A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information disclosure rubric. Among the 80,300 recent Google review replies collected, the study estimated that about 26% contained language that disclosed or confirmed patient information under its review rubric. Healthcare practices are routinely told to respond to online reviews.
From a reputation-management perspective, that advice makes sense: be responsive, be human, and show prospective patients that someone is listening. In most industries, a warm and personal reply is harmless. In healthcare, the word “personal” can be the problem.
A patient can choose to discuss their own diagnosis, treatment, visit, billing dispute, or outcome in a public review. A HIPAA-covered provider has a separate obligation. The fact that a patient disclosed information about themselves does not, by itself, give the provider permission to confirm it, expand on it, or connect the reviewer’s identity to care in a public reply.
The HIPAA Privacy Rule generally limits uses and disclosures of protected health information (PHI) unless the disclosure is permitted by the Rule or supported by a valid authorization. 2, 3, 4 Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Research Findings The study sampled 4,019 medical and dental practices across 10 clinical disciplines in California and the Pacific Northwest.
Of those, 2,972 practices replied to reviews. We collected 80,300 of their recent public Google review replies and screened every reply using a two-stage process. 1 First, a rule-based classifier tuned to favor recall flagged 26,147 replies as potentially disclosing patient information.
Second, flagged replies were adjudicated by a human reviewer against a single conservative rubric that looked only at what the practice itself disclosed. Replies were counted when the provider’s response confirmed a patient or visit relationship, disclosed a clinical detail, or referenced billing or insurance information tied to the reviewer. Generic thanks and replies that did not confirm care were cleared.
1 Seven disciplines were audited in full. For the three largest cohorts: chiropractic, physical therapy, and dental: the study used reproducible random samples of flagged replies and projected the confirmed rate across the remaining flagged replies, with 95% confidence intervals. In total, 9,844 replies were reviewed by hand.
Reviewers directly confirmed 7,991 disclosure-risk replies, with approximately 13,126 additional replies statistically projected across the three sampled cohorts. The combined estimate was approximately 21,117 public replies, or 26. 3% of all replies collected.
1 This should not be read as a national HIPAA violation rate. The study covered selected regions, reviewed recent Google replies rather than every platform, and classified disclosure language rather than making a legal determination about each practice’s HIPAA covered-entity status, patient authorization, or other case-specific facts. It is best understood as a measurement of public disclosure risk.
Among the seven fully audited disciplines, the share of replying practices with at least one confirmed disclosure-risk reply was: Discipline Replying practices with ≥1 confirmed disclosure Fertility / reproductive 90. 0% Sports medicine 76. 0% Pain management 69.
2% Dermatology 64. 3% Psychiatry / mental health 62. 2% Podiatry 62.
2% Pediatrics 60. 8% Source: SturdyWeb findings report. These practice-level rates apply only to the seven fully audited disciplines; the three largest cohorts were handled through sampled reply-level adjudication and projection.
The Most Common Problem is not a Dramatic Disclosure The most important finding was not that staff were posting long medical histories. Most were not. The more common failure was smaller: the practice confirmed something the reviewer had already said.
Among the disclosure-risk replies confirmed by hand, 58% confirmed patient or visit status, 41% disclosed a clinical detail such as a condition, procedure, result, symptom, or body part, and 1% referenced billing or insurance. In other words, the majority of the problem was not an explicit diagnosis. It was the provider publicly linking an identifiable person to the provision of care.
12 Two recurring behaviors explained much of what we saw. “Care narrators” repeated the patient’s story: what hurt, what procedure was performed, how treatment progressed, or what outcome occurred. “Visit confirmers” said less, but still acknowledged that the reviewer had been a patient, had visited the office, or had received care.
The distinction is easier to see in examples: Reply pattern Example Why it matters Clinical detail “We’re glad your sciatica improved after your adjustments.” Echoes a condition and treatment back to an identifiable reviewer. Patient/visit confirmation “Thank you for trusting our team with your care these past two years.”
Confirms a care relationship even without naming a diagnosis. Safer public response “Thank you for taking the time to share your feedback. We appreciate it.”
Acknowledges the review without confirming whether the reviewer received care. Examples are composed and de-identified to illustrate patterns observed in the study; they are not reproduced patient reviews. Why “the patient said it first” is Not a Safe Rule The misunderstanding is understandable.
A patient writes publicly, “My back pain improved after treatment,” so a staff member replies, “We’re glad your back pain is better.” To the person writing the reply, nothing new seems to have been revealed. HIPAA does not work that way.
Originally published at hipaajournal.com


