25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight

A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information disclosure rubric.

Among the 80,300 recent Google review replies collected, the study estimated that about 26% contained language that disclosed or confirmed patient information under its review rubric.

Healthcare practices are routinely told to respond to online reviews. From a reputation-management perspective, that advice makes sense: be responsive, be human, and show prospective patients that someone is listening. In most industries, a warm and personal reply is harmless. In healthcare, the word “personal” can be the problem.

A patient can choose to discuss their own diagnosis, treatment, visit, billing dispute, or outcome in a public review. A HIPAA-covered provider has a separate obligation. The fact that a patient disclosed information about themselves does not, by itself, give the provider permission to confirm it, expand on it, or connect the reviewer’s identity to care in a public reply. The HIPAA Privacy Rule generally limits uses and disclosures of protected health information (PHI) unless the disclosure is permitted by the Rule or supported by a valid authorization.2, 3, 4

Research Findings

The study sampled 4,019 medical and dental practices across 10 clinical disciplines in California and the Pacific Northwest. Of those, 2,972 practices replied to reviews. We collected 80,300 of their recent public Google review replies and screened every reply using a two-stage process.1

First, a rule-based classifier tuned to favor recall flagged 26,147 replies as potentially disclosing patient information. Second, flagged replies were adjudicated by a human reviewer against a single conservative rubric that looked only at what the practice itself disclosed. Replies were counted when the provider’s response confirmed a patient or visit relationship, disclosed a clinical detail, or referenced billing or insurance information tied to the reviewer. Generic thanks and replies that did not confirm care were cleared.1

Seven disciplines were audited in full. For the three largest cohorts: chiropractic, physical therapy, and dental: the study used reproducible random samples of flagged replies and projected the confirmed rate across the remaining flagged replies, with 95% confidence intervals. In total, 9,844 replies were reviewed by hand. Reviewers directly confirmed 7,991 disclosure-risk replies, with approximately 13,126 additional replies statistically projected across the three sampled cohorts. The combined estimate was approximately 21,117 public replies, or 26.3% of all replies collected.1

This should not be read as a national HIPAA violation rate. The study covered selected regions, reviewed recent Google replies rather than every platform, and classified disclosure language rather than making a legal determination about each practice’s HIPAA covered-entity status, patient authorization, or other case-specific facts. It is best understood as a measurement of public disclosure risk.

Among the seven fully audited disciplines, the share of replying practices with at least one confirmed disclosure-risk reply was:

Discipline Replying practices with ≥1 confirmed disclosure
Fertility / reproductive 90.0%
Sports medicine 76.0%
Pain management 69.2%
Dermatology 64.3%
Psychiatry / mental health 62.2%
Podiatry 62.2%
Pediatrics 60.8%

Source: SturdyWeb findings report. These practice-level rates apply only to the seven fully audited disciplines; the three largest cohorts were handled through sampled reply-level adjudication and projection.

The Most Common Problem is not a Dramatic Disclosure

The most important finding was not that staff were posting long medical histories. Most were not. The more common failure was smaller: the practice confirmed something the reviewer had already said.

Among the disclosure-risk replies confirmed by hand, 58% confirmed patient or visit status, 41% disclosed a clinical detail such as a condition, procedure, result, symptom, or body part, and 1% referenced billing or insurance. In other words, the majority of the problem was not an explicit diagnosis. It was the provider publicly linking an identifiable person to the provision of care.12

Two recurring behaviors explained much of what we saw. “Care narrators” repeated the patient’s story: what hurt, what procedure was performed, how treatment progressed, or what outcome occurred. “Visit confirmers” said less, but still acknowledged that the reviewer had been a patient, had visited the office, or had received care.

The distinction is easier to see in examples:

Reply pattern Example Why it matters
Clinical detail “We’re glad your sciatica improved after your adjustments.” Echoes a condition and treatment back to an identifiable reviewer.
Patient/visit confirmation “Thank you for trusting our team with your care these past two years.” Confirms a care relationship even without naming a diagnosis.
Safer public response “Thank you for taking the time to share your feedback. We appreciate it.” Acknowledges the review without confirming whether the reviewer received care.

Examples are composed and de-identified to illustrate patterns observed in the study; they are not reproduced patient reviews.

Why “the patient said it first” is Not a Safe Rule

The misunderstanding is understandable. A patient writes publicly, “My back pain improved after treatment,” so a staff member replies, “We’re glad your back pain is better.” To the person writing the reply, nothing new seems to have been revealed.

HIPAA does not work that way. PHI includes individually identifiable information about the provision of health care, health conditions, and payment for care. A provider’s public response is its own disclosure. Unless the disclosure is permitted by the Privacy Rule or supported by a valid authorization, the patient’s decision to post first does not create a blanket exception for the covered entity to discuss the patient publicly.234

OCR has already enforced this principle in the online-review context. Elite Dental Associates paid $10,000 to settle potential HIPAA Privacy Rule violations involving social-media disclosures of patients’ PHI. OCR imposed a $50,000 civil money penalty on Dr. U. Phillip Igbinadolor, D.M.D. & Associates after the practice impermissibly disclosed a patient’s PHI on a webpage in response to a negative review. New Vision Dental paid $23,000 to resolve an investigation involving PHI disclosed in responses to online reviews. Manasa Health Center paid $30,000 and entered a corrective action plan after OCR investigated disclosures of patient PHI in responses to negative Google reviews.5678

Those cases matter because they closely resemble the ordinary behavior measured in this study: a practice responding to a public review and saying too much. The risk is not theoretical, and it is not limited to large health systems.

AI can Turn a Scattered Mistake into a Repeatable Workflow

There is a second reason to address this now. Review-response tools increasingly offer automated or AI-assisted drafting. The research did not attempt to determine whether the replies we reviewed were written by people or generated by software, so the current findings should not be attributed to AI. The forward-looking risk, however, is straightforward.

A generative system prompted to “write a warm, personal response” will often use the content of the review as context. If the reviewer mentions a diagnosis, procedure, pregnancy, injury, medication, insurance issue, or treatment outcome, a personalization-first system may mirror that information back into the provider’s public response. Without a compliance rule in the workflow, automation can convert an occasional human mistake into a consistent process.

Healthcare organizations therefore need to govern the output, not just the tool. A review platform does not become safe because it has an AI feature, and a human approval step is only useful if the reviewer has been trained on what cannot be confirmed publicly.

What HIPAA Compliance Teams Should Do Now

The fix is not to stop responding to reviews. It is to change the response standard. Public replies can still be polite, timely, and useful without confirming anything about the reviewer’s care.

  1. Adopt a no-PHI public-reply rule that limits the default public response to the review itself and does not confirm patient status, visits, diagnoses, procedures, outcomes, medications, coverage, or payment.
  2. Move substantive conversations to a private channel by inviting the individual to contact the office through an approved private channel when a review raises a real service or care concern, rather than litigating the facts of the encounter in public.
  3. Audit historical responses across Google and other platforms, preserving an appropriate record and involving the privacy officer or counsel before any broad cleanup if a complaint, investigation, or litigation hold is pending.
  4. Train the people who actually post, including front-desk staff, office managers, marketing teams, and agencies with review-platform access, since general annual HIPAA training may not be specific enough to catch this workflow.
  5. Put AI-assisted replies behind the same policy by configuring templates and review instructions so the system never repeats clinical, visit, or billing details from the review, and by testing the workflow with deliberately sensitive examples before deployment.
  6. Create a small library of safe templates, such as “Thank you for taking the time to share your feedback. We appreciate it,” to reduce the pressure to improvise.

The Larger Lesson is That Reputation Management is Part of Healthcare Privacy

Healthcare privacy programs traditionally focus on EHR access, email, faxing, portals, vendors, and cybersecurity. Public-facing reputation workflows can sit outside that mental model because the information is already visible on the internet. That is precisely why review replies become a blind spot.

The patient’s post and the provider’s response are not the same act. One is an individual choosing to speak about themselves. The other is an organization speaking about an identifiable person in its capacity as a healthcare provider. Once that distinction is understood, the safe operating rule becomes simple: acknowledge the feedback without acknowledging the care.

Our data suggests many practices have never translated that principle into the day-to-day work of answering reviews. The opportunity for compliance teams is unusually practical. This is a public, searchable risk that can be audited, remediated, trained, and governed without changing clinical care. For many practices, a one-page policy and a disciplined cleanup may eliminate an exposure pattern that has been accumulating in plain sight for years.

Methodology and Limitations

The underlying findings report reviewed 4,019 practices across 10 clinical disciplines in California and the Pacific Northwest and collected 80,300 recent public Google review replies from the 2,972 sampled practices that responded to reviews. A rule-based screen flagged potentially disclosing replies, followed by human adjudication using a uniform conservative rubric. Seven disciplines were audited in full; chiropractic, physical therapy, and dental were assessed through reproducible random samples of flagged replies and statistical projection across the remaining flagged replies. The report contains no practice or patient names, and the examples in the report are redacted or composed.1

The study is not a legal adjudication of individual practices or replies, and it should not be interpreted as a nationally representative prevalence estimate. It did not review every historical reply or every platform, and it did not determine the HIPAA covered-entity status, authorization history, or other facts that could affect the legal analysis of a specific response. Those limitations are important; they do not change the operational pattern the study identified.

Disclosure and Disclaimer

The research described in this article was conducted by SturdyWeb, a service of Daevara Consulting, LLC. The author is affiliated with the organization that conducted the research. This article is provided for general educational purposes and is not legal advice. Whether a specific communication violates HIPAA depends on the facts and applicable law and should be evaluated by qualified counsel or a HIPAA compliance professional.

References

  1. SturdyWeb. “The Privacy Blind Spot in Your Members’ Review Replies.” Findings report prepared for medical and dental professional associations, August 2026.
  2. 45 C.F.R. § 160.103, definitions of individually identifiable health information and protected health information. Source
  3. 45 C.F.R. § 164.502, general rules for uses and disclosures of protected health information. Source
  4. 45 C.F.R. § 164.508, uses and disclosures for which an authorization is required. Source
  5. U.S. Department of Health and Human Services, Office for Civil Rights. Elite Dental Associates enforcement action: $10,000 settlement over social-media disclosures of patients’ PHI (2019). Source
  6. U.S. Department of Health and Human Services, Office for Civil Rights. Dr. U. Phillip Igbinadolor, D.M.D. & Associates enforcement action: $50,000 civil money penalty for impermissible disclosure in response to a negative online review. Source
  7. U.S. Department of Health and Human Services, Office for Civil Rights. New Vision Dental: $23,000 settlement over PHI disclosures in responses to online reviews (2022). Source
  8. U.S. Department of Health and Human Services, Office for Civil Rights. Manasa Health Center: $30,000 settlement involving PHI disclosed in responses to negative online reviews (2023). Source

Author: Robert Couts is the founder of Daevara Consulting. Robert has decades of experience working in technology and compliance and now focuses on helping small businesses succeed online, protecting and growing their reputation. You can contact Robert on LinkedIn.

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist