Guide

Reviews: responding without confirming anyone was ever a patient

Summary

You respond without ever confirming the person was your patient. Even a sympathetic, apparently harmless reply that acknowledges a treatment relationship discloses protected health information, and OCR has penalized practices for exactly that. Post a generic message that neither confirms nor denies care, invites the person to contact the office privately, and reveals nothing specific. To address specifics publicly, you need the patient's written HIPAA authorization first.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

Can I respond to a patient's online review at all?

You can respond to an online review — but not by confirming the reviewer was ever your patient. Under the Privacy Rule, acknowledging that a specific person received care is itself a use or disclosure of protected health information, permitted only where the rule allows it or the patient authorizes it 1. A public reply that references the visit, the diagnosis, or even a sympathetic apology for a long wait confirms the treatment relationship and steps outside those permissions.

The operative rule text treats identifiable health information as protected the moment it can be tied to an individual, and a review thread ties it to a named account 2. That is why the safe move is structural, not a matter of careful wording: you respond in terms that would be true of anyone, patient or not. If you are unsure whether the Privacy Rule even reaches your practice, start with the covered-entity test — but for almost every clinician who bills electronically, it does.

Why a reply that seems harmless is a HIPAA disclosure

The reason a warm, well-meant reply is dangerous is that it does the one thing HIPAA forbids in public: it verifies care. A line like 'we always strive to reduce wait times and apologize for your experience' reads as courtesy, but it confirms the person was seen, which is PHI. OCR has investigated and penalized practices — including small ones — that disclosed patient information while responding to online reviews 3.

The tell is specificity. Any detail that only a treating provider would know — the reason for the visit, the treatment, the outcome, even the date — narrows 'someone' to 'this patient' and converts a reply into a disclosure. The safest reviews to answer are the ones you answer as though you do not know whether the reviewer is a patient, because in a public reply you are not permitted to act as though you do.

What you can safely post: the neither-confirm-nor-deny reply

The reliable reply neither confirms nor denies that the reviewer is a patient. It states your general standards, invites a private conversation, and contains nothing specific. A workable skeleton reads: our practice takes all feedback seriously and is committed to high-quality, respectful care; we are not able to discuss any individual's care in a public forum; if you would like to speak with us, please contact the office directly. Every clause of that is true whether or not the reviewer was ever seen.

DoDon't
Speak in general terms about your standardsConfirm the person was a patient
Invite the reviewer to contact the office privatelyMention the visit, diagnosis, or treatment
Keep every reply identical and impersonalCorrect 'the record' with clinical facts
Move specifics entirely offlinePost dates, times, or outcomes

Using one standing template for every review removes the temptation to personalize under pressure — which is exactly when a specific, disclosing detail slips out.

Getting the patient's authorization to respond specifically

If you want to engage with the specifics publicly — to correct a genuinely false clinical claim, for instance — you need the patient's written HIPAA authorization first, and it has to be specific to that use. A valid authorization names what information may be disclosed, to whom, for what purpose, and when it expires, and it tells the patient they can revoke it 1. 'They posted about it first' is not consent; a patient waiving their own privacy in a review does not authorize you to confirm or expand on it.

In practice, authorization to litigate a review in public is rarely worth seeking. It is slow, it is awkward to ask for, and it can inflame the situation further. The realistic use of authorization is narrower — a patient who asks you to respond to their own post, or agrees to share their story, signs a specific authorization before you say anything identifiable.

Soliciting reviews and testimonials without crossing the marketing line

Soliciting reviews and testimonials is governed by the marketing rule, not just etiquette. HIPAA requires a patient's authorization before you use their protected health information for marketing, and a named testimonial with any care detail is marketing that needs a signed authorization 4. The same applies to the photos and testimonials you feature on your site; consent to treatment is not consent to be advertised, and the two authorizations are separate documents.

Two cautions round this out. First, if you use an outside service to request or manage reviews and it touches your patient contact list, that vendor is a business associate and needs a business associate agreement 5. Second, steering happy patients toward public review sites while diverting unhappy ones to a private channel — review gating — draws scrutiny under advertising rules and platform policies, so ask for feedback the same way from everyone.

When a review is defamatory or names you falsely

A defamatory or false review still does not license a PHI response. Your remedies stay outside the record: flag the review to the platform if it violates the platform's own policy, document it, and, for genuinely defamatory content, take non-HIPAA legal advice — none of which requires you to confirm the person was a patient. Responding with clinical facts to 'set the record straight' is the single most common way a bad review becomes a reportable disclosure.

When a wave of bad press lands at once, the discipline is the same at scale: a consistent, non-confirming public posture, with the real work done privately. Handling the bad week well is a reputation strategy, not a compliance loophole — the practices that come through cleanly are the ones that never once traded a patient's privacy for the last word.

Common questions

Confirming the person was seen is a disclosure even when the sentiment is positive, so a public thank-you for choosing the practice still verifies care. If you reply to good reviews at all, keep it generic and identical to every other reply — a simple appreciation of feedback that would read the same whether or not the reviewer was ever a patient of yours.

No. A patient revealing their own care in a review waives their privacy for their own post, but it does not authorize you to confirm, expand on, or correct it in public. The Privacy Rule permission has to run from the patient to you, in a specific written authorization. Until then, respond only in the neither-confirm-nor-deny form that reveals nothing about any individual.

Yes, but ask every patient the same way rather than screening for likely praise, and never publish a named testimonial with clinical detail without a signed authorization. Soliciting a review is fine; using protected health information to market the practice is what triggers the authorization requirement. Sending the same neutral request to everyone also keeps you clear of review-gating concerns under advertising rules.

Reviews live on third-party platforms, not in your medical record, so hiding or flagging one is not a records or access issue. Your only real constraint is your own response: do not reply with anything that identifies the reviewer as a patient. Flagging a policy-violating review to the platform, and documenting the incident internally, are both fine and involve no disclosure of protected health information.

If a reputation or review-management service can see your patient contact list or any protected health information, it is a business associate and needs a business associate agreement before you use it. A tool that only monitors public reviews and never receives PHI from you generally is not. Evaluate what data the vendor actually touches, not how the product is marketed to you.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkConfirming a treatment relationship is a use or disclosure of PHI permitted only where the Privacy Rule allows or a valid patient authorization exists.
  2. 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe operative Privacy Rule text governs permitted uses and disclosures of individually identifiable health information.
  3. 3.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkOCR has investigated and penalized practices, including small ones, for disclosing patient information while responding to online reviews.
  4. 4.HHS Office for Civil Rights (2026). Marketing. U.S. Department of Health and Human Services. linkHIPAA requires patient authorization before using PHI for marketing, which includes named testimonials with care detail.
  5. 5.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkA review-management vendor that receives patient contact information or PHI on the practice's behalf is a business associate requiring a BAA.

https://www.gale.care/for-providers/hip-responding-online-reviews · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)