In 2022 the HHS Office for Civil Rights settled with Manasa Health Center, LLC for $30,000 over four review responses that disclosed protected health information. The reviewer had publicly mentioned receiving care. The practice acknowledged that care. That acknowledgement alone — not a treatment detail, just the confirmation of patient status — was the violation.
Most healthcare practices don't know this. Most third-party review-management tools don't know this. Here's the rule, the templates, and the math.
Why HIPAA reaches review responses
HIPAA's Privacy Rule (45 CFR § 164.502) prohibits a covered entity from disclosing protected health information (PHI) without authorisation. PHI includes the fact that someone received care — not just the diagnosis or treatment.
When a patient publicly mentions in a review that they were seen at your practice, their disclosure is not your authorisation. You still cannot acknowledge the patient relationship publicly. The HHS Manasa settlement and the 2024 Anchorage Behavioral Health case both turned on exactly this issue.
The 11-word safe template
"Thank you for the feedback. We appreciate every comment as we continually improve."
That's it. 11 words. No confirmation, no reference to a visit, no procedure name. Use it for every positive review.
For negative reviews:
"We take all feedback seriously. Please call our office at [phone] to discuss."
Notice: no acknowledgement of any specific incident, no defence, no implied relationship.
Where practices most commonly cross the line
- "Glad we could help with your [procedure]!" Discloses both treatment and patient status.
- "Sorry your wait was long — we had two emergencies that morning." Discloses operational PHI of other patients.
- "Thanks for choosing us for your child's check-up!" Discloses patient status of a minor.
- "We'll see you at your follow-up next week." Confirms ongoing treatment relationship.
The legal framework non-attorneys should know
HIPAA breaches don't always require harm — the violation is the disclosure. Penalties range from $137 per violation (unknowing) to $68,928 per violation (wilful) under the 2024 inflation-adjusted tiers.
OCR can investigate based on a single complaint. Most healthcare review-related settlements have been triggered by patients reporting their own subsequent dissatisfaction with the response, not by random audits.
This is not legal advice — talk to your compliance officer. But the conservative template above protects against the most common failure modes.
Building a HIPAA-safe response system
- Train every team member who responds to reviews on the 11-word rule.
- Use a small template library — 4–5 variants of the positive template, 2–3 for negative.
- Document a review-response policy alongside your existing HIPAA policies.
- Run a quarterly audit of past responses against the rule. Edit or delete anything that crosses the line.
- For complex negative reviews, route to legal/compliance before responding publicly.
The grey areas the templates don't cover
The 11-word rule handles 90% of cases, but practices always hit edge cases. A few we get asked about constantly. If a patient posts a clinically detailed review naming their procedure: you still cannot confirm or expand on it — their disclosure isn't your authorisation, and acknowledging the treatment relationship is itself the violation. If the review is defamatory and false: your remedy is to report it to the platform for a content-policy breach, not to argue the facts publicly. If a patient asks you a question in a review: answer generically and move the specifics to a private channel — 'Please call our office and ask for the manager' is safe; 'Your insurance should have covered that cleaning' is not.
The unifying principle: nothing you say publicly should reveal that a specific person is or was a patient, or anything about their care. When in doubt, shorter is safer.
Train the whole team, not just the manager
The most common way practices get into trouble isn't the official review response — it's a well-meaning front-desk employee replying 'So glad we could fix your tooth, see you next month!' from the practice's logged-in account. HIPAA doesn't care about intent. One enthusiastic, untrained reply can become a reportable disclosure.
Build a tiny internal policy: only named, trained staff respond to reviews; everyone uses the approved template library; anything beyond a thank-you routes to the compliance lead. Document it alongside your existing HIPAA policies. It costs an hour and removes the single most common source of accidental violations — your own staff trying to be friendly.
"The patient's disclosure is never your authorisation. They can mention their visit publicly; you still can't confirm it."
— Senior strategist, The Review Makers