Testimonials and before-and-after photos are the highest-converting assets a medical practice can publish. A prospective patient reading clinical copy is evaluating claims. A prospective patient watching someone describe the same problem they have is evaluating a decision.
They are also the fastest route to a federal penalty, and the practices that get caught are almost never acting maliciously. A Delaware nursing home paid $182,000 after posting roughly 150 residents’ photos, and a physical therapy practice paid $25,000 for publishing testimonials without proper authorization. Both were proud of their patients. Both had a signed something on file. Neither had the right document.
The rule is not “do not use testimonials.” The rule is that a specific type of written authorization must exist before publication, and a general media release does not qualify. This post covers what that document requires, what your state board adds on top, and the practical workflow that keeps the assets legal for their whole lifespan.
Why a signed consent form is usually not enough
Practices consistently assume that any signed permission covers marketing use. It does not. HIPAA treats testimonials and patient imagery as marketing disclosures of protected health information, which triggers a specific authorization standard under the Privacy Rule. General consent forms and photo releases do not meet it.
The distinction that matters: PHI is the combination of identity and health information. A patient’s face alongside a treatment description is PHI. A voice recording plus condition details is PHI. Either element alone may not trigger the requirement, but the pairing that makes a testimonial persuasive is exactly the pairing that makes it regulated. This is the same logic behind the review response rules we covered in our guide to replying to patient reviews, where even confirming someone is a patient counts as disclosure.
OCR has been explicit and recent about this. In a settlement involving a provider that published a patient’s name, photo, and medical information as a website success story, the agency’s position was that a valid written authorization is generally required before posting an individual’s PHI in a testimonial or social media campaign.
The eight elements a valid authorization must contain
Under 45 CFR 164.508, an authorization missing any required element is invalid, and an invalid authorization is legally equivalent to no authorization at all. Build your form around these eight:
1. A specific description of the PHI being used. Write “photograph of face,” “video recording of voice,” “before and after images of treatment area.” Do not write “medical information.”
2. The person or class of persons authorized to make the disclosure. Your practice, named.
3. The recipients. Who receives the disclosure, including marketing vendors and the platforms where it will appear.
4. The purpose. Marketing and advertising, stated plainly.
5. An expiration date or event. Two years is a common practice standard.
6. The patient’s signature and date. A representative’s signature requires documentation of authority.
7. A statement of the right to revoke, and how to do it. Revocation must be a real, usable process.
8. A statement that treatment is not conditioned on signing. Care cannot depend on agreeing to be marketing material.
Two additions worth building in even though they sit outside the eight. First, language covering how far the material can travel: whether it can be copied, shared, or republished, and an acknowledgment that once content is public, third parties may redistribute it beyond your control. Second, channel specificity. Authorization for a website testimonial does not automatically extend to paid social ads or a video campaign.
Scope discipline matters after signing too. If a patient authorized their first name and a general description of their experience, you cannot later publish their full name, photo, or diagnosis without a new authorization. Every expansion of use needs its own signature.
What your state board adds
HIPAA is the floor, not the ceiling. State medical, dental, and nursing boards regulate advertising independently, and their penalties reach your license rather than your bank account. Public reprimands, fines, suspension, and revocation are all on the table.
Requirements vary meaningfully by state. California mandates specific consent documentation for patient images and requires the supervising physician’s name in promotional materials for med spas, with the Medical Board actively investigating advertising complaints. Georgia requires disclaimers when photos depict atypical results. Common prohibitions across many states include guarantees of results, comparative claims without evidence, and “risk-free” or “painless” language.
Two rules generalize well no matter where you practice. Before-and-after images must show real patients, never stock imagery. And a “results may vary” disclaimer belongs on every outcome-based visual, positioned where a reader actually sees it rather than buried in a footer.
Check your specific board’s advertising regulations before launching any campaign built on patient imagery. This is a one-hour task that prevents a license complaint, and it needs redoing whenever you enter a new state.
The FTC layer everyone forgets
A third regulator watches this content. If a patient received free treatment, a discount, or any compensation in exchange for their testimonial, that material connection must be disclosed. The disclosure has to be clear and near the testimonial, not tucked into terms of service. This sits alongside the FTC rules on incentivized reviews we covered in our guide to compliant review requests.
Truth-in-advertising substantiation applies too. Every material claim inside a testimonial, including outcome claims the patient makes themselves, should map to evidence you can produce. A patient saying something on camera does not transfer the substantiation burden away from your practice.
Photo-specific traps
The background gives you away. Visible charts, monitor screens, whiteboards with names, and other patients in frame all create disclosures the authorization never covered. Clear and check the frame before shooting, and review every image again before publishing.
Identifiability survives cropping. Tattoos, jewelry, distinctive scars, and unusual anatomy can identify a person even without a face. Cropping the head out does not automatically de-identify an image.
Consistency is a compliance issue and a credibility issue. Same lighting, angle, distance, and background across both images. Inconsistent conditions invite state board scrutiny for misleading representation, and patients read them as manipulated.
Storage counts. Patient images belong in encrypted, access-controlled systems, not on a staff member’s phone or a shared marketing drive. Everyone who handles them needs privacy training.
Revocation must actually work. When a patient revokes, the image comes down everywhere: website, social posts, ads, print collateral, and vendor libraries. Practices that cannot inventory where an image was published cannot honor a revocation, which turns one request into an ongoing violation.
The de-identified alternative
When authorization is impractical, de-identification is a legitimate path. Strip the eighteen HIPAA identifiers, including names, geographic detail below state level, dates beyond the year, and contact information, and the content is no longer PHI, so no authorization is required.
A de-identified testimonial reads something like: a patient in their forties who had managed a chronic condition for years described a meaningful change in their quality of life after treatment. Less vivid than a name and a face, and still useful for practices that want outcome stories without a paperwork program.
Be honest about the trade-off. De-identification that leaves enough specificity to be persuasive often leaves enough to identify someone in a small community. If your de-identified story would let a neighbor guess who it is, it is not de-identified. When in doubt, get the authorization.
The workflow that keeps this clean
1. Build one counsel-reviewed authorization form containing all eight elements, plus channel and redistribution language. One form, used every time.
2. Capture authorization before the shoot, not after. Retroactive signatures on published content do not cure the original violation.
3. Interview around experience, not diagnosis. Ask how the patient knew something needed to change, and what daily life looks like now. Avoid asking them to recite medical details on camera.
4. Review the asset against the authorization before publishing. Confirm the specific PHI used matches what was authorized, and that the channel is covered.
5. Log every publication location in a simple tracker: asset, patient, authorization date, expiration, and every URL and platform where it appears.
6. Audit quarterly. Pull expired authorizations, remove that content, and confirm nothing has drifted onto a channel the patient never approved.
7. Retain signed authorizations in the patient record and keep the evidence of consent indefinitely.
Frequently asked questions
Does a signed photo release cover HIPAA?
Usually not. A general media release rarely contains the eight elements HIPAA requires for a marketing authorization. Practices need a purpose-built form, and missing a single required element invalidates it.
The patient posted their own before-and-after photos on social media. Can we repost them?
Not without written authorization. Patients may publish anything about themselves. When your practice republishes it as marketing, the practice is disclosing a patient relationship, which requires a signed form.
Can we use a five-star Google review as a website testimonial?
Not without authorization. The review is the patient’s own speech on a third-party platform. Lifting it into your marketing is a separate disclosure by the practice.
How long does an authorization last?
As long as the expiration date on the form, commonly two years, unless the patient revokes earlier. Expired authorizations require the content to come down or be re-authorized, which is why the publication tracker matters.
What happens if a patient revokes after we have run ads with their photo?
Remove the content from every channel promptly and document the removal. Revocation is not retroactive for uses already made in reliance on the authorization, but continuing to publish after revocation is a fresh violation.
Do these rules apply to a cash-pay practice or a med spa?
Yes if you are a covered entity, and state board advertising rules apply regardless of billing model. Med spas in particular face heightened scrutiny, including physician supervision disclosure requirements in some states.
Can we blur faces instead of getting authorization?
Sometimes, if the result genuinely removes identifiability. Blurring a face while leaving distinctive tattoos, a recognizable setting, or a rare condition in frame does not de-identify the image.
The bottom line
Testimonials and before-and-after photos remain the strongest conversion assets in medical marketing, and they are fully usable. What they require is one properly built authorization form, a state board check, a frame you actually inspected, and a tracker that knows where every asset lives. The practices paying six-figure settlements did not skip patient permission. They skipped the paperwork that makes permission legally count.
CGColors builds these assets for medical practices with the compliance layer designed in: counsel-ready authorization workflows, state board checks before launch, and publication tracking that survives a revocation request. Your best proof gets to do its job, safely, so your practice is found first, called first, booked first.






