Dental Reviews and Ads: Where the PHI Line Sits
Replying to a dental review can confirm someone is a patient, which is a disclosure. Where the PHI line sits for review responses, review-gating, and reviews in ad creative.
A dental practice crosses the PHI line the moment a public review response confirms, denies, or details someone's care, because acknowledging that a named individual is a patient is itself a disclosure of protected health information, and Curve is the HIPAA-compliant tracking layer that keeps the same discipline on the measurement side when reviews feed into ads. The reviewer waived nothing by posting publicly. Their disclosure is theirs; yours is separately governed. That asymmetry is the whole rule, and it is where practices most often get caught. Curve includes a signed BAA on every plan.
The asymmetry nobody expects
A patient posts a one star review naming your practice, describing their root canal, complaining about the cost, and getting a detail wrong about what happened at the appointment.
Every instinct a business owner has is to correct the record. That instinct is the problem. The patient chose to disclose their own information, which they are entirely free to do. You did not gain permission to disclose it back. HIPAA restricts covered entities, not patients, and a public complaint is not an authorization.
This has been enforced. The Office for Civil Rights has taken action against dental practices specifically for responding to online reviews with patient details, including cases where the practice's response disclosed treatment information and payment disputes. The pattern is consistent enough that it is now one of the better known enforcement themes in small practice HIPAA.
And the bar is lower than most practices assume. You do not need to describe a procedure. Writing "we are sorry your visit did not meet expectations, please call our office to discuss your treatment plan" has confirmed that this person is a patient and that a treatment plan exists. That is a disclosure.
What a compliant response actually looks like
The safe response is generic to the point of feeling unsatisfying, and that is correct.
- Do not confirm the person is a patient. Not directly, not by implication, not by referencing "your visit."
- Do not mention any treatment, appointment, date, or payment. Including to correct an error the reviewer made.
- State your general practice policy and invite offline contact. "We take all feedback seriously and encourage anyone with concerns to contact our office directly" says nothing about anyone.
- Move the conversation off the platform. The substantive discussion belongs on a phone call, not in public.
Losing the argument publicly is the cost of compliance here. A practice that wins the exchange by explaining what really happened has traded a bad review for a regulatory exposure, and that is a bad trade at any review volume.
Review gating, and why it is a separate problem
Review gating means asking patients about their experience privately first, then directing only the happy ones toward a public review while routing unhappy ones to a feedback form.
This is prohibited by Google's policies and by the review platforms generally, and the FTC has treated it as a deceptive practice because it manufactures a misleading picture of consumer sentiment. In 2024 the FTC finalized a rule addressing fake and manipulated reviews, and suppression of negative reviews sits squarely inside it.
The compliance angle for dental practices is that gating is often built into the same patient communication platform that sends appointment reminders, which means the gating logic runs on patient data and the whole flow inherits both problems at once.
What is allowed is asking everyone. Send the same request to every patient, do not condition the ask on a predicted rating, do not filter based on a first response, and do not offer anything of value in exchange for a positive review specifically. Incentivizing reviews at all is a policy problem on most platforms; incentivizing positive ones is a legal one.
Review requests are patient communications
One thing practices overlook: the review request itself is a communication to a patient from a covered entity, sent because they received care. The list you send it to is a patient list.
That means the platform sending it needs a BAA, the list should not be uploaded to an ad platform as a custom audience, and the request should not name the procedure. "How was your implant consultation?" in an email subject line is a disclosure sitting in the reviewer's inbox preview on a shared family device.
Reviews in ad creative
Using patient reviews in advertising is where the marketing team and the compliance obligation collide most directly, and the rules are stricter than for a restaurant using the same review.
Written authorization is required. Using a patient's testimonial in marketing is a use of PHI for marketing purposes, and it requires a HIPAA-compliant written authorization from that patient. A public review is not an authorization. The person consented to publish their words on Google; they did not consent to appear in your Meta ads.
The authorization has to be specific. It should name the media, the duration, and the ability to revoke. A blanket "we may use your feedback in marketing" line in intake paperwork is weak, and it is worth having counsel look at the form you actually use.
Before and after photos are their own category. Orthodontic and cosmetic dental images are clinical images of an identifiable person. They need explicit written authorization, and Meta separately restricts before and after imagery in health and cosmetic advertising. Blurring the eyes does not solve either problem.
Aggregate claims are safer than individual ones. "Rated 4.8 across 600 reviews" discloses nothing about any individual and needs no authorization. It is also usually more persuasive than a single quote.
The star rating extension question
Google Ads seller ratings and location extensions pull aggregate review data automatically. That is aggregate, it comes from the platform, and it does not disclose an individual. It is fine.
What is not fine is manually pasting an individual patient's review text into ad copy without authorization, or building an ad around one person's story. The difference is whether an identifiable individual's care is being disclosed.
How Curve keeps review-driven marketing measurable without PHI
Reviews drive traffic, and practices reasonably want to measure what that traffic does. Curve is HIPAA-compliant ad tracking, marketing attribution, and analytics for healthcare, and it handles that measurement without letting patient identity flow into ad platforms.
The tracking script installs in place of the Meta Pixel and Google tag, so events reach Curve's US-hosted infrastructure rather than going straight outward. That interception is what makes the following controls enforceable.
- Per-destination field mapping. Only fields you explicitly map forward to a given destination, and the default is that nothing goes. A review platform integration that starts posting reviewer names into your funnel does not push them onward.
- Neutral event aliases. A conversion driven by a review campaign gets a neutral name outbound. Your reporting keeps the descriptive one.
- SHA-256 identifier hashing. Contact identifiers are hashed per each platform's conversion API requirements before forwarding, so no plaintext patient contact detail leaves.
- Incoming webhooks. Patient communication and practice management systems post outcomes back, matched by email, click ID, or bridge token, so review-driven bookings are attributable without exporting a patient list anywhere.
- Bridge tokens. Attribution survives when someone clicks from a review profile through to a separate booking tool.
- PHI-pattern detection. Payloads containing PHI-shaped values are flagged as a monitoring signal, which is how a practice discovers that a reputation platform integration started including free-text feedback fields.
- Offline conversion uploads. Attended appointments upload in bulk with click ID matching, so review-influenced campaigns can be judged on real outcomes.
A signed BAA is included on every plan. For the surrounding practice, see the dental marketing compliance checklist and why client-side pixels create the exposure.
A practical policy for the front desk
Most review disclosures come from a well meaning team member with platform access and no guidance, so the policy has to be operational rather than aspirational.
Name one person responsible for review responses. Give them two or three approved response templates that contain no patient specifics, and a rule that anything outside those templates gets escalated rather than improvised. Remove review platform access from everyone else.
Set a rule that no response is written on the same day the review appears. The disclosures that cause problems are written while someone is angry, and a day of delay removes most of them.
For any review alleging clinical harm, involve counsel before responding at all, including before posting a generic response. And keep a log of responses posted, because if a complaint arrives you will need to show what was said.
Frequently asked questions
Can we respond to a review that names our practice and describes treatment?
Only generically. You may thank the person for feedback and invite offline contact. You may not confirm they are a patient, reference their visit, or correct their account of what happened.
The reviewer already made their care public. Does that release us?
No. A patient may disclose their own information freely. That does not authorize the practice to disclose it. The obligation runs on you regardless of what the patient posted.
Is asking only satisfied patients for reviews illegal?
It violates Google's policies and the FTC has treated review suppression as deceptive. Ask every patient with the same message and do not condition the request on an expected rating.
Can we use a five star Google review in a Facebook ad?
Not without a HIPAA-compliant written authorization from that patient covering that use. The public posting is not an authorization for you to use their testimonial in marketing.
Are aggregate ratings safe to advertise?
Yes. An overall rating and review count disclose nothing about any individual, need no authorization, and are usually more credible in ad copy than a single quote.
Can we upload our patient list to request reviews through an ad platform?
No. A patient list uploaded to an ad platform is a disclosure of PHI to an entity that has not signed a BAA, and neither Meta nor Google signs one for its advertising products.
What about before and after photos with the eyes blurred?
Still requires written authorization, because the person remains identifiable in context and the image is clinical. Meta also restricts before and after imagery in health advertising independently of the HIPAA question.
Where to start
Audit the last year of your review responses first. Look for any reply that confirms someone is a patient, references a visit, or mentions a treatment or payment. Those are the ones worth having counsel look at, and worth editing where the platform allows it.
Then fix the process: single owner, approved templates, no same-day responses, and a documented rule that testimonials in advertising require written authorization on file.
On the measurement side, Curve provides the pipeline that lets you judge review and reputation campaigns on real outcomes without exporting patient identity: server-side collection to US-hosted infrastructure, per-destination field mapping, hashed identifiers, neutral event aliases, bridge tokens across booking handoffs, webhook and offline outcome matching, PHI-pattern monitoring, and a signed BAA on every plan.
Run the free compliance scanner against your practice site, review the DSO marketing technology stack, or visit curvecompliance.com to tighten the measurement side.
Reviewed August 2026. Review platform policies, FTC rules, and healthcare advertising requirements change frequently. Verify current requirements with counsel before implementation.
Related articles
- GuideDental Practice Facebook Ads After Meta 2026 Restrictions: What DSOs and Solo Dentists Can Still Do
- GuideIs Birdeye HIPAA Compliant? Reviews and Patient Data
- GuideGoogle Ads Healthcare Audience Targeting: Which Segments Are HIPAA-Safe (and Which Leak PHI)
- GuideAmazon Ads for Health Brands: PHI-Safe Conversions
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit