We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight
A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information disclosure rubric.
Among the 80,300 recent Google review replies collected, the study estimated that about 26% contained language that disclosed or confirmed patient information under its review rubric.
Healthcare practices are routinely told to respond to online reviews. From a reputation-management perspective, that advice makes sense: be responsive, be human, and show prospective patients that someone is listening. In most industries, a warm and personal reply is harmless. In healthcare, the word “personal” can be the problem.
A patient can choose to discuss their own diagnosis, treatment, visit, billing dispute, or outcome in a public review. A HIPAA-covered provider has a separate obligation. The fact that a patient disclosed information about themselves does not, by itself, give the provider permission to confirm it, expand on it, or connect the reviewer’s identity to care in a public reply. The HIPAA Privacy Rule generally limits uses and disclosures of protected health information (PHI) unless the disclosure is permitted by the Rule or supported by a valid authorization.2, 3, 4
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Research Findings
The study sampled 4,019 medical and dental practices across 10 clinical disciplines in California and the Pacific Northwest. Of those, 2,972 practices replied to reviews. We collected 80,300 of their recent public Google review replies and screened every reply using a two-stage process.1
First, a rule-based classifier tuned to favor recall flagged 26,147 replies as potentially disclosing patient information. Second, flagged replies were adjudicated by a human reviewer against a single conservative rubric that looked only at what the practice itself disclosed. Replies were counted when the provider’s response confirmed a patient or visit relationship, disclosed a clinical detail, or referenced billing or insurance information tied to the reviewer. Generic thanks and replies that did not confirm care were cleared.1
Seven disciplines were audited in full. For the three largest cohorts: chiropractic, physical therapy, and dental: the study used reproducible random samples of flagged replies and projected the confirmed rate across the remaining flagged replies, with 95% confidence intervals. In total, 9,844 replies were reviewed by hand. Reviewers directly confirmed 7,991 disclosure-risk replies, with approximately 13,126 additional replies statistically projected across the three sampled cohorts. The combined estimate was approximately 21,117 public replies, or 26.3% of all replies collected.1
This should not be read as a national HIPAA violation rate. The study covered selected regions, reviewed recent Google replies rather than every platform, and classified disclosure language rather than making a legal determination about each practice’s HIPAA covered-entity status, patient authorization, or other case-specific facts. It is best understood as a measurement of public disclosure risk.
Among the seven fully audited disciplines, the share of replying practices with at least one confirmed disclosure-risk reply was:
| Discipline | Replying practices with ≥1 confirmed disclosure |
| Fertility / reproductive | 90.0% |
| Sports medicine | 76.0% |
| Pain management | 69.2% |
| Dermatology | 64.3% |
| Psychiatry / mental health | 62.2% |
| Podiatry | 62.2% |
| Pediatrics | 60.8% |
Source: SturdyWeb findings report. These practice-level rates apply only to the seven fully audited disciplines; the three largest cohorts were handled through sampled reply-level adjudication and projection.
The Most Common Problem is not a Dramatic Disclosure
The most important finding was not that staff were posting long medical histories. Most were not. The more common failure was smaller: the practice confirmed something the reviewer had already said.
Among the disclosure-risk replies confirmed by hand, 58% confirmed patient or visit status, 41% disclosed a clinical detail such as a condition, procedure, result, symptom, or body part, and 1% referenced billing or insurance. In other words, the majority of the problem was not an explicit diagnosis. It was the provider publicly linking an identifiable person to the provision of care.12
Two recurring behaviors explained much of what we saw. “Care narrators” repeated the patient’s story: what hurt, what procedure was performed, how treatment progressed, or what outcome occurred. “Visit confirmers” said less, but still acknowledged that the reviewer had been a patient, had visited the office, or had received care.
The distinction is easier to see in examples:
| Reply pattern | Example | Why it matters |
| Clinical detail | “We’re glad your sciatica improved after your adjustments.” | Echoes a condition and treatment back to an identifiable reviewer. |
| Patient/visit confirmation | “Thank you for trusting our team with your care these past two years.” | Confirms a care relationship even without naming a diagnosis. |
| Safer public response | “Thank you for taking the time to share your feedback. We appreciate it.” | Acknowledges the review without confirming whether the reviewer received care. |
Examples are composed and de-identified to illustrate patterns observed in the study; they are not reproduced patient reviews.
Why “the patient said it first” is Not a Safe Rule
The misunderstanding is understandable. A patient writes publicly, “My back pain improved after treatment,” so a staff member replies, “We’re glad your back pain is better.” To the person writing the reply, nothing new seems to have been revealed.
HIPAA does not work that way. PHI includes individually identifiable information about the provision of health care, health conditions, and payment for care. A provider’s public response is its own disclosure. Unless the disclosure is permitted by the Privacy Rule or supported by a valid authorization, the patient’s decision to post first does not create a blanket exception for the covered entity to discuss the patient publicly.234
OCR has already enforced this principle in the online-review context. Elite Dental Associates paid $10,000 to settle potential HIPAA Privacy Rule violations involving social-media disclosures of patients’ PHI. OCR imposed a $50,000 civil money penalty on Dr. U. Phillip Igbinadolor, D.M.D. & Associates after the practice impermissibly disclosed a patient’s PHI on a webpage in response to a negative review. New Vision Dental paid $23,000 to resolve an investigation involving PHI disclosed in responses to online reviews. Manasa Health Center paid $30,000 and entered a corrective action plan after OCR investigated disclosures of patient PHI in responses to negative Google reviews.5678
Those cases matter because they closely resemble the ordinary behavior measured in this study: a practice responding to a public review and saying too much. The risk is not theoretical, and it is not limited to large health systems.
AI can Turn a Scattered Mistake into a Repeatable Workflow
There is a second reason to address this now. Review-response tools increasingly offer automated or AI-assisted drafting. The research did not attempt to determine whether the replies we reviewed were written by people or generated by software, so the current findings should not be attributed to AI. The forward-looking risk, however, is straightforward.
A generative system prompted to “write a warm, personal response” will often use the content of the review as context. If the reviewer mentions a diagnosis, procedure, pregnancy, injury, medication, insurance issue, or treatment outcome, a personalization-first system may mirror that information back into the provider’s public response. Without a compliance rule in the workflow, automation can convert an occasional human mistake into a consistent process.
Healthcare organizations therefore need to govern the output, not just the tool. A review platform does not become safe because it has an AI feature, and a human approval step is only useful if the reviewer has been trained on what cannot be confirmed publicly.
What HIPAA Compliance Teams Should Do Now
The fix is not to stop responding to reviews. It is to change the response standard. Public replies can still be polite, timely, and useful without confirming anything about the reviewer’s care.
- Adopt a no-PHI public-reply rule that limits the default public response to the review itself and does not confirm patient status, visits, diagnoses, procedures, outcomes, medications, coverage, or payment.
- Move substantive conversations to a private channel by inviting the individual to contact the office through an approved private channel when a review raises a real service or care concern, rather than litigating the facts of the encounter in public.
- Audit historical responses across Google and other platforms, preserving an appropriate record and involving the privacy officer or counsel before any broad cleanup if a complaint, investigation, or litigation hold is pending.
- Train the people who actually post, including front-desk staff, office managers, marketing teams, and agencies with review-platform access, since general annual HIPAA training may not be specific enough to catch this workflow.
- Put AI-assisted replies behind the same policy by configuring templates and review instructions so the system never repeats clinical, visit, or billing details from the review, and by testing the workflow with deliberately sensitive examples before deployment.
- Create a small library of safe templates, such as “Thank you for taking the time to share your feedback. We appreciate it,” to reduce the pressure to improvise.
The Larger Lesson is That Reputation Management is Part of Healthcare Privacy
Healthcare privacy programs traditionally focus on EHR access, email, faxing, portals, vendors, and cybersecurity. Public-facing reputation workflows can sit outside that mental model because the information is already visible on the internet. That is precisely why review replies become a blind spot.
The patient’s post and the provider’s response are not the same act. One is an individual choosing to speak about themselves. The other is an organization speaking about an identifiable person in its capacity as a healthcare provider. Once that distinction is understood, the safe operating rule becomes simple: acknowledge the feedback without acknowledging the care.
Our data suggests many practices have never translated that principle into the day-to-day work of answering reviews. The opportunity for compliance teams is unusually practical. This is a public, searchable risk that can be audited, remediated, trained, and governed without changing clinical care. For many practices, a one-page policy and a disciplined cleanup may eliminate an exposure pattern that has been accumulating in plain sight for years.
Methodology and Limitations
The underlying findings report reviewed 4,019 practices across 10 clinical disciplines in California and the Pacific Northwest and collected 80,300 recent public Google review replies from the 2,972 sampled practices that responded to reviews. A rule-based screen flagged potentially disclosing replies, followed by human adjudication using a uniform conservative rubric. Seven disciplines were audited in full; chiropractic, physical therapy, and dental were assessed through reproducible random samples of flagged replies and statistical projection across the remaining flagged replies. The report contains no practice or patient names, and the examples in the report are redacted or composed.1
The study is not a legal adjudication of individual practices or replies, and it should not be interpreted as a nationally representative prevalence estimate. It did not review every historical reply or every platform, and it did not determine the HIPAA covered-entity status, authorization history, or other facts that could affect the legal analysis of a specific response. Those limitations are important; they do not change the operational pattern the study identified.
Disclosure and Disclaimer
The research described in this article was conducted by SturdyWeb, a service of Daevara Consulting, LLC. The author is affiliated with the organization that conducted the research. This article is provided for general educational purposes and is not legal advice. Whether a specific communication violates HIPAA depends on the facts and applicable law and should be evaluated by qualified counsel or a HIPAA compliance professional.
References
- SturdyWeb. “The Privacy Blind Spot in Your Members’ Review Replies.” Findings report prepared for medical and dental professional associations, August 2026.
- 45 C.F.R. § 160.103, definitions of individually identifiable health information and protected health information. Source
- 45 C.F.R. § 164.502, general rules for uses and disclosures of protected health information. Source
- 45 C.F.R. § 164.508, uses and disclosures for which an authorization is required. Source
- U.S. Department of Health and Human Services, Office for Civil Rights. Elite Dental Associates enforcement action: $10,000 settlement over social-media disclosures of patients’ PHI (2019). Source
- U.S. Department of Health and Human Services, Office for Civil Rights. Dr. U. Phillip Igbinadolor, D.M.D. & Associates enforcement action: $50,000 civil money penalty for impermissible disclosure in response to a negative online review. Source
- U.S. Department of Health and Human Services, Office for Civil Rights. New Vision Dental: $23,000 settlement over PHI disclosures in responses to online reviews (2022). Source
- U.S. Department of Health and Human Services, Office for Civil Rights. Manasa Health Center: $30,000 settlement involving PHI disclosed in responses to negative online reviews (2023). Source
The post We Reviewed 80,300 Healthcare Review Replies. The HIPAA Risk Was Hiding in Plain Sight appeared first on The HIPAA Journal.
HIPAA Turns 30, but Its Protections Fall Short – National Partnership for Women & Families
HIPAA Breach Notification Deadline Starts at Discovery, Not Investigation Completion – Crowell & Moring LLP
US government is pushing to gain unprecedented access to your medical records – as data protections are weakening – swiowanewssource.com
US government is pushing to gain unprecedented access to your medical records – as data protections are weakening – hpenews.com
US government is pushing to gain unprecedented access to your medical records – as data protections are weakening – Shelby News
Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon – The HIPAA Journal
Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon
Data breaches have recently been announced by Terry J. Dubrow, MD, SunCloud Health, Integer Precision Technologies, Minnesota ENT, and Nipro Medical Corp.
Terry J. Dubrow, MD, California
Terry J. Dubrow, MD, a Beverly Hills, CA-based plastic surgeon, has notified the California Attorney General about a recent security incident involving patient information. The practice was contacted by an individual who claimed to have breached its computer systems and copied sensitive patient information. An investigation was launched to establish whether the claim was legitimate, and it was confirmed that there had been unauthorized access to parts of its network starting on January 16, 2026, and that files had been copied.
The affected data was reviewed, and on July 27, 2026, the practice confirmed that patients’ personal information had been obtained, including names, information collected on patient charts, and referring physician information. That information may have included contact information, Social Security numbers, driver’s license numbers or state ID numbers, birth dates, prescription information, treatment information, procedure images, and X-rays. The practice has implemented additional security measures to reduce the risk of similar incidents in the future, and the affected individuals have been offered complimentary identity theft protection services. The number of affected individuals has yet to be publicly disclosed.
SunCloud Health, Illinois
SunCloud Health, a Northbrook, Illinois-based behavioral health treatment network, has recently disclosed a data security incident involving the protected health information of 2,594 individuals. Unusual activity was identified in certain employee email accounts. Steps were taken to secure its email system, and an investigation was initiated to determine the cause of the activity. The investigation confirmed unauthorized access to certain employee email accounts between April 22, 2026, and May 4, 2026.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The affected accounts were reviewed, and on June 16, 2026, SunCloud Health determined that the accounts contained patient names and medical information related to the services provided, including diagnoses, medications, and treatment information. The affected individuals were notified by mail on July 23, 2026; existing security protocols have been enhanced, and IT systems are being monitored, with additional safeguards being evaluated.
Integer Precision Technologies, Massachusetts
Integer Precision Technologies, a Hudson, Massachusetts-based company that makes coatings for medical devices, has recently disclosed a data security incident involving a cloud-based SaaS file sharing application. While it is unclear exactly when the incident was detected or for how long access was possible, the investigation determined that an unauthorized third party accessed the application and copied files.
Assisted by a third-party data review firm, the company determined that the files contained personal information including names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account numbers, and some health-related information. The affected individuals have been offered 24 months of complimentary credit monitoring and identity theft protection services, and steps have been taken to enhance security. The number of affected individuals has yet to be publicly disclosed.
Minnesota ENT
Oakdale Ear, Nose, & Throat PA, doing business as Minnesota ENT, has started notifying individuals affected by a recent email security incident. It is unclear from the substitute breach notice when the security incident was detected, or for how long it lasted. The notice states that six employee email accounts were accessed by an unauthorized third party and, assisted by third-party cybersecurity experts, Minnesota ENT determined on July 15, 2026, that the accounts contained HIPAA-protected data.
Data compromised in the incident included first and last names, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. Notification letters started to be mailed to the affected individuals on August 12, 2026. The letters include information on the steps that can be taken to protect against data misuse. The number of affected individuals has yet to be publicly disclosed.
Nipro Medical Corp., New Jersey
Nipro Medical Corp., the U.S. subsidiary of the Japanese company Nipro Corp, has identified a security incident that exposed sensitive information. The New Jersey-based company provides medical supplies to hospitals, including renal care products, vascular and interventional devices, and disposable hospital supplies. Nipro said it identified suspicious activity within its IT systems and determined that an unauthorized third party may have viewed or acquired sensitive information such as credit and debit card information, Social Security numbers, and other government identifiers. The affected individuals have been offered 24 months of complimentary credit monitoring services. The number of affected individuals has yet to be publicly disclosed.
The post Data Theft/Extortion Incident Confirmed by Beverly Hills Plastic Surgeon appeared first on The HIPAA Journal.
