July 24, 2026
5 min
Discover the five dashboard design mistakes that undermine trust in your dental practice data, and learn practical ways to fix each one.
July 24, 2026
8 min
Learn how to respond to fake or unverified dental reviews while protecting patient privacy, avoiding HIPAA violations, and using safe response examples.

A one-star review shows up on your Google Business Profile from someone your team doesn't recognize. It names no procedure, no date, and no staff member — just a vague complaint. Every instinct says to set the record straight: "We have no record of you as a patient." That single sentence, meant to protect your practice's reputation, can create a HIPAA problem the review itself never did.
Responding to negative reviews is part of running a modern dental practice. But healthcare providers face a constraint most businesses don't: almost anything you say publicly about a specific patient's relationship with your practice can qualify as a disclosure of protected health information (PHI) — even when you're trying to defend yourself against someone who was never a patient at all.
Under HIPAA, confirming or denying that a specific named person is a patient is itself a disclosure of PHI, regardless of intent. The Department of Health and Human Services (HHS) has taken enforcement action against healthcare providers for exactly this pattern: responding to a negative online review by revealing details about a patient's diagnosis, treatment, or even the simple fact that they were seen at the practice.
This creates a genuine dilemma. The review might be fake, written by a competitor, misdirected to the wrong location, or based on a single bad interaction at the front desk. Whatever the case, the instinct to say "this isn't one of our patients" is functionally the same disclosure risk as confirming someone is a patient — you're making a statement about a specific person's relationship to your practice, tied to their name, in public.
Not every suspicious review is fraudulent, and it's worth distinguishing between categories before deciding how to respond:
The safe response framework below applies to all four categories, because the risk isn't about whether the review is fake — it's about what your response reveals.
The rule that protects your practice in every scenario: never confirm or deny that the reviewer is or was a patient. This holds true whether the review is glowing or scathing, accurate or fabricated.
A safe response follows three principles:
This is consistent with guidance the American Dental Association has issued around patient privacy and professional communication: providers are expected to maintain confidentiality even when patients waive their own privacy publicly. A patient posting their own treatment details doesn't give your practice permission to confirm or elaborate on them.
Risky response (avoid): "We checked our records and have no patient named [Name] who was treated here in [Month]. This review appears to be fake."
Why it's risky: This confirms the practice searched patient records tied to a specific name and made a public statement about the outcome — a PHI-adjacent disclosure, even though the intent was simply to correct the record.
Safe response: "We take all patient feedback seriously and would like to understand more about your experience. Please call our office at [phone number] so we can address this directly."
Why it works: It doesn't confirm or deny anything about the reviewer's patient status. It redirects the conversation to a private channel where any real issue can be resolved without public disclosure.
Safe response for an unmistakably fake or malicious review: "We're unable to identify this review with any patient interaction at our practice. We encourage anyone with a specific concern to contact us directly at [phone number]."
Why it works: Note the careful phrasing — "unable to identify this review with any patient interaction" avoids stating there is no patient by that name, which still edges toward confirming an absence. If your practice manager or marketing team is uncertain, the safest default is always the shorter, generic acknowledgment above.
If a review is clearly fraudulent — a competitor, a bot, or unrelated to any real patient interaction — most platforms allow you to flag it for removal:
Flagging is a better first move than a public rebuttal in cases where you're confident the review has no basis in a real patient encounter — it resolves the problem without creating a HIPAA exposure at all.
Most review-response HIPAA violations don't happen because a practice intended to disclose PHI. They happen because a well-meaning office manager or marketing coordinator responded in the moment, defending the practice's reputation without thinking through the privacy implications. A few safeguards prevent this:
Automated reputation management tools can help enforce this consistency by routing negative reviews to a designated staff member for review before any public response goes out, rather than leaving it to whoever happens to see the notification first.
Every negative review feels like it demands an immediate, specific defense. In dentistry, that instinct is exactly what creates legal exposure. The safest response is almost always the most generic one: acknowledge the concern, decline to confirm any details, and move the conversation offline. It protects patient privacy, it protects your practice from HIPAA enforcement risk, and — perhaps counterintuitively — it also tends to look more professional to anyone else reading the review thread.
If your team needs a system for catching and routing reviews before a rushed public reply happens, Convertlens's automated reputation management can help build that safeguard into your existing workflow.
No — stating that someone was never a patient is still a disclosure about their relationship (or lack of one) to your practice, tied to their name, in public. The safer approach avoids confirming or denying patient status in either direction.
A patient can disclose their own information publicly, but your practice's response still can't confirm, deny, or add to what they've shared. Respond generically and invite them to discuss further offline.
Yes, for the same reason. Even a glowing review that says "Dr. Smith did a great job on my crown" shouldn't be met with a response like "So glad we could help with your crown!" — that confirms the specific treatment publicly.
The practice — not the individual reviewer — bears compliance responsibility. This is why designating and training specific staff to handle responses matters more than most practices initially assume.
Yes, and the risk multiplies with scale. DSOs managing reputation across multiple locations need centralized response protocols precisely because more staff touching more reviews increases the chance of an off-script reply.
Sign Up Now & Someone from Our Team Will Be in Touch Shortly!
Use the form below to send us a message, and we’ll get back to you as soon as we can.