Every dental practice faces the same tension: a patient leaves a detailed negative review online, and you want to respond with context—but HIPAA rules make that legally risky. One wrong sentence can expose you to federal penalties, even if your intent was simply to defend your practice’s reputation.
This article explains exactly what dental practices can and cannot say when writing hipaa compliant review responses. No legal jargon, no theoretical scenarios—just concrete boundaries and practical examples you can apply today.
What HIPAA Actually Says About Online Reviews
The Health Insurance Portability and Accountability Act (HIPAA) protects patient health information. In the context of online reviews, HIPAA prohibits you from confirming or denying that someone is your patient, disclosing any treatment details, or sharing any protected health information (PHI) without written authorization.
Protected health information includes:
- Names combined with treatment details
- Appointment dates or visit history
- Diagnosis, procedures, or clinical observations
- Payment or billing information
- Any information that could identify the individual’s health status
The rule applies even when the patient publicly shared their own information first. Just because someone posts “Dr. Smith botched my root canal” doesn’t give you permission to discuss their case in your response.
The consequence for violations can be severe. Civil penalties range from $100 to $50,000 per violation, with annual maximums reaching $1.5 million. Criminal penalties can include fines up to $250,000 and imprisonment for knowing violations.
What You Cannot Say in Review Responses
These are the bright-line rules. If you cross any of these boundaries, you’re likely violating HIPAA.
Never Confirm or Deny Someone Is Your Patient
Even a simple “Thank you for visiting our practice” can be interpreted as confirming a patient relationship. Phrases like “We appreciate your business” or “Sorry your visit didn’t meet expectations” suggest you have records of their appointment.
This includes indirect confirmation. Writing “Our records show…” or “According to our notes…” clearly indicates you looked up their file, which means you’ve acknowledged them as a patient.
Never Discuss Treatment Details
You cannot address specific clinical claims, even to correct factual errors. If a reviewer says you performed the wrong procedure or missed a diagnosis, you cannot respond with clinical details about what actually happened.
This applies even when the patient gets the facts wrong. If someone claims you extracted the wrong tooth and you want to clarify which tooth was actually extracted, that clarification would violate HIPAA.
Never Reference Appointment History or Billing
Details about when someone visited, how many appointments they had, whether they completed treatment, or what they were charged are all protected information.
Statements like “You only came in once” or “You didn’t return for your follow-up” or “Your insurance covered that procedure” all disclose PHI.
Never Suggest You’ll Follow Up Offline
Many practices instinctively write “Please call our office so we can discuss this further” or “We’d like to review your records and make this right.” These responses imply you have records to review, which confirms a patient relationship.
What You Can Say in HIPAA Compliant Review Responses
The safe zone is narrower than most practice owners expect, but you’re not powerless. Here’s what’s permissible.
General Statements About Your Practice Standards
You can describe your normal protocols, quality standards, and practice policies without connecting them to any specific patient.
Example: “Our practice follows strict sterilization protocols and our team completes continuing education annually. We take all patient concerns seriously.”
Invitations to Contact You (Carefully Worded)
You can provide contact information without implying you have records or confirming a patient relationship. The key is neutral language that could apply to anyone.
Safe phrasing: “If you’d like to discuss your experience further, please contact our office manager at [contact info].” This works because it doesn’t assume the reviewer is a patient—they could be discussing anyone’s experience.
Expressions of Concern Without Acknowledgment
You can express general concern about negative experiences without confirming the person was your patient.
Example: “We’re sorry to hear about this experience. Patient comfort and quality care are priorities for our practice.”
Notice this response doesn’t say “your treatment” or “your visit”—it references “this experience” in a way that maintains distance.
Corrections to Factual Errors About Your Practice
If a review contains false information about your practice itself (not about a patient’s treatment), you can correct it.
Example: If someone claims your office has no emergency appointment availability, you can respond: “Our practice reserves appointment slots daily for dental emergencies. Patients can reach our emergency line at [number].”
This corrects misinformation about practice operations without discussing any individual’s care.
The One Exception: Written Authorization
There is exactly one scenario where you can discuss a patient’s specific case in a review response: the patient provides written HIPAA authorization specifically permitting you to respond to their review.
This authorization must:
- Be in writing and signed by the patient
- Specifically identify the review and platform
- Clearly state what information you’re permitted to disclose
- Include an expiration date
In practice, this exception is rarely useful. By the time you contact the patient to request authorization, draft the document, wait for them to sign and return it, the review has been public for days or weeks. Most patients who leave negative reviews won’t sign authorization anyway.
Some practices include a blanket review-response authorization in their new patient paperwork. The legal standing of these blanket authorizations is unclear, and many HIPAA attorneys advise against relying on them. The safer approach is to treat every review response as if you have no authorization.
Practical Templates for HIPAA Compliant Review Responses
Here are response templates that stay within HIPAA boundaries.
For Negative Reviews With Clinical Complaints
“We’re concerned to hear about this experience. Our practice is committed to evidence-based care and patient comfort. If you would like to discuss your concerns, please contact our office manager directly at [contact info].”
For Reviews Claiming Poor Customer Service
“We appreciate this feedback. Our team works to provide respectful, responsive service to everyone who contacts our practice. We take these concerns seriously and will review our front-office procedures.”
For Reviews With Billing Complaints
“We understand billing questions can be frustrating. Our practice provides detailed treatment estimates and works with patients on payment options. If you have questions about charges or insurance, our billing coordinator is available at [contact info].”
For Positive Reviews
Positive reviews are lower risk but still require care. Avoid confirming a patient relationship.
Safe response: “Thank you for this kind feedback. We’re glad to hear about your positive experience.”
Risky response: “Thank you for trusting us with your care” (implies patient relationship).
For more examples across different scenarios, see our guide on how to respond to patient reviews with HIPAA-safe examples.
Common Mistakes Dental Practices Make
These errors appear frequently in real review responses from dental practices.
The “Check Your Facts” Response
When a reviewer gets details wrong, the instinct is to correct them publicly: “You’re mistaken—we only performed a cleaning, not a filling.” This discloses treatment details and violates HIPAA, even if you’re correcting false information.
The Defensive Detail
Practices sometimes respond with process details that inadvertently confirm the patient relationship: “Our protocol is to take X-rays before any extraction, and we followed that protocol in this case.” The phrase “in this case” links your protocol to the reviewer’s specific treatment.
The Sympathy Confirmation
Empathetic language can cross the line: “We’re sorry the crown didn’t fit properly on your first visit.” This statement acknowledges a specific treatment and outcome, making it a HIPAA violation.
The Records Reference
“We’ve reviewed your file and don’t see a record of you reporting pain” explicitly confirms you maintain records on this person and searched them, which is a clear violation.
How to Reduce HIPAA Risk in Your Review Response Process
Most HIPAA violations in review responses happen because practices respond quickly without a review process. Here’s how to build in safeguards.
Assign One Person to Draft Responses
Designate a single staff member—commonly the office manager—to draft all review responses. This person should receive specific training on HIPAA boundaries for public responses.
Use a Second-Pair-of-Eyes Review
Before posting any response, have a second trained person review it specifically for HIPAA compliance. This catches mistakes that the original drafter missed.
Create a Pre-Approved Template Library
Develop a set of HIPAA-compliant response templates that cover common review scenarios. When your team uses pre-approved language, the risk of accidental disclosure drops significantly.
Monitor All Locations Where Patients Leave Reviews
You can’t respond compliantly if you don’t know reviews exist. Automated review monitoring ensures you see reviews across Google, Yelp, Healthgrades, and other platforms where patients commonly post. At Get Kandid, we read your reviews every day and send Email Alerts for negative reviews, so you can respond promptly without constantly checking multiple sites.
When Not Responding Is the Right Choice
Sometimes the HIPAA-compliant response is no response at all.
If a review contains so many specific details that any response would implicitly confirm the patient relationship, staying silent may be your safest option. This is particularly true for reviews that describe unusual circumstances or rare procedures—anything that would make the patient identifiable even without you naming them.
Similarly, if a reviewer is clearly trying to bait you into disclosing information (“I know what you wrote in my chart about me”), responding at all plays into their hand.
Not every review requires a response. In our validation set of 10 NYC businesses covering 14,000+ reviews, 9 of 10 responded to fewer than 21% of their reviews. While we commonly recommend higher response rates for reputation management, HIPAA compliance sometimes makes silence the right call for specific dental reviews.
For broader guidance on managing your online reputation while staying compliant, see our complete guide to dental review management.
FAQ: HIPAA and Review Responses
Can I respond to a review if the patient mentioned their own name and treatment details?
No. HIPAA prohibits you from confirming or adding to health information even when the patient discloses it first. The patient has the right to share their own information, but that doesn’t give you permission to discuss their PHI publicly. Your response must stay within the same boundaries regardless of what the patient shared.
What if a review contains completely false information about treatment I provided?
You still cannot discuss the specifics of that patient’s treatment to correct the record. Your options are to respond with general statements about your practice standards, or to say nothing. If the false review rises to the level of defamation, you may have legal remedies, but those remedies don’t include publicly disclosing PHI.
Can I ask Google or Yelp to remove a review that forces me to violate HIPAA if I respond?
You can request removal, but platforms commonly deny these requests. Google and Yelp don’t consider HIPAA complications to be a valid reason for removal. Reviews are typically only removed if they violate the platform’s content policies—such as containing hate speech, spam, or conflicts of interest. The fact that responding would be difficult for you legally isn’t grounds for removal in the platform’s eyes.
Is it safer to respond to positive reviews than negative ones?
Positive reviews carry less legal risk, but HIPAA still applies. You must avoid confirming the patient relationship or referencing their treatment. A simple “Thank you for the kind words” is safe. “Thank you for trusting us with your implant procedure” is not, because it confirms you treated this person and discloses the procedure type.
Tools to Help You Stay Compliant
Managing hipaa compliant review responses across multiple platforms is tedious when done manually. You need to monitor several review sites daily, draft compliant responses, and track which reviews you’ve addressed.
Get Kandid automates the monitoring piece. We read your reviews every day across Google, Yelp, and other major platforms where dental patients leave feedback. When a negative review appears, we send an Email Alert with a draft response that stays within HIPAA boundaries. You review the draft, adjust if needed, and copy-paste it to the platform—we never post on your behalf, so you maintain full control.
The monthly Get Kandid Report shows all your recent reviews in one place, so you don’t need to log into multiple platforms to see what patients are saying. For practices on the Pro plan and above, the Competitor Report tracks how nearby dental practices are handling their reviews, giving you competitive context.
Pricing is $29, $59, or $99 per month depending on the plan (annual subscriptions save 20%). Most reputation management tools we’ve analyzed have a median entry price around $199 per month—often with long contracts and sales calls. Get Kandid offers a simpler approach: request your first free Report with no card required and no call. See what your reviews look like in one consolidated view, then decide if the service is worth $29 a month to you.
Conclusion
HIPAA compliance in review responses comes down to one principle: never confirm, deny, or discuss anything about an individual’s health information, patient status, or treatment. The legally safe zone is narrow, but it’s wide enough to let you express concern, share your practice values, and provide contact information for offline follow-up.
Most dental practices will benefit from a small library of pre-approved templates and a two-person review process before posting responses. When in doubt about whether a response crosses the line, the safest choice is usually to say less—or to say nothing at all.
HIPAA violations aren’t theoretical risks. Federal penalties are real, and your responses are public evidence. The minor reputation benefit of a detailed rebuttal isn’t worth the legal exposure. Stay within the boundaries, respond where you can, and let your overall body of positive reviews speak for your practice quality.