered with a commercial mail receiving agency
5.  A clear explanation of how to opt out - written so an ordinary person recognizes, reads, and understands it, delivered through a reply address or another straightforward internet-based mechanism
6.  Opt-out rights for subscribers and members - patients enrolled in a membership or savings plan keep the right to stop marketing email; enrollment is not consent to promotions
7.  Prompt handling of opt-out requests - the mechanism must work for at least 30 days after the send, requests must be honored within 10 business days, and you may not charge a fee, demand identifying information beyond an email address and opt-out preferences, or require more than a reply email or a single web page
8.  Oversight of anyone acting on your behalf - hiring an agency or software vendor does not transfer the legal obligation

On subject lines: accuracy and open rate are not in tension. The dental email subject lines that get opened work by setting a specific expectation the body then delivers on, which is exactly what the statute asks for. Vague curiosity-gap lines underperform and carry legal risk at the same time.

On the advertisement disclosure: the statute makes the ad-identification requirement inapplicable when the recipient gave prior affirmative consent to receive the message. The opt-out notice and postal address requirements carry no such carve-out. In practice, few dental practices can produce clean, dated, per-recipient consent records for an entire patient base, so we recommend keeping the disclosure on all commercial templates rather than betting a defense on consent documentation you may not be able to reconstruct.


Why membership plan enrollment is not marketing consent


Requirement six is the one dental practices miss most often. If you promote an in-house membership plan and then email enrolled members about unrelated services, those members retain full opt-out rights. Enrollment in a savings plan is a commercial relationship, not blanket consent to promotions.


Which postal address a multi-location dental group should use


Use the address of the location the message promotes, not a corporate headquarters the patient has never visited. This satisfies the federal requirement and simultaneously reinforces name, address, and phone consistency, which is a local search ranking signal. It is one of the rare cases where a compliance requirement and a local SEO best practice are the same instruction.


How CAN-SPAM penalties are calculated


Civil penalties under CAN-SPAM are assessed per individual noncompliant email, not per campaign, and the maximum is adjusted for inflation. Federal agencies were advised in April 2026 that no annual inflation adjustment would apply for calendar year 2026, so the maximum published in January 2025 remains in effect. The per-message structure is what makes exposure serious: a single misconfigured reactivation blast to a patient base multiplies the maximum by the list size. More than one party can be held liable for the same message.


> Back to Table of Contents


Where HIPAA changes the answer CAN-SPAM gave you


Start from the fact that trips up most dental marketing teams: your patient email list is protected health information. The fact that a named individual is a patient of your dental practice is itself PHI. Uploading that list to an email platform is a use and disclosure of PHI, and every HIPAA rule about uses, disclosures, safeguards, and business associates attaches from that moment. If you have not yet mapped where patient data touches your marketing stack, the broader HIPAA compliance requirements for dental marketing are the right starting point.


What HIPAA counts as marketing


Under 45 CFR 164.501, marketing means a communication about a product or service that encourages recipients to purchase or use it. Communications that meet that definition require prior written authorization under 45 CFR 164.508(a)(3). But the definition carves out three categories, each available only when the practice is not receiving financial remuneration from a third party whose product or service is being described.
•  Treatment of the individual - including case management, care coordination, and communications directing or recommending alternative treatments, therapies, providers, or settings of care
•  Health-related products or services the practice itself provides - describing a health-related service provided by the covered entity making the communication
•  Refill reminders - communications about a drug currently prescribed for the individual, where any remuneration received is reasonably related to the cost of making the communication

The second exception is the one that matters most in dentistry. HHS guidance gives the parallel example directly: a hospital using its patient list to announce a new specialty group or newly acquired equipment through a general mailing is not conducting marketing. Translated to a dental practice, emailing your existing patients that you now offer clear aligners, that you have added same-day crowns, or that hygiene recall is open describes health-related services you provide. That is not HIPAA marketing, and no patient authorization is required.


When a dental email becomes HIPAA marketing


Three things flip the analysis: an aligner, whitening, or device manufacturer paying you to promote their product to your patients; promoting products or services that are not health-related; or disclosing your patient list to another company so that company can market its own offerings. That last category has no exceptions at all. Selling or transferring patient lists requires authorization from every individual on the list, and where remuneration is involved the authorization must say so.


Business associate agreements for dental email platforms


Your email service provider, recall and reactivation software, review request platform, and marketing agency are business associates whenever they create, receive, maintain, or transmit PHI on your behalf. HHS is explicit that a covered entity may use a business associate to make these communications, but only under an agreement limiting the business associate to your communication activities. A signed BAA also does not transfer your liability as the covered entity; it allocates responsibility between you, and OCR still looks to you.


Email encryption under the current HIPAA Security Rule


Be precise about what the rule says today. Encryption of transmitted electronic PHI is an addressable implementation specification under 45 CFR 164.312(e)(2)(ii), not a flat requirement. OCR guidance permits sending unencrypted email to a patient who has been warned of the risks and elects to proceed anyway.

A proposed Security Rule overhaul published in the Federal Register on January 6, 2025 would eliminate the addressable category and make encryption mandatory. As of August 2026 that rule remains proposed: the comment period closed in March 2025, no final rule has been published, and the Unified Agenda now targets July 2027 for final action. Plan for mandatory encryption, and treat it as one piece of your practice cybersecurity posture rather than an email-only project. Do not tell patients or staff it is already law.


Patient communication rights that live outside your email platform


Under 45 CFR 164.522(b), patients may request confidential communications by alternative means or at alternative locations, and you must accommodate reasonable requests. A patient asking you not to email a shared household or work address is exercising a privacy right, not setting a marketing preference, and your unsubscribe workflow will not capture it. Apply the minimum necessary standard to content as well: subject lines and preview text render on lock screens, so specific clinical detail belongs in the portal, not the campaign. The same HIPAA privacy risks in dental digital marketing surface anywhere patient data touches an ad platform, an analytics tool, or a tracking pixel.


> Back to Table of Contents


Building an unsubscribe system that actually holds


Two clocks run on every opt-out, and only one of them is federal.
•  The statutory clock - CAN-SPAM allows 10 business days to stop sending commercial email to an address that opted out
•  The mailbox provider clock - Google and Yahoo require bulk senders to honor one-click unsubscribe requests within two days
•  The mechanism window - your opt-out mechanism must remain functional for at least 30 days after the message was sent

Build to two days. Designing to the ten-business-day statutory ceiling means you are noncompliant with the mailbox providers who decide whether your appointment reminders get delivered at all. The faster standard also happens to be the one patients expect.


What you cannot require in an unsubscribe flow


You may not demand a fee, personally identifying information beyond an email address and opt-out preferences, or any step beyond sending a reply email or visiting a single web page. That rules out portal logins, identity verification screens, multi-page flows, mandatory exit surveys, and the perennial dental favorite — telling patients to call the office to be removed. A preference center letting patients choose which message types to keep is permitted and often reduces total attrition, but it must always include an option to stop everything.


Making one opt-out propagate across every system


A typical practice runs marketing consent status across a practice management system, an email platform, recall or reactivation software, a review request tool, and sometimes a separate group-level marketing platform. One unsubscribe in one system stops one system. We routinely find practices honoring opt-outs perfectly in the email platform while the recall tool keeps sending, which is a violation on every subsequent message. The problem compounds as you add automated email sequences and segmented patient lists, because each one maintains its own audience rules.
1.  Name one system of record for marketing consent status and make every other platform read from it
2.  Write the propagation path for a single opt-out through every system, with a target elapsed time under two days
3.  Seed a monitored test address in each system, unsubscribe it, and verify silence across all channels
4.  Reconcile weekly by exporting suppression lists from every platform and diffing them
5.  Decide the scope question for multi-location groups - whether an opt-out at one location suppresses across the group depends on whether the locations are separate legal senders, and the decision needs to be documented either way

Tell patients what an opt-out does not stop. Unsubscribing from marketing does not end true transactional messages, and patients who believe otherwise stop opening appointment confirmations. Say so plainly on the confirmation page: appointment, billing, and treatment communications continue.

Two rules people forget. You may not sell or transfer an address once it has opted out, with the narrow exception of handing it to a vendor hired specifically to help you honor the opt-out. And only new affirmative consent from the recipient restarts commercial email — a lapsed patient returning for a cleaning has not re-subscribed by walking in the door.


> Back to Table of Contents


Deliverability rules that now function as compliance rules


Mailbox provider requirements are not statutes, but they carry a faster and more certain penalty than the FTC does. Google and Yahoo began enforcing shared sender requirements in February 2024. Microsoft followed for Outlook, Hotmail, and Live addresses on May 5, 2025, and chose outright rejection over junk folder placement, returning a permanent 550 5.7.515 authentication failure rather than deferring the message.
•  Authentication for all senders - valid SPF and DKIM records, valid forward and reverse DNS for sending IPs, and TLS in transit
•  DMARC for bulk senders - a published policy, at minimum a monitoring policy, with SPF or DKIM aligned to the From domain
•  One-click unsubscribe - marketing mail from bulk senders must carry List-Unsubscribe and List-Unsubscribe-Post headers per RFC 8058, with requests honored within two days
•  Spam complaint rate - enforcement begins at 0.3 percent of delivered mail; Google’s own guidance is to stay below 0.1 percent
•  Bulk sender threshold - roughly 5,000 or more messages per day to a given provider’s consumer addresses from one sending domain

Most single-location practices sit under the bulk threshold, and it still matters. Authentication is a filtering input for every sender regardless of volume, unauthenticated mail is treated worse across the board, and a DSO consolidating locations onto one sending domain aggregates volume fast. Once you cross the threshold on a single large campaign, plan to be treated as a bulk sender going forward.


Why a buried unsubscribe link destroys deliverability


A hard-to-find unsubscribe link does not keep patients on your list. It routes them to the spam button instead, and reported spam is the metric that actually destroys a sending domain. Your appointment reminders, treatment plan follow-ups, and billing notices ride that same domain. Burying the unsubscribe to protect list size is the single most reliable way to stop reaching the patients who still want to hear from you. The durable fix is sending a newsletter patients actually want to open, not making the exit harder to find.

One deliberate exception: do not place one-click unsubscribe headers on genuinely transactional clinical mail. A patient who accidentally suppresses appointment reminders creates a scheduling and continuity-of-care problem, not a marketing one. Reserve the RFC 8058 headers for marketing streams and keep the two streams on clearly separated templates.


> Back to Table of Contents


State laws layered on the federal baseline


CAN-SPAM preempts state statutes that expressly regulate commercial email, but only partially. Under 15 U.S.C. 7707(b)(1), the preemption carve-out preserves state law to the extent it prohibits falsity or deception in a commercial message. States cannot set a different opt-out clock or a different footer format. They can and do pursue deceptive subject lines and forged headers, and state laws that are not email-specific — general consumer protection, contract, and fraud statutes — are not preempted at all.


How state privacy law HIPAA exemptions differ


The bigger state exposure is privacy, not spam. About twenty states have comprehensive consumer privacy laws in effect in 2026, with new laws in Indiana, Kentucky, and Rhode Island taking effect on January 1. Published counts vary by a state or two because a few of these laws are narrower in scope than the rest. Every one of them exempts HIPAA in some form, but the form varies in a way that matters enormously to dental marketing.
•  Entity-level exemptions - some states exempt HIPAA covered entities and business associates outright, which covers the practice as a whole
•  Data-level exemptions - Colorado, Oregon, Minnesota, and New Jersey following a January 2026 amendment exempt only qualifying data rather than the entity, meaning non-PHI personal data stays in scope
•  The practical gap - website visitors, lead form submissions from people who never became patients, event lists, purchased lists, and advertising platform audiences are generally not PHI and generally not exempt

Why this reaches a dental practice specifically: a prospect who submits an implant or aligner consultation form and never becomes a patient sits outside your HIPAA analysis but squarely inside several of these statutes. That is precisely the population most dental lead nurture sequences target.


Consumer health data and geofencing laws in Washington, Nevada, and California


Three states now regulate health-related consumer data and location targeting well beyond what HIPAA covers, and all three reach dental practices.
•  Washington - the My Health My Data Act governs consumer health data falling outside HIPAA, applies to any entity conducting business in or targeting Washington consumers, requires opt-in consent, and is enforceable as a per se violation of the state Consumer Protection Act, which carries a private right of action; it also bans geofencing within 2,000 feet of an in-person health care facility to identify, track, or advertise to people seeking care
•  Nevada - a comparable statute using an entity-level HIPAA exemption, a 1,700-foot geofence limit, and enforcement reserved to the state attorney general
•  California - Assembly Bill 45 took effect January 1, 2026, amending the Confidentiality of Medical Information Act to prohibit geofencing an entity that provides in-person health care services for purposes including identifying the people receiving those services or sending them notifications or advertisements, with narrow carve-outs that let a facility geofence its own location

Why the geofencing rules matter more than they look: targeting a radius around a competing dental office is a routine paid-media tactic, and Washington’s definition of consumer health data reaches information identifying a consumer as seeking health care services. In these three states that tactic is now a legal question rather than a media-buying preference, and California’s version applies to health care facilities broadly rather than only to reproductive health locations.


State dental board advertising rules still apply


State dental practice acts and state dental board advertising rules govern the content of professional advertising regardless of the channel — claims of superiority, specialty designations, before-and-after imagery, and guarantee language, all of which also sit under FTC advertising rules for dentists. An email can be flawless under CAN-SPAM, HIPAA, and every privacy statute and still draw a board complaint over a single sentence.


> Back to Table of Contents


Who is liable when your agency or vendor sends the email


You cannot contract the obligation away. The FTC is explicit that hiring another company to handle email marketing does not transfer legal responsibility, and that both the company whose service is promoted and the company that actually sends the message may be held responsible. The prohibition on emailing an address after it opts out also extends to anyone acting on the sender’s behalf who knows or should reasonably know about the opt-out.

Co-marketing triggers a separate analysis. When an email promotes more than one business — a joint campaign with an aligner brand, a specialist referral partner, or a financing company — the marketers may designate one of them as the sender for compliance purposes, provided that party initiates the message promoting its own services, is identified in the From line, and meets the initiator obligations. If the designated sender fails, every marketer in the message can be held liable as a sender. For a dental practice, that means a partner’s sloppy template becomes your exposure.


Questions to ask a dental email vendor or agency


These sit alongside the broader list of questions to ask a dental marketing company before signing a contract:
•  Will you sign a BAA - and does it limit use of the list strictly to our communication activities
•  Where does suppression live - which system is the source of truth, and how long does an opt-out take to propagate everywhere
•  Who controls the sending domain and DNS - and is it our domain or a shared vendor domain
•  Is DMARC published and aligned - and can you show current SPF, DKIM, and alignment status
•  Are RFC 8058 headers applied to marketing streams only - or blanketed across transactional templates too
•  Can you produce a per-message audit trail - showing opt-out request time and the time sending actually stopped
•  What happens at termination - who owns the list, the suppression file, and the domain reputation you built


Sending domain strategy for DSOs and multi-location groups


Consolidating every location onto one domain simplifies authentication and concentrates reputation. It also means one location’s complaint rate degrades delivery for every other location, and one location’s noncompliant campaign implicates the group. Separating subdomains by region or brand isolates risk at the cost of managing more authentication records. Neither answer is universally right, and it mirrors the same tradeoff you weigh when choosing a consolidated, location-specific, or hybrid DSO marketing structure. The failure mode is not deciding.


> Back to Table of Contents


Common dental email compliance failures


These are the patterns we encounter most often when auditing an existing dental email program, ordered roughly by how frequently they appear.
•  Assuming a health care exemption exists - CAN-SPAM has no carve-out for health care providers and none for business-to-business email either; a message to referring offices is covered too
•  Recall and reactivation emails with no opt-out - the most common single defect, usually justified by a footer claiming the message concerns the patient’s account; federal regulators have already penalized exactly that framing in another industry
•  Purchased new-mover or new-resident lists - these recipients are not patients, so no HIPAA analysis shields the data, and lists assembled through address harvesting implicate aggravated violation provisions
•  Campaigns sent from a front desk mailbox - no authentication, no suppression, no audit trail, and no way to prove when an opt-out was honored
•  Review requests routed only to patients staff expect to be happy - the FTC consumer review rule does not ban incentives outright, but it does prohibit conditioning them on a particular sentiment, and selective solicitation raises separate deception questions
•  Benefits-expiring campaigns sent to opted-out patients - justified internally as being for the patient’s benefit; it is still a commercial message to a suppressed address
•  Clinical detail in subject lines and preview text - visible on lock screens and in shared household inboxes, and rarely necessary to drive the open
•  Templates with no documented classification - leaves you unable to explain, months later, why a given template has no unsubscribe link
•  Unsubscribe flows requiring a portal login - exceeds what the statute permits you to require
•  Agency transitions without a suppression handoff - the incoming vendor starts from a clean list and immediately emails everyone who previously opted out

A pattern worth naming: nearly every one of these failures originates in a reasonable-sounding internal decision rather than negligence. Somebody concluded that a recall notice was clinical, that benefits expiring was a service to the patient, or that the agency was handling compliance. The fix is almost never a new tool. It is writing the decision down, assigning an owner, and testing it once a quarter.

Two of these reach past CAN-SPAM entirely. Review solicitation is governed by the FTC consumer review rule and by Google’s review policy for dental practices, which restricts how and where you may ask. Benefits-expiring sends are usually the largest year-end dental benefits campaign a practice runs, which makes a suppression failure there both the most likely and the most costly.


> Back to Table of Contents


Your 60-minute dental email compliance audit


Run this with whoever controls your email platform and whoever controls your practice management system in the same room. It surfaces the majority of defects in a single sitting. Keep the commercial-versus-transactional test open in another tab while you work through step two.
1.  Inventory every automated email (10 minutes) - list every template that sends without a human pressing send, including recall software, review requests, membership plan notices, and anything your agency runs
2.  Classify each one (10 minutes) - mark commercial or transactional against the five transactional categories, and record the decision and the date in the template itself
3.  Audit the footers (10 minutes) - confirm every commercial template carries an advertisement disclosure, the correct location postal address, and an opt-out explanation an ordinary patient would notice
4.  Test the opt-out end to end (10 minutes) - unsubscribe a seeded address, time how long until every system stops, and confirm no login, fee, or extra page was required
5.  Check authentication (10 minutes) - verify SPF, DKIM, and a published DMARC policy on the sending domain, confirm alignment, and pull the current spam complaint rate from postmaster tooling
6.  Confirm the paperwork (10 minutes) - locate signed BAAs for every vendor touching the patient list, and confirm each agreement limits use to your own communication activities

Score it honestly: ☐ every automated email inventoried ☐ every template classified and dated ☐ every commercial footer complete ☐ opt-out propagates everywhere in under two days ☐ authentication passing and complaint rate under 0.1 percent ☐ BAA on file for every vendor. Six of six is a healthy program. Four or fewer means you are relying on the fact that nobody has complained yet.

What this audit does not cover: it is an operational review, not a legal opinion. Classification of borderline templates, multi-entity opt-out scope for DSOs, HIPAA authorization language, and state-specific obligations are decisions for your health care counsel. Bring them this inventory rather than an abstract question, and the conversation gets much shorter.


> Back to Table of Contents


Get your dental email program reviewed


WEO Media - Dental Marketing builds and manages patient email programs for general practices, specialty practices, and DSOs as part of a complete patient pipeline, including classification review, suppression architecture, authentication setup, and template remediation. If you want a second set of eyes on an existing program or a compliant one built from scratch, call 888-246-6906 or schedule a consultation to talk it through with our team.


> Back to Table of Contents


FAQs


Does CAN-SPAM apply to dental appointment reminders?


Generally no, provided the reminder is genuinely transactional. A reminder that confirms an appointment the patient already booked falls within the transactional and relationship category, so it must carry truthful routing information but is otherwise exempt from most CAN-SPAM provisions. That exemption disappears the moment promotional content moves to the top of the message or the subject line implies an offer. Adding a whitening special above the appointment details converts the message into a commercial email subject to every requirement.


Do dental practices need HIPAA authorization to send marketing emails?


Usually not, when the practice is describing its own health-related services. HIPAA excludes from the definition of marketing communications that describe a health-related product or service provided by the covered entity making the communication, so emailing your patients about clear aligners, implants, or hygiene recall you offer yourself generally requires no authorization. Written authorization is required when a third party pays you to promote its product, when the offering is not health related, or when you disclose your patient list to another company for that company’s own marketing.


Is a dental recall email transactional or commercial?


Commercial. A recall notice asks the patient to book an appointment that does not yet exist, which is a solicitation rather than confirmation of a transaction the patient already agreed to. The FTC treats the five transactional categories narrowly and warns that an ongoing relationship with the recipient does not by itself make a message transactional. Recall, reactivation, unscheduled treatment, and benefits-expiring campaigns should all carry a full compliant footer with an advertisement disclosure, a physical postal address, and a working opt-out.


How long does a dental practice have to honor an email opt-out?


CAN-SPAM allows 10 business days, but that is no longer the operative deadline for most practices. Google and Yahoo require bulk senders to honor one-click unsubscribe requests within two days, and failing mailbox provider requirements degrades or blocks delivery of all your mail, including appointment reminders. Build the suppression workflow to the two-day standard. Separately, the opt-out mechanism itself must remain functional for at least 30 days after the message was sent.


Does a dental practice need a BAA with its email marketing platform?


Yes, whenever the platform creates, receives, maintains, or transmits protected health information on the practice’s behalf. A patient email list is PHI because it identifies individuals as patients of a dental practice, so uploading it makes the vendor a business associate. HHS permits a covered entity to use a business associate for these communications only under an agreement limiting the associate to the covered entity’s own communication activities. No vendor is HIPAA certified in any official sense; what matters is a signed agreement plus documented Security Rule safeguards.


Can a dental practice email people who never gave permission?


CAN-SPAM is an opt-out regime rather than an opt-in one, so prior consent is not a federal prerequisite for commercial email. That does not make purchased lists safe. Recipients who are not your patients receive no HIPAA exemption under state privacy laws, consumer health data statutes in Washington, Nevada, and California can apply to people identified as seeking health services, and lists assembled by harvesting addresses implicate aggravated violation provisions. Cold email to consumers also produces the spam complaints that destroy the sending domain your patient communications depend on.


What physical address should a multi-location dental group use in marketing emails?


Use the address of the location the message actually promotes. CAN-SPAM accepts a current street address, a post office box registered with the U.S. Postal Service, or a private mailbox registered with a commercial mail receiving agency, but a corporate headquarters the patient has never visited creates confusion and undercuts local search consistency. Matching the footer address to the promoted location satisfies the federal requirement and reinforces name, address, and phone consistency across your local listings at the same time.


Can a patient sue a dental practice for a CAN-SPAM violation?


Not under CAN-SPAM itself, which creates no private right of action for recipients. Enforcement authority runs to the Federal Trade Commission, state attorneys general, and internet access service providers. That is narrower protection than it appears, because the same conduct can generate a HIPAA complaint to the HHS Office for Civil Rights, a claim under a state consumer protection statute, or a private action under a consumer health data law such as Washington’s, which is enforceable through that state’s Consumer Protection Act.


We Provide Real Results

WEO Media helps dentists across the country acquire new patients, reactivate past patients, and better communicate with existing patients. Our approach is unique in the dental industry. We work with you to understand the specific needs, goals, and budget of your practice and create a proposal that is specific to your unique situation.


+400%

Increase in website traffic.

+500%

Increase in phone calls.

$125

Patient acquisition cost.

20-30

New patients per month from SEO & PPC.





Schedule a consultation that works for you


Are you ready to grow your practice? Talk to one of our Senior Marketing Consultants to see how your online presence stacks up. No strings attached. Just a free consultation from experts in the industry.


Copyright © 2023-2026 WEO Media and WEO Media - Dental Marketing (Touchpoint Communications LLC). All rights reserved.  Sitemap
WEO Media, 125 SW 171st Ave, Beaverton, OR 97006 / 888-246-6906 / weomedia.com / 9/1/2026