July 28, 2026
Every practice has heard them. Most practices believe at least two of them.
Some HIPAA myths make staff overly cautious, frustrating patients and slowing down care that HIPAA never intended to slow down. Others make staff overly comfortable, which is how practices end up in OCR investigations and corrective action plans.
Here are seven that come up constantly, what the rules actually say, and where practices genuinely get into trouble.
This may be the easiest way to turn a one-star review into a federal complaint.
A patient posts something unfair on Google. It is public, it is wrong, and it may be costing the practice new patients. The instinct to correct the record publicly is understandable.
What the rule actually says: A practice cannot disclose protected health information in a public response unless the patient has provided a valid authorization or another HIPAA permission applies. That includes confirming that the reviewer was a patient. The patient’s post is the patient’s disclosure to make. The practice’s response is a separate disclosure, and the practice is regulated.
Where practices get in trouble: OCR has repeatedly enforced this rule against small practices.
In 2019, Elite Dental Associates paid $10,000 and entered a corrective action plan after OCR investigated disclosures made in response to Yelp reviews. In 2022, OCR imposed a $50,000 civil money penalty against Dr. U. Phillip Igbinadolor & Associates after the practice disclosed PHI in response to a negative review. That amount needs context: the practice also failed to respond to OCR’s data request, did not respond to an administrative subpoena, and did not contest OCR’s findings.
Later in 2022, New Vision Dental paid $23,000 and entered a two-year corrective action plan after OCR found that it had disclosed names, treatment information, and insurance information in Yelp responses. OCR also identified deficiencies in the practice’s Notice of Privacy Practices and its policies and procedures. In 2023, Manasa Health Center paid $30,000 and entered a corrective action plan after OCR found that it had disclosed PHI of four patients in responses to negative Google reviews and failed to implement appropriate policies and procedures.
The pattern matters. The review response starts the problem. The investigation may then reach the practice’s policies, training, Notice of Privacy Practices, and cooperation with OCR.
Even a friendly response to a positive review can create risk if it confirms or implies that the reviewer was a patient. Without a valid authorization, keep the response generic.
What to do instead: Use a response that discloses nothing:
We take all feedback seriously. Please contact our office directly so we can address your concerns.
Then handle the issue offline. Adopt a written review-response policy and train every person who can access the practice’s review platforms.
What the rule actually says: It does not, as long as the information disclosed is appropriately limited. HHS has addressed this directly. Calling a patient’s name in a waiting room is a permitted incidental disclosure when the practice uses reasonable safeguards.
HIPAA recognizes that some limited disclosures are unavoidable byproducts of delivering care. It does not require practices to eliminate every possibility that someone might hear or see a patient’s name.
Where practices get in trouble: The problem is usually not the name. It is what comes after it.
“Mr. Alvarez, you are here for your HIV follow-up, right?” announced across a full waiting room is a different situation. So is a front-desk conversation about a patient’s diagnosis, medication, or balance spoken loudly enough for the room to hear.
Reasonable safeguards can be simple: keep voices low, avoid unnecessary clinical details, and move sensitive conversations away from the front desk when practical.
What the rule actually says: Sign-in sheets are permitted. HHS specifically allows them when the visible information is appropriately limited and reasonable safeguards are in place.
Where practices get in trouble: They ask for more information than the sign-in process requires. HHS specifically warns against displaying the medical problem for which the patient is seeking care.
Keep visible fields limited to what is actually needed for sign-in, usually the patient’s name and arrival or appointment time. Do not display the reason for the visit or other clinical information. If the practice believes another field is operationally necessary, assess whether it will be visible to other patients and whether a less revealing process would work.
What the rule actually says: You can. The Privacy Rule does not prohibit a provider from leaving a message on a patient’s answering machine or voicemail. HHS recommends limiting the information disclosed, such as leaving the practice name, callback number, and a request that the patient return the call.
Where practices get in trouble: They treat permission to leave a message as permission to leave the clinical update itself.
“This is Dr. Kim’s office calling about your biopsy results” may reveal more than necessary, particularly if someone else has access to the voicemail. A safer message is simply: “This is Dr. Kim’s office. Please call us at 555-0100.”
There is a second layer that practices often miss. Patients may request confidential communications by reasonable alternative means or at alternative locations. If a patient asks the practice to call a cell phone instead of a home number, or to send mail to a P.O. box instead of the home, the practice must accommodate a reasonable request.
That right can be especially important for patients in unsafe or sensitive living situations. Practices should have a reliable way to record and follow communication preferences.
What the rule actually says: HIPAA permits a provider to share information with a family member, friend, or another person identified by the patient when the information is directly relevant to that person’s involvement in the patient’s care or payment for care.
If the patient is present and capable of making decisions, the provider may share information if the patient agrees, if the patient has an opportunity to object and does not, or if the provider can reasonably infer from the circumstances that the patient does not object. A patient who brings a daughter into the exam room and discusses symptoms in front of her has ordinarily given the provider a reasonable basis to infer that the daughter may participate in that conversation.
If the patient is not present or is incapacitated, the provider may use professional judgment to determine whether a limited disclosure is in the patient’s best interest.
Two clarifications matter:
Where practices get in trouble: They go too far in either direction. Some practices refuse to speak to a spouse who is standing in the room helping manage medications. Others disclose information over the phone to someone claiming to be a relative without considering whether the person is actually involved in the patient’s care or whether the patient would object.
The practical answer is to ask the patient when possible, record preferences when useful, follow a consistent phone process, and disclose only the information directly relevant to the person’s involvement.
What the rule actually says: HIPAA does not categorically prohibit texting. It requires the practice to protect electronic PHI with reasonable and appropriate administrative, physical, and technical safeguards. The practice’s risk analysis should address the communication tools it actually uses.
HHS has expressly said that providers may communicate electronically with patients and that unencrypted email is not automatically prohibited when reasonable safeguards are applied. That supports the broader point that HIPAA is risk-based. It is not, however, blanket approval for sending any clinical information through standard SMS.
Standard SMS may be unencrypted, may appear on a locked screen, may be stored on personal devices, and may not provide the access controls, authentication, audit capability, or retention features a practice needs. A patient’s preference for texting does not erase the practice’s Security Rule obligations.
Patients may request communication by reasonable alternative means. Depending on the circumstances, a practice may be able to honor a request for unencrypted communication after explaining the risk. The practice still needs to determine what information may be sent, what safeguards apply, and whether the requested method is reasonable for the communication.
Where practices get in trouble: Staff send diagnoses, photographs, test results, or other clinical details from personal phones with no policy, no risk analysis, no access controls, no documentation, and no plan for retention or device loss.
If a practice texts patients, the channel should appear in its risk analysis and written policies. Use a secure patient portal or secure messaging platform for clinical information whenever practical. If standard SMS is used for limited communications, define exactly what may be sent, from which devices or systems, and how patient requests and communication preferences will be handled.
A staff member posts about an unusual case. A practice shares a before-and-after photo. Someone tells a story on social media about the patient who came in after a highly specific accident. No name appears, so it seems safe.
What the rule actually says: Removing the name is not enough. HIPAA recognizes two methods of de-identification: Expert Determination and Safe Harbor.
Under Safe Harbor, a practice must remove 18 categories of identifiers relating to the individual and the individual’s relatives, employers, or household members. Those categories include names, most geographic information smaller than a state, dates more specific than a year, full-face photographs and comparable images, and any other unique identifying number, characteristic, or code. The practice also cannot have actual knowledge that the remaining information could identify the individual.
That last point matters. In a small community, “the patient who came in Tuesday after the tractor accident” may identify exactly one person. Context can identify someone even when a name does not.
Where practices get in trouble: Social media and marketing. Practices publish clinical photos without a valid authorization. Staff discuss unusual cases in private Facebook groups. Employees vent about patients on personal accounts.
If a patient story, testimonial, or image identifies the patient and the practice wants to use it for promotional purposes, the practice generally needs a valid HIPAA authorization before publication. Blurring a face or omitting a name does not necessarily de-identify the material.
A workforce member’s personal social media account does not place the disclosure outside the practice’s compliance responsibilities. The practice must train its workforce, mitigate known harmful effects when practicable, and apply appropriate sanctions for violations.
The practical rule is simple: if the details are specific enough to make the story interesting, stop and determine whether the information has actually been de-identified under a recognized HIPAA method or whether a valid authorization is required.
Most of these myths are half-truths flattened into rigid rules of thumb.
Sign-in sheets are permitted until unnecessary medical information is displayed. Voicemails are permitted until the message reveals more than it needs to. Electronic communication is permitted, but not without a risk-based process and appropriate safeguards.
Practices handle these issues well when staff do not have to improvise. Written policies explain what is permitted. Training gives staff concrete examples. Documentation shows how the practice evaluated a communication method, honored a patient request, or responded when something went wrong.
Documentation does not cure an impermissible disclosure. It does, however, help a practice show that it had a defensible process, trained its workforce, and took a problem seriously when it arose.
If you want a fast, practical starting point, download our free First 60 Minutes After a HIPAA Breach checklist. It walks through the immediate steps a practice should take when it discovers a possible impermissible disclosure.
Download the Free First 60 Minutes Checklist →
If your practice needs the written policies, workforce materials, Security Risk Assessment, patient-rights tools, and breach-response documents that support the practices described above, the Complete HIPAA Compliance System provides them in one attorney-developed structure for $449.
See the Complete HIPAA Compliance System →
One short, practical compliance insight every Tuesday. No sales push.
Join the newsletterBrowse products