Can My Practice Post Patient Reviews? HIPAA Rules for Testimonials (2026)
OCR has fined practices for exactly this. A dental practice paid a federal settlement for disclosing patient information while responding to Yelp reviews; other practices have been penalized for confirming patient relationships in public replies. And with URMC's $2.85M and Froedtert's $2M settlements proving regulators now read marketing stacks line by line, the review workflow — how you ask, what you publish, how you reply — is squarely inside your 2026 compliance perimeter.
Here's the two-part answer practices actually need:
Yes, your practice can post patient reviews and testimonials — with the patient's signed HIPAA authorization. And no, you can almost never respond to a public review the way your instincts tell you to, because even confirming that the reviewer is your patient is a HIPAA disclosure.
The asymmetry that trips everyone: patients can talk, you can't
A patient posting "Dr. Patel fixed my sciatica, five stars" on Google discloses their own health information — perfectly legal, theirs to share. The trap is thinking their disclosure frees you to respond in kind. It doesn't. HIPAA binds the practice, not the patient, and their public post waives nothing.
That means when responding to reviews — positive or negative:
- Never confirm the reviewer is a patient. "Thank you for trusting us with your care!" confirms a treatment relationship. That's PHI.
- Never reference their visit, treatment, or your side of the story. The one-star review that misstates the facts is agonizing, and the practice that "sets the record straight" ("You missed two appointments and refused the X-ray") has just committed the textbook violation OCR settles over.
- Use the safe template instead: respond generically, without acknowledging patienthood — "We take feedback seriously and are committed to every patient's experience. Please call our office at [number] so we can help directly." It works for praise and complaints alike, moves the conversation offline, and shows other readers a professional practice.
- Train the whole team on this. Most review-response violations are a well-meaning office manager typing fast on a Friday.
Genuinely defamatory or fake reviews have remedies — platform flagging, and in extreme cases legal action — but a public HIPAA violation is never one of them.
Publishing testimonials on your own site: authorization, always
Reposting a Google review onto your website, or filming a patient testimonial, is the practice using PHI for marketing — which requires a signed, HIPAA-valid authorization, the same standard that governs before/after photos:
- Specific about what's used (the review text, name, photo, video) and where (website, social, ads).
- Voluntary, unbundled from treatment paperwork, and revocable — keep a register of where each testimonial appears so a revocation can actually be executed.
- Extra caution when the review contains health details. "They cured my incontinence" on your homepage, with a name and face, is exactly the content to run past the authorization language twice. Never copy a review containing health specifics onto your site on the theory that "it was already public" — public on their Google profile is not authorized on your marketing.
Widgets that auto-stream your Google reviews onto your site live in a gray zone the conservative practice avoids for health-detail-heavy reviews; curate with authorization instead.
See it live on your own practice
EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo
Soliciting reviews: where the real compliance work hides
Asking for reviews is legal and essential — Google rankings for local practices are substantially review-driven. But the mechanics of asking are regulated from three directions:
1. HIPAA governs the send. A review request references the patient relationship, sent to a patient's phone or inbox — the tooling that sends it is handling PHI and needs to be BAA-covered. (This is where most bolt-on review tools get shaky; see our comparison of Podium and Birdeye.)
2. The TCPA and carrier rules govern the SMS. Texting patients review requests requires proper consent and, since the A2P 10DLC regime, a registered brand and campaign — unregistered traffic gets filtered or blocked by carriers, and consent violations carry per-message statutory damages. This is plumbing most practices never see, so we automated it: PilotPractice handles 10DLC brand and campaign registration automatically, captures SMS consent (a2p_consent) at the point of booking, runs every outbound message through a per-message compliance check before it sends, and enforces opt-outs instantly and permanently. A "STOP" is honored by the system, not by a staff member remembering. (Full SMS playbook: HIPAA-compliant SMS marketing.)
3. The FTC governs the incentives. No paying, discounting, or gifting for reviews — incentivized reviews violate FTC endorsement rules and every platform's terms, and the FTC's 2024 fake-reviews rule added real teeth. Also banned in spirit and increasingly in law: "review gating" (only asking happy patients, or routing unhappy ones away from public platforms). Ask everyone, uniformly.
The ungated checklist: review program audit
No email gate. Run it this week.
- Read your last 10 review responses. Any that confirm patienthood or reference care? Edit or delete them today, and fix the template.
- Check who has the keys to your Google Business Profile and what training they've had.
- Match every website/social testimonial to a signed authorization. None on file = down it comes until one exists.
- Scan testimonials for health details and confirm the authorization language actually covers them.
- Audit the review-request channel: Is the SMS/email tool BAA-covered? Is the texting brand/campaign 10DLC-registered?
- Verify consent capture — where in intake or booking does the patient agree to receive texts?
- Test the opt-out. Reply STOP to your own campaign and confirm nothing follows.
- Check for incentives and gating in your current ask flow. Remove both.
- Confirm timing/volume sanity — a burst of 50 same-day reviews looks fake to Google and to the FTC.
- Build the revocation register for published testimonials.
The do-marketing answer
A compliant review engine is one of the highest-ROI systems in practice marketing: ask every patient, automatically, at the moment of peak satisfaction (post-visit, post-results), over registered and consented SMS; respond to everything within 48 hours using the safe template; and publish authorized testimonials on the service pages they're about, where they convert. Practices running this systematically compound review velocity month over month — which is precisely what local rankings reward.
PilotPractice runs the whole loop — consent capture at booking, registered and compliance-checked sends, opt-out enforcement, response templates, and authorized testimonial publishing — inside one BAA-covered platform, with SOC 2 and HIPAA controls documented at trust.pilotpractice.com. The full strategy lives in the 2026 HIPAA-compliant marketing guide, or book a demo and we'll audit your review workflow live.
PilotPractice security & compliance documentation: trust.pilotpractice.com
See it live on your own practice
EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo





