How to Reply to a Review Without Breaking Client Confidentiality
A fast, warm reply builds trust everywhere else. For a law firm or healthcare practice, the same reply can confirm a relationship or repeat a detail the business had no right to make public — regardless of what the reviewer already said.
Published September 14, 2026 · 6 min read
Every other version of this advice says the same thing: reply fast, sound human, don't be defensive. For a law firm, a healthcare practice, a therapist's office, or a financial advisory, that advice is incomplete in a way that actually matters. The reply itself can be the compliance problem — not because it's rude or slow, but because of what it confirms.
The rule that doesn't bend: don't confirm or deny the relationship
A one-star review says "Dr. Smith misdiagnosed me" or "this firm botched my custody case." The instinct is to respond directly — explain what actually happened, correct the record. That instinct is the trap. Simply replying in a way that treats the person as a known patient or client can itself be a disclosure, separate from whatever specifics you do or don't include in the text.
This isn't a theoretical risk. The U.S. Department of Health and Human Services' Office for Civil Rights has taken real enforcement action against healthcare practices for exactly this pattern — replying to a negative review by confirming someone was a patient or referencing their treatment, even when the intent was just to correct an inaccurate claim. For law firms, several state bar ethics opinions warn against the same thing: confirming a representation, or discussing case specifics publicly, can violate confidentiality obligations that exist independent of the client's own consent to sue or complain.
What the reviewer said about themselves does not change what you can say
This is the part that trips people up. A client or patient can waive their own privacy — they can name themselves, describe their case or diagnosis, and post it publicly, and that's their right. Your confidentiality obligation runs the other way and doesn't bend just because they went first. A reply that "sets the record straight" with your own version of the specifics is still a disclosure from your side, even if the reviewer volunteered theirs.
What is actually safe to post
- Generic, non-specific acknowledgment — "We take all feedback seriously and would welcome the chance to discuss this directly" — without confirming the person is or was a client or patient.
- An invitation to continue the conversation off-platform, by phone or a direct email, rather than litigating any detail in public.
- No names, dates, case types, diagnoses, treatments, amounts, or outcomes — not even to correct an inaccurate one.
- The same tone and turnaround for every review in this category, so a reply never inadvertently signals "this one was true" by reading differently from the rest.
Route it to someone who can actually decide, before it posts
A review-response SLA needs an escalation path for exactly this category — the same principle covered in our piece on making an SLA survive multiple locations: a review touching confidentiality shouldn't move on the same clock, or through the same approver, as a routine complaint about wait times or a rude phone call. It should route to a partner, a compliance officer, or whoever actually owns that risk, not to whoever normally handles the reply queue that day.
This is also the honest version of where Locivo actually helps here, and where it doesn't: AI-drafted replies for law firms and healthcare practices are built to default to that generic, non-specific tone — matching your professional voice without inventing case or treatment details that were never provided — and nothing posts automatically. Every draft sits for a human to read and approve first. What Locivo doesn't do is judge whether a specific review crosses a confidentiality line; that call still needs a person with the context and the authority to make it.
FAQ
If a reviewer already says they were my client or patient, can I confirm it in my reply?
No. The reviewer can disclose their own relationship with you; that doesn't extend permission to you to confirm it in a public reply. Treat every reply the same generic way regardless of what the reviewer already revealed.
What should a law firm or healthcare practice actually say in a reply to a negative review?
Something short, professional, and non-specific — acknowledging the feedback and inviting a direct conversation offline — without confirming a relationship, naming a case or diagnosis, or including any date, amount, or outcome.
Who should approve a reply to a review that raises confidentiality concerns?
Someone with the authority and context to make that judgment call — a partner, a compliance officer, or an equivalent role — on a separate, slower-if-needed approval path from the one used for routine reviews, not whoever is handling the general reply queue that day.
None of this is legal advice, and the specific rules vary by jurisdiction and profession. But the underlying principle holds everywhere it applies: for a regulated business, a review reply is not just a customer-service moment, it's a public statement with its own compliance exposure — and the safest reply is almost always the shortest, least specific one, sent from someone who actually has the standing to send it.
Own your reputation. Across every location, worldwide.
Free to start. Connect your Google Business Profile in under 2 minutes — no credit card required.