Local & AI visibility, in plain English
Reviews under HIPAA

What HIPAA actually says about reviews

The rules are narrower and clearer than the folklore suggests. Here is the practical version.

September 9, 2026 4 min read By PsychLocal Editorial Team

This lesson describes the practical shape of the rules as they apply to marketing. It is not legal advice, and you should confirm your own approach with counsel or your privacy officer. That said, most of what practices believe about reviews and HIPAA is wrong in both directions: some think they cannot have reviews at all, others respond to reviews in ways that create real exposure.

The core principle

HIPAA restricts what you may disclose. It does not restrict what a patient may say.

That single distinction resolves most confusion:

  • A patient can write anything they like about their care, name you, and describe their treatment. That is their information to share.
  • You cannot confirm, deny, or add to it in a way that discloses protected health information, which includes the simple fact that someone is or was a patient.

The asymmetry is uncomfortable but clear. The patient holds the right; you hold the obligation.

What counts as a disclosure

The trap is that acknowledgement alone is a disclosure. In a public reply, all of these confirm a treatment relationship:

  • Thanking someone for choosing your practice.
  • Saying you are sorry their treatment did not go as hoped.
  • Referring to their appointment, their visit, or their course of care.
  • Explaining what actually happened at their visit, even to correct an error.
  • Mentioning any clinical detail, diagnosis, or medication.
  • Saying you have refunded them or rescheduled them.

Note that the reviewer may have already disclosed all of this themselves. That does not transfer permission to you. Their disclosure is theirs; yours is a separate act.

Why the defensive reply is the dangerous one

The highest-risk moment is an unfair negative review. The instinct is to correct the record, and a factual, reasonable-sounding correction is exactly the reply that creates exposure, because it confirms the relationship and usually adds clinical detail.

A public reply is also permanent, indexed, and readable by every future patient. So even setting the regulatory question aside, arguing with a review is poor marketing.

What you can safely do

  • Respond in a way that acknowledges feedback generically without confirming anyone attended.
  • State your general standards and policies.
  • Provide an offline route to raise concerns.
  • Ask patients for reviews, which is permitted and covered later in this chapter.
  • Report reviews that violate platform policy.
  • Respond to positive reviews, using the same non-confirming pattern.

The next lesson gives a concrete response pattern that satisfies all of this while still reading as warm and human.

Testimonials and authorisation

You may use a patient story in marketing only with a valid, specific, written HIPAA authorisation, and even then advertising rules on testimonials still apply separately. Practical guidance:

  • Verbal permission is not sufficient.
  • A general consent form signed at intake is not authorisation for marketing use.
  • Authorisation must be specific about what is used and where, and it is revocable.
  • Reposting or screenshotting a public review into your own marketing turns the patient disclosure into your publication, which is a different act. Get authorisation first.
  • In psychiatry, consider whether soliciting a testimonial is appropriate at all given the sensitivity of the treatment relationship.

Beyond HIPAA

Two other layers apply and are easy to forget. State privacy laws may be stricter than the federal baseline. And professional body ethics codes place their own limits on testimonials and on soliciting from current patients, sometimes more restrictive than the privacy rules.

Staff training

Most breaches here are well-intentioned. A receptionist or practice manager sees an unfair review and replies. Make the rule explicit and simple:

  • One named person is responsible for review responses.
  • Everyone else escalates rather than replying.
  • Use pre-approved response templates, so nobody improvises under provocation.
  • Never reply the same hour you read a bad review.

The response pattern comes next.

Sources

Independent sources

  1. Summary of the HIPAA Privacy RuleU.S. Department of Health & Human Services, Office for Civil RightsAccessed September 2026
  2. Dental Practice Pays $10,000 to Settle Social Media Disclosures of Patients' Protected Health InformationU.S. Department of Health & Human Services, Office for Civil RightsAccessed September 2026OCR enforcement action arising from a provider disclosing patient information while responding to an online review.

Share this lesson

Disclaimer: This material is provided for marketing and visibility education purposes only, not as clinical, legal, or compliance advice. Practices should consult their own legal counsel or compliance officer to confirm that their marketing and operational strategies adhere to HIPAA, state regulations, payer directory rules, and professional board guidelines.

See this in your own data

Run a free scan of your practice's listings across our 90+ network destinations and see which of the things this lesson describes might need attention.

Keep going