Compliance

HIPAA-safe review responses: what a practice can and cannot say

You can reply to patient reviews. You cannot confirm that the reviewer is a patient. Here is the line, why it catches people out, and reply patterns that stay on the right side of it.

Two speech bubbles side by side, one open and one with a frosted panel across its face

A healthcare practice can reply to reviews. What it cannot do is confirm, imply, or discuss that the reviewer received care. Acknowledging someone as a patient is itself protected health information, which means a friendly reply can breach the rule just as easily as a defensive one. This is the single point that catches practices out, and once it is clear the rest is straightforward.

Why a warm reply can still be a disclosure

Most practices assume the danger sits in arguing with the reviewer, so they aim for polite. Consider a reply that reads: “We are so sorry your crown appointment ran late, please call the office and ask for Dr Patel.” Nothing in it is rude. It also confirms in public that this person is a patient, what procedure they had, and who treated them, all of which the practice disclosed rather than the patient.

The reviewer disclosing their own care does not release the practice from anything. A patient is free to say whatever they like about their own treatment. The practice is not free to confirm it.

What you cannot say

  • That the person is, or ever was, a patient.
  • Anything about their treatment, diagnosis, appointment, or medical history.
  • Which clinician saw them, or when.
  • Anything about their billing, insurance, or balance.
  • A correction to their version of events that relies on their record. This one is the hardest to resist and the most common breach, because the practice usually is right about the facts.

What you can say

  • That the practice takes feedback seriously and reviews every piece of it.
  • Your general policies, stated generally: how scheduling works, how billing questions are handled, what your standard is for wait times.
  • An invitation to contact the practice directly through a named channel.
  • A genuine, non-specific thank-you for positive feedback.

A reply pattern that works for a negative review

Thank you for taking the time to share this. We are not able to discuss anyone’s care in a public forum, so we would rather hear the detail directly. Please contact our practice manager on [number] or at [email] and we will look into it properly.

It acknowledges the feedback, explains the silence rather than looking evasive, and moves the conversation somewhere the practice can actually resolve it. Note what it does not do: it does not thank them for visiting, it does not apologise for a specific appointment, and it does not say “we have reviewed your file”.

The explanation of why you cannot say more matters more than practices expect. Without it, a short reply reads as stonewalling to a prospective patient. With it, the same reply reads as a practice that takes confidentiality seriously, which is exactly the impression you want.

And for a positive review

Thank you, we really appreciate you taking the time to write this. Feedback like this means a lot to the whole team.

Warm, non-specific, and it confirms nothing. The temptation is to write “so glad the implant went well” because the review already said so. Resist it.

Where practices most often slip

The pattern is almost always the same: a review contains a factual error, the practice knows exactly what happened, and the reply corrects the record. “You were actually seen within ten minutes of your scheduled time” is a defensible sentence in every industry except this one. Here it confirms the appointment, the timing, and the relationship in a single line.

The second common slip is delegation. A reply written by a front-desk team member or an outside marketing agency, working from the same templates used for restaurants and gyms, will sound helpful and specific. Specific is the problem. Anyone drafting replies on the practice’s behalf needs to understand the constraint before they are given access.

Where software helps, and where it does not

Software can draft a reply that avoids confirming treatment or patient status, and it can hold every reply for a human to approve before anything is published. That is how AI reply drafting is set up in ReviewsGauge, and it is why nothing posts automatically: the approval step is the control. It reduces the chance of an unsafe reply going out. It does not turn compliance into somebody else’s problem, and no vendor should tell you otherwise.

What software cannot do is decide your obligations for you. Coverage differs between a dental practice, a physician group, a therapy practice and a cash-pay aesthetic clinic, and a business associate agreement may be needed depending on how a vendor handles your data. That is a conversation for your compliance adviser, not a software feature comparison.

Frequently asked questions

Can we reply to a patient review at all under HIPAA?

Yes. Replying is permitted. Confirming that the person received care, or discussing that care, is what is not permitted. A generic acknowledgement with an invitation to make contact directly stays on the right side of that line.

The patient already said they were treated here. Does that change anything?

No. A patient may disclose their own information freely. That does not authorise the practice to confirm it publicly. Treat their disclosure as though it had not happened.

Can we ask a patient to take a review down?

Contacting a patient about their own review is itself a use of their information, and pressuring someone to remove honest feedback tends to go badly whether or not it is permitted. The safer route is a public reply inviting contact, then resolving it privately if they choose to get in touch.

Does this apply to a cash-pay aesthetic clinic?

It depends on whether the clinic is a covered entity, which turns on the services provided and how transactions are handled rather than on how the clinic describes itself. A clinic that is unsure should assume the constraint applies and confirm with its adviser. The safe reply pattern costs nothing to adopt either way.

Can an agency handle our review replies?

They can, provided they understand the constraint and, where required, the correct agreements are in place with them as a vendor. Give any outside party the reply pattern above before they publish anything, not after.

Is a reply that says nothing specific worth publishing?

Yes, and more than practices assume. Prospective patients are not comparing your account of events with the reviewer’s. They are checking whether the practice answers at all. More on why replies are read by the next customer.

This is a plain-English summary of a rule with real complexity, written to help a practice think about review replies. It is not legal advice. Confirm your own obligations with your compliance adviser.

Filed under: Compliance

Turn every visit into a 5-star review

ReviewsGauge asks every customer at the right moment, drafts your replies, and showcases the results on your site, automatically.

Free forever for Google · No card required