Trust, Ethics & Regulation · established evidence
The HIPAA Line: How Dental Practices Can Respond to Patient Reviews Without Risking a Violation
The American Dental Association's own guidance on managing online reviews warns that a public reply confirming someone was a patient, or referencing their treatment or cost, can constitute a HIPAA violation. That single fact puts most dental practices in a bind: staying silent looks unresponsive and costs the recency and volume that reviews need to keep working, but replying the way most businesses reply, thanking a patient by name for a great cleaning, can cross the exact line the ADA warns about. The fix is neither silence nor risk. It is a specific, repeatable way of writing that acknowledges feedback in broad terms, never confirms patient status, and moves anything sensitive to a private channel. This is general information based on ADA guidance and federal rules, not legal advice for your specific practice.
The exact rule most owners do not know
Most business owners assume review replies are a low-risk, purely reputational exercise: thank the happy ones, apologize to the unhappy ones, move on. Dentistry is different. The American Dental Association's Managing Dental Practice Online Reviews guidance is explicit that a public reply which confirms someone was a patient, or references their treatment or its cost, can itself be a HIPAA violation, regardless of whether the original review disclosed those details first.
This is a subtle but important distinction. HIPAA's Privacy Rule restricts a covered entity, the practice, from disclosing protected health information. A patient posting their own review and naming their own treatment is the patient's own choice to disclose; the practice replying and confirming or elaborating on that same information is the practice making a disclosure, and that is what the rule is built to prevent. The practice does not get to rely on the patient having said it first.
Why silence is not a safe default either
Faced with that risk, many practices simply stop replying to reviews altogether. That avoids the HIPAA exposure, but it creates a different, measurable cost. BrightLocal's 2026 Local Consumer Review Survey found 47 percent of consumers will not consider a business with fewer than 20 reviews, and 74 percent specifically look for reviews written in the last three months, meaning a practice's review presence has to keep moving, not sit static, to stay in consideration.
A pattern of unanswered reviews, especially unanswered negative ones, reads as neglect to a prospective patient scanning the page, independent of the HIPAA question entirely. The answer is not to choose between compliant and responsive. It is to build a way of replying that is both.
What a compliant reply actually looks like
The operating principle is simple to state and requires discipline to apply consistently: a reply should never confirm that the reviewer was a patient, never reference a specific treatment, procedure, or cost, and never add any identifying detail the patient did not already choose to disclose themselves, even if it seems harmless.
In practice, that means responses stay in broad, all-patient language. A positive review gets a general thank-you for the kind words and an invitation to reach out directly with any questions, without repeating back what the review described. A negative review gets an acknowledgment that the practice takes all feedback seriously and an invitation to continue the conversation by phone or through a private message, without confirming or disputing any clinical detail publicly. The private channel is where the specific, patient-identifying conversation belongs, not the public review thread.
This is a discipline, not a script that can be applied thoughtlessly. A review that names a specific hygienist by name for excellent work can be thanked warmly without echoing back the treatment described alongside it. The line to hold is narrow: warmth and general acknowledgment are fine, confirmation of patient status or clinical detail is not.
The FTC layer sits alongside HIPAA, not instead of it
HIPAA governs what a practice can say in a reply. A separate federal rule governs what reviews can exist in the first place. The FTC's Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, effective October 21, 2024, makes fake, incentivized-for-positivity, insider, and suppressed or gated reviews federal violations, with penalties up to $51,744 per violation. Enforcement precedent includes a $4.2 million settlement over review suppression practices.
The two rules compound rather than substitute for each other. A compliant dental review system has to clear both floors at once: every review has to come from a real patient, acquired without incentive or gating, and every reply has to stay inside the HIPAA privacy boundary, regardless of what the original review said.
A repeatable process beats a one-off legal read
Because the HIPAA line is easy to cross by accident, a single well-intentioned reply from a front-desk staff member under time pressure is a real, ongoing risk, not a one-time decision to get right and forget. The durable fix is a process: a defined reply framework that is reviewed once, then applied consistently to every new review as it arrives, so compliance does not depend on whoever happens to be answering that week remembering the rule correctly.
That is also why a standing review system, one that monitors new reviews as they land and prepares a reply for approval inside a pre-set privacy boundary, functions differently than an ad hoc approach. The discipline gets built into the workflow itself rather than re-derived under pressure every time a difficult review appears.
The evidence
Key findings, with their sources
-
A public review reply that confirms someone was a patient, or references their treatment or cost, can constitute a HIPAA violation.
established American Dental Association, Managing Dental Practice Online Reviews guidance, ada.org.
-
Fake, incentivized-for-positivity, insider and suppressed reviews are federal violations under FTC 16 CFR Part 465, effective October 21, 2024, with penalties up to $51,744 per violation.
established US Federal Trade Commission, Rule on the Use of Consumer Reviews and Testimonials, 2024.
-
47 percent of consumers will not consider a business with fewer than 20 reviews, and 74 percent look specifically for reviews written in the last three months.
established BrightLocal, Local Consumer Review Survey 2026.
-
FTC enforcement precedent for review suppression includes a $4.2 million settlement.
established FTC v. Fashion Nova review-suppression settlement, 2022.
Reference
Glossary
- Protected health information (PHI)
- Individually identifiable health information a covered entity, such as a dental practice, is restricted from disclosing under HIPAA's Privacy Rule, including confirming that a named person was a patient.
- Review gating
- Screening customers before inviting a review so only likely-positive ones are asked, or routing negative feedback to a private form instead of the public review platform. Prohibited under FTC 16 CFR Part 465.
- 16 CFR Part 465
- The FTC's federal rule, effective October 21, 2024, banning fake, incentivized, insider and suppressed consumer reviews and testimonials, with penalties up to $51,744 per violation.
Straight answers
Frequently asked questions
Can I say thank you for your visit in a reply to a patient review?
A general thank-you that does not confirm the person was a patient or reference their treatment is the safer pattern most practices use, phrased broadly rather than specifically. Because the exact line depends on wording and context, a practice handling this at scale should have its reply framework reviewed by qualified counsel, not rely on a single article for legal certainty.
What should I do about a negative review that discusses specific treatment details?
Acknowledge the feedback in general terms and invite the reviewer to continue the conversation privately, by phone or direct message, without confirming or disputing the clinical details in the public reply. The private channel is where any patient-specific discussion belongs.
Does the HIPAA reply risk apply to DSO-affiliated and multi-location practices too?
Yes. HIPAA's Privacy Rule applies to the covered entity making the disclosure, which is the practice or provider replying, not to the practice's ownership or organizational structure. Multi-location and DSO-affiliated practices need the same reply discipline applied consistently across every location and every provider replying to reviews.
Can I ask a happy patient for a review at all?
Yes, and you should, requesting reviews from real patients is not restricted by HIPAA. What is restricted is what the practice itself discloses in a public reply. Review requests are governed instead by the FTC's rules against gating and incentivizing, meaning every real patient should be invited, not just the ones expected to leave a positive review.
Provenance
Sources
- American Dental Association, Managing Dental Practice Online Reviews guidance, ada.org (established, primary regulatory guidance)
- US Department of Health and Human Services, HIPAA Privacy Rule, 45 CFR Parts 160 and 164 (established, federal regulation)hhs.gov
- US Federal Trade Commission, Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, 2024 (established, federal regulation)ecfr.gov
- FTC v. Fashion Nova review-suppression settlement, 2022 (established, enforcement precedent)
- BrightLocal, Local Consumer Review Survey 2026 (established, industry survey)brightlocal.com
Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.