Compliance · 5 min read

Clinics on WhatsApp: What Must Never Go in the Message Body

The PostEngage teamEngineering and support ·

Two different questions get muddled whenever a clinic looks at WhatsApp.

The first is which messages you are allowed to send. That one has a mechanical answer: inside the twenty-four-hour window a patient opens by writing to you, freely; outside it, pre-approved templates only, with opt-in.

The second is what those messages are allowed to say. That one has no mechanical answer at all, and it is the question that matters more.

The front desk is the automatable part

Strip a clinic's inbox down and a large share of it never touches medicine.

What are your timings. Is Dr Kulkarni in on Saturday. What does a first consultation cost. Do you take that insurance. Where do I park. Aaj open ho? Do I need to fast before the blood test. How do I get a copy of my last prescription.

Every one of those is a fact about the clinic, not a fact about a patient. They arrive as patient messages, which means they can be answered inside the service window without templates and without approval. That is the honest scope of a clinic automation: the front desk on a Sunday night.

An automation belongs in front of the clinic, not inside it.

The part that must be refused

Symptoms. Diagnoses. "Should I stop this medicine." "Is this rash serious." "Kya main emergency mein aaun?" "Can I take these two together." Test result interpretation. Dosage. Anything about a pregnancy, a child's fever, chest pain, or a mental health crisis.

None of that goes to an automated reply, ever. Not with a hedge, not with a disclaimer attached, not with a "this is not medical advice" line at the bottom. The reason is not only regulatory — though what a clinic may communicate, and by whom, varies by jurisdiction and is a question for your own regulator and legal advisers rather than for a blog. The reason is that a language model produces a fluent, calm, confident answer to every question put to it, and has no way to represent "the consequence of my being wrong here is a person who does not go to hospital tonight."

What goes in the template body

Here is the part clinics genuinely underthink.

WhatsApp lands on a phone that may be shared with a spouse, a parent, an adult child. Message previews show on a lock screen. A template you wrote for one reader is often read by two.

So the discipline is subtraction. Take out anything that is not needed to accomplish the message.

  • "Your appointment is confirmed for Tuesday, 11:15am." Not "your fertility consultation is confirmed."
  • "An update on your recent visit is ready. Please call the clinic or collect from reception." Not the result, not the test name, not the department.
  • "A payment is pending against your visit of 12 June." Not what the visit was for.

The message's job is to prompt a next action. The clinical content lives behind a phone call, a portal login, or a person at a desk. This costs you nothing and removes a category of harm that has no upside.

The same subtraction applies to the variables you fill templates with. If a variable does not need the patient's condition in it, do not build it that way — because once a template exists with a diagnosis field, somebody will use it.

A patient gave the clinic a phone number so the clinic could run their care. That is a purpose. Sending appointment logistics fits inside it comfortably; a monthly newsletter about the new physiotherapy wing does not, and a health-camp promotion certainly does not.

Opt-in is required before template messages on the platform, and separately, most places now have data protection expectations about notice, purpose and withdrawal that a clinic should take advice on rather than guess at. Rules vary and they are changing. The practical posture is the same everywhere: ask for the two permissions separately, write down when and how each was given, and make withdrawal something the front desk can actually action.

  1. Two boxes on the intake form. Appointment and care logistics. Clinic news and health programmes. Never one box doing both jobs.
  2. A named person who owns the number list. Who can send, who can add, who removes someone who asked to be removed.
  3. Templates reviewed by whoever signs off clinical communication. Approval by Meta is a platform check, not a clinical one.
  4. A written refusal list. The words and phrases that stop an automated reply entirely. Symptom vocabulary in every language your patients type in, including transliterated Hindi.

The platform in one paragraph

The WhatsApp Business Platform, the Cloud API, needs a Meta Business account and business verification. Templates go to Meta and come back approved or rejected. Meta charges per conversation, by category; the rates depend on the country and change, so treat cost as a shape to design around. The free WhatsApp Business app on the reception phone is a separate, simpler product and is often where a single-doctor clinic should stay.

What runs today

PostEngage answers Instagram comments and DMs, and nothing more. For clinics that is mostly the enquiry half — the reel about a procedure, the comments asking cost, the DM asking whether you treat something.

The clocks differ. A comment stays answerable for seven days; a DM thread for twenty-four hours, restarted only when the patient writes again. Templated replies are free and unlimited, and a credit is spent only when the AI writes new text — which is another argument for a clinic to run on fixed replies and refusals rather than generated ones. Free tier is 100 credits with no card, packs from ₹499.

Further reading that continues this: healthcare clinics on Instagram, dentists and doctors on the refusal list, and compliance and privacy for the data side.

One email when we publish.

No drip sequence, no “quick question” follow-up. Unsubscribe is one click and we honour it immediately.