There is a specific moment that produces more HIPAA exposure than any tracking pixel, any form, and any CRM in medical marketing. A practice owner reads a one-star review that is unfair, sits down, and writes a reply explaining what actually happened at that appointment.
That reply is a disclosure of protected health information to the entire internet, published by the covered entity, in writing, with a timestamp. It does not matter that the patient disclosed it first. It does not matter that the review is inaccurate. The Office for Civil Rights has settled cases on exactly this pattern, and the aggravating factor is always the same: the practice confirmed a person was a patient in order to correct them.
This guide covers how to generate reviews, how to respond to bad ones without stepping on that mine, and how to report reputation as something you manage rather than something that happens to you.
Why review volume matters more every year
Reviews were always a trust signal. They are now also a retrieval signal.
When a prospective patient asks an AI assistant which surgeon to see in their city, the systems answering that question read the same public corpus everyone else does: your reviews, their recency, their volume, and what they actually say. A practice with eleven reviews from 2023 is close to invisible in that context, regardless of how good the medicine is. We cover the broader mechanics in what happens when patients ask ChatGPT which surgeon to see.
The practical consequence: steady recent volume beats a high average from years ago. A 4.6 with forty reviews in the last twelve months is worth more than a 4.9 with twelve reviews across five years, both to patients and to the systems summarizing you.
Generating reviews without collecting bad ones
The sequence matters more than the ask.
Ask at the point of demonstrated satisfaction, not at discharge. For a procedure with a long result timeline, that moment is months after the visit, not the day of. Asking at discharge collects reviews about your parking.
Screen first, then ask. Send a short check-in question. Ask for the review only from the people whose answer was positive. Route anyone who signals a problem to a human who can fix it, before it becomes public.
This is a legitimate sequence and not review gating, provided you do one thing: never make the review itself conditional, and never offer anything in exchange for a positive one. Asking happy patients and helping unhappy ones is service. Filtering who is permitted to leave a review, or paying for sentiment, violates platform policy and FTC endorsement rules.
Make the physical act trivial. One link, one tap, landing directly on the review form. Every additional step costs a meaningful share of the people who intended to do it.
Never offer anything of value for a review. Not a discount, not a gift card, not an entry into a drawing. The FTC's updated Endorsement Guides treat incentivized reviews as material connections requiring disclosure, and platforms remove them independently.
Responding to negative reviews
The governing rule, and it has no exceptions: your response must never confirm, deny, or imply that the reviewer was ever a patient.
Not "we have no record of treating you." That confirms you checked records. Not "your procedure went exactly as planned." Not "you were advised of this during your consultation." Not a date, not a treatment, not a staff member's account of the visit.
What remains is narrower than people expect and more effective than they assume, because the audience for a review response is never the reviewer. It is the next prospective patient reading it. That person is evaluating one thing: how does this practice behave when someone is unhappy.
Template: a clinical complaint
Thank you for taking the time to share this. We take all feedback about our care seriously and we would like the opportunity to understand more. Please contact our office manager directly at [phone] or [email] so we can discuss your concerns privately. We are not able to discuss any individual's care publicly, and we appreciate your understanding of that.
The final sentence does real work. It tells every future reader why the response is not a rebuttal, which prevents the silence from looking like an admission.
Template: a service or wait-time complaint
We appreciate you letting us know. Running on time matters to us and we clearly did not meet that standard here. We would like to hear the details directly so we can address it. Please reach our office manager at [phone].
Service complaints carry less risk than clinical ones because acknowledging a general operational failing does not confirm a treatment relationship. Keep it general, and still do not confirm the visit.
Template: a review that appears to be fake or misdirected
We have not been able to match this feedback to any experience at our practice. If you have been in touch with our office and are not satisfied, please contact our office manager at [phone] so we can help.
Then report it through the platform's process. Do not argue in public, and do not say "you were never a patient here," which is the same disclosure in reverse.
Three rules that hold across all of them
- Respond within a few days, once. A single measured reply reads as confident. A thread reads as a fight.
- One person owns responses, trained on these constraints, with clinical replies reviewed before posting.
- Never let the physician reply from their personal account while annoyed. Nearly every settled case in this category began that way.
Reporting reputation as a managed number
Monthly, by location:
- New review volume, by platform. The number that predicts everything else.
- Running average, by platform and by location. A group practice with one weak location is invisible in a blended average.
- Sentiment themes. What are the negatives actually about? Wait times, billing, results, a specific staff member? Four reviews naming the same issue is an operations finding, not a marketing one.
- Response rate and time to response. Both should be near total and within days.
- Unresponded reviews older than 14 days, listed individually. This is the one that drives action.
By location matters more than most practices expect. A two-location group where one site sits at 4.8 and the other at 3.9 has a specific, fixable operations problem, and a blended 4.4 hides it completely.
The part that is not marketing
Review management surfaces problems. It does not solve them. A practice with a recurring complaint about wait times will not fix its rating with better responses, and should not try. The reporting exists to tell you what to go fix inside the practice.
That is also the honest answer to the question practices ask most often, which is whether reviews can be cleaned up. The negative ones that can be removed are the ones that violate platform policy, and they are a small minority. Everything else moves by volume: a practice generating twenty genuine reviews a month buries an old bad one in weeks without touching it.
Generating that volume depends on patients finishing their experience satisfied and being asked at the right moment, which is a function of everything upstream. The sequence that gets you there is in our retention and referrals guide.
See where your own growth leaks.
The free Practice Growth Audit traces your demand, your follow-through and your measurement, and hands you the gaps in writing. Built by hand, yours to keep.
