# HIPAA and Online Reviews in 2027: How NEMT Companies Can Reply Without a Violation

Canonical URL: https://nemtguide.com/guides/hipaa-online-reviews/ · Updated 2026-10-02

If HIPAA applies to your NEMT company, a public reply to a review may not confirm that the reviewer rode with you or mention the trip, the clinic, or their condition, even when they posted those details first. Thank them in general words, invite them to call, and handle the facts by phone. Never feature a rider's story without their signed authorization.

- Confirming that a reviewer rode with you can disclose health information, because it ties a named person to a medical ride.
- A rider posting the details first does not let you repeat them. Practices that answered patients' own reviews have paid OCR to settle.
- OCR's review and social media cases have cost providers $10,000 to $182,000, usually with two years of monitoring.
- A reply that leaks rider details is usually a breach: delete it, notify the rider within 60 days, and tell your broker fast.
- Ban rider information in staff posts, not talk about pay or working conditions, which federal labor law protects.

A rider posts that your van was 40 minutes late for dialysis and the driver was rude. Your first instinct is to set the record straight: the pickup was on time, the dialysis center changed the chair time, and the driver waited. That reply can be a HIPAA violation, and it is the kind federal regulators have fined providers for.

## Does HIPAA apply to your review replies?

HIPAA reaches your replies if your company is a covered entity or a business associate. A NEMT company that bills Medicaid or a health plan electronically may be a covered entity, and a company running broker trips under a business associate agreement is bound as the broker's subcontractor. See [HIPAA for NEMT providers](https://nemtguide.com/guides/hipaa-for-nemt/) to work out which you are. Until you know, treat every reply as covered.

The rule is short. A covered entity or business associate may not use or disclose protected health information except as the Privacy Rule permits ([45 CFR 164.502(a)](https://www.ecfr.gov/current/title-45/section-164.502)). A business associate may disclose it only as its business associate agreement allows.

### Why "yes, you rode with us" is a disclosure

Health information covers anything that relates to a person's health, the health care they receive, or payment for it, and it becomes protected when it identifies the person ([45 CFR 160.103](https://www.ecfr.gov/current/title-45/section-160.103)). A reply that confirms a named reviewer rode with you to a medical appointment ties that person to health care. For a Medicaid trip, it also hints at how their care is paid for. Add the clinic, the pickup time, or "your wheelchair" and the reply discloses more. See [protected health information](https://nemtguide.com/glossary/protected-health-information/) for the full list of identifiers.

It does not matter that the rider posted first. The Privacy Rule has no exception for details a patient shares in public. In three of the four review cases below, OCR says the provider was answering the patient's own review.

### Texas adds its own law

Texas reaches companies that HIPAA may miss. Its medical records privacy law covers anyone who collects, uses, or stores protected health information, or simply comes into possession of it (Texas Health and Safety Code 181.001). A covered entity may not disclose that information electronically without the person's separate authorization for each disclosure, outside listed exceptions such as treatment and payment between covered entities (181.154). The attorney general can seek up to $5,000 per negligent violation and $25,000 per knowing one each year, and up to $1.5 million a year for a pattern (181.201). See the [Texas NEMT guide](https://nemtguide.com/states/texas/).

## What OCR has fined providers for

These six cases from HHS's Office for Civil Rights (OCR) involve review replies, website posts, and a press release about patients. Most began with a patient's complaint, and most settlements also came with a corrective action plan that OCR monitors for two years. Amounts ranged from $10,000 to $2.4 million.

| Case and date announced | Paid | What went public |
|---|---|---|
| Memorial Hermann Health System, Texas (May 10, 2017) | $2.4 million | A patient's name in the title of a press release |
| Elite Dental Associates, Dallas (October 2, 2019) | $10,000 | A patient's last name and condition, and other patients' details, in review replies |
| U. Phillip Igbinadolor, D.M.D. & Associates, North Carolina (March 28, 2022) | $50,000 penalty | A patient's information on a webpage answering a negative review |
| New Vision Dental, California (December 14, 2022) | $23,000 | Patients' names, treatment, and insurance details in replies to reviews |
| Manasa Health Center, New Jersey (June 5, 2023) | $30,000 | A patient's mental health diagnosis and treatment, and three other patients' details |
| Cadia Healthcare Facilities, Delaware (September 30, 2025) | $182,000 | Success stories about 150 patients, posted without written authorization |

Three lessons repeat across them:

- **Small companies are not exempt.** OCR reduced Elite's amount because of its size and finances, and still settled. The North Carolina practice ignored OCR's data request and subpoena, and OCR imposed a $50,000 civil money penalty.
- **Missing policies make it worse.** Elite, New Vision, and Manasa were also cited over their privacy policies, and Elite and New Vision over their notice of privacy practices.
- **The fix includes notices.** Manasa had to send breach notices within 30 days to everyone whose information it had posted online, and report them to HHS. Memorial Hermann was also cited for not documenting the sanctions it gave staff in time.

## How to word a reply that discloses nothing

A safe reply could have been written about any company and any customer. Before you post, read it as a stranger would and ask whether it tells them anything about this person.

Leave out:

- Any confirmation that the reviewer is a rider, a patient, or a broker member
- Dates, pickup times, wait times, and "our records show"
- Addresses, clinics, hospitals, dialysis centers, and appointment types
- Wheelchairs, stretchers, oxygen, escorts, or any condition
- The broker, health plan, or program that paid for the trip
- The driver's name or van number, which point to one trip

For a complaint:

> "Thank you for taking the time to share this. We take every concern seriously and want to hear more. Please call our office at [number] and ask for our operations manager."

For praise:

> "Thank you for the kind words. We share every compliment with our drivers and dispatchers."

You may describe your general policies, such as calling ahead when a driver is running late, as long as the sentence says nothing about this reviewer's trip. Do not argue the facts in public, even when the review is wrong.

### Take the facts to a private call

The Privacy Rule lets you disclose a person's information to that person (45 CFR 164.502(a)(1)(i)). Call the rider at the number in your records, confirm you are speaking with them, and go through what happened. Write the call into your [complaint log](https://nemtguide.com/templates/nemt-complaint-log/). If the trip came from a broker, check whether your contract makes you report rider complaints. See [NEMT broker complaints](https://nemtguide.com/guides/broker-rider-complaints/).

## If a reply already gave away rider details

Act the same day. A covered entity must mitigate, as far as practicable, any harm from a disclosure that broke its policies or the rule ([45 CFR 164.530(f)](https://www.ecfr.gov/current/title-45/section-164.530)).

1. **Take the reply down or edit it.** Screenshot it first for your records.
2. **Assess it as a breach.** A disclosure the Privacy Rule does not permit is presumed a breach unless a documented risk assessment shows a low probability that the information was compromised (45 CFR 164.402). A post the public could read is hard to clear that way.
3. **Notify the rider.** If you are the covered entity, do it without unreasonable delay and no later than 60 calendar days after you discover the breach (45 CFR 164.404).
4. **Log it for HHS.** For fewer than 500 people, a covered entity reports it through the HHS breach portal within 60 days after the end of the calendar year (45 CFR 164.408). Use a [HIPAA breach log](https://nemtguide.com/templates/hipaa-breach-log/).
5. **Tell the broker fast.** WellTrans's subcontractor business associate agreement, revised October 16, 2025, requires a report of any disclosure the agreement does not allow within one business day. Modivcare's 2025 provider training says to report any breach involving member information, big or small, immediately to your provider relations contact or its privacy officer.
6. **Apply and document sanctions** if a staff member posted it (45 CFR 164.530(e)).

For the full breach process, see [what to do after a NEMT data breach](https://nemtguide.com/guides/nemt-data-breach/).

## Rules for drivers' and dispatchers' own posts

Your workforce includes employees, volunteers, trainees, and anyone else whose work you directly control, paid or not (45 CFR 160.103). You must train them on your privacy policies and apply sanctions when they break them (45 CFR 164.530(b) and (e)). Modivcare's 2025 provider training lists posting a member's trip records on social media as an improper disclosure.

Put these in your social media policy:

- No photos or video taken in or around the van that show a rider, a manifest, or a dispatch screen. A full-face photo is one of HIPAA's listed identifiers, even in the background of a selfie (45 CFR 164.514(b)).
- No posts about a rider, a pickup, or a destination, even without a name. "Drove a regular to chemo at 5 a.m. again" can be enough for the rider's neighbors.
- No check-ins or location tags at clinics, hospitals, or riders' homes while on a trip.
- No one answers a review as the company except the person you assign, and no one shares rider details from any account.

Keep the policy aimed at rider information. Federal labor law protects employees who discuss pay, benefits, and working conditions with coworkers, including on social media, whether or not they have a union (NLRB). Under the standard the NLRB adopted on August 2, 2023, a work rule that would tend to chill those rights is presumed unlawful unless the employer proves it serves a legitimate and substantial business interest that a narrower rule could not. The agency's general counsel said on August 26, 2026 that she will ask the Board to overturn that standard, and until it does, it still applies. "No rider information online" protects riders. "No negative posts about the company" invites a labor charge.

In Texas, employees must finish training on state and federal health privacy law within 90 days of hire and sign a statement that they did (Texas Health and Safety Code 181.101). Build the social media rules into [HIPAA training for NEMT staff](https://nemtguide.com/guides/hipaa-training-for-nemt-staff/) and Part 8 of the [NEMT HIPAA policy template](https://nemtguide.com/templates/nemt-hipaa-policy/).

## Using reviews and rider stories in your marketing

Featuring a rider in your marketing is a different act from replying to them. Marketing means a communication that encourages people to buy or use a product or service (45 CFR 164.501), and any use of protected health information for marketing needs the person's written authorization (45 CFR 164.508(a)(3)). That covers posting a rider's photo, story, or thank-you note on your website or social pages. Texas separately requires clear written or electronic permission for marketing uses (181.152).

A valid authorization describes the information, says who discloses it and to whom, states the purpose, gives an expiration date or event, and carries the rider's signature and date. It must also tell the rider they can revoke it in writing, and whether their rides depend on signing it (45 CFR 164.508(c)). They cannot, because a covered entity may not condition treatment or payment on an authorization (45 CFR 164.508(b)(4)), so say so.

The FTC adds rules about the reviews themselves. Asking for reviews and never paying for good ones is covered in [NEMT marketing](https://nemtguide.com/guides/nemt-marketing/). Three more apply when a review stings:

- **No threats to get a review removed.** Groundless legal threats, physical threats, intimidation, and knowingly false public accusations are banned (16 CFR 465.7(a)).
- **No hiding bad reviews on your own site.** If your website shows reviews, it may not suggest they are all or most of them while you hold back the negative ones. You may withhold reviews under neutral rules applied to all, such as one that contains another person's personal information (16 CFR 465.7(b)).
- **No gag clauses.** A form contract term that bars or penalizes honest reviews is void from the start (15 U.S.C. 45b). The FTC's guidance, dated February 2017, tells businesses to remove such terms from form contracts and online terms even if they never enforce them. Check your private pay rider agreement.

Do not offer a refund or a free ride in exchange for a better review, since paying for reviews of a particular sentiment is banned (16 CFR 465.4). The FTC can seek civil penalties of up to $53,088 per violation of its rules (16 CFR 1.98), and on September 15, 2026 it said that amount stays the same for 2026.

## A review response routine in six steps

1. **Pick one responder.** The owner or a trained manager answers every review. Drivers and dispatchers never do.
2. **Use two approved replies.** Keep the complaint and praise wording above in your policy and post only those.
3. **Answer within one business day.** A quick, plain reply shows readers you care without saying anything about the rider.
4. **Call the rider privately.** Confirm who you are speaking with, fix what you can, and log the call.
5. **Check the broker rules.** Report the complaint if your agreement requires it.
6. **Review the policy each year.** Retrain staff when you change it, and keep the training records for 6 years (45 CFR 164.530(j)).

## Frequently asked questions

### Can I reply to a bad review at all under HIPAA?

Yes. HIPAA limits what you disclose, not whether you answer. A short reply that thanks the reviewer, says you take every concern seriously, and gives a phone number and a job title to ask for discloses nothing. What you cannot do is confirm the person rode with you or mention a trip, time, place, or condition.

### The rider already said they ride with us to dialysis. Can I respond to that?

Not with any detail. The Privacy Rule has no exception for information a patient made public. OCR's cases against Elite Dental Associates (2019), New Vision Dental (2022), and Manasa Health Center (2023) all began with a patient's own review. Each practice answered with that patient's information, and each paid a settlement.

### Can I thank a rider by name for a five-star review?

Thank them without confirming anything: "Thank you for the kind words. We share every compliment with our team." Using their name next to a reference to their ride, their clinic, or their driver ties them to a medical trip. Save personal thanks for a phone call or a card sent to their address on file.

### Can I post a rider's thank-you note or photo on our website?

Only with a signed HIPAA authorization if HIPAA applies to you. Marketing use of protected health information needs one under 45 CFR 164.508(a)(3). On September 30, 2025, OCR announced that five Delaware rehabilitation and nursing facilities paid $182,000 for posting 150 patients' success stories without written authorization.

### Can I discipline a driver who posts about a rider?

Yes, and HIPAA requires it. A covered entity must have and apply sanctions against workforce members who break its privacy policies, and document them (45 CFR 164.530(e)). Write the rule into your policy and training first, so drivers know the line before they cross it.

### Can I get a fake or unfair review taken down?

You can flag it to the site under the site's own rules and ask the reviewer to call you. You cannot use a groundless legal threat, intimidation, or a knowingly false public accusation to get it removed (16 CFR 465.7), and a no-negative-reviews clause in your rider agreement is void under federal law (15 U.S.C. 45b).

## Official resources

- [HHS OCR: HIPAA resolution agreements and civil money penalties](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html)
- [HHS OCR: Breach portal, report a breach to HHS](https://ocrportal.hhs.gov/ocr/breach/)
- [eCFR: 45 CFR 164.508, HIPAA authorizations](https://www.ecfr.gov/current/title-45/section-164.508)
- [FTC: Consumer Review Fairness Act, what businesses need to know](https://www.ftc.gov/business-guidance/resources/consumer-review-fairness-act-what-businesses-need-know)
- [eCFR: 16 CFR part 465, Use of Consumer Reviews and Testimonials](https://www.ecfr.gov/current/title-16/part-465)
- [NLRB: Social media and protected concerted activity](https://www.nlrb.gov/about-nlrb/rights-we-protect/the-law/employees/social-media)
