A negative review naming specific treatment details puts a medical practice in a real bind: the instinct to correct the record can itself create a HIPAA problem. Here's how to respond without making things worse.
The core rule: never confirm someone was a patient
Under HIPAA, confirming that a specific person was a patient, even in the course of defending your practice against an unfair review, is itself a disclosure of protected health information. This holds true even if the reviewer has already disclosed their own treatment details publicly. The practice's response should never confirm or deny a treatment relationship, regardless of what the reviewer has said.
What a compliant response actually looks like
A safe response acknowledges the reviewer's experience in general terms, invites them to discuss the specifics privately, and does not reference any treatment detail, date, or outcome, even to dispute an inaccuracy. Something like: "We take all feedback seriously and would like to understand more about your experience. Please contact our office directly so we can address this properly." This response works whether or not the reviewer was ever actually a patient.
What to avoid, even when a review feels unfair
- Never state or imply whether the reviewer was or wasn't a patient at your practice.
- Never reference specific treatment dates, procedures, or outcomes, even to correct a factual inaccuracy in the review.
- Avoid detailed point-by-point rebuttals in public that would require referencing the specifics of what happened.
- Don't screenshot or forward review content internally in ways that could expose PHI beyond people who need to see it for the practice's response process.
When a review contains clearly false information
It's frustrating to see an inaccurate review you can't correct in detail without a HIPAA violation. In practice, most patients reading reviews understand that a healthcare provider is limited in how it can respond, and a calm, professional, non-specific response tends to read better to prospective patients than a defensive or detailed rebuttal would anyway. If a review crosses into defamation or contains information that suggests a genuine legal issue, that's a conversation for your attorney, not a public response.
A simple response process
- Have a single, HIPAA-safe response template ready before a negative review arrives, so no one is drafting language under pressure in the moment.
- Route any response through a designated person, rather than letting anyone on staff respond ad hoc.
- Invite the conversation offline every time, regardless of what the review contains.
- Escalate to legal counsel only if the review raises a genuine legal concern beyond typical dissatisfaction.
Tridigiam helps set up review-response processes and templates that stay inside these limits by default. We're a marketing agency, not a HIPAA compliance auditor, so a full review of your practice's response protocol should still involve your own compliance or legal resource.
For the fuller HIPAA-and-marketing picture, see our Medical Practice Marketing: The Complete Guide.
Frequently asked questions
What if the reviewer already named their own diagnosis in the review?
The practice still shouldn't confirm or reference it. The reviewer disclosing their own information doesn't change the practice's own HIPAA obligations in its response.
Can we ask the platform to remove a review that discloses too much detail?
Most review platforms have a reporting process for reviews that violate their own content policies, which is worth pursuing separately from how your practice responds publicly.
Should front desk staff be allowed to respond to reviews directly?
Generally no. Routing responses through one trained, designated person reduces the risk of an off-the-cuff response that inadvertently discloses something.
Resources
Need marketing that actually moves the needle?
Tridigiam is a Las Vegas marketing and advertising agency built for regulated and growth-focused businesses. Call (702) 748-7005 or request a consultation.





