Blog
The Review Response That Cost a Dental Practice $50,000
A patient left a review. The practice replied with details about their treatment. That reply was a HIPAA disclosure, and OCR fined the practice $50,000.
The trap is narrower and stranger than most practices realise: merely confirming that someone is a patient is itself protected health information. You don't need to mention a diagnosis, a procedure, or a date. "We're sorry your visit didn't meet expectations" has already said they were there.
This is not legal advice. It's the pattern, the enforcement record, and what to do instead.
The rule that surprises everyone
A public review does not waive anything.
The instinct is that someone who posts publicly about their own care has opened the door. Legally, they haven't. The individual's privacy rights are unaffected by what the individual chose to publish — the obligation sits on you regardless of what they said or how unfair it was.
That asymmetry is genuinely uncomfortable. A patient can post something inaccurate, and you cannot correct the record, because correcting it requires confirming they're a patient.
The enforcement record
Not theoretical. Documented OCR actions on this exact conduct include:
| Action | Outcome |
|---|---|
| Dental practice disclosing PHI in a Google review response | $50,000 |
| Provider with multiple PHI disclosures across review pages | $10,000 plus a corrective action plan |
| Plastic surgery provider, alleged PHI in a review response | Complaint letter |
And the penalty isn't the whole cost. An OCR investigation consumes staff time, requires counsel, and looks at more than the thing that triggered it. A review response can open a file that finds problems elsewhere.
What a safe response looks like
The workable pattern is a reply that would make sense if the reviewer were a complete stranger:
"Thank you for the feedback. We take all concerns seriously and would like to discuss this directly. Please call our office at [number] and ask for the practice manager."
Why it works: it confirms nothing, discloses nothing, addresses no specifics — and it does the only job a public reply actually has, which is showing future readers that the practice responds to concerns like adults.
What must stay out: whether the person is or was a patient, what was treated, when they were seen, what was said in the room, anything about billing, and any correction of their account of events. That last one is the hardest, and it is the one that generates penalties.
Build a small set of pre-approved templates with your privacy officer or counsel, and make it a rule that nobody replies to a healthcare review off the cuff. The $50,000 reply was almost certainly written by someone annoyed at their desk.
Who this applies to that doesn't expect it
Practices covered by HIPAA that don't always think of themselves that way: dental, med spas offering medical services, physical therapy, chiropractic, mental health, and private practices of every kind.
Med spas are the most common trap. A practice that thinks of itself as a beauty business, marketing on before-and-after photos and enthusiastic testimonials, may be handling PHI throughout — and the marketing instincts that work in aesthetics are precisely the ones that create exposure here.
The knock-on effects for marketing
Testimonials and before-and-afters need documented authorisation. Not a verbal yes on the day. If your marketing shows patients, the paperwork behind that needs to exist and be specific.
Retargeting and audience lists need care. A custom audience built from a patient list, or a pixel firing on a page tied to a condition, is a category of exposure worth reviewing with counsel before it goes live rather than after.
Review requests are fine. Asking every patient for a review is normal and doesn't disclose anything — you're contacting your own patient through your own channel. It's the public reply that carries the risk, not the ask. The review generation guide covers the method, and gating remains off the table for everyone.
Your vendors are exposure too. Any tool touching patient data — CRM, review platform, call recording, AI assistants — needs the compliance posture to match. Call recording at a healthcare practice is a conversation to have with counsel, not a setting to switch on.
The practical version
Never reply to a healthcare review without a template someone qualified approved. Take it offline, confirm nothing, correct nothing.
The best defence against a bad review is volume of good ones, which is entirely within your control and carries none of this risk. A practice with 300 reviews absorbs an unfair one. A practice with eleven doesn't — and it's the practice with eleven that feels compelled to argue.
Talk to healthcare counsel about your actual marketing stack, not just your review replies. It's a cheaper conversation than an OCR file.
Sources
- Bass, Berry & Sims — How can healthcare providers respond to online patient reviews without violating HIPAA?
- National Law Review — Disclosing patient information in responses to online reviews: recent OCR enforcement
- Workplace Privacy Report — Dentist faces $50,000 OCR penalty over review response
- ADA — Managing dental practice online reviews
Written by Jared DeValk, founder of Nashville Digital. Published September 8, 2026.
Nothing here is legal advice and we are not healthcare compliance counsel. Talk to a qualified attorney about your practice's specific obligations.