ReviewReactionStart free trial →
← All posts

The legal line on review responses: what you can and can’t say

Jul 27, 2026 · 14 min read

A dental practice - the Office for Civil Rights never named it - developed a habit. When a patient left a critical Yelp review under a screen name, the practice replied with the patient’s full legal name. Sometimes visit details. Sometimes insurance information. OCR called the pattern “habitual,” and the practice paid $23,000 plus a corrective action plan to make the investigation go away. Nobody sued them over the original reviews. The responses were the violation.

That’s the thing most legal advice about review responses misses: the review is somebody else’s legal problem. The response is yours. Every reply you post is a public, timestamped document written on behalf of your business, screenshot-able forever, and admissible as evidence of what your business said. Three separate bodies of law care about what’s in it - privacy law, defamation law, and FTC consumer-protection rules - and the standard advice (“stay polite, take it offline”) only protects you from one of the three, and only sometimes.

Why “just be professional” is not legal advice

The generic guidance treats legal risk as a tone problem. Don’t be rude, don’t threaten anyone, don’t swear. Fine. But look back at that $23,000 settlement: those responses were probably polite. The dangerous sentences in review responses are almost never the angry ones. They’re the helpful ones.

“We checked your file and your appointment was actually at 2pm” is helpful. It’s also a disclosure of protected health information if you’re a covered entity. “This reviewer was fired for theft and is retaliating” feels like setting the record straight. It’s also a factual claim about a named-ish individual that you’d better be able to prove in court, because you just published it. “We’ll remove the charge if you take the review down” feels like customer service. Depending on how it’s phrased and documented, it can brush up against the FTC’s 2024 review rule and most platforms’ terms of service.

Polite, helpful, and illegal can all be the same sentence. So let’s take the three bodies of law one at a time.

Layer one: privacy law, where the enforcement is real

If you’re in healthcare, this layer has teeth, and the teeth have been getting sharper. Three settlements on the public record trace the line:

Elite Dental Associates, Dallas - $10,000 (2019). An office manager replied to a Yelp review by confirming the patient’s name, describing the treatment plan, and disclosing the outstanding balance. OCR opened the investigation because of the response, settled for $10,000, and imposed a two-year corrective action plan. We’ve covered this case in depth in our dental reputation guide because it’s the textbook fact pattern.

The unnamed practice - $23,000. The habitual full-names-on-Yelp case from the opening of this post. The detail worth dwelling on: OCR treated the pattern as aggravating. One bad response is an incident. A practice that does it every time has a compliance failure.

Cadia Healthcare Facilities - $182,000 (settled September 2025). Five Delaware care providers posted patient “success stories” - names, photos, diagnoses, outcomes - on their public websites and social pages without valid HIPAA authorizations. About 150 patients affected. Not a review response, but the same legal mechanism: PHI published to a public marketing surface. And there’s a twist that should worry anyone who thinks deleting a bad post fixes it - Cadia shut the program down in March 2022 and still got penalized, partly for failing to send breach notifications to the affected patients. The takedown didn’t end the exposure. Per the HHS press release (2025), OCR’s position is that written authorization is generally required before a covered entity posts a patient’s PHI in any testimonial or social campaign.

$10,000, $23,000, $182,000. That’s not a random walk, that’s a trend line. And the broader context matches: OCR had logged 18 settlements and civil monetary penalties by the end of July 2025 - a record enforcement pace. If your compliance posture on review responses was set in 2019, it was calibrated to a $10,000 problem that has since 18x’d.

The operating rule for covered entities is brutal in its simplicity: you may not confirm or deny that the reviewer is your patient. Not their appointment time, not their procedure, not their balance, not “we’re sorry your visit went poorly” - that last one confirms a visit. The compliant response thanks the reviewer generically, states policy in the abstract, and offers a private channel. It feels like answering with one hand tied behind your back. It is. Tie the hand anyway.

Outside healthcare, the privacy layer is thinner but not absent. Lawyers carry confidentiality duties that survive the client publicly criticizing them - state bars have disciplined attorneys for revealing case details in review responses, and the rules vary enough by state that we wrote a separate piece on bar association rules . Accountants, therapists, financial advisors: if your engagement involves confidential client information, assume the duty follows you into the reply box.

Layer two: defamation, which cuts both ways

Defamation comes up in two directions, and businesses routinely confuse them.

Direction one: the review defaming you. Yes, a review can be defamatory. In September 2024, the Ohio Fifth District Court of Appeals let a Texas law firm’s suit proceed against the posters of 60-plus negative reviews that originated from Ohio, ruling the reviews could be defamatory rather than protected opinion - because they contained factual claims that could be proven true or false. The decision summary is on Court News Ohio (2024) and it’s worth reading because it shows what a winnable case actually looks like: specific provable falsehoods, a coordinated posting pattern that suggests bad faith, and identifiable defendants.

Now notice what that case did not look like: one angry customer who exaggerated. “Worst service I’ve ever had” is opinion. “They charged my card twice and refused to refund it” is a factual claim - but you still have to prove it’s false, prove damages, identify the poster, and survive the anti-SLAPP motion if you’re in California, Texas, or any of the other states with strong statutes. Most suits against reviewers die on one of those four hills. The realistic cost-benefit math is its own topic - we ran it in can you sue over a false review - but the short version is that litigation is the right tool only in rare, well-documented cases, and the Ohio case is what one of those rare cases looks like.

Direction two: your response defaming the reviewer. This is the one nobody warns owners about. The moment your response makes a factual claim about the reviewer - “she was never a customer,” “he was banned for harassing staff,” “this is a fired employee” - you have published a statement about a person to every future reader of your profile. If the claim is false, or even partially wrong (it was a different Jennifer), you’ve handed the reviewer a defamation claim gift-wrapped, with your business name signed at the bottom.

The safe formulations are verifiable from your side alone: “We have no record of a transaction matching this description” is a statement about your records, which you can prove. “This person was never here” is a statement about the world, which you might not be able to. The gap between those two sentences is where lawsuits live.

Layer three: the FTC, now with a rule and a penalty number

The FTC’s Rule on Consumer Reviews and Testimonials took effect October 21, 2024, with civil penalties of up to $53,088 per violation. Most of the coverage focused on fake reviews - buying them, selling them, posting insider reviews without disclosure. But the rule also reaches conduct that shows up in review responses and review handling:

  • Review suppression. Using unfounded legal threats or intimidation to get negative reviews removed or to deter people from posting them. The lawyer letter you fire at an honest reviewer isn’t just a Streisand-effect risk anymore; if the threat is baseless, it can itself be a rule violation.
  • Selective publication. Displaying reviews on surfaces you control in a way that suppresses the negative ones while implying you’re showing everything.
  • Insider responses and testimonials. If your staff post glowing reviews, or your response quotes a “customer” who is actually your office manager’s cousin, the disclosure failure is the violation.

And enforcement has started. In December 2025 the FTC sent its first warning-letter sweep under the rule (2025) to ten companies, and the first settlement with an alleged Consumer Review Rule violation landed in January 2026. The grace period, such as it was, is over. If your review strategy includes offering anything of value contingent on the review’s content - discounts, refunds, freebies - re-read the incentive rules before you send the next one, because most of the advice circulating on review incentives predates the rule.

The first settled case under the rule, in January 2026, involved a business-opportunity seller called Growth Cave: a judgment of roughly $48.6 million (largely suspended for inability to pay) and a permanent industry ban. The allegation pattern worth noticing wasn’t exotic - testimonials reused across unrelated products, insider testimonials without disclosure. Ordinary marketing shortcuts, reclassified as rule violations with a penalty number attached. If your testimonial page was assembled before October 2024 and nobody’s re-reviewed it since, that’s a this-quarter task.

A worked example: the same review, three responses

Brightway Physical Therapy in Spokane gets this 1-star review from “K. M.”:

“Billed my insurance for sessions that never happened. When I called about it the front desk hung up on me. Filing a complaint with the state. Avoid this place.”

That review contains a provable factual claim (billing for phantom sessions - that’s a fraud allegation) and a threat of regulatory escalation. Here’s the response the owner drafted at 11pm:

“Kelly, this is completely false. Our records show you attended all six billed sessions between January and March, you signed in each time, and your insurer approved every claim. You were upset because we wouldn’t waive your copays. We have the documentation and will defend ourselves against any complaint.”

Count the problems. It confirms K. M. is a patient (HIPAA - PT clinics are covered entities). It names her beyond her own screen name. It discloses her treatment dates, session count, and insurance posture. It attributes a motive (“upset because we wouldn’t waive your copays”) - a factual claim about her state of mind the clinic cannot prove. Five distinct legal exposures, in a response that is, by tone, perfectly professional.

Here’s the version that survived review by the clinic’s malpractice carrier the next morning:

“Thank you for the feedback. We can’t discuss any individual’s care or billing in a public forum, but billing accuracy is something we audit monthly against sign-in records, and any patient who believes there’s an error on their account can reach our billing coordinator, Dana, directly at (509) 555-0142. We’ll review the specifics with you privately, and if we’ve made a mistake, we’ll fix it.”

Note what this response still accomplishes for the audience that matters - the next 40 prospects who read it. It signals a monthly audit process, a named human, and a willingness to be wrong. The clinic posted it 14 hours after the review landed, the reviewer called Dana, the dispute turned out to be a coordination-of-benefits error by the insurer, and the review came down voluntarily nine days later. The 11pm draft would have made the state complaint worse and added an OCR complaint on top.

The seven sentences to never publish

Across the three legal layers, these constructions account for most of the real-world damage:

  1. Anything confirming a customer relationship in a regulated industry. (“Sorry your appointment ran late” counts.)
  2. The reviewer’s real name when they didn’t use it.
  3. Dates, prices, balances, diagnoses, or service details specific to the reviewer.
  4. Unprovable factual claims about the reviewer. (“Never a customer,” “fired for cause,” “known scammer.”)
  5. Legal threats you don’t intend to act on - or, post-2024, legal threats with no basis at all.
  6. Offers of money or goods conditioned on editing or removing the review, stated in public.
  7. Admissions of legal fault. “We’re sorry this happened” is empathy; “our technician’s mistake caused the damage” is an exhibit in the eventual claim. There’s a real craft to apologizing without admitting, and if you want a starting structure, the apology-without-admission templates on replysmith.net were built for exactly this line.

The employee complication

One scenario sits at the intersection of all three layers and deserves its own flag: the review that involves an employee - either written by one, or written about one.

When a current or former employee reviews you, your instincts are all traps. Outing them in the response (“this is a disgruntled ex-employee”) is an unprovable factual claim if you’ve guessed wrong, and even when you’re right, publicly characterizing a former worker’s motives invites a defamation claim with an identifiable plaintiff. Meanwhile, employee speech about working conditions can carry federal labor law protection - the National Labor Relations Board has taken a broad view of what counts as protected concerted activity, and retaliating against the speech can be its own violation. The cleaner path is to flag the review with the platform under conflict-of-interest rules (with evidence) and keep the public response generic. Anything beyond generic belongs in a conversation with employment counsel, not a reply box.

When a customer’s review names one of your staff - “Brandon was rude and incompetent” - remember your response speaks about an employee with employment rights, to the public, on the permanent record. “We’ve addressed this with the team member involved” confirms discipline occurred, which most employment counsel would rather you not publish. “We hold our whole team to a clear service standard and we’re reviewing this internally” covers the same ground without creating a personnel record in a Google thread.

The part nobody tells you

Legal review of responses sounds expensive, so almost nobody does it. But you don’t need a lawyer per response. You need a lawyer once, per template.

Here’s the move: write the five response skeletons your business actually uses - billing dispute, service complaint, suspected fake, angry-but-fair, regulated-topic - and pay for one hour of counsel review on the set. For healthcare practices, the HIPAA-compliant response set is a pre-vetted starting floor. Your malpractice or general liability carrier likely has a free risk-management hotline that will look at the drafts at no cost - it’s one of the few benefits in the policy nobody redeems. After that, every individual response is just filling in a reviewed structure, and the marginal legal cost of responding drops to zero.

The asymmetry is what makes this worth an hour of your life. A compliant response and a violating response take the same five minutes to write. One of them is a $23,000 mistake with your business name on it, indexed by Google, screenshot before you can edit it. The other is invisible. Nobody ever got credit for the disclosure they didn’t make.

And once the legal floor is handled, everything we argue in the negative review response playbook still applies on top of it: the response is for the next prospect, not the reviewer. Legal safety and persuasive writing aren’t in tension. The constrained response - no names, no specifics, no counter-accusations, policy stated in the abstract, private channel offered - reads as more composed than the unconstrained one almost every time.

Write like everything you post will be read aloud in a deposition. Occasionally, it will be.