A patient leaves a one-star review claiming you botched their crown, double-billed them, or “didn’t even look at the X-ray.” You know it isn’t true. You have the chart. Every instinct says: set the record straight.
That instinct has cost practices between $10,000 and $50,000 in federal penalties, plus two years of government-monitored corrective action plans. The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services has announced at least four enforcement actions against practices whose only mistake was replying to an online review with too much detail. Every one of them was a small practice. Every one of them started with a patient complaint.
This guide covers what the HIPAA Privacy Rule actually prohibits in a review reply, what those four practices did wrong, what you can safely say, and when the smarter move is to pursue removal instead of a response.
Why a review reply can be a HIPAA violation
The HIPAA Privacy Rule (45 CFR 164.502) prohibits a covered entity from using or disclosing protected health information (PHI) without the patient’s written authorization, outside of a short list of permitted purposes. Responding to a review is not on that list.
PHI is broader than most practice owners assume. It is any individually identifiable information that relates to a person’s health, treatment, or payment for care, held by a covered entity. That includes the fact that a specific person is your patient at all. So the moment you write “We’re sorry your visit on Tuesday didn’t go well,” you have confirmed patient status, a date of service, and — by replying at all — that a treatment relationship exists.
Three myths get practices in trouble:
- “They disclosed it first.” A patient’s decision to post about their own care does not authorize you to discuss it. HIPAA restricts what the provider discloses. The patient is free to say anything; you are not.
- “The review is anonymous.” In the 2022 civil money penalty case below, the patient posted under a pseudonym. The practice replied with the patient’s real name. Anonymity on the reviewer’s side does not protect you — it makes your reply the identifying act.
- “I only confirmed what was already public.” A reply that adds any new detail — dates, procedures, insurance, balances, no-shows — is a disclosure. Even repeating the patient’s own claims while confirming their patient status is a disclosure.
Four OCR enforcement actions every practice should know
These are public cases. Each began with a patient complaint to OCR, not an audit.
Elite Dental Associates, Dallas (October 2019) — $10,000
A patient posted a negative Yelp review. The practice responded by disclosing the patient’s last name, details of her treatment plan, and her insurance information. OCR found impermissible disclosures affecting multiple patients, plus missing policies and an inadequate Notice of Privacy Practices. The practice paid $10,000 and entered a corrective action plan.
U. Phillip Igbinadolor, DMD & Associates, Charlotte (2022) — $50,000 civil money penalty
A patient posted a negative Google review under a pseudonym. The practice replied on its Google page with the patient’s name, the dates he visited, and the reasons for treatment. OCR told the practice the reply was an impermissible disclosure and asked it to remove the response. The practice did not cooperate with the investigation and declined to contest the findings. OCR imposed a $50,000 civil money penalty under the “willful neglect, not corrected” tier — the highest culpability level in the HIPAA penalty structure. The lesson is not just about the reply; it is about refusing to take it down when told to.
New Vision Dental, California (December 2022) — $23,000
The practice repeatedly disclosed patient names, treatment details, and insurance information in Yelp responses — information the patients had not included in their own reviews. OCR also cited failures to maintain privacy policies and an adequate Notice of Privacy Practices. The practice paid $23,000 and accepted a two-year corrective action plan monitored by OCR.
Manasa Health Center, New Jersey (June 2023) — $30,000
A psychiatric practice responded to a negative Google review and disclosed the patient’s mental health diagnosis and treatment. OCR’s investigation found similar disclosures for four patients. The settlement required a $30,000 payment, a corrective action plan, and a breach report to HHS covering every individual whose PHI had been disclosed online without authorization.
The pattern across all four: small practices, Google or Yelp, a reply written in the heat of the moment, and a penalty that was the cheapest part of the outcome. The corrective action plan — rewriting policies, retraining staff, submitting to OCR monitoring for up to two years — is the real cost.
Where the line actually is
You are allowed to respond to reviews. You are not allowed to disclose PHI when you do. In practice that means writing every reply as if you do not know whether the reviewer is a patient.
Never include:
- Any confirmation the reviewer is or was a patient (“your appointment,” “your treatment,” “when you came in”)
- Dates or frequency of visits, including missed appointments
- Procedures performed, recommended, or declined
- Diagnoses, symptoms, prescriptions, or lab results
- Insurance carrier, coverage decisions, balances, or payment history
- Staff accounts of what happened during the visit
- The reviewer’s name, even if they posted under it
You can include:
- A general statement about the standards your practice holds itself to
- A general description of how your practice handles complaints, billing questions, or scheduling
- A statement that privacy law prevents you from discussing any individual’s care publicly
- An invitation to contact the office manager or privacy officer directly, with a phone number or email
- Thanks for feedback, expressed generically
Note what is missing from the second list: any denial of the specific accusation. “We did not double-bill this patient” confirms patient status and discloses billing history. The frustrating truth is that HIPAA prevents you from winning the argument in public. Your reply’s job is to show prospective patients that the practice is professional and reachable — not to litigate.
Safe response templates
Each template below is written to work whether or not the reviewer is a patient. Edit the practice name and contact details; do not add specifics.
Template 1 — general negative review
“Thank you for taking the time to share this. Our practice is committed to providing every person with attentive, respectful care, and we take all feedback seriously. Federal privacy law prevents us from discussing any individual’s care or visit publicly, but we would welcome the opportunity to speak with you directly. Please contact our office manager at [phone] or [email].”
Template 2 — billing or insurance complaint
“We appreciate you raising this. Billing and insurance questions can be frustrating, and our team works to resolve them quickly and clearly. Privacy regulations do not allow us to address any individual account publicly. If you would like to review a statement or coverage question, please contact our billing coordinator at [phone] and we will look into it right away.”
Template 3 — wait time or front-desk complaint
“Thank you for this feedback. We know that time is valuable, and we are continually working to improve scheduling and front-desk communication for everyone who visits us. If you would like to discuss your experience, our office manager can be reached at [phone]. We appreciate the chance to do better.”
Template 4 — mental health, aesthetic, or other sensitive specialties
“Thank you for sharing your perspective. Because of the confidential nature of our work and the privacy laws that govern it, we do not comment publicly on any individual’s experience with our practice. We are always available to talk directly, and you can reach our practice administrator at [phone] or [email].”
Practices in psychiatry, addiction medicine, reproductive health, and aesthetic medicine should default to Template 4 and be even more restrained. The Manasa case involved a psychiatric practice; the sensitivity of the specialty was part of why OCR treated it seriously. If you run a cosmetic or aesthetic practice, our reputation management for plastic surgeons and aesthetic medicine page covers the platform-specific issues those practices face.
Google’s AI-drafted review replies are a HIPAA landmine
In March 2026, Google began testing a “Reply to reviews with AI” feature inside Google Business Profile. It generates a suggested reply based on the content of each review, which the owner can edit before posting. It is rolling out gradually in the United States and a few other markets.
For most businesses, this is a convenience. For a covered entity, it is a trap. The model writes a good reply by echoing the review: if a patient complains about a root canal, the draft will likely say something about the root canal. If the patient mentions their insurance denial, the draft may reference the claim. Posting that draft confirms patient status and treatment in one click. The model has no concept of PHI and no knowledge of HIPAA.
If your practice uses AI to draft replies — Google’s tool or any other — the rule is simple: strip every specific before posting, and make sure the person hitting submit has been trained on the list above. The same applies to any marketing agency replying on your behalf. Texas Medical Liability Trust has reported cases where a marketing vendor’s suggested reply to a review would have violated HIPAA had the practice posted it. You, not the vendor, are the covered entity.
When the right move is removal, not response
HIPAA creates an asymmetry: the reviewer can say anything, and you cannot rebut it. That is exactly why review removal matters more in healthcare than in almost any other industry. Your reply cannot fix a false review; only removal or suppression can.
Platforms do not remove reviews because they are negative or because you say they are inaccurate. They remove reviews that violate their content policies. On Google, that includes reviews that are spam or fake, off-topic, posted by someone with a conflict of interest (such as a former employee or competitor), harassing, or that disclose someone else’s private information. Yelp, Healthgrades, Vitals, Zocdoc, and RateMDs each have their own guidelines and dispute channels.
The difficulty for a medical practice is that the strongest evidence a review is false is often the chart — and you cannot send the chart to Google. Effective removal requests for healthcare providers have to be framed around the platform’s policy violation without disclosing PHI. That is a specific skill, and it is the core of what we do on our Google review removal and Yelp review removal services. For a walkthrough of what platform policy actually allows this year, see our guide to what works for Google review removal in 2026. If you suspect a coordinated or fake review campaign, our fake review removal service covers the pattern-based approach.
When a review cannot be removed, the alternative is to change what people see. A steady flow of legitimate patient reviews, an accurate and complete Business Profile, and consistent responses to positive reviews all reduce the weight of one bad review. A Google Business Profile audit is the fastest way to find out where your profile is leaking trust.
Build the policy before you need it
Every OCR corrective action plan in the cases above required the practice to write policies it should have had already. Doing it voluntarily costs nothing and removes most of the risk:
- Designate one responder. One person — usually the office manager or privacy officer — replies to reviews. Nobody else, including the physician, replies ad hoc.
- Write a one-page policy. List the prohibited content above, require the templates, and require a second set of eyes before any reply that departs from a template.
- Train everyone with login access. Include the receptionist who has the Google Business Profile password. Document the training.
- Log every reply. Date, platform, template used, approver.
- Never move the conversation to DMs with PHI. A private message on Google or Yelp is still a disclosure. Take it to the phone or to a HIPAA-compliant channel.
- If a risky reply is already live, delete it now. Then document what was disclosed, consult your privacy officer or counsel, and assess whether breach notification obligations apply. Under the Breach Notification Rule, an impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability the PHI was compromised. The Manasa settlement required exactly this kind of breach reporting.
Practices that want this handled end to end — HIPAA-aware response drafting, platform-specific removal, and monitoring across Google, Yelp, Healthgrades, and Vitals — can start with our reputation management for doctors and medical practices and reputation management for dentists services, or book a consultation.
Frequently asked questions
Can a doctor or dentist respond to a Google review at all?
Yes. HIPAA does not prohibit responding to reviews. It prohibits disclosing protected health information when you do. A reply that does not confirm the reviewer is a patient and does not reference any detail of their care is permitted.
If the patient already posted details about their treatment, can I reference them?
No. The patient’s disclosure of their own information does not authorize yours. Repeating or confirming details from their review, or adding new ones, is an impermissible disclosure. In the New Vision Dental case, OCR specifically noted that the practice’s replies added treatment and insurance details the patients had not included in their own reviews.
Is saying “we can’t discuss this due to HIPAA” itself a confirmation that they are a patient?
It can read that way, which is why the safest wording is impersonal: “Privacy law prevents us from discussing any individual’s care publicly.” That statement is true whether or not the reviewer is a patient, and it is the standard approach used across healthcare compliance guidance.
Can I ask the reviewer to sign an authorization so I can respond fully?
A valid HIPAA authorization would permit a specific, limited disclosure. In practice, an unhappy reviewer rarely signs one, and even with an authorization, a detailed public rebuttal tends to escalate rather than resolve. The better use of that conversation is a private resolution and, if appropriate, a request that the reviewer update or remove the post.
Does this apply to med spas, chiropractors, therapists, and dentists?
HIPAA applies to covered entities: providers who electronically transmit health information in connection with standard transactions such as insurance claims. Most dental, chiropractic, therapy, and medical practices qualify. Some cash-only aesthetic practices may fall outside HIPAA, but state privacy and consumer protection laws still apply, and patients expect the same discretion. Treat the rules above as the floor regardless.
Can I delete a negative review myself?
No platform lets a business delete a review directly. You can flag it for a policy violation and, if the platform declines, escalate through its dispute process. Reviews that do not violate any policy stay up, which is why response quality and overall review volume matter.
This article is general information for healthcare practice owners, not legal advice. Consult your privacy officer or healthcare counsel about specific situations.


