In October 2019, a Dallas dental practice paid $10,000 to settle with the HHS Office for Civil Rights after responding to a patient's online review with the patient's last name and details about their treatment and insurance. In 2023, OCR settled with a New Jersey behavioral health provider for $30,000 over the same pattern: negative reviews, defensive replies, protected health information published to the open internet. Neither disclosure involved a hacker. Both involved someone with a keyboard and a grievance.

This article is the operational build-out of a HIPAA social media policy for the person who has to write it, get it signed, train on it, and produce it when a complaint lands. It covers scope, approval routing, photo authorization, vendor agreements, discipline, and the breach clock that starts the moment a post goes live.

What a HIPAA Social Media Policy Must Contain

HIPAA never uses the phrase "social media." There is no rule numbered for Instagram. What binds you is 45 CFR 164.502(a) — you may not use or disclose PHI except as permitted — plus the administrative safeguards at 164.308 that require sanctions, training, and workforce oversight.

A defensible HIPAA social media policy answers these eight questions in writing:

  • Scope: which accounts are covered (practice-owned, provider professional, personal accounts of workforce members) and which activities count as posting.
  • Prohibited content: any of the 18 identifiers at 164.514(b)(2), including full-face photos, dates of service, and room or bed numbers visible in the background.
  • Approval routing: who reviews a draft post before publication and how that approval is recorded.
  • Review and comment response: the exact approved reply language, and the rule that no reply may confirm or deny a treatment relationship.
  • Patient authorization: when a signed 164.508 authorization is required, who obtains it, and where it is filed.
  • Vendor rules: which outside firms touch accounts and which of them require a Business Associate Agreement.
  • Incident reporting: how a workforce member reports a bad post and the deadline for doing so.
  • Sanctions: the specific disciplinary tiers applied when the policy is violated.

If your current policy is a paragraph in the employee handbook that says "be professional online," you do not have a policy. You have a sentence.

The Review-Response Trap That Generates Most Enforcement

A patient posts a one-star review naming your practice and describing their visit. Your office manager, correctly annoyed, replies to set the record straight. That reply is a disclosure of PHI by a covered entity, and there is no treatment, payment, or operations exception that covers it.

Two facts drive this and both surprise people:

The patient waived nothing. When a patient discloses their own health information publicly, HIPAA still restricts what you may say. Their post is not an authorization. It is not consent. It is not a shield.

Confirming the relationship is itself a disclosure. "We have no record of the wait time you describe" tells the world this person was your patient. So does "please call our billing office to discuss your balance."

Load one approved reply into your policy and permit no improvisation:

Thank you for the feedback. Privacy law limits what we can discuss publicly. Please contact our office at [number] and ask for the Privacy Officer so we can address your concerns directly.

Nothing in that reply confirms anything. Name the two people authorized to post it. Everyone else forwards the review link to them and takes no action. OCR's resolution agreements and civil money penalties page carries several examples of practices that learned this the expensive way, and the corrective action plans attached to those settlements read almost exactly like the policy elements above.

Photos, Video, and the Authorization You Actually Need

Your new laser arrives. A staff member films a thirty-second reel in the treatment hallway. In the background: a scheduling monitor, a whiteboard with initials and procedure codes, and a patient's shoulder.

That is three disclosures in one clip. Stripping the patient's name does not de-identify them — full-face photographic images and comparable images are themselves listed identifiers, and a visible schedule board tied to your practice location fails the de-identification standard on its own.

What a Compliant Photo Authorization Contains

A HIPAA authorization under 45 CFR 164.508(c) is not a model release. It must include, in plain language:

  1. A specific description of the information to be used — "pre- and post-treatment photographs of the face and jawline taken on [date]."
  2. The name of the person or class authorized to make the disclosure (your practice).
  3. The name of the person or class receiving it — name the platforms and your marketing vendor explicitly.
  4. The purpose. "Marketing and promotional use on practice-owned social media accounts and website."
  5. An expiration date or event.
  6. The patient's right to revoke in writing, how to do it, and the limitation that revocation does not undo prior use.
  7. A statement that information disclosed may be redisclosed by the recipient and is no longer protected by the Privacy Rule. This one matters enormously for social media — once it is public, it is public.
  8. A statement that treatment is not conditioned on signing.
  9. Signature and date.

File the signed authorization in the designated record set. Store the file name of the exact image next to it. Eighteen months later, when the patient calls to revoke, you need to find and remove that specific asset within a defined window — set yours at ten business days and write it into the policy.

The Pre-Post Checklist Your Approver Runs

Before any image or video publishes, one named approver confirms: no faces without authorization on file, no screens or paper visible, no wristbands, no charts, no whiteboards, no visible appointment lists, no audio containing a patient name, no geotag that reveals a treatment location the patient did not agree to expose. Approver initials and date go into a shared log. That log is your evidence.

Your Marketing Agency Is Probably a Business Associate

Here is where most practices have a paperwork gap. If your outside marketing firm, reputation management platform, or contract videographer creates, receives, maintains, or transmits PHI on your behalf — and handing them patient before-and-after photos is exactly that — they are a business associate under 45 CFR 160.103 and you need a signed BAA before they touch anything.

Sort your social media vendor list into three buckets:

  • BAA required: agencies that receive patient photos or testimonials, reputation platforms that ingest your patient list to solicit reviews, contractors with logins to accounts where patients send direct messages.
  • BAA not required: the social platform itself, when you are merely publishing content to it as a member of the public. Publishing a de-identified educational post to a public platform is not a business associate relationship.
  • Decide deliberately: scheduling tools and inbox aggregators. If patients can DM your account and the tool stores those messages, the tool is holding PHI. Get the agreement.

If you found a vendor in bucket one without a signed agreement, close that gap this week. The Business Associate Agreement generator walks you through six steps and exports a signature-ready PDF or DOCX — one-time purchase, no subscription — which is faster than waiting on your agency's legal review of a document they have probably never drafted.

Separately from HIPAA: if you incentivize reviews or repost patient testimonials, the FTC's Endorsement Guides require disclosure of any material connection between your practice and the endorser. Two agencies, two obligations, one post.

Personal Accounts, Sanctions, and the Labor Law Guardrail

Your policy reaches workforce members' personal accounts only insofar as they disclose PHI. It does not reach their opinions about their employer. Overbroad clauses — "employees may not post negatively about the practice" — invite National Labor Relations Act problems around protected concerted activity regarding wages and working conditions.

Draw the line at information, not sentiment. Prohibited: any patient identifier, any photo taken inside clinical space, any detail that could reasonably identify a patient even without a name. "Wild shift, this one guy came in with a nail in his foot" identifies a patient in a town of 4,000.

Write three sanction tiers and apply them consistently, because 164.308(a)(1)(ii)(C) requires sanctions and inconsistency is what OCR investigators notice:

  • Tier 1 — no PHI disclosed, policy technically violated (posted from the break room showing a corner of a monitor): documented counseling, retraining within 14 days.
  • Tier 2 — PHI disclosed to a limited audience, removed promptly, self-reported: written warning, retraining, privacy officer review of all prior posts by that individual.
  • Tier 3 — PHI disclosed publicly, or concealment, or repeat offense: termination and breach analysis.

Every tier produces a signed, dated record in the personnel file. No record, no sanction program.

When a Post Becomes a Reportable Breach

Impermissible disclosure of unsecured PHI is presumed a breach unless your four-factor risk assessment under 45 CFR 164.402 demonstrates a low probability of compromise. Public internet posting makes that demonstration hard — you cannot claim the recipient was trustworthy or that the data was unlikely to be viewed.

The clock runs from discovery, and discovery includes what any workforce member other than the person who caused it knew or should have known:

  • Immediately: delete the post, capture a screenshot first for the file, note the timestamp of publication and removal.
  • Within 5 business days: complete and document the four-factor assessment.
  • Within 60 days of discovery: notify affected individuals in writing.
  • Fewer than 500 individuals: log it and report to HHS within 60 days after the close of the calendar year.
  • 500 or more: notify HHS and prominent media within 60 days.

You can see how these land publicly on the OCR breach reporting portal. Record engagement metrics too — views, shares, screenshots by others — because a post that circulated for six hours is a different assessment than one deleted in ninety seconds.

The Evidence File a Surveyor or Investigator Will Ask For

Policy on paper is not compliance. Assemble a single folder containing:

  1. The signed, dated, version-numbered social media policy, with an annual review date.
  2. Workforce acknowledgment signatures, refreshed at hire and annually.
  3. Training records showing the review-response scenario was taught, with content and date.
  4. The post-approval log with approver initials.
  5. Signed patient authorizations mapped to specific published assets.
  6. Executed BAAs for every marketing, reputation, and scheduling vendor touching PHI.
  7. Any sanction records applied under the policy.
  8. The account inventory: every practice-affiliated handle, its platform, its owner of record, and who holds credentials.

That last item catches practices constantly. A departed office manager still holds the password to a page nobody has posted to since 2022. Recover it or formally close it, and document which you did.

A 30-Day Rollout You Can Actually Finish

Days 1–5: inventory every account associated with your practice name, including provider-personal professional accounts. Identify credential holders. Revoke access for anyone no longer employed.

Days 6–12: audit the last 24 months of posts and review replies. Screenshot and remove anything with identifiers. Run a breach analysis on each removal and document the outcome, even when the conclusion is low probability of compromise.

Days 13–20: draft the policy against the eight elements above. Name the approver and the backup approver. Adopt the standard review reply. Build the authorization form if you do not have a compliant one. HHS keeps the underlying rule text and guidance on its Privacy Rule guidance pages.

Days 21–26: send BAAs to every vendor in bucket one. Do not let a campaign launch before the signature returns.

Days 27–30: train the full workforce in a 30-minute session built around three real scenarios — the angry review, the hallway reel, the staff member's personal post. Collect signed acknowledgments. Calendar the annual refresh.

Next Step

Start with the vendor gap, because it is the one you cannot fix retroactively after an incident. Pull your list of marketing, video, and reputation vendors, mark the ones that receive patient photos, testimonials, or contact lists, and generate a signature-ready Business Associate Agreement for each. If your broader policy set is also thin — sanctions, training records, risk analysis — the full compliance document toolkit covers the rest of the file an investigator will ask to see. Then write the policy, and give your front desk one approved sentence to use when the next one-star review lands.