top of page

Text Messaging Violations and Penalties Businesses Need to Know

2 minutes ago
7 min read
Fines and penalties for different text messaging violations


A single text message can break several rules at once. Between federal law, state law, carrier registration requirements, and industry specific regulations, businesses that send SMS in the US and Canada are exposed to a wide range of violations, each with its own fine structure. This guide lists the actual violations under every major framework and the exact penalties attached to them.



TCPA Violations and Fines (Federal, US)


The Telephone Consumer Protection Act, or TCPA, is the primary federal law governing business text messages in the United States. It is enforced by the FCC and through private lawsuits.


Violation

Fine

Sending marketing texts without prior express written consent

$500 per message

Continuing to text after a recipient replies STOP

$500 to $1,500 per message

Texting outside the 8am to 9pm recipient local time window

$500 to $1,500 per message

Texting a number on the National Do Not Call Registry

$500 to $1,500 per message

Using an autodialer or prerecorded content without proper consent

$500 to $1,500 per message

Willful or knowing violation of any of the above

Up to $1,500 per message, no cap on total liability


Because the fine applies per message, exposure scales directly with list size. A campaign sent to 10,000 non-consenting contacts creates theoretical exposure between $5 million and $15 million. Real settlements confirm this is not just theoretical: Kaiser Permanente agreed to pay $10.5 million in a 2025 case over texts sent after recipients replied STOP, and Zales Jewelers paid more than $7.5 million to resolve a separate TCPA class action the same year.



State Mini-TCPA Violations and Fines (US)


More than fifteen states have passed their own telemarketing statutes that impose additional violations and higher fines on top of the federal TCPA. These apply to any business texting a resident of that state, regardless of where the business is based.


State

Violation

Fine

Florida (FTSA)

Texting outside 8am to 8pm, or texting without consent

$500 per violation, treble for willful violations

Oklahoma (OTSA)

Sending more than three texts in 24 hours, even with consent

$500 to $1,500 per violation

Texas (SB 140)

Texting outside 9am to 9pm Monday through Saturday or noon to 9pm Sunday

Up to $5,000 per violation

Washington

Violating the state's commercial solicitation rules

Up to $1,000 per violation for repeat conduct

Connecticut

Any qualifying telemarketing text violation

Up to $20,000 per violation

Virginia (effective January 2026)

Failing to honor a STOP request for 10 years

$500 first violation, $1,000 second violation, $5,000 for each violation after that

Maryland

Violations similar to Florida and Oklahoma

Comparable to $500 to $1,500 per violation


A campaign that fully complies with federal TCPA rules can still trigger a violation and fine under Florida, Texas, or Connecticut law if contacts in those states are on the list.



A2P 10DLC Violations and Fines (Carrier Enforced, US)


A2P 10DLC violations are enforced directly by carriers such as AT&T, T-Mobile, and Verizon through The Campaign Registry, not by a government agency. Since February 2025, carriers block 100 percent of unregistered traffic outright, and non-compliant senders are billed for specific violations. Getting the 10DLC registration process right avoids both the fines below and permanent message blocking.


Violation

Fine

Phishing, smishing, or social engineering content (Tier 1 Sev-0)

$2,000 per violation

Illegal content, must be legal in all 50 states and federally (Tier 2 Sev-0)

$1,000 per violation

SHAFT content violations, Sex, Hate, Alcohol, Firearms, Tobacco (Tier 3 Sev-0)

$500 per violation

Third or later repeat content violation from the same sender

$10,000 per instance

Evading 10DLC rules through snowshoeing, dynamic routing, or unauthorized number replacement

$1,000 per incident

Sending unregistered traffic that still reaches a carrier

Outright blocking, plus a per-message surcharge (T-Mobile charged up to $0.012 per SMS and $0.021 per MMS for unregistered traffic in 2024)


These fines are contractual, not statutory. They come from carrier codes of conduct like T-Mobile's, and most SMS platforms pass them directly to the sending business under their own terms of service.



Not Sure If You're Registered?


Unregistered 10DLC traffic gets blocked outright, and carrier fines land on the business, not just the platform.




HIPAA Violations and Fines for Text Messages (US)


HIPAA violations apply specifically when a covered entity or business associate texts protected health information, or PHI, without proper safeguards such as encryption, access controls, and a signed business associate agreement.


Violation Tier

Culpability

Fine Per Violation

Annual Cap

Tier 1

No knowledge of the violation

Roughly $145 to $50,000

Around $25,000 to $36,500

Tier 2

Reasonable cause, should have known

Roughly $1,000 to $50,000

$100,000

Tier 3

Willful neglect, corrected within 30 days

Roughly $10,000 to $50,000

$250,000

Tier 4

Willful neglect, not corrected

Roughly $50,000 to $250,000

$1.9 million


Criminal violations are prosecuted separately by the Department of Justice.


Criminal Violation

Fine and Penalty

Knowingly obtaining or disclosing PHI

Up to $50,000 and 1 year in prison

Obtaining PHI under false pretenses

Up to $100,000 and 5 years in prison

Obtaining PHI with intent to sell, transfer, or use for personal gain or harm

Up to $250,000 and 10 years in prison


A common example is a practice sending appointment recall texts through a standard, non-secure texting tool without a business associate agreement in place. A patient name paired with appointment context already qualifies as PHI, which is enough to trigger a Tier 3 or Tier 4 violation depending on whether the practice corrects the issue once notified. Businesses handling patient communication typically move to a HIPAA compliant text messaging platform specifically to avoid this exposure.



Texting Patients Without a Safety Net?


Standard texting tools were never built to handle protected health information. See how a HIPAA compliant setup protects your practice and your patients.




CASL Violations and Fines (Canada)


The Canadian Anti-Spam Legislation, or CASL, is enforced by the CRTC and treats SMS the same way it treats commercial email.


Violation

Fine

Sending a commercial text without consent

Up to $10,000,000 CAD per violation for a business

Sending without a functioning unsubscribe mechanism

Up to $10,000,000 CAD per violation for a business

Failing to identify the sender

Up to $1,000,000 CAD per violation for an individual

Relying on expired or channel mismatched consent

Real settlements typically range from $5,000 to $250,000 CAD


Implied consent under CASL expires 24 months after a completed transaction, or 6 months after an inquiry that did not convert, and consent collected for one channel, such as email, does not carry over to SMS. Directors and officers can be held personally liable for violations regardless of company size. A major national retailer paid $120,000 CAD in 2024 over a broken unsubscribe link alone, with no allegation of intentional wrongdoing required.



How These Violations Stack on a Single Message


The same non-compliant text can trigger fines under multiple frameworks at once, since each one polices a different part of the message.


Framework

What It Penalizes

A2P 10DLC and CTIA

Registration, content, and carrier level compliance

TCPA and state mini-TCPA laws

Consent, timing, and opt-out compliance

HIPAA

Handling of protected health information

CASL

Consent, sender identification, and unsubscribe compliance in Canada


A healthcare business texting Florida patients from an unregistered number without a signed business associate agreement could realistically face a carrier fine, a federal TCPA claim, a Florida FTSA claim, and a HIPAA penalty from that single flawed campaign.



How to Avoid These Violations and Costly Mistakes


Most of the fines above trace back to a handful of preventable gaps rather than deliberate wrongdoing. Building these habits into your texting program closes most of that exposure before it starts.


  • Get consent in writing and keep a record of it: Store the timestamp, the exact language shown, and which channel it was collected through, since consent for email does not carry over to SMS under CASL or state law.

  • Register every number and use case under A2P 10DLC before sending a single message: This avoids both outright blocking and the per-message surcharges carriers apply to unregistered traffic.

  • Honor STOP requests immediately and never re-add a number without fresh consent: Several of the largest TCPA settlements came from businesses that kept texting after someone opted out.

  • Build campaigns around the strictest time window that applies, not just the federal 8am to 9pm rule: Florida, Oklahoma, and Texas all use tighter or different windows, and the recipient's location decides which one applies.

  • Screen every contact list against state residency, not just your own business location: A campaign that is fully compliant where you operate can still violate a state law where your recipient lives.

  • Never send PHI through a standard texting tool without a signed business associate agreement: Encryption, access controls, and audit trails need to be in place before the first message, not added after a complaint.

  • Refresh consent before it expires: Under CASL, implied consent lapses 24 months after a purchase and 6 months after a non-converting inquiry.

  • Keep marketing and transactional content separate, and avoid SHAFT categories entirely in shared or ambiguous use cases: Carrier content fines apply regardless of intent.

  • Audit your SMS platform's terms of service for who absorbs carrier fines: Most platforms pass 10DLC violation fees straight to the business, so this is worth knowing before a violation happens, not after.

  • Route compliance questions through one owner inside the business: Fragmented ownership across marketing, IT, and legal is where most of these gaps quietly form.



Frequently Asked Questions


What is the fine for a single TCPA violation?

Standard TCPA violations carry a fine of $500 per message, rising to $1,500 per message for willful or knowing violations, with no cap on total liability.


What happens if a business sends texts from an unregistered 10DLC number?

Carriers block the traffic outright, and non-compliant senders can be fined up to $10,000 per violation depending on the carrier's specific penalty schedule.


What is the maximum HIPAA fine for a texting violation?

HIPAA fines can reach $250,000 per violation with an annual cap of $1.9 million for willful neglect that is not corrected, and criminal penalties can add up to 10 years in prison in cases involving intent to sell or misuse PHI.


What is the maximum CASL penalty for a text message violation?

CASL allows penalties of up to $10,000,000 CAD per violation for a business and $1,000,000 CAD per violation for an individual, though most real world settlements are far lower.


Can more than one law apply to the same text message?

Yes. A single message can violate carrier rules, federal TCPA, a state mini-TCPA law, and HIPAA at the same time if the underlying facts overlap.


Do state telemarketing laws increase TCPA exposure?

Yes. More than fifteen states have their own mini-TCPA laws with penalties that can exceed the federal TCPA, and compliance with federal rules alone does not prevent a state level violation.



Final Thoughts


Every framework covered here targets a different part of the same text message, which is why violations rarely happen in isolation. A missing consent record, an unregistered number, or an unencrypted health message can each trigger a separate fine, and in the worst cases, several fines at once. Businesses that avoid this exposure typically rely on SMS compliance software and a secure business texting platform built around these specific rules rather than trying to track every statute manually.


If your business needs a texting setup built around these violation categories from the start, talk to our team.


Build Your Texting Program the Right Way


From consent tracking to 10DLC registration to secure delivery, our team can help you set up a texting program that avoids these violations from day one.



 
 
bottom of page