Photos and testimonials: written authorization or nothing
Summary
Only with a valid written HIPAA authorization signed before you use them. A patient's photo, name, or story used to promote your practice is marketing under the Privacy Rule, and marketing with protected health information requires authorization — not a verbal okay, not a treatment consent, not a thumbs-up text. The same rule catches the reply button: publicly confirming that someone is your patient, even to answer a review, is a disclosure. Get the signed form first, or use nothing identifiable.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
Can I use patient photos or testimonials?
Only with a valid written HIPAA authorization, signed before the material goes anywhere. Using a patient's image, name, or story to promote your practice is marketing, and the Privacy Rule requires a signed authorization before you use protected health information for marketing — there is no implied or verbal consent that will do 1Ref 1HHS Office for Civil Rights (2026).Marketing.That using PHI for marketing requires a signed HIPAA authorization, with only narrow exceptions, and how HIPAA defines marketing.. A happy patient saying 'feel free to use my story' is not authorization; the form is.
The instinct to share a glowing note is human, but the rule does not turn on how positive the content is. It turns on whether the material reveals that a specific person is your patient.
Why this counts as 'marketing' — and why marketing needs a signature
Marketing, in HIPAA terms, is a communication that encourages someone to use a service, and using PHI to make it is what triggers the authorization requirement 1Ref 1HHS Office for Civil Rights (2026).Marketing.That using PHI for marketing requires a signed HIPAA authorization, with only narrow exceptions, and how HIPAA defines marketing.. A testimonial names or identifies a patient; a photo shows one. Both are protected health information once tied to your practice, because they reveal that the person received care from you 2Ref 2HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.That the Privacy Rule governs use and disclosure of PHI and requires authorization outside treatment, payment, and operations.. That is the disclosure — not the flattering content, but the fact of the treatment relationship.
This is also where the covered-entity test matters: if HIPAA applies to your practice at all, it applies to your marketing, and the same authorization standard governs a website banner and a social post alike.
Revocation, minors, and expiration
Every authorization must let the patient revoke it, and you honor a revocation going forward: you stop new uses, though you cannot always retrieve material already printed or widely shared 3Ref 3Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The rule text on the core elements of a valid authorization, revocation, and the de-identification standard.. Build an expiration into the form so stale permissions lapse on their own. For a minor or an incapacitated adult, the person who signs is the personal representative — usually a parent or guardian — under the same state-deferring rules that govern their records 5Ref 5HHS Office for Civil Rights (2026).Personal Representatives.That a personal representative signs for a minor or incapacitated adult under state-deferring rules..
Keep a way to act on a revocation quickly: know where each piece of authorized content lives so that 'please take it down' can actually happen, not just be promised.
A compliant workflow for photos and testimonials
Set it up once and the rule enforces itself. Keep a dedicated marketing-authorization form separate from clinical consents, collect the signature before anything is used, log it, and diary the expiration. Posting identifiable patient content without that signed form is an impermissible disclosure — and an impermissible disclosure of unsecured PHI is a breach, with its own notification duties 6Ref 6HHS Office for Civil Rights (2026).Breach Notification Rule.That an impermissible disclosure of unsecured PHI is a breach carrying notification duties.. Vet your website too.
- One marketing-authorization form, never buried in the intake packet.
- Signed before use; logged; expiration diaried.
- The reply button is a disclosure — never confirm treatment in public.
- Watch the tracking-pixel problem on your site, and prefer pixel-free measurement for analytics.
The patient in the background
Marketing photos of your own space carry a hidden risk: the patient who walks through the frame. An office-tour video, a grand-opening photo, or a waiting-room shot can capture a recognizable patient who never agreed to appear in your marketing — and their presence in your office is itself the disclosure of a treatment relationship.
Shoot promotional images when no patients are present, or review every frame for anyone identifiable before it is published. The same caution applies to what sits in the background: a schedule, a name on a monitor, a chart left on a desk. Treat the whole frame as potential PHI. When you cannot avoid an identifiable person, a signed authorization is the only fix — and if you cannot get one, the image does not run.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Marketing. U.S. Department of Health and Human Services. linkThat using PHI for marketing requires a signed HIPAA authorization, with only narrow exceptions, and how HIPAA defines marketing.
- 2.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThat the Privacy Rule governs use and disclosure of PHI and requires authorization outside treatment, payment, and operations.
- 3.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The rule text on the core elements of a valid authorization, revocation, and the de-identification standard.
- 4.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR has penalized impermissible disclosures, including public responses to patient reviews, in small practices.
- 5.HHS Office for Civil Rights (2026). Personal Representatives. U.S. Department of Health and Human Services. linkThat a personal representative signs for a minor or incapacitated adult under state-deferring rules.
- 6.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThat an impermissible disclosure of unsecured PHI is a breach carrying notification duties.
https://www.gale.care/for-providers/hip-photos-testimonials-consent · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.