Blog · Compliance

Social media replies and the PHI hiding in public comments

A kind public reply can still identify a patient and their condition. Train staff to move the conversation to a secure channel.

Review sites and Facebook comments feel like customer service. For a covered entity they are a disclosure surface. Confirming an appointment time, a procedure, or even that someone is "your patient" in public can be more than a courtesy.

A safer reply pattern

Thank the person. Do not confirm the visit, the clinician, or the condition. Invite them to call the office or use a secure form. Never paste details from the chart into a public box, and never ask them to email more history to a consumer inbox.

Give staff a real alternative

People reply in public when the official channel is painful. If patients can submit a concern through a personalized HIPAA form, or continue a thread in healthcare email, the front desk has somewhere to point. HIPAA Companion forms and email exist so "please contact us privately" is a working link, not a slogan.

Add social media to annual HIPAA training. Show two real (de-identified) reply examples: one that stays generic, and one that accidentally confirms care.