Patient reviews can help others assess dentists and offices, voice complaints, and explain their perspective. Responses from dental practices can raise privacy concerns if they include details about appointments, treatments, payments, or patient relationships.
An article published through the Journal of Medical Internet Research says, “These findings suggest that online patient reviews could be used as a data source for understanding the patient experience and healthcare quality in dentistry.” Dental providers may have legitimate business interests in monitoring and responding to reviews. Just like patients need to safeguard their privacy when posting reviews, HIPAA places limits on dental office responses. The key is not to disclose protected health information (PHI). Dental offices can thank reviewers, acknowledge concerns, and offer to continue the conversation through HIPAA compliant email or another secure channel.
Does HIPAA apply to online patient reviews
Dental offices should already know whether HIPAA applies to their business. HIPAA covered entities, as defined by the Department of Health and Human Services (HHS), are healthcare providers who transmit health information electronically in connection with certain transactions.
The HIPAA Privacy Rule covers any individually identifiable health information maintained or transmitted by a covered entity or business associate. It includes oral, electronic, or written forms of PHI. Electronic protected health information (ePHI) could even include a patient’s full name if it is associated with dental treatment, insurance, payment, appointments, or other healthcare information. HIPAA generally does not restrict patients from disclosing their own health information. But that does not give permission for the dental practice to confirm details about the patient or treatment in a public forum.
Where the potential for exposure of PHI comes into play
Say a reviewer states that they received treatment from Dr. Smith. The practice should not confirm the patient received a specific procedure, treated by Dr. Smith, had a successful outcome, or provide additional details. Instead, the dental office could post a neutral response after the review.
A response could disclose PHI or create a HIPAA risk by:
- Confirming that the reviewer received treatment or appointments at the office
- Identifying the reviewer with their full name
- Discussing the date of an appointment, late appointment policy, or missed appointment
- Confirming a diagnosis or recommended treatment
- Discussing medications or prescriptions
- Explaining payment, insurance decisions, outstanding balances, refunds, or billing policies
- Recounting conversations with the patient or their family
- Correcting patient conduct or violations of the dental practice policies
Violations like the above are the result of posting patients’ full names along with answers to the reviewers’ complaints. According to the HHS resolution agreement with New Vision Dentals, the practice disclosed information that reviewers hadn’t even included in their original reviews.
New Vision Dental was required to pay $23,000 for the HIPAA violations. In another case, Elite Dental Associates paid $10,000 because their employees may have violated the Privacy Rule when discussing patient care on social media websites. Staff also need to protect patient health information during the review screening process. For example, HIPAA violations can occur if an employee emails a review screenshot to themselves through a personal email account.
The difficulty with confirming reviewers are patients
Reviewers might go by their initials, a nickname, share an account with family members, or use an anonymous username. The reviewer might be a parent, caregiver, former patient, or someone that the practice has never treated. As a result, employees may not be able to definitively confirm who wrote a review without guessing. Claiming the practice did or did not find the reviewer in its records publicly can cause additional privacy concerns. Even if the practice knows who wrote the review, it still should not publicly confirm that person’s relationship with the practice. The best course of action is to craft a public response that the practice would feel comfortable posting under any review without verifying if the author was a patient.
Reviewers, on the other hand, can be directed to contact a specific employee if they wish to continue their conversation. Once the person contacts the practice, it can confirm their identity and ensure HIPAA safeguards are in place before discussing treatment or billing details. HIPAA compliant email enables authorized employees to pick up where they left off in a private conversation while maintaining appropriate access controls and transmission safeguards. HIPAA compliant email also gives the practice a chance to confirm if the person has the authority to discuss another patient. Recognizing the name of a parent or caregiver does not necessarily mean that the practice can discuss that patient’s information with them under all circumstances.
How to consider HIPAA in a response to a negative, false or specific review
Potential patients can form lasting impressions of a provider based on negative reviews. One study suggests that how providers respond matters. In another Journal of Medical Internet Research study, researchers found, “The presence of a physician response decreases the influence of negative reviews through direct and moderating effects. We propose some practical implications for physicians, health care providers, and online medical service platforms.”
While the study did not focus on dentistry specifically, dental offices should consider these findings when crafting a response strategy. An appropriately worded response can still add value to the conversation without discussing patient-specific details.
If a review seems false, dental practices should not email patient records to show the reviewer is wrong. Instead, consider preserving a copy of the review, flagging the post through the website’s review process, and consulting with legal counsel or a professional liability insurer when needed. Likewise, practices should instruct employees never to confirm or deny that someone was a patient or underwent a specific procedure. Saying “You declined the treatment we recommended” confirms that the reviewer received dental care.
HIPAA compliant email can support secure follow-up, but it does not by itself make the communication compliant. Before accessing patient records and email accounts, the privacy officer, practice manager, or provider should verify the person’s identity, authority, and email address before disclosing PHI.
How can policies, templates, and staff training help dental practices manage online reviews
Office managers can minimize impulsive or emotionally charged responses by creating a review management process. Ideally, the policy would detail who monitors reviews, who has the authority to post a response, which templates employees can reference for guidance, and when an issue needs to be escalated.
When creating the process, practices may want to remind employees to:
- Confirm reviewers are patients privately, not publicly
- Resist the urge to discuss treatment, appointments, billing, or insurance in a public forum
- Preserve the review as provided, not through personal Facebook accounts or email
- Consult with licensed providers or the privacy officer before sending a response through encrypted email
- Utilize a neutral template when posting public responses
- Redirect patient-specific conversations to a private method of communication
- Report unintentional disclosures to the privacy officer
- Escalate all credible threats, legal claims, and suspected false reviews
- Business associate agreements covering the applicable email services
The corrective action plan we took note of from New Vision Dental requested policies addressing when PHI can and cannot be disclosed, appropriate email and social media use, authorizations, employee training, and breach notifications. The practice even created a separate policy to address when employees need to obtain patient authorization.
Similar topics can be integrated into initial and annual HIPAA training. Rather than telling employees what not to do, practices can use scenario-based exercises to demonstrate how an innocent response could inadvertently confirm someone’s patient status or disclose treatment information.
FAQs
Can a dental practice say that it has no record of the reviewer?
It is generally safer not to make that statement publicly. The practice may not be certain who wrote the review, and discussing whether someone appears in its records can create unnecessary privacy risk.
Can a dental practice correct false treatment information in a review?
The practice should not use PHI to correct the reviewer publicly. It can provide general information about its policies without connecting those policies to the reviewer, report the post to the platform, and address patient-specific facts privately.
What should a practice do if an employee accidentally posts PHI?
The practice should remove the information when possible, preserve evidence of what was posted, notify its privacy officer, and investigate immediately.
