Please note: This review reflects information we gathered on the date it was researched and may now be out of date. Providers frequently change their pricing, plans, medications, and policies. Any ratings, reviews, and customer feedback are gathered from publicly available online sources and may have since changed or no longer be accurate. Always do your own research and confirm the latest details directly with the provider before making any decision.
EZ Texting Review: Marketing Says Encrypted, Contract Says Not
EZ Texting is business SMS software — mass texting, automation and two-way messaging, from about $25 a month. It is not a consumer health product and most readers of this site will have no use for it. We have reviewed it for the ones who might: the clinicians, dietitians, coaches and practice managers who text patients. For them there is one thing on this page that matters, and it is that the company's healthcare page describes it as an end-to-end encrypted HIPAA-compliant option while its Terms of Service say messages are transmitted unencrypted.
Our Verdict
EZ Texting · eztexting.com · from ~$25/month
The healthcare page and the contract disagree about encryption
Healthcare page: “Choose a HIPAA-compliant SMS platform. Use an SMS platform, like EZ Texting, offering end-to-end encryption and secure data storage.” Terms of Service: “You acknowledge that text messages and voice broadcasts are transmitted unencrypted and that eavesdropping of communications by third parties is possible.” Both live on 11 August 2026. A buyer evaluating this for patient messaging is being told two incompatible things, and the one that governs is the one that says unencrypted.
No business associate agreement mentioned anywhere
We searched five pages — homepage, pricing, healthcare, compliance, and a Terms of Service running to over 72,000 characters — for BAA and business associate. Zero matches on every page. HIPAA itself appears only on the healthcare page, seven times, and nowhere in the Terms. Under HIPAA a covered entity needs a signed BAA before a vendor handles protected health information. If one is available, the company does not say so anywhere we could find.
The TCPA tooling is real, and it is the reason to consider them
Double opt-in, automated opt-out, a SafeSTOP feature that removes contacts on request, and A2P 10DLC brand registration. Their compliance page also states the exposure accurately: $500 to $1,500 for every message sent to someone who has not properly opted in. Per message. For a practice with a list of two thousand patients, one careless campaign is an existential number, and consent infrastructure that works is worth more than any feature on the pricing page.
Their direct answer on HIPAA is honest
Asked on their own page whether SMS for healthcare is HIPAA compliant, they answer: “No, SMS is not inherently HIPAA compliant.” They go on to advise avoiding sensitive patient identifiers and not sharing detailed medical information by SMS. That is correct and more candid than we expected. It makes the encryption sentence further down the same page harder to explain, not easier.
A promotional deadline that expired in 2022
The live pricing page reads “Promotional Pricing Until December 5, 2022.” We read it in August 2026. On its own this is trivial. On a product whose value proposition is regulatory compliance, a pricing page nobody has reviewed in nearly four years is a reasonable prompt to ask when the compliance pages were last checked.
Our Top Recommended Provider: CoreAge Rx
After reviewing dozens of GLP-1 telehealth providers, CoreAge Rx is the one we recommend most. CoreAge Rx is one of our partners — read on for why we recommend them:
Flat-Rate Pricing
Same cost at every dose level — no price jumps as you titrate up.
Verified Pharmacies
US-licensed physicians and NABP-verified 503A compounding pharmacies you can trust.
Everything Included
Medication, supplies, free shipping, and ongoing clinical support — no hidden fees.
Active Community of Members
Ask questions, share progress, and get answers from other patients on the same journey — alongside ongoing clinical support from your care team.
0
Mentions of BAA across five pages
$500–$1,500
TCPA exposure per non-consented message
~$25
Entry plan per month, plus per-message rates
2022
Promo deadline still live on the pricing page
The two laws that decide whether you can use this
1. HIPAA, and the sentence in the contract
If you are a covered entity — a clinician, a practice, a clinic — HIPAA governs what you may do with protected health information, and it governs the vendors you hand it to. The mechanism is the Business Associate Agreement: before a supplier creates, receives, maintains or transmits PHI on your behalf, you need a signed BAA setting out their obligations. No BAA, no lawful disclosure. It is not a formality that can be inferred from a vendor's general security posture.
We looked for one. Across the homepage, the pricing page, the healthcare industry page, the text-marketing compliance page and a Terms of Service document running past 72,000 characters, the terms BAA and business associate returned zero matches each. HIPAA appears seven times, all on the healthcare page, and not once in the Terms. It is possible a BAA is available on request through sales; we can only report that the company does not mention one in any material we could read.
Then there is the encryption question, where the marketing and the contract point in opposite directions. The healthcare page tells you to use a platform like EZ Texting offering end-to-end encryption. The Terms tell you that messages are transmitted unencrypted and that eavesdropping by third parties is possible, and recommend that you send sensitive information by some other protected method. Those cannot both be true. The Terms are the document you agree to, and their version is also the technically accurate one — ordinary SMS traverses carrier infrastructure without end-to-end encryption regardless of what any platform does at its own edge.
2. TCPA, where the real financial risk lives
Most people worrying about texting patients worry about HIPAA. The larger practical exposure for a small practice is the Telephone Consumer Protection Act, because its damages are statutory, per message, and do not require anyone to prove harm. EZ Texting's own compliance page states the range correctly: $500 to $1,500 for every message sent to someone who has not properly opted in.
Run that arithmetic against a patient list. Two thousand contacts imported from a practice management system, one promotional campaign about a new weight-management programme, and no documented prior express written consent for marketing messages — the theoretical exposure runs into seven figures. This is among the most litigated areas of US consumer law precisely because the maths is so unforgiving, and clinics are not exempt from it.
This is where EZ Texting earns most of its score. Double opt-in, automated opt-out handling, SafeSTOP removing contacts when they text stop, and A2P 10DLC brand and campaign registration are the infrastructure that keeps a sender on the right side of both the statute and the carriers. Building that yourself is expensive and getting it wrong is worse. If you are going to send bulk SMS at all, doing it through a platform with real consent plumbing is the correct decision.
3. Pricing, and what is not in the headline number
Plans begin around $25 a month. Per-message rates tier by plan and volume: $0.04 on the entry tier, then $0.035, then $0.03, reaching $0.01 on an enterprise plan quoted at $500 or more per month. The lower rates require a volume commitment, with messages above the commitment charged at $0.04.
Two costs sit outside the plan price and are easy to miss. Telecom fees are charged on the entry tier and waived on higher ones, and carrier pass-through fees are billed separately based on actual usage. Setup is same-day on standard plans but quoted at four to twelve weeks for enterprise, which matters if you were planning around a launch date. Model your real monthly send volume before comparing headline prices, because the per-message line will dominate the subscription line quickly.
Can you use it? A decision table for practices
| What you want to send | Contains PHI? | Verdict |
|---|---|---|
| “Your appointment is Tuesday at 2pm” | Minimal | Generally acceptable with consent; standard low-risk use |
| Anything naming a medication, dose or diagnosis | Yes | Not without a signed BAA — which we could not find offered |
| Lab or test results | Yes | No. Their own page names test results as the example to avoid |
| Marketing a new programme to your patient list | Maybe | TCPA territory: needs prior express written consent |
| Gym, coaching or non-clinical business | No | HIPAA does not apply; TCPA still does. Reasonable fit |
In its favour
- Genuine TCPA infrastructure: double opt-in, automated opt-out, SafeSTOP, and A2P 10DLC registration.
- States the TCPA exposure accurately at $500 to $1,500 per non-consented message rather than glossing over it.
- Answers the HIPAA question honestly: no, SMS is not inherently HIPAA compliant.
- Gives correct baseline guidance — avoid patient identifiers, do not send detailed medical information by SMS.
- Terms explicitly disclaim interpreting the law and place compliance responsibility on the sender, which is appropriate.
- Transparent per-message tiering and same-day setup on standard plans.
- Entry pricing around $25/month is accessible for a small practice.
Against it
- Healthcare page recommends it as offering end-to-end encryption; Terms state messages are transmitted unencrypted.
- Terms also warn that eavesdropping by third parties is possible, on the same product marketed to clinics.
- Zero mentions of BAA or business associate across five pages including a 72,000-character Terms of Service.
- HIPAA appears nowhere in the Terms, only in marketing copy.
- Telecom and carrier pass-through fees are billed outside the headline plan price.
- Lower per-message rates require a volume commitment, with overages at $0.04.
- A promotional deadline of December 2022 still displayed on the live pricing page.
- Enterprise setup quoted at four to twelve weeks.
Our verdict: 2.7 out of 5
Solid consent infrastructure and honest baseline guidance, undermined by a marketing page that promises encryption the contract explicitly disclaims.
As an SMS platform this is competent and reasonably priced, and the TCPA tooling is the genuinely valuable part. Statutory damages of $500 to $1,500 per message make consent management the highest-stakes feature in the product, and EZ Texting takes it seriously — double opt-in, automatic opt-out, SafeSTOP, carrier registration. A small practice doing this itself would get it wrong, and getting it wrong is measured in multiples of annual revenue.
Their healthcare page also starts from an honest place. Asked directly whether SMS is HIPAA compliant, they say no. They tell readers not to send patient identifiers or detailed medical information. That is more candid than a company selling into healthcare had to be, and we would have scored this well above three if the page had stopped there.
It does not. A few paragraphs later the same page recommends choosing a HIPAA-compliant platform and using one like EZ Texting offering end-to-end encryption and secure data storage. The Terms of Service — the document a customer actually signs — say that messages are transmitted unencrypted and that eavesdropping by third parties is possible, and advise sending sensitive information some other way. A clinic manager reading the healthcare page could reasonably conclude they had found an encrypted, HIPAA-suitable platform. The contract says otherwise, and the contract is right about the technology.
Compounding it: not one mention of a business associate agreement anywhere we looked, including a Terms of Service running past seventy-two thousand characters. A BAA is the specific instrument HIPAA requires before a vendor touches PHI. Its complete absence from the written record is the single most important fact for any covered entity considering this platform, and it is not addressed on the page written specifically for them.
So: 2.7. If you run a gym, a coaching practice or any business outside HIPAA's reach, this is a reasonable SMS platform and the consent tooling is a real asset — mind the telecom and carrier fees that sit outside the headline price. If you are a covered entity, use it only for content containing no PHI, and if you need more than that, ask them directly and in writing whether they will sign a BAA before you send a single message. Do not take the encryption claim from the marketing page. Their own contract tells you not to.
Frequently asked questions
Why is this on a GLP-1 site?
It arrived in our affiliate queue and there is no consumer health angle to it — EZ Texting is business software. We have reviewed it for the slice of readers who are on the other side of the consultation: clinicians, dietitians, coaches and clinic managers who are considering texting patients about appointments and adherence. If that is not you, this page will not be useful and we would rather say so than pretend.
What is the contradiction you found?
EZ Texting's healthcare page advises readers to choose a HIPAA-compliant SMS platform and to use one like EZ Texting offering end-to-end encryption and secure data storage. Its Terms of Service state that you acknowledge that text messages and voice broadcasts are transmitted unencrypted and that eavesdropping of communications by third parties is possible. Both statements were live when we checked. The Terms are the binding document.
Can I use it for patient communication under HIPAA?
Not for protected health information, on the evidence available. Under HIPAA a covered entity must have a Business Associate Agreement with any vendor that creates, receives, maintains or transmits PHI on its behalf. We searched five EZ Texting pages including a 72,000-character Terms of Service for BAA and business associate. Both returned zero on every page. Without a signed BAA, routing PHI through the platform is not something a covered entity can do compliantly.
So can healthcare providers use SMS at all?
Yes, within limits, and EZ Texting's own healthcare page states them correctly. Its direct answer to whether SMS is HIPAA compliant is a plain no, and it advises that medical professionals should refrain from texting medical information that is personal, sensitive and specific from a platform that is not HIPAA compliant, avoid sensitive patient identifiers, and not share detailed medical information by SMS. Appointment reminders without clinical detail are the standard low-risk use. That guidance is sound — it just sits on the same page as the encryption claim.
What about TCPA?
This is where the platform is genuinely strong, and the exposure is real: their own compliance page correctly states that the TCPA carries penalties of $500 to $1,500 for every message sent to someone who has not properly opted in. Per message, and a patient list can be thousands of people. EZ Texting provides double opt-in, automated opt-out, a SafeSTOP feature that removes contacts automatically, and A2P 10DLC registration support. For a small practice, that tooling is worth more than the software itself.
What does it cost?
Plans start around $25 a month, with per-message rates tiering from $0.04 down through $0.035 and $0.03 to $0.01 on the enterprise tier, which is quoted at $500+ per month. Telecom fees are waived on higher tiers and charged on the entry plan, carrier pass-through fees are billed separately based on usage, and lower per-message rates require a volume commitment with overages at $0.04. Setup is same-day on standard plans and four to twelve weeks on enterprise.
Anything else that undermines confidence?
A small thing that says something. The live pricing page carries the line Promotional Pricing Until December 5, 2022. We read it in August 2026 — a promotional deadline nearly four years past, still published on the page where customers choose a plan. It is not harmful in itself, but a compliance-sensitive product with a four-year-stale pricing page invites questions about what else is not being reviewed.
What should a clinic actually do?
Decide first whether your messages will contain PHI. If they will not — appointment reminders with no clinical detail, no diagnosis, no medication named — a mainstream SMS platform with strong consent tooling is a reasonable choice, and this is one. If they might, you need a vendor that will sign a BAA and will say so in writing, and you should ask EZ Texting directly whether they will before you commit. Get the answer in writing, and do not rely on a marketing page's description of encryption when the contract says the opposite.
For practices: ask about the BAA first
Before sending anything containing patient information, ask EZ Texting in writing whether they will execute a business associate agreement, and keep the answer. The link below is an affiliate link paying us $14.00 — which does not change our advice that the contract, not the marketing page, describes what this product does.
Visit EZ Texting (affiliate link)Pricing, terms and page content verified 11 August 2026 and subject to change.
Compare Other GLP-1 Providers
See how other telehealth providers stack up.
Mochi Health
Obesity Medicine SpecialistsBoard-certified obesity medicine specialists with both brand-name and compounded GLP-1 options
Read Review →Amazon One Medical
Brand-Name, No CompoundingFDA-approved Wegovy, Zepbound and Foundayo from $149/month cash, $25 with insurance and $50/month for eligible Medicare members — the first mainstream route to approved medication at prices that compete with compounded. We earn no commission from it
Read Review →Henry Meds
Top RatedWell-established telehealth platform with fast physician reviews and competitive pricing
Read Review →PlushCare
Insurance AcceptedMajor telehealth platform with brand-name FDA-approved GLP-1s, insurance support, and 1M+ members treated
Read Review →Form Health
Comprehensive ProgramMultidisciplinary obesity medicine program with physicians, dietitians, and behavioral coaching
Read Review →GoodRx Care
Trusted BrandTelehealth platform from GoodRx with transparent pricing and established trust
Read Review →Scope and legal disclaimer
This is a review of business software, published on a consumer health site because it appeared in our affiliate queue. It contains no medical content and nothing here is medical advice. It is also not legal advice: we are not lawyers, HIPAA and TCPA obligations depend on your specific circumstances, and enforcement positions change. Descriptions of HIPAA's business associate requirement and of TCPA statutory damages are general summaries provided so that a reader knows which questions to ask, not a substitute for counsel. Any healthcare organisation considering SMS for patient communication should obtain advice from a qualified healthcare attorney or compliance officer and obtain any vendor assurances in writing.
Sources · date reviewed: 11 August 2026
- eztexting.com/industries/healthcare — retrieved 11 August 2026. Source for the verbatim question and answer “Is SMS for Healthcare HIPAA Compliant? No, SMS is not inherently HIPAA compliant…”, for the guidance to avoid sensitive patient identifiers and not share detailed medical information by SMS, and for the recommendation to “Choose a HIPAA-compliant SMS platform. Use an SMS platform, like EZ Texting, offering end-to-end encryption and secure data storage.”
- eztexting.com/terms — retrieved 11 August 2026, approximately 72,400 characters. Source for the verbatim clause “You acknowledge that text messages and voice broadcasts are transmitted unencrypted and that eavesdropping of communications by third parties is possible. EZ Texting recommends that you ensure sensitive and valuable information is communicated by a protected and/or encrypted method.”, for the sender's obligation to comply with the TCPA and related laws, and for the disclaimer that EZ Texting is in no way attempting to interpret any laws.
- eztexting.com/text-marketing-compliance — retrieved 11 August 2026. Source for the statement that the TCPA can levy penalties of $500 to $1,500 for every message sent to people who have not properly opted in, and for the SafeSTOP opt-out description.
- eztexting.com/pricing — retrieved 11 August 2026. Source for per-message tiers of $0.04, $0.035, $0.03 and $0.01, the $500+ per month enterprise tier, telecom fee treatment by tier, carrier pass-through fees billed separately, volume commitments with $0.04 overages, setup times of one business day or four to twelve weeks, and the line reading “Promotional Pricing Until December 5, 2022”.
- Keyword audit conducted 11 August 2026 across the homepage, pricing, healthcare, compliance and terms pages: BAA returned zero matches on all five; business associate returned zero on all five; HIPAA returned seven matches on the healthcare page and zero on the other four.
- Regulatory background: HIPAA requires a covered entity to execute a business associate agreement before a vendor creates, receives, maintains or transmits protected health information on its behalf. The TCPA provides statutory damages of $500 per violation, trebled to $1,500 for wilful or knowing violations, and requires prior express written consent for marketing messages to mobile numbers.
- Katalys offer listing #1446, retrieved 11 August 2026 — $14.00 commission, United States targeting, sub-network Impact.
We did not create an account, contact sales, or attempt to obtain a business associate agreement; it is possible one is available on request and simply undocumented publicly, and we have said so rather than concluding otherwise. We did not contact the company before publishing, and we would update this page if a BAA offering or a correction to the encryption language were published.
Affiliate disclosure
GLP1Drugs.org earns $14.00 per referral through the links on this page. We have rated EZ Texting 2.7 out of 5, credited its TCPA tooling, and led the review with a contradiction between its healthcare marketing and its Terms of Service. No company reviewed here sees or approves our copy before publication.