Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Can We Reply to That Review? HIPAA Q&AData Privacy
5 min readFor Compliance Officers

Can We Reply to That Review? HIPAA Q&A

These questions come from privacy officers, compliance managers, and practice administrators who've reached out after reading our analysis of 80,300 healthcare review replies. Many were surprised to learn that 26% of the replies we examined potentially disclosed patient information. The confusion isn't about the HIPAA Privacy Rule itself; it's about how that rule applies when someone on your team is typing a Google review response at 4 PM on a Friday.

Here's what people are actually asking.

Can we respond to reviews at all, or is it safer to just ignore them?

You can and should respond. Just don't confirm anything about the reviewer's care.

The HIPAA Privacy Rule doesn't prohibit public communication. It limits uses and disclosures of protected health information unless the disclosure is permitted by the Rule or supported by a valid authorization. The problem isn't the reply; it's what gets said in the reply.

A safe response acknowledges the feedback without acknowledging the care relationship: "Thank you for taking the time to share your feedback. We appreciate it." That works for positive and negative reviews. It's compliant, even if it's not exciting.

The unsafe pattern is personalization that confirms the reviewer received care, mentions a condition or procedure, or references billing. "We're glad your sciatica improved after your adjustments" might feel warm, but you've just publicly linked an identifiable person to a diagnosis and treatment.

The patient posted about their own diagnosis publicly. Doesn't that mean we can talk about it too?

No. The patient's decision to disclose their own information does not create permission for you to confirm, expand on, or repeat it.

This is a common misconception. Your reply is a separate disclosure, made by a HIPAA-covered entity, in your capacity as a healthcare provider. The fact that the patient said it first doesn't change your obligations under the Privacy Rule.

The Office for Civil Rights (OCR) has enforced this principle repeatedly. Elite Dental Associates paid $10,000 to settle potential violations involving social-media disclosures. Dr. U. Phillip Igbinadolor, D.M.D. & Associates faced a $50,000 civil money penalty after impermissibly disclosing a patient's PHI on a webpage in response to a negative review. New Vision Dental paid $23,000, and Manasa Health Center paid $30,000 and entered a corrective action plan for similar issues.

The safe rule: if the review mentions a clinical detail, your public reply doesn't.

What if the review is factually wrong or unfair? Can we at least correct the record?

Not in public, and not by discussing the patient's care.

If someone posts "They billed me twice for the same X-ray," your instinct may be to explain what actually happened. Doing so in a public reply confirms the person was a patient, received an X-ray, and had a billing issue, all of which are protected health information tied to an identifiable individual.

Instead, invite them to a private channel: "We'd like to address your concerns directly. Please contact our office manager at [number] so we can review this with you." That shifts the conversation to a space where you can verify identity, discuss specifics, and resolve the issue without creating a public record.

The review will still be visible, and it may still be wrong. That's frustrating. But a HIPAA violation in response to an unfair review doesn't make the situation better.

We use an AI tool to draft review responses. Does that change anything?

It changes the risk profile, not the rule.

A generative system prompted to "write a warm, personal response" will often use the content of the review as context. If the reviewer mentions a diagnosis, procedure, or treatment outcome, a personalization-first system may mirror that information back into your public response. Without a compliance rule in the workflow, automation converts an occasional human mistake into a repeatable process.

You need to govern the output. Configure your templates and instructions so the system never repeats clinical, visit, or billing details from the review. Test the workflow with deliberately sensitive examples before you deploy it. And make sure the person approving AI-drafted replies has been trained on what cannot be confirmed publicly, a human approval step is only useful if the human knows what to look for.

The tool doesn't become safe because it has an AI feature. It becomes safe when the workflow enforces a no-PHI rule.

Who on our team needs to be trained on this?

Everyone who posts public replies or approves them.

That often includes front-desk staff, office managers, marketing coordinators, and third-party agencies with access to your review platforms. General annual HIPAA training may not be specific enough to catch this workflow, because the risk isn't obvious until someone is actually drafting a response.

Your training should cover three points: what counts as confirming care (patient/visit acknowledgment, clinical details, billing references), why "the patient said it first" isn't a safe rule, and what a compliant reply looks like in practice. A small library of safe templates reduces the pressure to improvise.

If you've outsourced review management, your vendor needs the same training and the same policy. The Business Associate Agreement doesn't eliminate your compliance obligation; it just defines who's responsible when something goes wrong.

Do we need to go back and delete old replies that confirmed patient information?

Audit first. Preserve a record. Involve your privacy officer or counsel before any broad cleanup, especially if you're aware of a complaint, investigation, or litigation hold.

Historical replies are discoverable, and a mass deletion without documentation can create its own problems. If you find disclosure-risk replies, your next step depends on whether you've received a complaint, whether you're under investigation, and what your legal counsel advises.

What you can do immediately is stop the pattern going forward. Adopt a no-PHI public-reply rule, train the people who post, and audit new replies for the next 90 days to confirm the workflow has changed.

The larger issue isn't any single reply. It's that many practices have been running this workflow for years without realizing the exposure was accumulating in plain sight.

Where to go for more

Start with your HIPAA Privacy Rule compliance documentation and confirm that your policies explicitly address public-facing communication, including review platforms and social media. If your current policy is silent on public replies, that's the gap.

OCR's guidance on social media and HIPAA is a useful reference, though it doesn't provide reply-by-reply instruction. The enforcement actions cited above, Elite Dental, Igbinadolor, New Vision Dental, Manasa Health Center, are public and searchable, and they show what OCR considers a violation in this context.

If you're using a review-management platform or AI tool, request documentation on how the system handles PHI and what configuration options are available to enforce a no-disclosure rule. If the vendor can't answer that question clearly, that's a signal.

This is a solvable problem. The fix is a one-page policy, a disciplined audit, and training that connects the Privacy Rule to the actual work of answering reviews. Most practices can eliminate this exposure in a single compliance cycle, if they know to look for it.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like