Complying with HIPAA When Responding to Negative Online Reviews

September, 2026 HIPAA

Negative online reviews are an increasingly common challenge for healthcare organizations. A patient may post a critical review about a provider, staff member, appointment, billing issue, communication problem, or overall experience with the healthcare organization. It is understandable that a healthcare provider will want to set the record straight. However, responding publicly can possibly cause the healthcare provider to run afoul of HIPAA. Here is what healthcare providers should keep in mind when replying to negative online reviews. 

How Can Responding to Negative Online Reviews Cause HIPAA Compliance Issues?

An online space such as Google reviews is outside the healthcare organization’s walls. That doesn’t mean that the healthcare provider can forget about HIPAA. When reviews are especially negative, concerned healthcare providers may, to defend their business, potentially violate HIPAA. Here are some areas of concern:

  • Patient information can be accidentally disclosed. Even confirming that someone is a patient can reveal protected health information (PHI) under HIPAA. Imagine someone leaves a negative comment regarding the wait time. A response such as “We remember treating your irritable bowel disease promptly last Tuesday” may disclose information that should remain private.
  • Responding to specific complaints can reveal PHI. A healthcare provider might be tempted to explain a patient’s diagnosis, treatment, appointment, or billing situation to defend the organization. Sharing those details publicly can create a HIPAA violation. For instance, if the patient complains about the billing process being difficult to navigate, a healthcare organization might write, “Sorry you were confused about the billing, but we already explained to you what ABC Health Insurance Company covers for diabetes management.” This response could create a HIPAA issue because the clinic has publicly disclosed details about the patient’s medical condition, appointment, and billing/insurance information.
  • Staff may accidentally disclose more than intended. Employees responding to online reviews may try to be helpful or defend the organization but accidentally reveal protected health information (PHI). For example, an employee might mention a patient’s name, appointment date, medical procedure, diagnosis, medication, or billing information. A response such as “Sorry your shoulder surgery did not meet your expectations” discloses what the person was treated for and that they were seen at the facility.

Frequently Asked Questions:

What advice would a HIPAA compliance attorney give a medical practice dealing with negative reviews?

The advice is two-fold: use a standard response and train staff on this issue. 

Draft (and have it reviewed by a healthcare law attorney) a standard response when someone makes a negative comment about the practice. A standard response can help employees avoid disclosing information in the moment. The response should be professional, brief, and neutral. It should avoid confirming, denying, or volunteering confidential information, prevent impulsive responses, and direct the request to the appropriate person or department.

Additionally, walk staff through the healthcare organization’s practice when responding to negative online reviews. Healthcare organizations can reduce risk by having a clear policy for handling online reviews. Employees should know who is authorized to respond and who should receive complaints or questionable reviews for further review. A simple internal process can help prevent an employee from posting an emotional response or accidentally disclosing confidential information. Staff training should emphasize that even a well-intentioned response can create problems if it reveals patient information.

What information should we avoid giving in a response? 

Avoid information that could identify the patient or reveal details about their relationship with your practice. This can include diagnoses, treatments, medications, appointment information, medical history, billing details, or statements confirming that someone received care. Employees should also avoid discussing private conversations or explaining what happened during a patient’s visit. Additionally, photos, videos, lab results, or anything else that records the visit should not be uploaded online to dispute the negative review.

What if we know that the complaint is totally false?

If a healthcare provider believes an online review is false, the best approach is to stay calm and avoid an emotional response. Employees should not try to argue with the reviewer, reveal patient information, or post details about what actually happened. Even if the reviewer shares private information publicly, the practice still needs to be careful about what it says in response. Instead, the practice should save a copy of the review and have the appropriate person, such as a compliance officer, privacy officer, manager, or attorney, review it. The practice can then determine whether the review violates the website’s rules and whether to report it, challenge it, or address it through another appropriate option. Providers should consider addressing the issue through a private communication channel instead.

What if the patient discloses personal health information? 

A patient may choose to share personal health information in an online review, but that does not necessarily mean the healthcare provider can publicly repeat or confirm the information. Employees should not assume that a patient’s public disclosure gives them permission to disclose additional information. When a review includes detailed medical information, it is particularly important to route the response through a HIPAA compliance attorney. 

What should staff do if they accidentally disclose PHI in the response?

If an employee believes a response may have disclosed PHI, the organization should promptly follow its established incident-response and HIPAA compliance procedures. The organization may need to assess what information was disclosed and who could have accessed it. Consulting qualified HIPAA counsel can help determine the appropriate response and whether breach-notification requirements apply.

Contact a HIPAA Compliance Attorney 

HIPAA violations can create significant legal and financial concerns for health care providers. Contacting a HIPAA healthcare compliance attorney can help an organization determine whether a response to an online review may have disclosed PHI. An attorney can also review the organization’s policies and advise staff on how to respond to negative reviews while protecting patient privacy.