HIPAA & Google Reviews: What You Can Legally Say | MrRepo
A patient posts a one-star review of your practice. It's inaccurate. It leaves out the part where they no-showed twice, argued about their balance, and refused the treatment you recommended. You know the full story, and the full story makes you look reasonable.
Type that story into the reply box and you have committed a federal privacy violation.
That is not a hypothetical. Between 2019 and 2025, the HHS Office for Civil Rights (OCR) has penalized at least four providers specifically for what they wrote in response to online reviews — including three dental practices — plus a fifth for posting patient "success stories" on its own website. The penalties ranged from $10,000 to $182,000.
Meanwhile, the pressure to have a strong review profile has never been higher. In rater8's 2026 Patient Choice Report, 75% of patients said they would not book with a provider rated below 4.0 stars, and 44% won't go below 4.5. For comparison, BrightLocal's 2026 Local Consumer Review Survey found 68% of consumers set a 4.0 minimum across all business types and 31% require 4.5. Patients hold healthcare to a higher bar than they hold restaurants.
So practices are squeezed from both sides: they need reviews more than a coffee shop does, and they have far less freedom to talk about them. This guide covers exactly where the line sits — what you can say, what you can ask for, and the templates that keep you on the right side of both OCR and the FTC.
A note on scope: this is general information for practice owners and office managers, not legal advice. HIPAA applies to covered entities and their business associates; state privacy, dental board, and medical board rules can be stricter. Run your final policy past your own counsel.
Table of contents
<a name="enforcement"></a>
What the enforcement record actually shows
Most compliance articles gesture vaguely at "HIPAA risk." The record is more specific than that, and reading the actual cases tells you where the line is far better than any summary.
| Provider | Year announced | Amount | What happened |
|---|---|---|---|
| Elite Dental Associates (Dallas, TX) | Oct 2019 | $10,000 settlement | Responded to a Yelp review disclosing the patient's last name, treatment plan details, insurance information and costs. Notice of Privacy Practices also fell short of the minimum content required by 45 CFR 164.520(b). |
| Dr. U. Phillip Igbinadolor, D.M.D. & Associates (Charlotte/Monroe, NC) | Mar 2022 | $50,000 civil money penalty | Replied to a Google review naming the patient, reciting his treatment history and missed appointments, disparaging him, and signing off "Get a life." |
| New Vision Dental (South Pasadena, CA) | Dec 2022 | $23,000 settlement | Replied to Yelp reviews using patients' full names even though the reviewers had posted under pseudonyms, and disclosed visit, treatment and insurance details the patients had never made public. |
| Manasa Health Center (Kendall Park, NJ) | Jun 2023 | $30,000 settlement | A psychiatric practice disclosed diagnoses and mental-health treatment details for at least four patients while responding to negative Google reviews. |
| Cadia Healthcare Facilities (DE) | Sep 2025 | $182,000 settlement | Posted 150 patients' photos, names and details of their conditions, treatment and recovery as "success stories" on its website and social media without signed authorizations. |
Three details in that table deserve more attention than they usually get.
First, the Igbinadolor case was a civil money penalty, not a settlement. OCR classified it as "willful neglect — not corrected," which under 45 CFR 160.404(b)(2)(iv) carries a floor of $50,000 per violation. The trigger for "not corrected" was simple: the post went up in September 2015, OCR told the practice in August 2016 that it was impermissible, and the reply was still live when OCR issued its Notice of Proposed Determination in October 2020. Roughly five years. The cheap fix — deleting the comment — was available the entire time.
Second, New Vision Dental is the case that should scare you most, because the practice was arguably telling the truth. The problem wasn't fabrication. It was that the patients had deliberately reviewed under pseudonyms and the practice named them, then added details the patients themselves had never posted. Accuracy is not a defense. Disclosure is the violation.
Third, Cadia in 2025 shows the exposure isn't limited to review replies. OCR Director Paula M. Stannard put it plainly: "Generally, a valid, written HIPAA authorization from an individual is necessary before a covered entity or business associate can post that individual's PHI in a website testimonial or through a social media campaign." If your site has a smiling before-and-after page, or your front desk posts birthday shout-outs on Instagram, that is the same legal category as a review reply — and at $182,000, it's currently the most expensive one on record.
<a name="no-waiver"></a>
Why HIPAA still applies after the patient goes public
This is the single most common misunderstanding in practice management, and it's the one that generates the penalties.
The intuition goes: they published it themselves, so it's public, so it's fair game. HIPAA doesn't work that way. The Privacy Rule restricts what you may disclose. It says nothing about what the patient may disclose about themselves, and it contains no mechanism by which a patient's own public statement releases you from your obligations.
As the Medical Group Management Association put it when asked whether a patient waives their rights by posting a review: no — and HIPAA has no "waiver" concept at all. The only route to permission is a written authorization that satisfies 45 CFR 164.508.
Now the part that catches careful people out. Under 45 CFR 160.103, "individually identifiable health information" includes information that relates to the provision of health care to an individual and identifies them. Confirming that a named person received care from you is therefore itself a disclosure of protected health information — before you have said one word about what the care involved.
The practical consequence, as the health care team at Bass, Berry & Sims noted in 2024, is that even a warm reply to a five-star review is technically a violation if it confirms or implies that the reviewer was your patient. "Thank you so much, we loved seeing you last Tuesday!" is a HIPAA disclosure. So is "We're glad your crown is feeling better."
That's an uncomfortable rule, because it collides with everything else you know about reputation management. Our guide on how to respond to positive reviews applies straightforwardly to a restaurant or a salon. In a clinical setting, the same instincts need a filter.
<a name="safe-reply"></a>
The only safe way to reply to a review
The workable approach is to reply in a way that is completely content-free about the individual and completely substantive about your practice's process. You are speaking to the hundreds of prospective patients reading the thread, not to the reviewer.
This matters more than it used to. In rater8's 2026 data, 66% of patients said a provider's response to reviews directly influences whether they trust that provider — up from 42% a year earlier, the largest single-year jump in that study. Silence is expensive. Tebra's 2025 survey of 203 US providers found 45% never respond to negative reviews at all. Doing this correctly is a real competitive gap.
Template 1 — negative review (the default)
Thank you for taking the time to share this. Patient privacy laws prevent us from discussing anyone's care — or confirming whether someone is a patient — in a public forum, so I'm not able to respond to specifics here. That restriction is not an evasion; it applies to every practice. What I can tell you is that we take concerns about [wait times / billing / communication] seriously, and we review every one of them. Please call our office at [number] or email [address] and ask for [name] so we can look into this properly.
— [Name], [Role]
Why this works: it never confirms a treatment relationship, it explains why it can't (which reads as competence rather than stonewalling), it names a category of concern without confirming this person experienced it, and it moves the conversation off the public thread.
Template 2 — positive review
Thank you — reviews like this genuinely make our team's week. Privacy rules mean we can't discuss individual experiences publicly, but we're grateful you took the time, and we'll make sure the whole team sees it.
Short, warm, and it never says "you" in a way that confirms anything.
Template 3 — a review you believe is not from a patient
Thank you for the feedback. We're not able to discuss individual experiences publicly, and we have no record matching this description. If you've been in our care and something went wrong, please contact us directly at [number]. If this was posted in error or about a different practice, we'd appreciate you taking a look.
Note the careful phrasing: "no record matching this description" is not the same as "you were never our patient," which would itself be a disclosure — a denial confirms you searched your records for a named person.
The three sentences to delete from any draft
Before anything goes live, scan the reply for these and cut them:
Any date, procedure, diagnosis, balance, insurer, or appointment history. Even "you were last seen in March" is PHI.
Any second-person confirmation of care — "when you came in," "your treatment," "we saw you."
Any correction of the patient's account. Correcting the record requires disclosing the record.
One more discipline, learned from the Igbinadolor case: if something non-compliant is already live under your practice's name, take it down today. The $50,000 floor attached to the failure to correct, not to the original post.
<a name="asking"></a>
Asking patients for reviews without breaking HIPAA
Here's the encouraging half of the story. HIPAA restricts what you say about patients far more than it restricts what you ask of them — and asking is where the actual growth is. rater8's 2026 report found 68% of patients would leave a review if their doctor asked, while 42% rarely or never leave reviews on their own.
Is a review request "marketing" under HIPAA? On the text of the rule, no. 45 CFR 164.501 defines marketing as a communication "about a product or service that encourages recipients of the communication to purchase or use the product or service." A neutral invitation to share feedback doesn't encourage a purchase. Using a patient's contact details to send it is a use of PHI for health care operations — which expressly includes quality assessment, evaluating practitioner performance, and customer service — and is permitted without authorization under 45 CFR 164.506. Be aware this is a reading of the regulation, not a published OCR ruling; there is no HHS FAQ addressing review solicitation by name. Document your reasoning in your policy.
Three rules keep the request itself clean:
The message contains no PHI beyond the minimum necessary. "Thanks for visiting us today" is fine. "How was your root canal?" is not — text messages get read on lock screens by other people.
Any vendor that touches patient contact data is a business associate and needs a signed BAA. This is the step practices skip most often.
Never make the ask conditional on how the patient feels. Filtering happy patients toward Google and unhappy ones elsewhere is review gating, which violates Google's policies regardless of HIPAA.
Texting patients: the TCPA problem nobody mentions
HIPAA is not the only statute in play. Under the Telephone Consumer Protection Act, a text that promotes your practice's commercial standing is an advertisement, and advertising texts to a mobile number require prior express written consent — a higher bar than the "prior express consent" that covers appointment reminders.
The healthcare carve-out at 47 CFR 64.1200(a)(2) does not rescue you here. It covers treatment-related messages: refill reminders, appointment reminders, post-discharge follow-up. A review request isn't a health care message, and a message that mixes both purposes gets treated as marketing.
Practically: add explicit, separately-signed consent to receive non-clinical messages to your intake paperwork, keep the record, and honor opt-outs. The FCC's revocation rules that took effect in April 2025 require any reasonable revocation method to be honored within 10 business days.
And the FTC rule, which applies to everyone
The FTC's Rule on the Use of Consumer Reviews and Testimonials (16 CFR Part 465) took effect 21 October 2024. It bans fake and AI-generated reviews, buying reviews conditioned on positive sentiment, undisclosed reviews written by staff or their relatives, and suppressing negative reviews through threats. Maximum civil penalties currently run to $53,088 per violation — that's the 2025 figure, carried into 2026 because the annual inflation adjustment was cancelled.
The staff-reviews prohibition is worth flagging for practices specifically. Asking your hygienists or their spouses to post five-star reviews without disclosing the relationship is a straightforward violation, and it's common. For compliant request scripts and timing, see our guide on how to ask for Google reviews.
<a name="non-clinical"></a>
Most negative healthcare reviews aren't about clinical care
This is the finding that should change how you read your review page.
In the largest peer-reviewed analysis to date — Sehgal and colleagues in JAMA Network Open (2025), covering 1,099,901 Yelp reviews of 138,605 US healthcare facilities between 2017 and 2023 — the topic most strongly correlated with a negative rating was payment issues (r=0.25), edging out poor treatment (r=0.24). Poor phone experience and long hold times were among the strongest drivers of low ratings. On the positive side, kindness and relief of anxiety (both r=0.32) outranked anything clinical.
A 2025 British Dental Journal study of 48,862 dental reviews found the same shape: negative reviews were driven consistently by staff behavior, appointment scheduling and cancellations, and telephone access — administrative pain points, not clinical outcomes.
Patient-stated deal-breakers from rater8's 2026 survey line up with that. Asked which complaint in a review would stop them booking: rude or unhelpful staff (52%), "the doctor didn't listen" (52%), substandard care (45%), long wait times (41%), billing issues (40%).
Four of the top six are front-desk and back-office problems.
That reframes the whole exercise. If most of your one-star reviews are about a phone that rings out, a bill nobody explained, or a receptionist having a rough week, then your review score is largely an operations metric wearing a clinical costume — and it is fixable without touching clinical care.
It also explains why a private feedback channel matters more in healthcare than anywhere else. A patient annoyed about a 40-minute wait who is handed an easy, private way to say so at the front desk usually takes it. The same patient, handed nothing, says it on Google — where you are legally barred from explaining yourself. Every complaint you capture privately is one you can actually resolve, in a channel where you're permitted to discuss the specifics.
That's the core of how MrRepo is built: a QR code at checkout gives every patient the same two options — leave a public Google review or send private feedback straight to the practice — with no filtering, no gating, and no ranking of who sees which option. You can try the interactive demo to see what the patient sees. It also solves a quieter problem covered in our post on the silent customer: the patients who say nothing and simply don't rebook.
<a name="fake"></a>
What to do about a fake or defamatory review
Sometimes the review is from a competitor, a former employee, or someone who has confused you with another practice. The instinct to correct the record publicly is exactly the instinct that produced the $50,000 penalty.
The compliant sequence:
Do not respond with facts. Not even "this person was never a patient here." As covered above, a denial is a disclosure.
Document it. Screenshot with a visible timestamp and URL before anything changes.
Report it through Google's process as a policy violation — conflict of interest, off-topic, or fake engagement. Our walkthrough on reporting and removing fake Google reviews covers the escalation path when the first report fails.
Reply with Template 3 only if the review is visible and unanswered — for the audience, not the author.
Escalate to counsel if it's defamatory and persistent. Be aware that the FTC rule's suppression provisions prohibit unfounded legal threats to remove reviews, so this is a step for a lawyer to take, not a front-desk email.
One thing worth internalizing: a small number of negative reviews is not the crisis it feels like. A profile of nothing but five-star reviews reads as manufactured, and Tebra's 2025 data found 71% of patients trust a provider more when they respond thoughtfully to a negative review. A compliant, human reply to criticism is an asset. Our guide to responding to negative reviews covers the general framework; in a clinical setting, apply it with the privacy filter above.
<a name="policy"></a>
Turning this into a workable office policy
Every one of the OCR corrective action plans above required written policies and workforce training. That's the compliance floor, and it's also just good operations. A one-page policy covering these six points is enough for most practices:
One named person is authorized to post replies under the practice's name. Nobody else, ever.
Every reply is drafted, then reviewed against the three-sentence delete list before it goes live. A 24-hour cooling-off period on negative reviews prevents most of the damage — the Igbinadolor reply reads like something written in the first ten minutes.
Approved templates are stored where staff can find them, so nobody improvises at 6pm on a Friday.
No staff, family members, or vendors post reviews for the practice. Disclosed or not, it's an FTC problem and a Google policy problem.
No testimonials, before-and-afters, or patient photos go on the website or social media without a signed 164.508 authorization on file. Audit what's already up — Cadia's $182,000 was for content that had been sitting on a website for years.
Annual training, documented. Include the front desk and anyone with access to the practice's social accounts, not just clinicians.
Then check what's already live. Search your practice name on Google and Yelp, read every reply your practice has ever posted, and remove anything that names a patient or confirms a treatment relationship. That audit costs an afternoon and it is the highest-value hour in this entire article.
<a name="faq"></a>
Frequently asked questions
Can I respond to a Google review at all if I'm a HIPAA-covered entity? Yes. You can respond as long as the response contains no protected health information and does not confirm or deny that the reviewer is or was a patient. Generic, process-focused replies that invite the person to contact the office privately are compliant and are what OCR-adjacent legal guidance recommends.
The patient already said they're my patient. Why can't I acknowledge it? Because HIPAA restricts your disclosures, not theirs, and it has no waiver mechanism. In every OCR case above, the patient had already posted publicly and OCR still found an impermissible disclosure. In the New Vision Dental case, OCR specifically penalized the disclosure of details the patients had not made public themselves.
Is thanking someone for a five-star review a HIPAA violation? It can be, if the thanks confirms or implies they received care from you. Legal commentary is explicit on this point. Keep positive replies generic — thank the reviewer for the feedback without referencing a visit, a procedure, or a relationship.
Can I ask patients for Google reviews? Yes. A neutral request for feedback is not "marketing" as HIPAA defines it, and using patient contact details to send it falls under health care operations. Keep PHI out of the message itself, sign a BAA with any vendor handling that data, and never route patients differently based on how satisfied they seem.
Can I offer a discount or a gift card for a review? No. The FTC rule prohibits buying reviews conditioned on a particular sentiment, Google's policies prohibit incentivized reviews outright, and in healthcare incentives can also implicate state fee-splitting and anti-kickback rules. There is no version of this that is worth the exposure.
What about patient testimonials on my own website? You need a signed HIPAA authorization meeting 45 CFR 164.508 for each individual before posting their name, photo, or any detail of their condition or treatment. This is what Cadia Healthcare settled for $182,000 in September 2025 across 150 patients.
Does responding to reviews actually help my ranking? Responses don't directly move rankings, but review volume, rating and recency are established local ranking factors, and responding measurably increases the rate at which people convert from your profile. See our breakdown of how Google reviews impact local SEO for the mechanics.
We're a small practice. Would OCR really come after us? Elite Dental Associates was a small Dallas practice and still paid $10,000 — OCR reduced the amount specifically because of the practice's size, financial position, and cooperation. Igbinadolor's practice was two locations in North Carolina and paid $50,000 because it did not cooperate and did not take the post down. Size affects the number, not the outcome.
<a name="takeaways"></a>
Key takeaways
OCR has penalized at least five providers over public disclosures, from $10,000 to $182,000. Three of the review-reply cases were dental practices.
Accuracy is not a defense. New Vision Dental disclosed true information; the violation was disclosing it at all.
Confirming someone is your patient is itself a PHI disclosure — which is why even positive-review replies need a privacy filter.
Patients do not waive HIPAA by posting publicly. There is no waiver mechanism in the rule.
Delete non-compliant replies today. The $50,000 penalty attached to failing to correct, not to the original post.
Healthcare is judged harder: 75% of patients won't book below 4.0 stars, against 68% of consumers across all business types.
Asking is legal and it works — 68% of patients say they'd leave a review if their provider asked — but review-request texts need TCPA written consent, and incentives are off the table under the FTC rule ($53,088 max per violation).
Most one-star healthcare reviews are operational, not clinical: payment issues, phone access and wait times dominate the peer-reviewed data. Capture those privately and you fix the score at its source.
Audit your website too. Testimonials and before-and-afters without a signed 164.508 authorization are the same violation as a bad review reply — and currently the most expensive one.