A patient leaves a warm five-star review naming the hygienist who cleaned her teeth. The front desk manager, meaning well, drafts a reply with a chatbot: thank you for trusting us with your cleaning, we will see you at your six-month recall. That reply just confirmed to the public that this named person is a patient and what she came in for.
That is the shape of nearly every compliance problem we see when a medical, dental, chiropractic or therapy practice starts using AI for marketing. The tools are rarely the trouble. The habit of feeding real patient detail into them is.
Protected health information, usually shortened to PHI, is anything that ties a specific person to their care. It is broader than a diagnosis. A name alongside an appointment date qualifies. So does a photograph, an intake form, an email from a patient, or a claim number. The working test: if a stranger reading it could figure out that this individual was treated by you, treat it as protected.
The second half matters more than most owners realize. The moment PHI enters an outside tool, the company behind that tool is handling patient data on your behalf, which makes it what the rules call a business associate. That relationship has to be papered in a signed business associate agreement before any data moves. A free consumer chatbot has no such agreement with your practice and will not sign one.
Most of what a practice publishes has nothing to do with any individual:
Unsafe use is easy to describe. Pasting a patient email into a general chatbot to help word the reply. Dropping a chart note in for a summary. Asking a tool to write a personalized message referencing someone's symptoms. Uploading a spreadsheet of names and procedures to build a campaign list. Each moves protected data into a vendor you have no agreement with, and deleting the chat afterwards does not undo it.
Write one reply and reuse it. Something like: thank you for the kind words, we appreciate you taking the time. No name, no confirmation that the person was seen, no reference to any service. For a negative review the same discipline applies with more at stake. Do not defend yourself with details. Say you take feedback seriously, give a phone number, and take it offline.
AI can help you draft that neutral wording once. It should not be handed the review thread and told to answer in your voice, because the personalization it reaches for is exactly the detail you cannot confirm.
Analytics and advertising pixels record which page a visitor loaded. On a page about anxiety treatment, addiction recovery, fertility or a named diagnosis, the page address alone suggests a health condition, and it usually travels with an identifier the ad platform can match to a person. Practices install them without a second thought, because every marketing guide says to.
Have someone technical list every tracking script on your site and check which pages carry them. Condition-specific pages and anything behind a patient login deserve particular care. If a vendor will not sign an agreement, it should not be running there.
If your practice has no compliance officer and no process for approving new software, do not start with patient-facing AI. Use it for public content only and revisit the question when someone can own the decision.
This article is general information, not legal advice. Your compliance officer or your attorney decides what is acceptable for your practice, and their answer overrules anything here.
Yes, provided the post is general education and contains no patient information. Writing about what to expect after an extraction is fine. Writing about a specific case, even with the name removed, is riskier than it looks, because small details can identify someone in a small community. Keep it general and have a clinician review it before publishing.
Better not to. Using their name in your reply is your practice acknowledging the relationship, and that acknowledgement comes from you rather than from them. A short, generic thank-you carries no risk and reads perfectly well. Save the warmth for their next visit.
It is a signed contract between your practice and any outside company that will handle patient data for you, setting out how they protect it and what happens if they do not. Any vendor whose software touches protected information needs one, including scheduling tools, email platforms and AI services. No signature means no patient data goes in.
Generally not, as long as they carry only the date, the time, your practice name and a location. Trouble starts when the message names a procedure or a provider whose specialty gives the reason away. Confirm the patient agreed to be contacted that way, and keep the wording as plain as possible.
Want this handled for you?
Get a free audit of your website, Google reviews, and local SEO — we’ll show you exactly where you’re losing customers. Delivered in 24 hours, no sales call.
Get my free audit → or book a 15-min callWe help local businesses in Stamford, Greenwich, Norwalk, and Fairfield County implement AI marketing that generates real results.
Get Your Free AI Marketing Audit →