Executive Summary
Law firms use SMS for intake follow-ups, appointment reminders, document-request nudges, and billing notices because clients actually read texts. That convenience collides with three compliance layers: TCPA/FCC consent rules for marketing and certain automated texts, carrier A2P 10DLC Brand + Campaign registration for US local-number traffic, and professional-conduct / confidentiality duties that treat ordinary SMS as a high-risk channel for privileged facts. Ordinary carrier SMS is not a substitute for a secure client portal. Firms that succeed treat SMS as a narrow, consented, matter-aware notification channel—registered through their CSP—while keeping advice, strategy, and sensitive documents off the open text path.
Short answer: Yes, law firms can text clients—but use firm-controlled numbers, documented purpose-specific consent, STOP/HELP handling, 10DLC registration for A2P local traffic, and a written policy that keeps privileged content out of SMS.
Who This Is For / Who It Is Not For
For: US law firms and legal-ops teams adding or fixing client SMS; intake vendors and MSPs supporting firms; compliance counsel scoping TCPA + ethics risk.
Not for: Solo practitioners seeking end-to-end encrypted “legal SMS” guarantees from carriers; anyone wanting invented fine amounts or guaranteed Campaign approval; non-US messaging programs outside 10DLC.
Definitions
| Term | Meaning |
|---|---|
| SMS for law firms | Business texting from firm systems to clients/prospects (A2P), not personal attorney phones |
| A2P 10DLC | Application-to-person messaging over US 10-digit long codes requiring Brand + Campaign registration |
| Prior express written consent | Higher TCPA consent standard for many telemarketing/advertising texts (see 47 CFR § 64.1200) |
| Matter-linked messaging | Texts tied to a matter ID in the practice-management system for auditability |
| Secure portal / E2EE chat | Encrypted client messaging product—not the same as carrier SMS |
| TCR | The Campaign Registry; CSPs register Brands/Campaigns there |
Why Firms Text—and Where It Goes Wrong
High-performing use cases:
- Conflict-check / intake “reply YES to continue” workflows (carefully designed)
- Hearing, deposition, and appointment reminders
- “Documents uploaded—please review in portal” links
- Payment reminders and trust-accounting notices (content-sensitive)
- Staffing / court-run logistics with existing clients
Failure patterns:
- Attorneys texting from personal mobiles with no retention
- Marketing blasts to purchased lists or old consult lists without PEWC
- Case strategy discussed over SMS
- Unregistered 10DLC traffic blocked by carriers
- No STOP handling or shared firm opt-out list
TCPA and FCC Rules (Not Legal Advice)
Under 47 CFR § 64.1200, consent requirements intensify when messages are advertisements or telemarketing, and when autodialed/prerecorded rules apply. Text messages are treated as calls in key FCC/TCPA contexts. Marketing “free consult” blasts typically need prior express written consent with clear disclosures. Appointment reminders to existing clients may rest on different consent theories—but firms should not invent exemptions. Revocation must be honored when expressed by any reasonable means; STOP replies are a per se reasonable method under recent FCC rule text.
Practice implication: Separate Marketing Campaigns from Customer Care / Account Notification Campaigns in 10DLC, and align consent records to each purpose.
10DLC / TCR Registration for Legal Practices
Per Twilio’s A2P 10DLC docs, US A2P SMS/MMS over 10DLC requires registration. Firms register through a CSP (or practice platform that embeds a CSP)—not directly on TCR as Brands (TCR resources).
Typical Brand fields: legal entity name matching EIN, website, authorized contacts, industry (often LEGAL). Campaign packages need accurate descriptions, sample messages naming the firm, and a verifiable opt-in narrative (message_flow).
| Firm message type | Common Campaign framing | Consent posture |
|---|---|---|
| Hearing / appointment reminder | Customer Care / Account Notification | Client relationship + clear SMS disclosure at engagement |
| Intake status / “we received your form” | Customer Care | Documented opt-in on intake form |
| Newsletter / webinar / PI solicitation | Marketing | Prior express written consent |
| Mixed reminders + promotions on one number | Mixed / Low-Volume Mixed | Higher friction; prefer split Campaigns |
| OTP for portal login | 2FA | Transactional consent at enrollment |
Ethics, Privilege, and “Secure SMS” Reality
Bar ethics opinions increasingly expect competence with technology risks. Ordinary SMS lacks end-to-end encryption, can be backed up to personal clouds, and may be readable on shared devices. Treat SMS as notification, not advice delivery.
Controls:
- Written SMS policy approved by managing partner / GC
- Firm-owned numbers only; ban matter texting on personal phones
- Matter ID in templates; retain transcripts in DMS/PMS
- Deep links to portal for documents—not attachments with PHI/PII dumps
- Train staff that “quick text advice” creates malpractice and privilege risk
- Prefer purpose-built secure messaging or portals for privileged dialogue
Decision Framework
- Inventory every text workflow (intake, reminders, marketing, billing).
- Classify each as marketing vs informational.
- Map consent artifact per workflow (form checkbox, engagement letter, keyword).
- Choose channel: 10DLC local, toll-free verification, or short code.
- Draft Campaign samples that match production templates.
- Register Brand → Campaign via CSP; attach numbers only after approval.
- Implement STOP/HELP, quiet hours, and suppression sync to CRM.
- Quarterly audit: random sample of consent vs send logs.
Requirements Matrix
| Control | Marketing SMS | Client care SMS | Privileged dialogue |
|---|---|---|---|
| PEWC / written marketing consent | Required in most cases | Often not marketing—still document permission | Prefer portal |
| 10DLC Brand + Campaign | Yes if 10DLC | Yes if 10DLC | Prefer non-SMS |
| Firm-owned number | Yes | Yes | Yes |
| STOP/HELP | Yes | Yes | Yes |
| Matter linking / retention | Recommended | Required operationally | Required |
| Encryption E2EE | Not provided by SMS | Not provided by SMS | Use secure product |
Risk / Failure Modes
| Risk | Mitigation |
|---|---|
| TCPA class exposure from blast texts | PEWC, vendor DNC scrub, purpose separation |
| Carrier blocking unregistered traffic | Complete 10DLC registration before scale |
| Privilege waiver via SMS advice | Policy + portal escalation |
| Lost texts on personal phones | Centralized messaging platform |
| Staff ignoring STOP | Automated opt-out + shared suppression |
| Website/privacy gaps blocking Campaign | Public policies with SMS language |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Approve SMS policy | Managing partner | Policy PDF |
| Select messaging platform / CSP | IT / ops | Vendor MSA |
| Collect EIN + website | Finance | Brand packet |
| Draft consent language for intake + engagement | Ethics counsel | Form copy |
| Split Marketing vs Care Campaigns | Legal ops | Campaign worksheets |
| Register Brand/Campaign | Ops | TCR IDs via CSP |
| Configure STOP/HELP webhooks | Engineering | Test log |
| Train intake staff | Office manager | Attendance record |
| Quarterly consent audit | Compliance | Audit memo |
Soft CTA: Firms preparing Brand packets and public SMS disclosures can use MyTCRPlus tools and microsite options to organize registration evidence—without any approval guarantee.
Sample Message Patterns (Illustrative Only)
Use samples that name the firm, state purpose, and include opt-out language your CSP requires:
Appointment reminder (care):
“Smith & Lee LLP: Reminder—your consultation is Tue 3/12 at 2pm. Reply STOP to opt out of texts. For case details, use the client portal.”
Document nudge (care):
“Smith & Lee LLP: New documents await your review in the portal: [link]. Reply STOP to opt out.”
Marketing (requires PEWC):
“Smith & Lee LLP: Join our free estate-planning webinar Thu 7pm. Reply STOP to opt out. Msg & data rates may apply.”
Never put settlement strategy, medical details, Social Security numbers, or full account numbers in SMS.
Operating Model for Multi-Office Firms
Multi-office and multi-brand firms should decide whether Brand registration is at the parent LLC, each office PLLC, or a DBA used publicly. Match the EIN and website to the Brand that appears in message samples. Franchise-like personal-injury marketing shops often need clearer reseller/ISV declarations when a marketing vendor sends on the firm’s behalf.
Create a RACI:
| Activity | Intake | Marketing | IT | Ethics counsel | Managing partner |
|---|---|---|---|---|---|
| Consent language | C | R | I | A | I |
| Campaign registration | C | C | R | C | A |
| STOP suppression | I | C | R | I | I |
| Privilege training | C | I | I | R | A |
| Vendor MSA review | I | C | C | R | A |
Vendor Diligence Questions
Before buying a “legal SMS” product, ask:
- Which CSP submits our Brand/Campaign to TCR?
- Who is the Brand of record—firm or vendor?
- How are STOP events synced to our CRM within minutes?
- Where are message logs stored, and for how long?
- Can we export matter-linked transcripts for discovery holds?
- Does the product support separate Marketing vs Care messaging services?
- Is there a written subprocessors list and BAAs if HIPAA-adjacent practices apply?
- What happens to numbers and Campaigns if we churn?
Quiet Hours, Frequency Caps, and Client Experience
Even when TCPA residential calling-hour rules are framed around telephone solicitations, client experience and state mini-TCPA statutes may constrain night-time texts. Set platform quiet hours in the client’s time zone, cap reminder frequency, and suppress after bounce/ steers to call. Over-texting drives STOP rates that can harm Campaign reputation with carriers.
Recordkeeping Package for Audits and Litigation Holds
Retain: opt-in timestamp, source URL or PDF of form, IP/user agent if web, exact disclosure text shown, Campaign ID, message template version, delivery reports, and STOP timestamp. Map retention to your file-retention policy and litigation-hold playbook. SMS logs are discoverable—write every template as if a judge will read it.
Bridging to Secure Messaging
A practical architecture:
- SMS: “You have a secure message” with portal link
- Portal: privileged Q&A, document exchange, e-sign
- SMS: only status pings and OTP
This preserves SMS open rates without putting the privilege payload on the carrier path. Explain the model in engagement letters so clients know what will (and will not) arrive by text.
Step-by-Step Launch Plan (90 Days)
Days 1–15 — Discover. Inventory numbers, CRMs, intake forms, and any shadow IT texting. Interview intake and billing about current client expectations. Flag any purchased-list marketing.
Days 16–30 — Design. Finalize consent copy, engagement-letter SMS clause, Campaign worksheets, and portal deep-link templates. Choose Brand entity and website URL that will survive TCR/CSP review.
Days 31–50 — Register. Submit Brand, complete any OTP/vetting steps, then submit Care and Marketing Campaigns separately. Do not blast while pending.
Days 51–70 — Integrate. Wire STOP/HELP webhooks, quiet hours, matter ID tokens, and retention export. Pilot with internal staff numbers across AT&T, T-Mobile, and Verizon.
Days 71–90 — Operate. Enable production for one practice group, monitor opt-out rate and carrier error codes, then expand. Schedule the first quarterly consent audit.
Comparison: SMS vs Portal vs Phone
| Dimension | Carrier SMS | Secure client portal | Voice call |
|---|---|---|---|
| Open rate | Typically high | Medium | Medium |
| Privilege suitability | Poor | Strong (if configured) | Strong with documentation |
| 10DLC needed | Yes for local A2P | N/A | N/A |
| TCPA marketing risk | High if promotional | Lower for in-portal notices | High if solicitation |
| Audit trail | Depends on platform | Usually strong | Needs notes/recording policy |
| Client preference | Often preferred for reminders | Preferred for documents | Preferred for advice |
Use SMS as the alert layer, portals as the content layer, and calls as the counsel layer.
Related Reading on MyTCRPlus
Pair this guide with registration and consent deep-dives: the complete TCR registration process, single vs double opt-in for SMS, and the consent evidence trail video. Those resources help legal ops produce Brand packets and Campaign samples that match what CSPs and reviewers expect—while counsel remains responsible for TCPA and ethics judgments.
FAQ
Is SMS confidential enough for attorney-client advice?
Generally no for ordinary SMS. Use a secure portal or encrypted legal messaging product for privileged content.
Do law firms need 10DLC?
If you send US A2P traffic over local 10-digit numbers from software, yes—register Brand + Campaign through your CSP.
Can we text leads from a purchased list?
High risk. Marketing texts typically need prior express written consent from the recipient for your firm’s messages.
Should solo attorneys use their personal cell?
Avoid for client matters. Use a firm-controlled number with retention and STOP handling.
What use case should we pick in TCR?
Match reality: reminders ≈ customer care/account notification; solicitations ≈ marketing. Mislabeling causes rejection.
Does Campaign approval equal TCPA compliance?
No. Registration is carrier identity/use-case transparency; TCPA is separate federal consent law.
How do we handle STOP?
Auto-acknowledge, suppress immediately across campaigns as appropriate, and keep audit logs.
Are appointment reminders exempt from consent rules?
Do not assume blanket exemption. Document client permission and follow FCC/TCPA guidance with counsel.
What about state bar ethics opinions?
Follow your jurisdiction’s technology competence and confidentiality rules; they may be stricter than carrier rules.
Can MyTCRPlus guarantee approval?
No. Tools help preparation only.
Key Takeaways
- SMS works for notifications—not privileged advice.
- Layer TCPA consent, 10DLC registration, and ethics controls.
- Split marketing vs care Campaigns and consent records.
- Use firm-owned numbers with retention and STOP/HELP.
- Ordinary SMS is not end-to-end encrypted.
- Register through your CSP before scaling US local A2P traffic.
- Audit consent evidence quarterly.
- When in doubt, move sensitive dialogue to a portal.
Disclaimer
Informational only—not legal advice. TCPA, ethics, HIPAA (if applicable), and carrier rules change. Consult qualified counsel and your CSP before launching firm SMS programs.