How to Respond to a Fake Dental Review Without Violating HIPAA

Learn how to respond to fake or unverified dental reviews while protecting patient privacy, avoiding HIPAA violations, and using safe response examples.

A one-star review shows up on your Google Business Profile from someone your team doesn't recognize. It names no procedure, no date, and no staff member — just a vague complaint. Every instinct says to set the record straight: "We have no record of you as a patient." That single sentence, meant to protect your practice's reputation, can create a HIPAA problem the review itself never did.

Responding to negative reviews is part of running a modern dental practice. But healthcare providers face a constraint most businesses don't: almost anything you say publicly about a specific patient's relationship with your practice can qualify as a disclosure of protected health information (PHI) — even when you're trying to defend yourself against someone who was never a patient at all.

Why Dental Reviews Are a HIPAA Minefield

Under HIPAA, confirming or denying that a specific named person is a patient is itself a disclosure of PHI, regardless of intent. The Department of Health and Human Services (HHS) has taken enforcement action against healthcare providers for exactly this pattern: responding to a negative online review by revealing details about a patient's diagnosis, treatment, or even the simple fact that they were seen at the practice.

This creates a genuine dilemma. The review might be fake, written by a competitor, misdirected to the wrong location, or based on a single bad interaction at the front desk. Whatever the case, the instinct to say "this isn't one of our patients" is functionally the same disclosure risk as confirming someone is a patient — you're making a statement about a specific person's relationship to your practice, tied to their name, in public.

What Counts as a "Fake" or Unverified Review

Not every suspicious review is fraudulent, and it's worth distinguishing between categories before deciding how to respond:

  • No record of the reviewer — the name doesn't match anyone in your PMS, and no appointment history exists.
  • Wrong location — the review clearly describes a different office, sometimes even a different practice with a similar name.
  • Competitor or troll activity — vague, generic complaints with no specific details, sometimes posted alongside similarly vague reviews of other local practices.
  • A real patient, misremembered details — the person was a patient, but the specifics (date, provider, procedure) are inaccurate or exaggerated.

The safe response framework below applies to all four categories, because the risk isn't about whether the review is fake — it's about what your response reveals.

The Response Framework That's Always Safe

The rule that protects your practice in every scenario: never confirm or deny that the reviewer is or was a patient. This holds true whether the review is glowing or scathing, accurate or fabricated.

A safe response follows three principles:

  • Acknowledge without confirming. Thank the reviewer for their feedback and express concern, without validating that they received care at your practice.
  • Take it offline. Invite them to call the office directly to discuss their experience — this moves any patient-specific conversation to a private, secure channel.
  • Never include identifying details. No names, dates, procedures, insurance information, or outcomes — ever, regardless of what the reviewer included in their own post.

This is consistent with guidance the American Dental Association has issued around patient privacy and professional communication: providers are expected to maintain confidentiality even when patients waive their own privacy publicly. A patient posting their own treatment details doesn't give your practice permission to confirm or elaborate on them.

Real Example Language

Risky response (avoid): "We checked our records and have no patient named [Name] who was treated here in [Month]. This review appears to be fake."

Why it's risky: This confirms the practice searched patient records tied to a specific name and made a public statement about the outcome — a PHI-adjacent disclosure, even though the intent was simply to correct the record.

Safe response: "We take all patient feedback seriously and would like to understand more about your experience. Please call our office at [phone number] so we can address this directly."

Why it works: It doesn't confirm or deny anything about the reviewer's patient status. It redirects the conversation to a private channel where any real issue can be resolved without public disclosure.

Safe response for an unmistakably fake or malicious review: "We're unable to identify this review with any patient interaction at our practice. We encourage anyone with a specific concern to contact us directly at [phone number]."

Why it works: Note the careful phrasing — "unable to identify this review with any patient interaction" avoids stating there is no patient by that name, which still edges toward confirming an absence. If your practice manager or marketing team is uncertain, the safest default is always the shorter, generic acknowledgment above.

When and How to Flag a Review

If a review is clearly fraudulent — a competitor, a bot, or unrelated to any real patient interaction — most platforms allow you to flag it for removal:

  • Google Business Profile allows flagging reviews that violate content policies, including reviews with no connection to a genuine customer experience.
  • Yelp has a similar reporting mechanism, though removal isn't guaranteed and can take time.
  • Documentation matters. Keep an internal record of why a review was flagged (no matching patient record, no matching appointment date) without putting that reasoning in the public response itself.

Flagging is a better first move than a public rebuttal in cases where you're confident the review has no basis in a real patient encounter — it resolves the problem without creating a HIPAA exposure at all.

Training Your Team to Not Reply Off-Script

Most review-response HIPAA violations don't happen because a practice intended to disclose PHI. They happen because a well-meaning office manager or marketing coordinator responded in the moment, defending the practice's reputation without thinking through the privacy implications. A few safeguards prevent this:

  • Designate one person (or a small, trained group) as the only staff authorized to respond to reviews publicly.
  • Create approved response templates for common scenarios — the safe language above is a starting point — so no one is drafting a reply from scratch under pressure.
  • Require a second look before anything goes live, especially for negative reviews that name specific details.
  • Treat review responses like any other patient-facing communication — subject to the same privacy standards as a phone call or email, because legally, they are.

Automated reputation management tools can help enforce this consistency by routing negative reviews to a designated staff member for review before any public response goes out, rather than leaving it to whoever happens to see the notification first.

Every negative review feels like it demands an immediate, specific defense. In dentistry, that instinct is exactly what creates legal exposure. The safest response is almost always the most generic one: acknowledge the concern, decline to confirm any details, and move the conversation offline. It protects patient privacy, it protects your practice from HIPAA enforcement risk, and — perhaps counterintuitively — it also tends to look more professional to anyone else reading the review thread.

If your team needs a system for catching and routing reviews before a rushed public reply happens, Convertlens's automated reputation management can help build that safeguard into your existing workflow.

Frequently Asked Questions on Replying to Fake Reviews

Can I say "this person was never a patient" if it's true?

No — stating that someone was never a patient is still a disclosure about their relationship (or lack of one) to your practice, tied to their name, in public. The safer approach avoids confirming or denying patient status in either direction.

What if the review includes the patient's own treatment details?

A patient can disclose their own information publicly, but your practice's response still can't confirm, deny, or add to what they've shared. Respond generically and invite them to discuss further offline.

Should I ever respond to positive reviews the same way?

Yes, for the same reason. Even a glowing review that says "Dr. Smith did a great job on my crown" shouldn't be met with a response like "So glad we could help with your crown!" — that confirms the specific treatment publicly.

Who is responsible if a HIPAA violation happens through a review response?

The practice — not the individual reviewer — bears compliance responsibility. This is why designating and training specific staff to handle responses matters more than most practices initially assume.

Does this apply to DSOs managing reviews across multiple locations?

Yes, and the risk multiplies with scale. DSOs managing reputation across multiple locations need centralized response protocols precisely because more staff touching more reviews increases the chance of an off-script reply.

shape-light
dot-lightdot-light

Related Blogs

Discover the five dashboard design mistakes that undermine trust in your dental practice data, and learn practical ways to fix each one.

Discover practical strategies to reduce missed calls, improve appointment bookings, and maximize marketing ROI with smarter call handling and recovery workflows.

Five clear signs your dental CRM no longer fits your practice's size or complexity, and what to check before switching systems.

Ready to Get Started?

Sign Up Now & Someone from Our Team Will Be in Touch Shortly!

Contact Us

Use the form below to send us a message, and we’ll get back to you as soon as we can.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.