The challenge
A US healthcare staffing communications provider texts health staff about shifts at the facilities where they work. Working through a technology partner, we built it a passwordless staff portal and ran a Twilio A2P 10DLC migration for its staff alerts.
Staff move between facilities, but their records did not always move with them. People kept getting notifications for places they no longer worked, and they had no easy way to correct their own details. Administrators, meanwhile, were looking after more than 3,000 facility locations.
The texts went out through an email marketing tool with limited delivery tracking. Moving them was more than a copy job. Business texting in the US runs on registered numbers, and consent and opt-outs must follow the Telephone Consumer Protection Act (TCPA).
So the provider needed two things at once: a way for staff to keep their own records current, and a sending setup whose every message it could account for.
What we built
We delivered the first phase in two parts, on React and Node.js with MongoDB on AWS.
A staff portal reached from every text. Each SMS carries a unique login link. Staff enter their mobile number, receive a one-time code and land on their own settings, with no password to remember. Code requests are rate-limited.
From there, staff edit their name, number and current facility, picking it from a searchable list of more than 3,000 locations. They also choose which notifications they want to receive.
An admin dashboard. Admins search and edit staff records, manage the facility list and import or export data by CSV. They schedule SMS to chosen facilities or groups. Every change is logged with the time and the admin who made it, and roles separate super admins, regional managers and support staff.
The move to Twilio. We began by documenting the existing workflows and templates. Then we:
set up Twilio messaging services and registered the numbers for A2P 10DLC;
rebuilt each template with a short login link to the new portal;
cleaned the contact list of duplicates and invalid numbers, and linked each contact to a current facility;
added webhooks for delivery receipts, bounces and opt-outs, and retried failed sends within carrier limits.
How it works day to day
Picture a health worker who has just started at a new facility. The next alert still names the old one, so she taps the link in the message, confirms the code sent to her phone, searches for the new facility and saves it. The following alert reaches her for the right place.
If she later replies to opt out, a webhook records it and the texts stop. Consent and opt-out handling were built with the TCPA in mind, and every message is logged for compliance checks.
On the admin side, a regional manager can open the audit log to see who changed a record and when. The same manager can schedule a message to the staff at one facility without touching anyone else's settings.
The result
Staff now fix their own name, number, facility and notification choices from their phone, without a password. Administrators manage staff and facilities from one dashboard, with an audit trail, and send SMS to the groups they choose.
Notifications go out through Twilio, and delivery, failure and opt-out events are tracked instead of assumed. The same partner has since asked us to scope a secure enterprise messaging platform.
What the research says
Phones are where staff are. Pew Research Center found that 98% of US adults own a cellphone and 91% own a smartphone, in a survey run from February to June 2025 (Pew Research Center, Mobile Fact Sheet). A link inside a text meets people on the device they already carry.
Passwords are the weak point. Verizon's 2025 Data Breach Investigations Report found that about 88% of breaches in its basic web application attack pattern involved stolen credentials (Verizon DBIR 2025). Signing in with a one-time code sent to the staff member's phone leaves no password to steal or reuse.
Unregistered numbers don't get through. According to Twilio's own changelog, unregistered messages sent to the US from +1 10DLC numbers have been blocked since September 1, 2023 (Twilio, vendor notice). Registering the numbers for A2P 10DLC was part of the move, not an afterthought.
Where AI fits next
These ideas are not in the portal today. A model could sort free-text SMS replies into opt-outs, questions and shift responses for staff to act on. It could flag records that look stale, such as a facility with no recent replies, and prompt an update. Delivery history could also point to numbers likely to fail before a send.
Planning a Twilio A2P 10DLC migration?
Before you move business texting to a new provider, it helps to answer four questions:
Who registers the brand and campaigns, and who keeps the consent records?
How will opt-outs collected by the old system carry over on day one?
Can recipients fix their own details, or does every change go through an admin?
Which delivery events do you need to see, and who acts on a failed send?
See how we approach web application development and legacy modernization, read our guide to the signs a legacy system needs modernization, or explore our healthcare software work.



