Legal Theories Win Cases. Operations Win the Ones That Never Get Filed.
By David A. Prado, The Prado Law Firm, LLC

I spent four years as plaintiffs' counsel building TCPA, FCRA, and FDCPA cases. Today I sit on the other side twice over: as a General Counsel writing compliance playbooks, and as counsel to marketing companies reaching patients and healthcare providers through the very channels I used to build cases around.
That second seat comes with a twist most TCPA lawyers never see: HIPAA rides along on every message.
The ground that moved
-
McLaughlin v. McKesson changed everything underneath you. The Supreme Court held that district courts are not bound by the FCC's interpretations of the TCPA. Courts owe agency views respect now, not obedience. The informational vs. marketing framework healthcare has leaned on for a decade is open to fresh challenge, district by district. Uniformity is gone.
-
The revocation rules are live, and the big one is coming. For covered calls and texts, opt-outs must be honored within 10 business days, seven standardized keywords operate as automatic revocations, and any reasonable opt-out language counts too. On January 31, 2027, "revoke all" takes effect: a single STOP is treated as revoking consent to robocalls and robotexts from the sender across campaigns and sending numbers. If your systems track opt-outs by phone number instead of by person, you are not ready.
-
The action moved to the states. The Eleventh Circuit vacated the one-to-one consent rule and the current FCC is deregulating, but plaintiffs still filed roughly 2,600 federal TCPA cases in 2025, and states are filling the gap. Texas now reaches texts, with statutory damages up to $5,000 per violation. Oregon capped call attempts and tightened calling hours. More states are in line.
The twist When the recipient is a patient rather than a provider, every message must clear two frameworks whose definitions refuse to line up. The TCPA asks whether the message is telemarketing and what consent you hold. HIPAA asks whether it is "marketing" requiring written authorization. A message can be informational under the TCPA and still be marketing under HIPAA. A patient's phone number, in the right hands, is itself PHI.
A TCPA exemption does not cure a HIPAA authorization gap, and a signed HIPAA authorization does not confer TCPA consent. One text message, two statutes, and FCC, FTC, and OCR all holding enforcement pens, before the plaintiffs' bar even wakes up.
What building those cases taught me Plaintiffs' lawyers rarely attack your legal theory first. They attack your operations. The opt-out that took 12 days. The reassigned number that kept getting messages. The classification memo nobody implemented.
So the playbooks I write treat every "technically not required" safeguard as required. DNC and reassigned-number screening regardless of classification. Quiet hours narrower than the law demands. Consent and authorization tracked by person, not by number. Opt-outs honored immediately and globally.
Legal theories win cases. Operations win the ones that never get filed.
