Asking patients for a review is generally permitted under HIPAA, according to dental compliance guides, but the way a practice asks and, above all, how it replies decide the risk. In GoHighLevel a review request can go to every patient after a visit, and the practice's policy should bar detailed replies, republishing without authorization, filtering, and rewards. The bottom line: ask everyone, say nothing about the care in public, and keep the incentive out of it.

What is allowed, and what is not

ActionPosition
Asking every patient for a reviewGenerally allowed, per a dental marketing compliance guide
Asking only patients who seem happyReview gating, which Google's policy prohibits
Offering a discount or gift for a reviewGoogle bans incentives, and the FTC rule bars incentives conditioned on sentiment
Replying with details of careOCR has penalized dental practices for this
Republishing a patient's review with their name or photoVendor guides advise written HIPAA authorization
Conditioning care on a reviewNot allowed under any guide we reviewed

OCR and the dental practices

Dental practices have been the main targets. A dental practice paid $10,000 in 2019 after replying to a Yelp review with a patient's last name, treatment plan, insurance, and cost details. New Vision Dental paid $23,000 in 2022, and another dental practice received a $50,000 civil money penalty for disclosing patient information in response to a negative review. A compliance firm advises that the only permissible replies are a thank you or an invitation to contact the office. A patient's own public review is the patient's disclosure, according to dental marketing guides, but the practice's reply that confirms the person is a patient or describes care is the practice's disclosure.

The FTC rule

The FTC's Consumer Reviews and Testimonials Rule, 16 CFR Part 465, took effect in October 2024. It bars buying reviews or giving incentives conditioned on the writing of positive or negative reviews, and review suppression, including misrepresenting that reviews on a website represent most or all of those submitted when negative ones were suppressed. Law firm summaries put the civil penalty at up to $53,088 per violation. Soliciting reviews without compensation is not itself covered, and commentary is not uniform on how the rule treats each gating scenario, so ask counsel.

Dental specifics

Build it in GoHighLevel

GoHighLevel's help portal has a Review Requests section covering customized request messages by SMS and email. A third party guide describes Reviews AI as drafting or posting replies, so confirm that drafts require approval in your account.

GoHighLevel's help portal says accounts are not HIPAA compliant by default, and that HIPAA Compliance is a paid upgrade, $297 a month as an account wide add on, that must be enabled for the agency and then configured for the sub accounts that need it. Third party guides add that the add on provides a business associate agreement, encryption, audit logging, and multi factor authentication, that the practice also needs its own agreement with the agency, and that GoHighLevel itself recommends avoiding protected health information in SMS and email even with the add on. Whether the AI features are covered by the agreement is a question to put to HighLevel in writing before any patient data reaches them.

  1. Connect the practice's Google Business Profile in the reputation settings.
  2. Write a plain request with no incentive and no satisfaction question first.
  3. Build a workflow with the Appointment Status trigger set to Showed Up that waits 2 days and sends the request to every patient with a documented contact preference, once, with one reminder.
  4. Send requests for minors to the parent.
  5. Exclude patients tagged Complaint, and route their complaints to the practice manager.
  6. Write the reply policy, and set any Reviews AI to draft only with compliance approval.

Worked example

For example, a practice with 800 visits a month sends 800 requests. At a 4 percent review rate, that is 32 new reviews a month (800 times 0.04), and each is unscreened and authentic.

Mistakes to avoid

How this was handled before

Practices relied on word of mouth and directory listings. Google reviews changed the stakes, and OCR's cases against dental practices showed that the reply, not the request, is where the privacy risk sits.

What to measure after launch

Track requests sent, reviews posted, replies approved, and replies posted. Audit every public reply against the policy each quarter.

Check before you switch it on

US text messages sent from a standard 10 digit number need A2P 10DLC registration. The HighLevel support portal says registration is required for texts to US recipients from 10 digit long code numbers and that toll free numbers do not require it. HighLevel's opt in guidelines also say a person cannot be forced to agree to text messages in order to submit a form, so keep the consent box optional. One compliance guide separates informational texts, which need documented consent, from marketing texts, which need prior express written consent. Ask your attorney which category your reminders fall into. Have counsel confirm how HIPAA, the FTC rule, and your dental board treat review requests and displayed testimonials. This is general information, not legal advice.

Questions people ask

Can a dental office ask patients for Google reviews?

A dental marketing compliance guide says asking is permissible under HIPAA. Ask every patient, offer nothing, and keep the request free of health details.

What have dental practices paid OCR over review replies?

$10,000 in 2019, $23,000 in 2022, and a $50,000 civil money penalty against another dental practice.

Can I repost a patient's review on my website?

Vendor guides advise written HIPAA authorization before featuring a patient's review with identifying details.

Ready to try it yourself? Start a GoHighLevel account here.

You can also see this in action in our GoHighLevel capabilities demo.