New FTC review rules for patient reviews are no longer theoretical. In December 2025, the FTC sent warning letters to ten companies about possible violations of its Consumer Review Rule, and two were healthcare businesses. For dental and medical practices, that is a signal the rule finalized in 2024 is now being enforced, with a maximum civil penalty of $53,088 per violation.
The rule does not ban asking patients for reviews. It bans faking them: paying for reviews, writing them on a patient’s behalf, hiding negative feedback behind a gated review-request flow, or threatening a patient who posts an honest complaint. A practice that emails patients after a visit and simply asks for an honest review on Google or Yelp is compliant. A practice that offers a discount in exchange for a five-star review, or has staff post reviews under invented names, is not.

What the New FTC Review Rules Actually Prohibit
The rule, formally titled the Rule on the Use of Consumer Reviews and Testimonials, took effect in October 2024 and applies to any business that solicits or displays reviews, including dental and medical practices. It prohibits five specific practices:
- Fake or fabricated reviews. Writing, buying, or paying for a review that misrepresents a real patient’s experience, including AI-generated reviews presented as if a patient wrote them.
- Undisclosed insider reviews. An employee, owner, or family member posting a review of the practice without disclosing the relationship.
- Incentivized reviews that hide the incentive. Offering a discount, gift card, or free service in exchange for a review, when that exchange is not disclosed.
- Review suppression. Threatening legal action, intimidating a patient, or using a review-gating tool that routes negative feedback away from public platforms while only publishing positive comments.
- Fake indicators of influence. Buying followers, likes, or engagement to make the practice’s social presence look more trusted than it is.
What’s Still Allowed, and Still Worth Doing
Neutral review requests remain fully compliant. A post-visit text or email that simply asks the patient to share their honest experience on Google, without steering them toward a specific rating or offering anything in return, is exactly what the rule permits. That request matters for more than compliance: recent review activity is also a ranking factor for how a practice appears on Google Business Profile. So is training front-desk staff to mention, verbally, that the practice appreciates reviews. So is using a review-management platform, as long as it sends requests to every patient rather than filtering out anyone who indicates a bad experience first. If that platform sends the request by text message, it also needs to follow the consent rules covered in our guide to TCPA texting rules for practices.
Where the Rule Overlaps With HIPAA (the Part Most Compliance Guides Skip)
Most legal explainers of the FTC rule treat it as a standalone marketing issue. For dental and medical practices, it is not. A review request is triggered by the fact that someone was a patient, and the fact that someone was a patient is itself protected health information. That creates two exposure points that are specific to healthcare, and that generic FTC compliance guides do not address.

The first is the review-request platform itself. Many practices route post-visit review requests through the same texting or email tool they use for appointment reminders. If that tool logs patient names, visit dates, or treatment types, it needs a signed Business Associate Agreement, the same requirement covered in our guide to HIPAA-compliant marketing tracking. A tool that is fine for a retail business is not automatically fine for a dental office, even if the FTC has no objection to how it is used.
The second is how staff respond to a negative review. Replying “we’re sorry your root canal on March 3rd didn’t go as planned” is a HIPAA violation on its own, independent of anything the FTC rule covers, because it publicly confirms that a named reviewer was a patient and discloses the treatment they received. The compliant response acknowledges the concern without confirming any detail about the person’s care, and invites them to discuss it privately.
Compliant vs. Non-Compliant Review Requests
| Practice area | Compliant | Non-compliant |
|---|---|---|
| Requesting reviews | Automated post-visit email or text asking for an honest review, sent to all patients | Offering a discount, gift card, or free service in exchange for a review |
| Who posts | Only the patient who was actually treated | Staff, owners, or family members posting on the practice’s behalf without disclosure |
| Responding to a negative review | A brief, professional reply with no patient-specific details, followed by a private outreach | Confirming treatment details or the fact of the visit in a public reply |
| Handling unhappy patients | Sending the same review request to every patient | Gating requests so only satisfied patients are asked to post publicly |
| Marketing platform | Review-request tool covered under a signed BAA | Routing patient-triggered requests through a non-HIPAA-compliant marketing tool |
What Enforcement Looks Like in 2026
These FTC review rules carry real financial exposure once enforcement moves past a warning letter. The FTC’s December 2025 warning letters were not fines. They were a signal that the agency is actively monitoring compliance, and a warning letter is typically the step before an enforcement action if the underlying practice continues. The maximum penalty is $53,088 per violation as of 2026, and the FTC counts each individual fake or incentivized post as its own violation. A practice with a dozen incentivized reviews is not looking at one fine. It is looking at up to a dozen.
In practice, the businesses most likely to draw attention are the ones running review-gating software, the kind that surveys patients first and only sends the public review link to those who rate the visit highly. The FTC has flagged this pattern specifically, because it functions as a form of review suppression even without an explicit threat or payment involved.
A Review Request That Stays Inside the Rule
The safest version of a review request is short, neutral, and applies to every patient the same way. A practical template for a post-visit text or email:
“Thank you for visiting us today. If you have a minute, we’d appreciate an honest review of your experience on Google: [link]. It helps other patients find us and helps us know what to improve.”
Nothing in that message references a specific rating, offers anything in exchange, or filters who receives it. That is what separates a compliant request from one that draws FTC attention.
Common Mistakes Practices Make
- Treating review-gating as a best practice. Many marketing vendors still sell “smart review funnels” that only publish positive reviews. That is the single most common FTC exposure point for healthcare businesses right now.
- Outsourcing review responses to a general social media team. A team unfamiliar with HIPAA will often write a reply that confirms treatment details to sound personal and helpful, which is precisely what creates the violation.
- Assuming the FTC rule is the only rule that applies. Because the request is healthcare-specific, both the FTC’s rule and HIPAA’s privacy requirements apply at the same time, and clearing one does not clear the other.
Frequently Asked Questions
Can a dental or medical practice ask patients to leave a review?
Yes. Asking every patient for an honest review, without an incentive attached, is fully compliant with the FTC’s Consumer Review Rule and is the recommended approach for growing a review count.
What counts as a “fake” review under the FTC rule?
A review is fake if it misrepresents the reviewer’s actual experience, was written by someone who was not a real patient, was paid for or incentivized without disclosure, or was generated by AI and presented as a genuine patient account.
Can a practice offer a discount in exchange for a review?
Only if the incentive and the fact that it was offered in exchange for a review are clearly disclosed. An undisclosed discount-for-review exchange is one of the rule’s specific prohibitions.
How much can a practice be fined for a review violation?
The maximum civil penalty is $53,088 per violation as of 2026. Each individual fake or improperly incentivized review can count as a separate violation.
Can staff respond to a negative review without violating HIPAA?
Yes, as long as the public reply contains no details that confirm the person was a patient or describe their treatment. Address the concern generically and invite them to continue the conversation privately.
Does the FTC rule apply to AI-generated review responses or content?
Yes. The rule specifically covers AI-generated reviews or testimonials presented as if they reflect a real patient’s experience, and this applies regardless of which tool generated the content.
The FTC’s Consumer Review Rule is not a reason to stop asking for reviews. It is a reason to check how the request is built, who it is sent to, and what the practice’s response workflow actually says when a review comes back negative. For most dental and medical practices, the fix is not a new legal strategy. It is auditing the review-request tool for a BAA and rewriting the negative-review response script so it never repeats a patient’s treatment details in public.


