A2P 10DLC for Medical Spas: The Compliance Guide Every Owner Needs in 2026
Carrier enforcement passed in February 2025. If your medspa is sending appointment reminders, review requests, or marketing texts from an unregistered number, those messages are not being delivered. Here is what A2P 10DLC actually is, why it is the single most common GoHighLevel pain point in 2026, and how we handle it as part of every NexioBit CRM build.
A2P 10DLC is the registration system US carriers use to verify which businesses are sending SMS and for what purpose. Since February 2025, AT&T, T-Mobile, and Verizon block 100% of unregistered traffic from 10-digit numbers. Medspas that send appointment reminders, review requests, or marketing texts without registering are silently losing message delivery.
If you run a medspa on GoHighLevel and your texts are going nowhere, this is almost always the reason. NexioBit handles 10DLC registration as part of every CRM build so you never have to think about it. Below is what A2P 10DLC actually means, what it costs to ignore, and why DIY registration fails for medspas more often than any other vertical.
Why I am writing this guide
I have set up GoHighLevel for medspas across multiple states, and A2P 10DLC is the single most common reason medspa owners contact me in panic. Their appointment reminder workflow runs. Their automation fires. GoHighLevel shows “message sent.” But patients are not receiving anything. Front desk staff start hearing “I never got my reminder” complaints. Review request flows show 90% delivery on paper and zero actual reviews coming in.
Every time, the root cause is the same: the medspa is sending A2P (application-to-person) messages from numbers that were never registered under 10DLC. Carriers block the messages silently. There is no error in GoHighLevel. The texts just disappear.
I am writing this because the topic is buried under twenty layers of telecom jargon that no medspa owner should have to learn. You should not have to understand TCR vetting scores, brand registration tiers, or campaign throughput limits to send a “your appointment is tomorrow at 2pm” text. But you do need to know that this system exists, what it costs if you ignore it, and what your options are.
“The first thing I check when a medspa says their texts are not landing is their A2P 10DLC verification status. Nine times out of ten, that is the answer. The second thing I check is whether their CSP even has visibility into rejected registrations, because half of them do not.”
What is A2P 10DLC?
A2P 10DLC is the carrier-enforced registration system for business SMS sent over standard 10-digit US phone numbers. A2P means “application-to-person” (any message sent from a software platform to a consumer), and 10DLC means “10-digit long code” (a regular local phone number, as opposed to a short code or toll-free number).
Before 10DLC existed, businesses sent marketing texts from regular phone numbers and carriers had no way to tell the difference between a person texting their friend and a CRM blasting promotional messages. Spam was unchecked. Consumers were drowning in unsolicited texts. The carriers responded by building 10DLC.
Now, every business that wants to send A2P traffic from a 10-digit number must register with The Campaign Registry (TCR), a central database that tracks every business sending SMS in the US. Registration happens through your CSP (Campaign Service Provider), which is your SMS platform: GoHighLevel, Twilio, Bandwidth, ActiveCampaign, or similar. The CSP submits your business information to TCR, which verifies it, assigns a vetting score, and approves or rejects individual messaging campaigns.
If you are not registered, your messages are blocked. If your campaign is registered but your content violates the rules, you can be fined and your brand can be blacklisted across all carriers.
What changed in February 2025
Before February 2025, carriers were inconsistent. T-Mobile blocked unregistered traffic aggressively. AT&T and Verizon were softer. Many medspa owners ran unregistered SMS for years without consequences because messages were filtered, not blocked.
That ended. Since February 2025, AT&T joined T-Mobile and Verizon in blocking 100% of unregistered A2P traffic from 10-digit numbers. There is no grey area anymore. If your medspa is not registered, your texts are not being delivered, full stop.
The penalties matter too. T-Mobile fines up to $10,000 per content violation. SHAFT violations (sex, hate, alcohol, firearms, tobacco) carry the same maximum. Grey-route evasion (trying to disguise A2P traffic as person-to-person to avoid registration) costs $1,000 per incident, $10 per message. These are not theoretical numbers. They are published in carrier policy documents and assessed against CSPs, who pass them through to customers.
Separately, the Telephone Consumer Protection Act (TCPA) imposes statutory damages of $500 to $1,500 per unsolicited text. The FCC enforces TCPA, not the carriers, and the penalties stack on top of 10DLC fines. Kaiser Permanente settled a TCPA class action for $10.5 million in 2025. SiriusXM settled for $28 million. These cases involve unsolicited marketing texts, which is exactly the category your medspa promotional campaigns fall into.
Why medspas keep getting blocked more than other businesses
Medspas are not specifically targeted. The problem is that medspa messaging hits three categories that TCR scrutinizes more carefully than most other industries:
1. Healthcare-adjacent language triggers extra review
Texts that mention “treatments,” “consultations,” or specific procedures (Botox, fillers, weight loss injections, hormone therapy) read as healthcare to TCR’s review process, even though medspas are technically elective wellness businesses, not regulated healthcare providers. Healthcare campaigns face stricter content review, longer approval times, and more rejection.
2. Weight loss is on the carrier sensitivity list
Carriers maintain content sensitivity lists for industries that historically generated spam complaints. Weight loss is high on that list. If your medspa offers Semaglutide, Tirzepatide, HCG, or any weight loss service, your campaign descriptions get extra review. Generic language like “lose weight fast” or “results guaranteed” will get rejected. Sometimes even legitimate medical weight loss campaigns get rejected because the content reads as a weight loss spam pattern.
3. Promotional offers look like spam patterns
The classic medspa SMS marketing playbook is “$20 off Botox this Friday” or “limited spots for our Black Friday filler special.” From a TCR reviewer’s perspective, this is identical to the patterns used by spam senders. Discount language, time pressure, and treatment names combine to flag campaigns automatically. Legitimate medspas with real customers get caught in the same filters as actual spammers.
The result: medspas are more likely than most businesses to have campaigns rejected on first submission, sit in extended review queues, or get partially approved (transactional reminders approved, marketing campaigns rejected).
The HIPAA and 10DLC overlap nobody talks about
Here is the angle most 10DLC guides miss for medspas: your appointment reminders, treatment-specific texts, and patient follow-ups potentially contain Protected Health Information under HIPAA. A reminder that says “Hi Sarah, your Botox appointment with Dr. Patel is tomorrow at 2pm” arguably contains PHI: a name, a treatment, and a provider association.
Most medspas send these texts through GoHighLevel without thinking about the HIPAA angle because the carrier infrastructure (TCR, the CSP, AT&T, T-Mobile, Verizon) is not a HIPAA-covered entity in the traditional sense. But the messages themselves still contain patient information.
If your medspa is operating under a HIPAA-compliant framework, two things must be true. First, the SMS platform you use must be willing to sign a Business Associate Agreement (BAA). GoHighLevel will sign one, but you must request it explicitly and configure your sub-account in HIPAA mode. Standard GoHighLevel accounts are not HIPAA-compliant by default. Second, your message content must be designed so that even if a text is intercepted, the PHI exposure is minimized. Generic reminders like “Hi Sarah, your appointment is tomorrow” are safer than specific reminders that name treatments or providers.
None of this changes 10DLC registration requirements. You still need to register. But the way you write your campaign descriptions and message templates affects both 10DLC approval and HIPAA exposure.
What 10DLC registration actually involves
I am keeping this high-level on purpose. The point of this article is not to teach you the registration process. The point is to help you understand what registration is so you can decide whether to handle it yourself or have it done for you.
At a basic level, 10DLC registration has two stages:
Stage 1: Brand registration
You register your business as a brand with The Campaign Registry. This requires your legal business name, EIN (or equivalent), website, address, and a vetting process. TCR assigns your brand a vetting score (low, medium, or high), which determines your throughput limits (how many messages per second you can send) and how strictly your campaigns are reviewed.
One-time brand registration fee is $4.50. Optional standard brand vetting (recommended for medspas to improve throughput) is $41.50.
Stage 2: Campaign registration
Once your brand is registered, you register individual campaigns. A campaign is a specific use case: appointment reminders is one campaign, marketing promotions is another campaign, post-visit review requests is a third. Each campaign requires sample messages, opt-in flow documentation, and an explanation of how patients consent to receive these specific messages.
Campaign verification fee is $15 per campaign. Most medspas need at least 2-3 campaigns to cover their normal use cases. Monthly carrier surcharges then apply per message sent, varying by carrier.
The timeline reality
| Stage | Typical timeline | Rejection rate |
|---|---|---|
| Brand registration submission | Same day | Low |
| Brand vetting score assigned | 2-3 business days | n/a |
| First campaign submission | Same day | n/a |
| Campaign approval (first try) | 3-10 business days | Moderate to high for medspas |
| Campaign resubmission (if rejected) | 3-10 business days | Lower on second pass |
| Full live, all campaigns approved | 2-6 weeks total | n/a |
Timelines from carrier documentation and our experience registering medspas on GoHighLevel. Your actual timeline varies based on submission quality, content categories, and TCR queue depth.
Why DIY 10DLC fails for medspas more than for other businesses
If you are reading this and thinking “this is just paperwork, I can handle it myself,” you might be right. Plenty of medspa owners do handle their own registration. But the rejection patterns I see repeat themselves across nearly every DIY medspa registration:
Pattern 1: Wrong sample messages
Owners submit sample messages that mention specific procedures, discounts, or provider names. TCR rejects them. The rejection note is vague (“content does not meet carrier guidelines”), so the owner has no clear path to fix it. They guess, resubmit, get rejected again.
Pattern 2: Weak opt-in documentation
Medspas often collect patient consent through paper forms or an in-app checkbox that does not survive scrutiny. TCR wants to see exactly how a patient agreed to receive each campaign type. “We have a form” is not enough. They want a screenshot of the form, the exact language, and a privacy policy link.
Pattern 3: Mismatched business information
The legal entity name on your EIN, the name on your business license, the name on your domain WHOIS record, and the name you put on your TCR registration all need to match. Medspas often have a DBA that is different from the legal entity, or a holding company structure that confuses the verification.
Pattern 4: Choosing the wrong campaign type
TCR offers different campaign types (transactional, marketing, mixed, healthcare, low-volume). Picking the wrong one means your medspa pays higher per-message surcharges or gets stricter content review. Most owners pick wrong on the first submission.
Pattern 5: No HIPAA consideration
Owners get approved on 10DLC and start sending without realizing their campaign templates were designed for general SMS marketing, not for healthcare-adjacent messaging that should consider PHI exposure.
None of these are catastrophic. All of them are fixable. But they cost weeks of delay during a period when your medspa is trying to drive bookings, and every week your campaigns are stuck in TCR limbo is a week of texts your patients are not receiving.
How we handle A2P 10DLC in a NexioBit GHL build
This is the soft pitch. I will keep it honest.
When a medspa engages NexioBit for a GoHighLevel build, A2P 10DLC registration is part of the standard scope. We do not charge extra for it. We handle it because we have done it for enough medspas that the patterns are predictable, and because the alternative is your launch getting delayed by 4-6 weeks while you figure out why TCR keeps rejecting your campaigns.
Specifically, what we do as part of the build:
- Pre-register your brand before the rest of the GHL build is ready, so the 2-3 day brand vetting window happens in parallel with everything else
- Write your campaign descriptions in the language TCR approves, based on medspa-specific patterns we know work
- Configure your sample messages to clear both 10DLC review and HIPAA exposure considerations
- Document your opt-in flow on your website with the language and structure TCR requires
- Submit and manage campaigns through GoHighLevel, including resubmission if anything gets rejected on first pass
- Get you A2P Verified on every phone number you plan to send from, with the green compliance badge visible in your GHL dashboard
The screenshot at the top of this article is what that looks like when it is done correctly. Two numbers, both marked “A2P Verified,” the green “You are now A2P 10DLC compliant” banner visible. That is the state your medspa needs to be in before a single appointment reminder goes out.
For medspas that already have GoHighLevel and just need 10DLC fixed, we offer that as a standalone engagement. But honestly, if your CRM is GoHighLevel and 10DLC is broken, the rest of your GHL setup probably has issues too. Our full medspa GHL build rebuilds the entire stack the right way, with compliance baked in from day one.
Should you fix your 10DLC right now?
Five questions to ask yourself. If you answer yes to two or more, A2P 10DLC is actively costing your medspa revenue.
- “Have I noticed more no-shows since early 2025?” If patients stopped getting your reminders in February 2025, your no-show rate climbed and you may not have connected the dots to 10DLC enforcement.
- “Do my Google review request texts have a much lower response rate than they used to?” If review velocity dropped, your review request flow is sending into a void. Patients are not receiving the message.
- “Does my GoHighLevel dashboard show ‘message sent’ but staff is hearing ‘I never got the text’?” Classic blocked-traffic pattern. GHL shows success on your end; carriers block silently on the patient end.
- “Have I ever registered my brand with The Campaign Registry?” If you do not know, you have not. Brand registration is explicit and requires submitting your EIN.
- “Do I see an A2P Verified badge on my phone numbers in GoHighLevel?” Open GHL, go to Settings, Phone Numbers. Each number should show an “A2P Verified” green badge. If yours do not, you are not compliant.
If two or more of these are yes, you are losing revenue every week your registration sits incomplete. Book a 30-minute call and we can tell you specifically what your GHL account is doing right now, what is broken, and what it takes to fix it.
What medspa owners actually ask me about A2P 10DLC.
Direct answers to the eight questions I hear most on discovery calls when 10DLC comes up.
Do I need A2P 10DLC if my medspa only sends appointment reminders?
Yes. 10DLC applies to all A2P traffic regardless of message volume or content type. Transactional reminders are still A2P messages sent from an application (your CRM) to a person (your patient). Carriers block unregistered transactional traffic the same way they block unregistered marketing traffic. There is no exception for low-volume or transactional-only senders.
Is GoHighLevel A2P 10DLC compliant out of the box?
No. GoHighLevel is a CSP (Campaign Service Provider) that can register you for 10DLC, but registration is not automatic. When you set up a new GoHighLevel sub-account, you are not registered. You must complete brand registration and campaign registration through the GoHighLevel interface before sending any SMS. Most medspas miss this step because GoHighLevel does not block you from sending; the carriers block your messages downstream.
How much does A2P 10DLC cost for a medspa?
Direct registration fees are $4.50 for brand registration, $41.50 for standard brand vetting, and $15 per campaign. Most medspas need 2 to 3 campaigns (transactional reminders, marketing, review requests), so the registration cost ranges from $76 to $106 total one-time fees. Monthly carrier surcharges add a few cents per message and vary by carrier. Compliance costs are minor compared to the cost of having appointment reminders silently fail for weeks.
What happens if my medspa sends SMS without registering for 10DLC?
As of February 2025, all messages from unregistered 10-digit numbers are blocked by AT&T, T-Mobile, and Verizon. Your CRM may show “sent,” but recipients receive nothing. T-Mobile additionally fines up to $10,000 per content violation and $1,000 per evasion attempt. Separately, the Telephone Consumer Protection Act adds statutory damages of $500 to $1,500 per unsolicited message, enforced through class actions.
How long does A2P 10DLC registration take for a medspa?
Brand registration is approved within 2 to 3 business days. Campaign approval typically takes 3 to 10 business days per campaign. If your first campaign submission is rejected (common for medspas), the resubmission takes another 3 to 10 business days. Total realistic timeline from start to fully approved is 2 to 6 weeks, with medspas tending toward the longer end because of healthcare-adjacent content review.
Why does TCR keep rejecting my medspa SMS campaigns?
The most common rejection reasons for medspas are vague opt-in documentation, sample messages that mention specific procedures or discounts, weight loss content that pattern-matches to spam, and mismatched business entity information. The rejection notes from TCR are usually vague, which makes self-resolution slow. Most rejections are fixable by rewriting campaign descriptions in the specific language TCR approves and providing screenshot evidence of your opt-in flow.
Does A2P 10DLC apply to toll-free numbers or only local numbers?
A2P 10DLC applies only to 10-digit local long codes. Toll-free numbers (1-800, 1-888, etc.) have a separate verification process called toll-free verification, with similar but distinct requirements. Short codes (5 to 6 digit numbers) are a third separate path. Most medspas use local numbers because they look more personal to patients, so 10DLC is the relevant framework.
Can I just use my personal cell phone to text patients to avoid 10DLC?
Technically yes, but this creates worse problems than 10DLC registration. Personal-cell SMS does not scale, is not auditable, leaks PHI through your personal device, fails any HIPAA review, and patients cannot opt out properly. The carriers also detect “snowshoeing” (spreading traffic across multiple personal numbers to evade A2P) and can block those numbers too. The right answer is to register properly under 10DLC, not to find workarounds.
Abubakar Nazir
Founder & Principal · NexioBit
I run NexioBit, an AI-powered marketing agency that works exclusively with US medical spas. We deploy GoHighLevel as the marketing layer for aesthetic practices, including HIPAA configuration, A2P 10DLC registration, AI voice agents, and the workflows behind real revenue numbers like the SoCal Slim build. If your medspa texts are not landing and you are not sure why, that is a 30-minute call away from being diagnosed. No sales rep, no slides.
More about NexioBitWant your medspa texts actually delivering?
30-minute call, no sales rep. I will look at your GoHighLevel account, your current 10DLC status, and your campaign templates, and tell you exactly what is broken and what it takes to fix it. Free if it does not help, honest either way.
Book my compliance check call