The Challenge
New Vision Dental faced a common issue: negative patient reviews that needed addressing. A team member responded publicly, revealing patients' full names and details not mentioned by the reviewers. This included information about appointments, treatments, and billing decisions, all visible online.
The Office for Civil Rights (OCR) investigated and found the practice violated the HIPAA Privacy Rule. New Vision Dental had to pay $23,000 and implement a corrective action plan. Similarly, Elite Dental Associates paid $10,000 after employees discussed patient care on social media. These cases show how quickly reputation management can turn into a compliance issue when staff aren't clear on Privacy Rule boundaries.
The Environment and Constraints
Dental practices operate in a review-driven market. Research from the Journal of Medical Internet Research shows online reviews are a key source for understanding patient experiences and healthcare quality. Potential patients often read these reviews before booking appointments, so practices have business reasons to monitor feedback and address concerns.
However, HIPAA applies regardless of reputation management efforts. The Privacy Rule covers any identifiable health information maintained or transmitted by a Covered Entity or Business Associate. This includes Electronic Protected Health Information (ePHI) like a patient's full name when linked to treatment, appointments, insurance, or payment. Confirming someone received care or discussing their appointment history is considered PHI disclosure.
Reviewers might use initials, nicknames, or anonymous usernames. Staff can't always identify the reviewer without guessing. Even if they recognize a name, they can't confirm the person's relationship with the practice publicly. Parents and caregivers add complexity, as recognizing a name doesn't mean the practice can discuss that patient's information with them.
The Approach Taken
OCR's corrective action plan for New Vision Dental required policies on when PHI can be disclosed, appropriate email and social media use, authorizations, employee training, and breach notifications. The practice developed a policy for obtaining patient authorization.
The framework from these enforcement actions focuses on three operational boundaries:
Public responses must be generic. Craft replies that work whether the author is a patient or not. Thank the reviewer, acknowledge their concern in general terms, and offer to continue the conversation privately. Don't confirm treatment, appointments, billing disputes, or the patient-practice relationship.
Private follow-up requires identity verification. When someone contacts the practice after a public review, verify their identity and authority before accessing records or discussing specifics. HIPAA-compliant email enables authorized employees to maintain access controls and transmission safeguards, but technology alone doesn't ensure compliance. Staff must confirm who they're speaking with before disclosing PHI.
Escalation protocols prevent impulsive responses. Establish who monitors reviews, who can post responses, which templates staff can use, and when to escalate issues to the Privacy Official or legal counsel. Preserve reviews as provided and report credible threats, legal claims, and suspected false reviews immediately.
Results and Metrics
New Vision Dental's $23,000 settlement and Elite Dental Associates' $10,000 penalty highlight the cost of non-compliance. Beyond financial penalties, both practices faced the administrative burden of implementing corrective action plans and the reputational damage from public enforcement actions.
The broader outcome is a clearer operational standard: practices can engage with reviews without violating HIPAA, but only if staff understand the difference between general policy discussion and patient-specific confirmation. Research shows provider responses can decrease the influence of negative reviews. The value of responding exists, but it requires discipline.
What They Would Do Differently
The violations stemmed from employees not recognizing that confirming a reviewer's patient status or treatment details is PHI disclosure. New Vision Dental's corrective action plan addressed this through scenario-based training rather than abstract policy reminders.
Consider these preventable mistakes:
- Using patients' full names in responses
- Confirming the reviewer received treatment or had appointments
- Discussing dates, late appointment policies, or missed appointments
- Explaining payment decisions, insurance claims, or outstanding balances
- Correcting patient conduct or policy violations publicly
- Emailing review screenshots to personal accounts during the screening process
Each error reflects staff acting without clear guidance. An employee screenshots a review and emails it to their personal account to discuss with a colleague later. Someone sees a false claim and wants to set the record straight with billing records. A front-desk worker recognizes a username and confirms the person's appointment history. These responses feel natural but cross the Privacy Rule boundary.
Takeaways for Your Team
Build response templates that never confirm patient status. Your standard reply should work whether the reviewer is a current patient, former patient, family member, or someone you've never treated. "Thank you for your feedback. We'd like to understand your concerns better. Please contact [Privacy Official name] at [HIPAA-compliant email] so we can address this privately" works in every scenario.
Train staff on the confirmation problem specifically. Don't just tell employees not to disclose PHI. Walk through examples: "You declined the treatment we recommended" confirms the reviewer received care. "We have no record of you as a patient" discusses whether someone appears in your records. "Dr. Smith never treated you" confirms both the provider relationship and treatment status. Use real review language (anonymized) in training scenarios.
Verify identity before discussing specifics privately. When someone responds to your invitation to continue the conversation, confirm their identity and authority before accessing records. Ask security questions, verify email addresses, and check whether they have authorization to discuss another patient's information before proceeding.
Document your review management process. Detail who monitors reviews, who has posting authority, which templates to use, when to escalate, and how to preserve evidence. Include Business Associate Agreements covering your email service. Make this process part of initial and annual HIPAA training.
Flag false reviews through platform processes, not PHI disclosure. If a review seems fabricated, preserve a copy, report it through the website's review system, and consult legal counsel or your professional liability insurer. Don't email patient records to prove the reviewer wrong.
The $23,000 penalty New Vision Dental paid provided clarity for the rest of the industry. You can respond to reviews. You just can't confirm who received treatment while doing it.



