Marketing a healthcare practice on social media demands more than good content and scheduling tools. It demands legal literacy. At Monk Creatives, we have worked with healthcare clients across a range of disciplines, and one truth keeps surfacing: the practices that build the strongest social presence are the ones that treat compliance as a creative constraint rather than a barrier. When you understand the rules governing patient privacy in the United States, you can build a social media programme that attracts patients, builds authority, and keeps your practice’s license and reputation intact.
HIPAA, the Health Insurance Portability and Accountability Act, and the privacy standards it introduced in 1996, along with the HITECH Act of 2009, apply to covered entities such as hospitals, clinics, and physician practices, as well as their business associates. If your practice transmits health information electronically for billing or insurance purposes, you almost certainly fall under HIPAA’s definition of a covered entity. That means every post, story, reel, and reply you publish on social media can have legal consequences if it touches on protected health information, or PHI. This guide walks through what that means in practice and how to build a social media operation that respects patient privacy while still achieving genuine marketing results.
What HIPAA actually means for your social media activity
PHI is any individually identifiable health information that relates to a person’s past, present, or future physical or mental health, or to the provision of healthcare to that person. Under HIPAA, there are 18 identifiers that, when linked to health information, make that information protected. These include names, all subdivisions of a geographic region smaller than a state, dates directly related to an individual, phone numbers, email addresses, Social Security numbers, medical record numbers, account numbers, and even photographs of a person’s face.
The practical implication is brutal in its simplicity: if you post a before-and-after photo that a patient agreed to share, but the background of that photo includes a calendar with the patient’s appointment date, you may have just published PHI. If you share a testimonial in which a patient mentions their city and condition, and their city narrows their geographic area to a recognisable group of fewer than 20,000 people under the Small Population Rule, that too may constitute a violation. These are not edge cases, they are the kinds of situations that generate complaints and, in the worst instances, enforcement actions.
HIPAA does not contain a social media-specific exception. The same standards that govern your billing software and patient records apply to your Instagram grid. This means that a “marketing” exemption for “facility directories” does not extend to posts you publish to attract new patients. If you are unsure whether a piece of content contains PHI, the safest test is to ask: could a reasonable person identify the patient from this post? If the answer is yes, you need documented authorisation before publishing.
The difference between consent, authorisation, and implied permission
A common mistake healthcare practices make is assuming that a patient’s verbal agreement to “use my photo” satisfies HIPAA’s requirements. It does not. HIPAA distinguishes between consent, a general agreement to treatment, and a specific authorisation for the use or disclosure of PHI for marketing purposes. An authorisation must be obtained in writing, must identify the information to be disclosed, must state who is authorised to make the disclosure, must identify the recipient, must describe the purpose of the use, and must include an expiration date. Blanket consent forms signed at intake almost never satisfy this standard.
In practice, this means that if you want to use a patient’s testimonial, photograph, or even a success story that could be traced back to them, you need a properly drafted HIPAA authorisation. Many practices work with legal counsel to build a standard form that meets the requirements while remaining patient-friendly. The form should be signed before any content is created, not after. If the patient withdraws their authorisation at any point, you must remove the content from your channels promptly and document the removal.
Some practices attempt to use implied permission, relying on a patient’s active social media presence, such as tagging the practice in a post, as de facto consent to feature that content. This is legally risky. A patient tagging your practice in a post about their experience does not constitute a HIPAA authorisation for your account to repost that content. If you want to reshare patient-generated content, obtain written authorisation first, or use a content release form that specifically covers social media republication.
Which social media platforms carry the highest risk
Not all platforms carry the same level of risk for healthcare marketing. A practice’s LinkedIn page, where content tends to be educational and population-health-oriented, presents a different risk profile than an Instagram account where team members might reply to direct messages from patients who believe they are communicating privately with the practice. The following table summarises the key risk dimensions across the most commonly used platforms in US healthcare marketing.
| Platform | Primary Risk | Recommended Controls | Best Used For |
|---|---|---|---|
| Public comments containing PHI from patients; misconfigured privacy settings on Pages | Moderate all comments; disable patient-physician messaging on the Page; post with no identifying patient details | Community education, event promotion, practice news | |
| Stories and DMs with patients who believe conversations are private and HIPAA-covered | Do not use DMs for clinical communication; publish a clear notice that DMs are not for medical advice; moderate comments | Visual brand storytelling, educational reels, community building | |
| YouTube | Video content that includes patient faces, voices, or identifying information without authorisation | Use only consented and signed-off footage; review every frame of video for background identifiers before publishing | Long-form educational content, procedure explainers, patient education |
| Lower direct risk, but team members may inadvertently share patient-adjacent content | Establish a clear social media policy for employee accounts; monitor tagged content | Professional networking, thought leadership, recruitment | |
| TikTok | Algorithm-driven reach means errors spread fast; comment sections are high-volume and unmoderated | Extremely tight content review before publishing; aggressive comment moderation; consider avoiding for PHI-sensitive practices | Broad reach educational content, viral health literacy (non-clinical) |
The single most important control across every platform is a documented content review process that sits between content creation and publication. Every post, regardless of who wrote it, should pass through at least one reviewer who is trained to spot PHI, misattributed claims, and language that could be construed as a guarantee of outcome. At Monk Creatives, when we support healthcare clients with their social media management, the review step is non-negotiable and is documented in the workflow. This is not bureaucracy for its own sake, it is the discipline that lets a practice publish confidently at scale.
What kind of content is actually safe to publish
The safest category of social media content for healthcare practices is population-level educational material. General information about a condition, its symptoms, risk factors, and when to seek care, does not contain PHI and can be published freely, provided the content is accurate and does not cross into providing specific medical advice to an identifiable individual. Educational posts about diabetes management, for example, are generally safe. A post about how a specific patient’s diabetes management improved after treatment at your practice is not, unless you have a HIPAA authorisation and the content contains no identifying information.
Behind-the-scenes content that shows your facility, your team, or your technology can be compelling and is generally low-risk, but it requires diligence. A photo of your team in a conference room is fine. A photo of your team standing beside a patient’s medical chart is not. Even seemingly innocuous details, a lab coat with a name, a whiteboard with a room number, can create an inference that violates privacy. Train whoever is taking these photos to scan the frame before the shutter is pressed.
Testimonials and success stories are among the most powerful tools in healthcare social media marketing, but they are also the most regulated. The HIPAA authorisation requirements described earlier apply here in full. In addition, the Federal Trade Commission’s testimonial guidelines, under the FTC Act, require that any testimonial reflecting a typical experience include a clear and conspicuous disclosure if the experience is not typical. A practice that publishes a patient’s glowing five-star experience without noting that results vary may face regulatory scrutiny from both HIPAA and FTC angles.
For practices that want to go further with their social presence, a properly structured website development project can create a hub that extends the authority and trust signals from social media into a compliant, owned platform. Social media drives traffic to the hub; the hub holds the content that social platforms restrict.
Responding to patient comments and direct messages
One of the subtler risks in healthcare social media is the comment thread. A patient may leave a comment on your post that says something like, “Thanks Dr Smith, the medication you prescribed last Tuesday is working great.” That comment, posted publicly, contains PHI. It identifies a patient by name (or enough context to identify them), references a specific date, and references a specific clinical intervention. The practice is not the one who published the PHI, but it may still bear responsibility for allowing it to remain on a channel it controls.
The correct response is to have a policy and a team member designated to handle this situation. The practice should remove the comment, reply to the patient privately, through a channel that is not public, and document the removal. The same principle applies to direct messages. If a patient sends a message to your practice’s social media account asking about symptoms, medication side effects, or appointment results, your team must not provide clinical advice in that channel. The message itself may not be PHI until the patient discloses health information, but once they do, you have received PHI through an unsecured channel. The appropriate response is to redirect the patient to a secure, HIPAA-compliant communication method, a patient portal, a phone call to the office, or an in-person visit, and document the redirection.
Practices that invest in proper social media management with a designated community manager trained in healthcare compliance avoid this category of risk entirely. Community managers can be trained to recognise PHI in comments and to respond with a standard redirection script that protects both the patient and the practice.
Building a content approval workflow that works
A compliant social media operation for a healthcare practice needs a workflow that is both rigorous enough to catch issues and lightweight enough that your team will actually use it. At a minimum, the workflow should include: a content creator who drafts the post, a compliance reviewer who checks for PHI and clinical accuracy, an approver, usually a clinician or practice administrator, who signs off on clinical content, and a scheduler who publishes only after approval is documented.
Documentation is the through-line of HIPAA compliance. Every post should have a record of who created it, who reviewed it, who approved it, and when it was published. If a question ever arises about a piece of content, from a patient complaint, a regulator, or an internal audit, you should be able to produce that record. Many practices use a simple spreadsheet or project management tool to track this. The investment is small; the protection it provides is substantial.
For practices looking to deepen their social media capability beyond compliance into genuine growth, our social media growth resources explore strategy frameworks that go beyond the regulatory floor and help practices build meaningful audience engagement.
Handling a privacy breach or accidental PHI disclosure
Even with the best controls in place, mistakes happen. A team member might publish a photo that includes a patient’s chart in the background. A comment containing PHI might sit on a post for several hours before it is noticed. The question is not whether a breach is possible, it is whether your practice has a response plan that minimises the harm and satisfies your legal obligations.
Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach that affects 500 or more individuals. For breaches affecting fewer than 500 individuals, the practice must notify affected individuals and, in some cases, the Secretary of Health and Human Services and the media. The notification must include a description of the breach, the types of information involved, the steps individuals should take to protect themselves, and a description of what the practice is doing to investigate and mitigate the breach.
On social media, a breach typically takes the form of a post that should not have been published. The immediate steps are: remove the post from all platforms as quickly as possible, document the removal and the circumstances of the breach, assess whether the disclosed information qualifies as PHI, and notify your privacy officer and legal counsel. If the post was visible for a significant period, or if it was shared by followers before removal, the notification obligations under the Breach Notification Rule may be triggered. Having a documented breach response plan, and rehearsing it, is the single most effective thing a practice can do to manage the fallout from an accidental disclosure.
Training your team on HIPAA and social media
The weakest link in any compliance system is the person who does not know the rules. Many healthcare practices have excellent HIPAA training for clinical staff but leave social media responsibilities to a marketing team or an external agency that has never received formal HIPAA training. This is a gap that needs to be closed. Every person who has any role in creating, reviewing, approving, or publishing social media content for a HIPAA-covered practice should receive baseline training on what PHI is, how it can appear in social media content, and what to do if they suspect a breach.
Training should be refreshed at least annually and should be documented. The training record becomes part of your compliance documentation if you are ever audited. For practices that work with external agencies, the agency’s team members who touch your social media accounts should receive the same training, or you should work with an agency that already understands healthcare compliance. When you are reviewing social media management services, ask specifically about HIPAA training for the team members who will work on your account. The agencies that take this seriously will have a clear answer.
State laws and professional board rules that go beyond HIPAA
HIPAA is a federal floor, not a ceiling. Many states have privacy laws that are stricter than HIPAA, and state medical boards have their own rules about advertising and patient testimonials. In California, for example, the Confidentiality of Medical Information Act imposes additional requirements on the use of medical information for marketing purposes. In Texas, the medical board’s rules on advertising require that testimonials be from actual patients, that the practice not pay for testimonials, and that any paid endorsement be clearly disclosed.
Professional societies add another layer. The American Medical Association’s Code of Medical Ethics includes opinions on physician use of social media that address everything from friending patients on personal accounts to the use of patient images in educational content. The American Dental Association, the American Psychological Association, and other professional bodies have their own guidance documents that their members are expected to follow. Before launching or expanding a social media programme, a practice should review the rules from its state medical board, its professional society, and any applicable state privacy law. Legal counsel with healthcare experience is the right resource for this review.
Practical checklist: compliant vs. non-compliant social media content
Use the following checklist as a practical decision-making tool when evaluating whether a piece of content is ready to publish. This is not a substitute for legal advice, but it captures the most common decision points that determine whether a post is likely to comply with HIPAA and related regulations.
| Content Element | Generally Compliant | Generally Non-Compliant |
|---|---|---|
| Patient photographs | Photo with signed HIPAA authorisation; face not clearly identifiable; stock or model photography | Photo of an actual patient without written authorisation; photo with identifying background details |
| Patient testimonials | Testimonial with signed authorisation; no identifying details; outcome disclosure included | Testimonial that names the patient; testimonial with location details that narrows identity |
| Before-and-after photos | Photo with signed authorisation; face cropped or obscured; consent on file | Before-and-after set without signed authorisation; photo including face without consent |
| Clinical education posts | Population-level health information; no identifiable individuals; references to peer-reviewed literature | Clinical advice directed at a specific patient; outcome guarantees |
| Staff and facility photos | Photos of empty treatment rooms; team photos with signed consent from each person shown | Photos showing patient charts, name badges, appointment schedules, or equipment screens |
| Comments and replies | Redirecting commenters to secure channels; generic engagement with no clinical content | Providing clinical advice in a public comment; sharing patient details in a reply |
| Contests and promotions | Giveaway with no health information required; clear terms and conditions | Contest that asks entrants to share health information; prize that involves a clinical service without disclosures |
| User-generated content | Reposted content with a signed content release that covers social media republication | Reposting a patient’s post that contains health information without specific authorisation |
Working with a social media agency in a regulated industry
Many healthcare practices choose to outsource their social media management to an agency. This is a sensible decision, social media at scale demands consistent publishing, community management, and content strategy that most practices cannot deliver in-house alongside clinical operations. But outsourcing does not outsource your legal responsibility. The practice remains the covered entity and remains responsible for every piece of content published under its name.
When selecting an agency, look for evidence of healthcare experience. An agency that has worked with healthcare clients will understand the unique constraints of the space and will have workflows designed around them. Review the agency’s portfolio for healthcare work. Ask about their content review process and whether they have a designated compliance reviewer on healthcare accounts. Ask whether they carry professional liability insurance that covers social media content. Ask for references from current or past healthcare clients. These questions are not an inconvenience, they are the due diligence that protects your practice.
Agencies with experience in healthcare social media understand that the content calendar is a living document that needs to account for compliance review time, not just creative time. A post that looks great from a brand perspective but cannot be published because the compliance review flagged a PHI concern is not a success, it is a missed opportunity that could have been avoided with better briefing. Clear briefs that specify what the practice wants to communicate, combined with a compliance checkpoint before publication, produce the best results. If your agency does not have a compliance checkpoint built into its workflow, ask why, and consider whether it is the right agency for your practice.
For practices that are also evaluating their broader digital presence, a website development project alongside social media management creates a cohesive digital ecosystem. The website becomes the authorised, compliant home for detailed patient information, appointment booking, and educational resources, all the content that social platforms restrict or penalise. Social media feeds traffic to the site; the site converts that traffic into appointments and patient relationships.
Frequently asked questions
Can I post patient success stories on social media?
You can post patient success stories on social media, but only if you have a HIPAA-compliant written authorisation from the patient that specifically covers social media publication. The authorisation must meet all HIPAA requirements, including identification of the information to be disclosed, the purpose, the recipient, and an expiration date. The story itself must not contain any of the 18 HIPAA identifiers, name, geographic subdivision, dates, contact information, or any other detail that would allow someone to identify the patient. If you cannot publish the story without including an identifier, you cannot publish the story at all.
What should I do if a patient comments with PHI on one of my posts?
Remove the comment as quickly as possible and document the removal, including the time and date of removal and a brief description of the content. Respond to the patient through a private, non-public channel to let them know you have removed the comment for privacy reasons and to redirect them to a secure method of communication for any clinical questions. Report the incident to your privacy officer and document it in your incident log. If the comment was visible for a significant period, or if it was shared or screenshotted by other users before removal, consult your legal counsel about whether the Breach Notification Rule applies.
Does HIPAA apply to my personal social media accounts as a physician?
Yes, HIPAA applies to your personal social media accounts if you use them in a professional capacity. Posting about a patient you treated, even on your personal account, is still a disclosure of PHI if the post contains identifying information. Many medical boards have specific rules about physician social media use, and posting patient information on personal accounts is one of the fastest ways to trigger a board investigation. The safest approach is to keep your personal and professional accounts completely separate and to apply the same HIPAA standards to both.
Are there any social media platforms that are automatically HIPAA-compliant?
No social media platform is automatically HIPAA-compliant. Major platforms, including Facebook, Instagram, X, TikTok, LinkedIn, and YouTube, are not HIPAA Business Associates by default. This means they do not sign a Business Associate Agreement that obligates them to protect PHI in the way that HIPAA requires. Some platforms offer enterprise-level BAA options for healthcare organisations, but these are typically available only for advertising products, not for organic social media posting. This means that you should never use social media direct messaging, comments, or any platform feature to communicate PHI with patients. Use only HIPAA-compliant patient portals and secure messaging systems for clinical communication.
What training does my team need to manage social media compliance?
Every team member who creates, reviews, approves, or publishes social media content, including external agency staff, should receive baseline HIPAA training that covers what constitutes PHI, how PHI can appear in social media content, what to do if they suspect a breach, and the specific approval workflow your practice uses. Training should be refreshed annually and documented. Many healthcare associations offer social media-specific HIPAA training modules that can be completed online. The cost is minimal, and the documentation protects your practice in the event of an audit or complaint.
Can I use patient reviews and ratings from Google or Yelp in my social media content?
Patient reviews posted on public platforms like Google, Yelp, or Healthgrades are publicly available, but that does not mean you have the right to repost them on your own social media channels. The patient who wrote the review retains copyright in their words, and reposting without permission may constitute copyright infringement in addition to any privacy concerns. The safest approach is to ask the patient for written permission to quote their review, to verify that the review does not contain PHI, and to credit the review appropriately. Alternatively, you can paraphrase the sentiment in your own words without directly quoting the review text.
Building a social media presence that respects patient privacy while still achieving genuine marketing results is entirely possible, but it requires structure, training, and discipline. The practices that get it right treat compliance as a system, not a one-time checklist. They document their workflows, train their teams, review every piece of content before it goes live, and have a clear response plan for the moments when things go wrong despite everyone’s best efforts. The result is a social media programme that attracts patients, builds community trust, and protects the practice’s most valuable asset, its reputation for caring for patients with integrity.
If your healthcare practice is ready to build a social media programme that respects patient privacy while driving real engagement, the team at Monk Creatives can help. Reach out at info@monkcreatives.com or visit our social media management page to learn more about how we work with healthcare clients.