HIPAA-Compliant Ways to Ask Patients for Google Reviews

  • Posted: August 09, 2026

Most medical practices sit at one of two broken extremes. Some never ask for reviews at all, convinced that HIPAA forbids it, and watch their Google profile fill up with the rare angry patient who reviews unprompted. Others bolt on a review tool their software vendor upsold them, blast every patient with automated texts, and never check what data that tool receives or what the messages say.

Both extremes lose. The first loses rankings and new patients. The second collects legal exposure with every send.

Here is the accurate middle: asking patients for reviews is legal. HIPAA does not prohibit it. What HIPAA, the FTC, and Google’s policies regulate is how you ask, what your messages reveal, which patients you ask, and what your tools do with patient information behind the scenes. This post covers all four, and it ends with template language you can hand to your front desk today.

This is the companion piece to our guide on responding to reviews without a HIPAA fine. That post covers what to do after reviews exist. This one covers generating them.

Why review volume is the whole game

Recall the math from the response guide: patients who read reviews vastly outnumber patients who write them, and unhappy patients write at a higher rate. Left alone, every practice profile drifts negative. The only structural fix is volume. A steady flow of genuine reviews raises your average, buries the outliers, feeds the recency signals that local rankings reward, and gives prospective patients a sample size they can trust.

Volume does not happen organically in healthcare. Satisfied patients think of their visit as private, not as an experience to broadcast. They need a prompt. Which means every practice serious about local search needs a review generation system, and every review generation system in healthcare needs a compliance layer.

The three tripwires

Everything that goes wrong with review generation falls into three categories.

Tripwire 1: PHI in the ask. The request itself is a communication about a patient, so its content and channel matter. A text reading “How was your therapy session with Dr. Lee on Tuesday?” discloses a provider relationship and visit details to anyone who sees that phone screen, and it hands the same details to whatever software sent it. Keep every outbound message generic: thank the person for visiting the practice, invite feedback, link to the review page. Nothing about services, conditions, providers, or dates.

Tripwire 2: Review gating. Gating means screening patients first, then steering happy ones to Google and unhappy ones into a private feedback form. Tools sold this as a feature for years. It violates Google’s review policies, and the FTC’s rule on consumer reviews and testimonials, in force since late 2024, prohibits suppressing or preventing negative reviews. Penalties can reach tens of thousands of dollars per violation. [STAT CHECK: verify current per-violation penalty amount under the FTC rule before publishing.] Ask everyone, the same way, every time. Consistency is both the legal posture and, conveniently, the best defense if a competitor ever files a complaint.

Tripwire 3: Bought, bribed, or insider reviews. No discounts for reviews, no gift card raffles, no staff or family members posting, no purchased reviews. The FTC rule covers all of it, Google removes it when detected, and in healthcare, incentives for referrals and endorsements can raise additional regulatory problems that no marketing benefit justifies. Genuine patients, unpaid, asked consistently. That is the entire permissible universe.

Channel rules: how the ask can travel

In person. The safest channel and the most effective one. A front desk mention at checkout, paired with a card or QR code, converts better than any automated message because a human just asked. QR codes on signage or receipts disclose nothing about any individual.

Email. Permissible for patient communication when the patient has provided their email for contact. Keep the subject line and body generic, honor opt-outs immediately, and send from a system covered by a Business Associate Agreement, because the send list is a patient list.

Text message. Effective and heavily regulated. Beyond HIPAA’s rules on the content, the Telephone Consumer Protection Act requires prior consent for automated texts, so your intake forms need a communication consent that covers messages of this kind. Generic content, easy opt-out, consented recipients only. [STAT CHECK: confirm current TCPA consent standard language with counsel before publishing template consent copy.]

Never through a personal device or account. Staff texting patients from personal phones to ask for reviews moves patient contact information outside every safeguard the practice has. All asks run through practice systems.

The compliant workflow, step by step

1. Pick the moment. Ask within a day or two of the visit, while the experience is fresh. Same timing for every patient.

2. Ask everyone. Every patient gets the same request through the same channels. No screening, no cherry-picking. Your happy majority is the statistical engine; let it run.

3. Lead with the human ask. Train front desk staff on a one-line script at checkout. The automated message that follows becomes a reminder, not a cold pitch.

4. Send one generic follow-up. One email or consented text with the direct link to your Google review page. One polite reminder a few days later at most. Then stop.

5. Route the link straight to Google. Use your Google Business Profile’s review link. No intermediate survey that filters by sentiment.

6. Log and audit monthly. Track asks sent, reviews received, and opt-outs. A monthly fifteen-minute audit catches a misconfigured tool before it becomes a pattern.

Template language your practice can use

Adapt the bracketed pieces and have your compliance officer or counsel glance over the final versions once.

Front desk script, at checkout: “Thanks for coming in today. If you have a minute, we’d really appreciate a Google review. There’s a QR code on the card, and it takes about a minute.”

Email: Subject: We’d value your feedback “Thank you for visiting [Practice Name]. Feedback helps us improve and helps others in the community find care. If you’re willing, you can leave a Google review here: [link]. It takes about a minute. Thank you.”

Text message (consented recipients only): “Thank you for visiting [Practice Name]. If you have a minute, we’d appreciate a Google review: [link]. Reply STOP to opt out.”

One reminder, if no review after several days: “A quick follow-up from [Practice Name]: if you’d like to share feedback, our Google review link is here: [link]. Thank you either way. Reply STOP to opt out.”

Notice what every template omits: the provider seen, the service received, the visit date, and any reference to health. A stranger reading any of these messages learns only that the recipient visited a practice at some point. That is the standard each message must meet.

The tool question: what your review software knows

Automated review requests require software, and that software receives patient names, contact details, and visit timing to do its job. That combination is protected health information. So the vendor decision is a compliance decision:

  • The vendor must sign a Business Associate Agreement before receiving any patient data. Several major review platforms offer healthcare plans with BAAs; confirm in writing, not from a sales page. [STAT CHECK: verify BAA availability for any vendors named in the published version.]
  • Confirm the tool does not gate by default. Many still ship with sentiment pre-screening switched on. Turn it off and document that you did.
  • Confirm what the tool does with the data beyond sending requests. Some platforms use client data for their own analytics or marketing. The BAA and settings must restrict that.
  • If the tool integrates with your practice management system or EHR, the data path between them needs the same scrutiny.

A practice that cannot get a BAA from its review vendor has its answer: that vendor cannot be in the workflow.

Frequently asked questions

Is it a HIPAA violation to ask a patient for a Google review?

No. The request is permissible when the message contains no protected health information, travels through consented and covered channels, and goes to patients consistently rather than selectively.

Can we ask only the patients we know are happy?

No. Selective asking is review gating, which violates Google’s policies and the FTC’s consumer review rule. Ask every patient the same way. Your satisfied majority will carry the average.

Can we offer a small discount or raffle entry for leaving a review?

No. Incentivized reviews violate Google policy and FTC rules, and incentives tied to endorsements create additional regulatory risk in healthcare. The review must be voluntary and unpaid.

A patient wants to mention their treatment in the review. Is that a problem for us?

No. Patients may share anything about their own care; that is their right, not your disclosure. Your obligations apply to what the practice communicates, including your reply, which must never confirm or discuss their care. See our review response guide for exactly how to reply.

Can we reuse a Google review as a testimonial on our website?

Not without written HIPAA authorization from the patient. A review on Google is the patient speaking on a public platform. Republishing it in your marketing is the practice disclosing a patient relationship, which requires signed authorization on file.

Do review request texts really require special consent?

Yes. Automated texts fall under the TCPA in addition to HIPAA, so intake paperwork should capture consent to receive messages of this kind, and every text needs a working opt-out. When in doubt, use email and the in-person ask.

How many reviews should a practice aim for?

More than the practices you compete with in the map pack, arriving steadily rather than in bursts. Recency matters as much as totals: a profile whose latest review is eight months old reads as dormant to both patients and ranking systems.

The bottom line

The practices with the strongest review profiles are not lucky, and they are not cutting corners. They ask every patient, at the same moment, in generic language, through covered tools, and then they respond to what comes in without ever confirming who walked through their doors. It is a system, it is boring, and it compounds monthly into the local rankings and trust signals that decide who gets the next new patient call.

CGColors builds that system as part of local SEO for medical practices: compliant request workflows, vetted tooling with BAAs, counsel-ready templates, and the response library from our companion guide. Reviews become an asset that grows on schedule, and your practice gets found first, called first, booked first.

About the author

Saurabh

Saurabh Srivastava is the founder of CGColors and a digital marketing professional with extensive experience in SEO, PPC, Google Ads, web development, and online growth strategies. He works closely with businesses to improve their online visibility, generate qualified leads, and achieve sustainable growth through data-driven digital marketing.

Over the years, Saurabh has worked on digital marketing campaigns across a wide range of industries, gaining hands-on experience in search engine optimization, paid advertising, local SEO, conversion tracking, and website strategy. His approach focuses on practical solutions, measurable results, and strategies tailored to each business’s specific goals.

Through the CGColors blog, Saurabh shares actionable insights, strategies, and lessons from his real-world experience in digital marketing, SEO, PPC, web development, and growing businesses online

Copyright @ 2017-2021 CGCOLORS, INC. . All Right Reserved.