HIPAA-safe review responses
In healthcare, confirming that someone was your patient is itself a disclosure. That changes how you reply, and most template advice will get you in trouble.
- Confirming someone was a patient is itself a disclosure, and their post does not release you.
- Reply generically: no confirmation, no detail, no specific apology.
- Thanking a reviewer for a named procedure is the same breach as correcting one.
- Applies to home care, behavioural health and therapy as well as dental and medical.
The trap in an ordinary reply
A standard response reads: “We are sorry your visit did not meet expectations, please call the office.” That sentence confirms the reviewer was a patient, and for a covered entity that confirmation is protected health information disclosed publicly.
The reviewer disclosing it themselves does not release you. Their post is their choice about their own information; your reply is your disclosure, and the obligation is yours.
What a compliant response looks like
Do not confirm or deny that the person was a patient. Do not reference any detail from their review, even to correct it. Do not apologise for a specific experience, because that acknowledges the experience.
Reply generically, about your practice's standards and process, and provide a route to discuss it privately. Something close to: “We take all feedback seriously. Our practice is committed to a high standard of care. If you would like to discuss a concern with our office, please contact us at [number].”
It reads flatter than a normal reply. That flatness is the compliance.
The parts people get wrong
Correcting the record. The instinct to say “actually you were seen on time and the delay was in the lab” is exactly the disclosure the rule prohibits.
Thanking a positive reviewer for a specific treatment. A five-star review naming a procedure is the reviewer's disclosure. Thanking them for that procedure is yours.
Asking staff to reply informally. The obligation attaches to the practice, not the individual account.
This applies more widely than dental and medical
Home care, behavioural health, physical therapy, and any business handling protected health information as a covered entity or business associate.
Where you are unsure whether you are covered, get that answered before writing any reply, because the answer changes every sentence.
What we do and do not do here
We write and manage compliant response frameworks and we train the person who posts them. We do not give legal advice, and where a review looks like it may involve a reportable complaint we say so and stop.
Any practice running review responses at volume should have the framework reviewed by counsel once. It is a small cost against the alternative.
“It reads flatter than a normal reply. That flatness is the compliance.”
