Yes, as long as the AI never sees patient records and the reply never confirms the reviewer is a patient or mentions anything about their care, even details they posted themselves. Use AI to draft short, warm, general replies from the review text alone, and invite the person to contact the practice privately so specifics can be discussed there.
The instinct that gets practices into trouble is wanting to set the record straight. A reviewer says the practice overcharged them for a crown that failed, and the tempting reply explains the treatment, the warning they were given and the payment plan they agreed to. Every one of those facts is confidential, and a reply that uses them can breach confidentiality whether a person or an AI wrote it. AI makes it easier to reply well, and also easier to reply badly at speed.
Why "they mentioned it first" doesn't protect you
A patient can say whatever they like about their own care in public. The practice can't, because its duty of confidentiality doesn't lapse just because the patient spoke first. Regulators have treated review replies as disclosures in exactly this way. One health-privacy regulator settled with a dental practice for $10,000 in 2019 after its replies to online reviews disclosed a patient's surname, condition, treatment plan, insurance and cost details. It reached a $23,000 settlement with another dental practice and imposed a $50,000 penalty on a third in 2022 over online disclosures. In 2023 a psychiatric practice paid $30,000 after its responses to negative Google reviews disclosed diagnoses and treatment information about four patients.
Those amounts are small next to the damage to trust. Prospective patients read replies to see how a practice treats people who complain. A reply that argues clinical detail tells them their own details might end up online too.
Five things a reply must never contain
- Confirmation that the reviewer is a patient. "We're sorry your visit last Tuesday…" confirms they came in. So, oddly, does "we have no record of you", which confirms they aren't; avoid both.
- Any clinical detail: condition, treatment, results, medication, the tooth, the knee, the diagnosis.
- Dates, times or which clinician they saw.
- Money: fees, insurance, payment plans, outstanding balances.
- Your side of what happened. Even a gentle correction ("our records show you were advised…") discloses the record.
Setting up the AI so it can't leak
The safest set-up is simple: the AI only ever sees the public review text, never the patient's name from your records, the booking, or any notes. It works from what anyone could read online. Save a prompt like this in a shared place so everyone uses the same rules:
You draft public replies to online reviews for a healthcare
practice. Strict confidentiality rules apply.
NEVER: confirm or deny that the reviewer is or was a
patient; mention any condition, treatment, clinician, date,
fee, insurance or payment; repeat any detail from the review
back to them; correct or dispute their account; say "our
records show"; use their name.
ALWAYS: thank them; acknowledge the feeling or general topic
(waiting, communication, cost, experience) in general terms;
invite them to contact [role] on [contact route] so we can
talk privately; sign off as [practice name].
Keep it to 2-4 sentences, warm, not defensive.
Review:
[paste review text only]
An illustrative test. The review: "Waited 40 minutes past my appointment and nobody said a word. The receptionist was rude when I asked. Won't be back." An illustrative draft:
Thank you for taking the time to leave this feedback.
Long waits without an explanation are frustrating, and we
want everyone who contacts us to be treated with courtesy.
We'd welcome the chance to talk this through - please
contact our practice manager on [contact route].
[Practice name]
Almost right. What to fix: nothing confidential slipped through, but "everyone who contacts us" was a small choice by the AI to avoid "visits us". Keep it. If the draft had said "we're sorry about your wait on Thursday", the date would confirm a visit and it comes out. Read every draft against the five rules before posting, even when the prompt is locked down; AI follows instructions most of the time, not all of the time.
Here's the kind of slip that gets through. The review: "The hygienist was brilliant with my nerves, first time I haven't dreaded it." Same prompt, illustrative draft: "Thank you so much for your lovely review. We're delighted you felt more comfortable during your visit, and we'll pass your kind words on to our hygiene team." It reads as warm and harmless, and it breaks two rules: "during your visit" confirms the reviewer attended, and "our hygiene team" echoes the service they received. The fixed version: "Thank you so much for your lovely review. Comments like this mean a great deal to the whole team." When a slip like this turns up, add the phrase that caused it ("your visit", "your appointment", "your treatment") to the NEVER list, so the prompt improves each time rather than relying on the reviewer catching it forever.
Four reviews, unsafe and safe replies side by side
A complaint that includes treatment and cost
Review: "Paid $900 for a crown that fell off after two weeks. When I went back they wanted to charge me again. Disgraceful."
Unsafe reply (the kind a well-meaning manager writes, or an AI writes if it's given the notes): "We're sorry to hear about your crown. As discussed at your appointment on 3 May, the tooth had limited structure and a crown carried a higher risk of failure, which we explained before treatment. We offered a replacement at a reduced fee."
Safe reply: "Thank you for your feedback. We're sorry to hear you're unhappy, and we take concerns like this seriously. We'd like to understand what's happened and see how we can help, so please contact our practice manager directly on [contact route]."
The unsafe version confirms the person is a patient, names a date and discloses the clinical risk discussion. The safe version says none of that and still looks responsive.
A glowing review that names a clinician and a procedure
Review: "[Physio's first name] got me back running after my knee surgery. Best physio I've had."
Unsafe reply: "Thanks so much! [Physio's first name] loved working on your knee rehab, and it's great to hear you're back to running after the operation."
Safe reply: "Thank you for such kind words. It's lovely to hear, and we'll pass your message on to the team."
Positive reviews catch practices out because a friendly reply feels harmless. But "your knee rehab" and "after the operation" confirm treatment details, and naming the clinician confirms who treated them. The warm, general version loses nothing.
A review from someone who may not be a patient at all
Review: "Rang three times to book and nobody answered. Went elsewhere."
Unsafe reply: "We can't find any record of you contacting us or being registered here."
Safe reply: "Thanks for letting us know. We're sorry it was hard to get through. We're looking at how we handle calls at busy times, and if you'd like to get in touch, you can reach us on [contact route]."
Saying you have no record reveals something about your records, and if they are in fact a patient registered under another name, it's simply wrong.
A parent writing about their child's treatment
Review: "Our 8-year-old was terrified of the dentist but the team were amazing with him and the filling was done in no time. Thank you!"
Unsafe reply: "Thank you! He was so brave, and we're glad the filling was quick. We look forward to seeing him at his check-up."
Safe reply: "Thank you for taking the time to write this. It's wonderful to read, and we'll share it with the team."
The child is the patient here, and the reviewer isn't. A reply that confirms the child's treatment or a future appointment discloses a minor's care to anyone reading, including people the parent may not want to know. Tell the AI in the prompt that the patient may be someone other than the reviewer, and that the same rules apply to them.
A triage routine for every new review
| Review type | Action | Who approves | When |
|---|---|---|---|
| Positive, no detail | AI draft from the saved prompt | Any trained staff member | Within a week |
| Positive with clinical details | AI draft; check no detail is repeated | Practice manager | Within a week |
| Negative about service (waits, phones, parking) | AI draft; invite private contact | Practice manager | Within 2 working days |
| Negative about clinical care or fees | Short generic reply; manager contacts the patient privately if they can be identified | Practice manager and clinical lead | Within 2 working days |
| Mentions harm, a complaint or legal action | Don't reply yet; follow your complaints process and ask your indemnity provider | Owner | Same day review |
| Abusive, fake or off-topic | Report through the platform; don't engage | Practice manager | Same week |
Keep a simple log of reviews and replies: date, rating, type, who approved. After a few months it shows patterns worth fixing in the practice itself, such as repeated comments about phones on Monday mornings. You can use AI to sort the log's review text into themes, since it's all public anyway. Replying to negative reviews with AI has more on tone for difficult ones.
A filled-in quarter's log for an illustrative physiotherapy clinic holds 38 reviews. Asked to "group these public reviews into themes, count each theme and quote one short phrase per theme", the AI returned (illustrative): friendly staff, 16 ("made me feel at ease"); getting through on the phone, 9 ("rang four times"); running late, 6 ("45 minutes in the waiting room"); price, 4 ("more than I expected"); parking, 3. The clinic moved one receptionist's lunch break away from the Monday-morning peak and, next quarter, phone complaints fell to 3. Only the clinic can say whether the lunch change caused that, but the log gave it something specific to try. Check the counts by hand on a sample: models sometimes put the same review under two themes.
A ten-minute drill for everyone who posts replies
The five rules are easy to agree with and easy to forget on a busy afternoon. A short exercise makes them stick. Take four or five real-looking reviews, run them through a deliberately loose prompt that doesn't include the rules, and give the drafts to staff to mark up. Each person circles anything that would confirm a visit, reveal care, name a clinician, mention money or dispute the account.
An illustrative loose draft for a podiatry clinic: "Thanks for your review! We're glad the nail surgery went smoothly, and [clinician's first name] will be pleased to hear the dressing changes were painless. See you at your six-week check." Staff who spot all four problems (the procedure, the clinician, the aftercare detail and the follow-up appointment) have understood the rules. Those who spot one or two need another example.
Repeat the drill when someone new starts posting replies, and whenever you change the prompt or the tool. It also tests the prompt: if the locked-down version ever produces a draft with one of those details, tighten the wording and note the change in the log. The drill costs ten minutes, and it builds the habit of reading every draft for what it gives away, not only for tone.
Should AI post replies automatically?
For a healthcare practice, no. Several review management tools can generate and post replies without a person seeing them, which may be fine for a coffee shop but leaves no chance to catch a clinical detail repeated back. Use AI to draft and a person to post. The broader argument is in whether to let AI auto-post replies to Google reviews; in a practice, the confidentiality risk settles it.
The same applies to replies the platform suggests. Google has been testing AI-suggested review replies with some Business Profile accounts since March 2026, which means a practice manager may see a ready-made reply without having set up any AI at all. Those suggestions are written from the review text, and a friendly model's instinct is to echo it: for the knee-surgery review above, a suggestion along the lines of "So glad your knee recovery is going well!" would be the natural output. Treat a suggested reply exactly like your own AI's draft. Read it against the five rules, and if the practice's rule is that replies come from the saved prompt, write that down so nobody accepts a suggestion with one tap.
A small practical trap: Google says owner replies can take up to 30 days to appear. A manager who posts a careful reply, sees nothing and posts it again can end up with two replies, or a second, hastier one. Log the reply as sent and check back after a few days before posting anything new.
When a review is fake, abusive or defamatory
Resist replying in kind, and resist proving the reviewer wrong with facts from your records. Report the review through the platform if it breaks its rules. If it makes serious false allegations, keep a screenshot and speak to a solicitor or your indemnity provider before doing anything public. A calm one-line reply, or none, protects you better than a detailed rebuttal. Handling a fake or unfair review with AI's help covers how AI can help you draft the report to the platform, which is private and can include more context than a public reply.
Some threats arrive before any review does. An illustrative message to the practice's inbox: "Refund my deposit by Friday or I'll leave one-star reviews on every site you're on." That's review extortion, and Google added detection for it and a dedicated report form in April 2026. Don't reply publicly and don't negotiate over a refund in writing because of the threat. Keep the message, report it through Google's extortion form, deal with any genuine refund question through your normal complaints route, and if reviews do appear, reporting them is easier with the threat already on record. Note too that Google allows one appeal per reported review, so gather the screenshots before you appeal, not after.
Where the real conversation happens
The point of every safe reply is to move the conversation somewhere private. When the person gets in touch, the practice manager can confirm who they are, look at the record and discuss what happened with the patient directly, where confidentiality allows it. That conversation is where problems actually get resolved, and a patient who feels heard sometimes updates their own review afterwards.
AI can help there too, drafting a follow-up letter or email to the patient from the manager's notes, as long as the tool is one your practice has approved for patient information. The patient data confidentiality checklist sets out which tools qualify.
For the crown review earlier, the manager's notes after the phone call might read: "Crown debonded 2 weeks post-fit. Pt upset about re-cement fee. Agreed: re-cement free, review in 3 months, apologised for how it was explained at the desk." The AI's illustrative first draft of the follow-up email thanked the patient, confirmed the free re-cement and the review appointment, and added "as a gesture of goodwill, we'll also waive any fee for a replacement crown if needed". Nobody agreed that. It's the private-channel version of the same failure as a public reply that says too much: a helpful-sounding addition that commits the practice. The version sent kept only the three agreed points, in the order the patient would care about them: the apology, the free re-cement, then the review date. Private channels don't need the public reply's restraint about clinical detail, but they need the same discipline about promises.
Other questions about replying to patient reviews
Could we ask the patient for written permission to discuss their case in a reply?
In principle a patient can give written permission, but it's rarely worth it. A public back-and-forth about someone's treatment helps nobody, and it invites other readers to judge a clinical dispute from one side's summary. It's almost always better to take the conversation private, resolve it directly and, if the patient is happy with the outcome, let them update their own review.
Can we get a negative review removed?
Only if it breaks the platform's own rules, for example if it's fake, abusive, off-topic or posted by someone with a conflict of interest. Use the platform's reporting process and keep your public reply calm in the meantime. A review that's simply unfair or wrong usually stays, which is why a measured reply matters: other patients read it too.
Is it better not to reply at all?
Not replying is always confidentiality-safe, and for some reviews, such as abusive ones, it's the right call. But a short, warm reply to most reviews shows prospective patients that the practice listens. The generic reply patterns in this tutorial let you reply to nearly every review without saying anything about the reviewer's care.
Further reads
- How to Get More Google Reviews With Automated Review Requests — Asking for reviews automatically without breaking platform rules.
- AI Review Management Tools for Small Businesses (2026) — Review management tools compared, with AI reply features.
- What Is Review Gating and Can It Get Your Business Penalised? — Why filtering who gets asked for a review can get you penalised.
- Dental Practice AI Mistakes: Consent, Data, and Over-Automation — Wider consent and data mistakes dental practices make with AI.
- Marketing a Physio Clinic With AI: Posts, Tips, and Newsletters — Marketing a clinic with AI once your review replies are safe.
- How to Answer Restaurant Complaints With AI Without Escalating — De-escalation techniques from a sector without confidentiality limits.
- AI Tools for Physiotherapy Clinics: What Each One Actually Does — What each AI tool a physio clinic might buy actually does, what it doesn't, and which two to start with.
- Which Dental Front Desk Tasks Can AI Take Over? — Task by task: which dental reception jobs AI handles well, what each looks like in practice, and the calls, forms and conversations that stay with your team.
- Eight Practical AI Uses for an Independent Optician — Recalls, enquiries, plain-English prescriptions, lens reorders, frame copy, reviews, referral letters and stock: how each works in a small practice.
- Can You Use AI to Write Testimonials? Where the Legal Line Is — Where the legal line sits for AI and testimonials: an allowed-grey-never table, what the rules prohibit, an approved-edit workflow and a consent email.
- 12 Custom GPT Examples for Small Businesses, With Setup Notes — Twelve assistants small businesses built as custom GPTs, rebuilt as Projects and Gems after the GPT retirement, each with instructions, files and sharing.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: published settlement and penalty notices from a health-privacy regulator concerning practices' online review replies (2019, 2022, 2023), as reported by health-privacy trade publications and law-firm summaries (checked September 2026); Google Business Profile help on owner replies, review appeals and extortion reports.