Skip to content

Passwordless Staff Portal and Twilio Move for Healthcare SMS Alerts

A passwordless staff portal reached from each SMS, an admin dashboard for 3,000+ facilities, and a compliant move of staff alerts to Twilio.

HealthcareA US healthcare staffing communications provider, delivered through a technology partner ยท 4 min read

Health worker in scrubs checking details on a tablet at a reception counter
Client
A US healthcare staffing communications provider, delivered through a technology partner
Industry
Healthcare
Platforms
Web
Download one-pager (PDF)
  1. The challenge

    Health staff received SMS notifications for facilities they no longer worked at and had no easy way to fix their details. Administrators managed more than 3,000 facility locations. Notifications ran through an email marketing tool with limited delivery tracking, and any move had to comply with US messaging rules.

  2. What we built

    Working through a technology partner, we built a mobile-first staff portal and an admin dashboard in React and Node.js on AWS. Each SMS carries a unique login link, and staff sign in with a one-time code. We moved sending to Twilio, registered numbers for A2P 10DLC and handled delivery and opt-outs through webhooks.

  3. The result

    Staff fix their own name, number, facility and notification choices from their phone without a password. Administrators manage staff and facilities, see an audit trail and send SMS to chosen groups. Notifications go out through Twilio with delivery, failure and opt-out events tracked.

What the system does.

The parts of the system that made the difference for the client and the people who use it.

  • Login link in every SMS

    Each notification carries a unique link that takes the staff member straight to their settings.

  • Passwordless sign-in

    Staff enter their mobile number and receive a one-time code, with rate limits on requests.

  • Facility search

    Staff pick their current facility from a searchable list of more than 3,000 locations.

  • Admin dashboard

    Admins search and edit staff, manage facilities, import and export by CSV, and schedule SMS to chosen groups.

  • Audit logs and roles

    Every change is logged with time and admin; super admins, regional managers and support staff have different rights.

  • Twilio migration

    Existing workflows audited, templates rebuilt with login links, and contacts cleaned of duplicates and invalid numbers.

  • A2P 10DLC and opt-outs

    Numbers registered for application-to-person messaging, with consent and opt-out handling built to TCPA rules.

  • Delivery tracking

    Webhooks capture delivery receipts, bounces and opt-outs, and failed sends are retried within carrier limits.

Built with

The tools behind it, layer by layer.

  1. Front end

    • React
  2. Back end

    • Node.js
    • Express.js
  3. Database

    • MongoDB
  4. Cloud and hosting

    • AWS
  5. CI/CD and DevOps

    • GitHub Actions
    • Git
  6. Integrations

    • Twilio Verify
    • Twilio Messaging

The full story

The challenge

A US healthcare staffing communications provider texts health staff about shifts at the facilities where they work. Working through a technology partner, we built it a passwordless staff portal and ran a Twilio A2P 10DLC migration for its staff alerts.

Staff move between facilities, but their records did not always move with them. People kept getting notifications for places they no longer worked, and they had no easy way to correct their own details. Administrators, meanwhile, were looking after more than 3,000 facility locations.

The texts went out through an email marketing tool with limited delivery tracking. Moving them was more than a copy job. Business texting in the US runs on registered numbers, and consent and opt-outs must follow the Telephone Consumer Protection Act (TCPA).

So the provider needed two things at once: a way for staff to keep their own records current, and a sending setup whose every message it could account for.

What we built

We delivered the first phase in two parts, on React and Node.js with MongoDB on AWS.

A staff portal reached from every text. Each SMS carries a unique login link. Staff enter their mobile number, receive a one-time code and land on their own settings, with no password to remember. Code requests are rate-limited.

From there, staff edit their name, number and current facility, picking it from a searchable list of more than 3,000 locations. They also choose which notifications they want to receive.

An admin dashboard. Admins search and edit staff records, manage the facility list and import or export data by CSV. They schedule SMS to chosen facilities or groups. Every change is logged with the time and the admin who made it, and roles separate super admins, regional managers and support staff.

The move to Twilio. We began by documenting the existing workflows and templates. Then we:

  • set up Twilio messaging services and registered the numbers for A2P 10DLC;

  • rebuilt each template with a short login link to the new portal;

  • cleaned the contact list of duplicates and invalid numbers, and linked each contact to a current facility;

  • added webhooks for delivery receipts, bounces and opt-outs, and retried failed sends within carrier limits.

How it works day to day

Picture a health worker who has just started at a new facility. The next alert still names the old one, so she taps the link in the message, confirms the code sent to her phone, searches for the new facility and saves it. The following alert reaches her for the right place.

If she later replies to opt out, a webhook records it and the texts stop. Consent and opt-out handling were built with the TCPA in mind, and every message is logged for compliance checks.

On the admin side, a regional manager can open the audit log to see who changed a record and when. The same manager can schedule a message to the staff at one facility without touching anyone else's settings.

The result

Staff now fix their own name, number, facility and notification choices from their phone, without a password. Administrators manage staff and facilities from one dashboard, with an audit trail, and send SMS to the groups they choose.

Notifications go out through Twilio, and delivery, failure and opt-out events are tracked instead of assumed. The same partner has since asked us to scope a secure enterprise messaging platform.

What the research says

  • Phones are where staff are. Pew Research Center found that 98% of US adults own a cellphone and 91% own a smartphone, in a survey run from February to June 2025 (Pew Research Center, Mobile Fact Sheet). A link inside a text meets people on the device they already carry.

  • Passwords are the weak point. Verizon's 2025 Data Breach Investigations Report found that about 88% of breaches in its basic web application attack pattern involved stolen credentials (Verizon DBIR 2025). Signing in with a one-time code sent to the staff member's phone leaves no password to steal or reuse.

  • Unregistered numbers don't get through. According to Twilio's own changelog, unregistered messages sent to the US from +1 10DLC numbers have been blocked since September 1, 2023 (Twilio, vendor notice). Registering the numbers for A2P 10DLC was part of the move, not an afterthought.

Where AI fits next

These ideas are not in the portal today. A model could sort free-text SMS replies into opt-outs, questions and shift responses for staff to act on. It could flag records that look stale, such as a facility with no recent replies, and prompt an update. Delivery history could also point to numbers likely to fail before a send.

Planning a Twilio A2P 10DLC migration?

Before you move business texting to a new provider, it helps to answer four questions:

  1. Who registers the brand and campaigns, and who keeps the consent records?

  2. How will opt-outs collected by the old system carry over on day one?

  3. Can recipients fix their own details, or does every change go through an admin?

  4. Which delivery events do you need to see, and who acts on a failed send?

See how we approach web application development and legacy modernization, read our guide to the signs a legacy system needs modernization, or explore our healthcare software work.

Common questions

What is an A2P 10DLC migration?

It moves business text messaging onto standard 10-digit US numbers that are registered for application-to-person traffic. In this project we set up Twilio messaging services, registered the numbers for A2P 10DLC, rebuilt the templates and moved cleaned contact data across.

How do staff sign in without a password?

Every SMS carries a unique login link. Staff enter their mobile number, receive a one-time code and go straight to their settings. Code requests are rate-limited.

How are SMS opt-outs handled?

Webhooks capture opt-outs along with delivery receipts and bounces, and consent and opt-out handling were built to TCPA rules. Under the FCC's rules, a reply such as "stop" is a valid way to revoke consent and must be honored within ten business days at most.

What can administrators do in the dashboard?

They search and edit staff, manage more than 3,000 facility locations, import and export by CSV and schedule SMS to chosen facilities or groups. Every change is logged with the time and the admin, and roles separate super admins, regional managers and support staff.

What was the system built with?

React and Node.js, with MongoDB on AWS, Twilio Verify for one-time codes and Twilio Messaging for the alerts.

More of our work.

Projects that used the same services or served the same industry.

See all our work

Free project estimate

Talk through a project like these.

Thirty minutes with a founder, not a salesperson. Bring the problem; leave knowing what we'd build first and what it would cost.

What you get back

  • An indicative budget range
  • A realistic timeline
  • What moves the cost up or down
  • A reply within 4 business hours
  • Answered by a founder
  • NDA on request, before you share details

Tell us what you need

A few lines is plenty. You get a number before any call.

Fields marked * are required.