Testimonials
Blog / Compliance 9 min read

Patient Testimonial Consent Form and HIPAA Authorization

July 25, 2026 · Testimonials

If you are a HIPAA covered entity, publishing a patient testimonial requires a written authorization under 45 C.F.R. 164.508, not a consent form. The distinction matters: a consent to treat, a photo release, or a signature on your notice of privacy practices does not cover marketing. A valid authorization has to describe the specific information being used, name who may use it and who may receive it, state the purpose, carry an expiration date or event, and be signed and dated by the patient. It must also tell the patient they can revoke it. In September 2025, five nursing facilities paid $182,000 to settle an OCR investigation that started with exactly this: patient success stories posted to a website without valid authorizations.

Why a testimonial counts as protected health information

The usual objection is that the patient volunteered the story, so nothing was disclosed. That is not how the Privacy Rule works. Protected health information is individually identifiable health information held or transmitted by a covered entity, and a testimonial published by a medical practice identifies the person as a patient of that practice. The moment you post it, you have disclosed that this named, photographed person received care from you. Add a mention of the condition, the procedure, or the recovery, and you have disclosed the clinical detail too.

The patient telling their own story on their own Facebook page is their business, and HIPAA does not restrict what patients say about themselves. The rule binds you. When your practice takes that story and puts it on your website, in an ad, or in an email campaign, the covered entity is making the disclosure, and the disclosure is for marketing.

Marketing is the trigger, and it needs authorization

Section 164.508(a)(3) requires an authorization for any use or disclosure of PHI for marketing. There are only two exceptions, and neither one helps with a testimonial:

  • a face-to-face communication made by the covered entity to the individual, and
  • a promotional gift of nominal value provided by the covered entity.

A website page, a video on YouTube, a Google Business Profile post, and an email newsletter are none of those things. There is also a money clause worth knowing: if the marketing involves financial remuneration to the covered entity from a third party, the authorization itself has to say so. That catches practices that feature a device or drug in a patient story while being paid by the manufacturer.

What a valid patient testimonial authorization must contain

Section 164.508(c)(1) lists the core elements and 164.508(c)(2) lists the required statements. Miss one and the authorization is defective, which under the Rule means it is not valid at all. Here is each requirement next to what it looks like on a testimonial release.

RequirementSourceWhat to actually write
Description of the information164.508(c)(1)Identify it specifically and meaningfully. "My first name, my photograph, my video recording, and my description of my knee replacement and recovery." Not "my information."
Who may make the use or disclosure164.508(c)(1)Your practice, by legal name.
Who may receive it164.508(c)(1)Be honest about reach: the practice website, social media accounts, and the general public who view them. A public post means an unlimited audience, so say that.
Purpose of each use or disclosure164.508(c)(1)"Marketing and advertising of the practice." Vague purposes are a common defect.
Expiration date or event164.508(c)(1)A date, or an event tied to the individual or the purpose. "Three years from signature" or "until I revoke it in writing" both work. "None" does not.
Signature and date164.508(c)(1)The patient's, or a personal representative with a description of their authority.
Right to revoke164.508(c)(2)State that the patient may revoke in writing, how to do it, and that the revocation does not undo what you already did in reliance on it.
No conditioning164.508(c)(2)State that treatment, payment, enrollment, and eligibility for benefits are not conditioned on signing. This one is not optional and it is not a formality.
Potential for redisclosure164.508(c)(2)Warn that once disclosed, the information may be redisclosed by the recipient and may no longer be protected by the Privacy Rule. On a public web page this is simply true.

Two more mechanical requirements: the authorization has to be in plain language, and you must give the patient a copy of what they signed.

The $182,000 lesson

On September 30, 2025, OCR announced a settlement with five facilities operating as Cadia Healthcare. The investigation began over a patient success story posted on a public website without a valid HIPAA authorization. That post included the patient's name, a photograph, and details of their condition, treatment, and recovery. OCR found the success story program had compromised the PHI of 150 patients in total. Cadia paid $182,000 and accepted a two-year corrective action plan that requires updated policies, workforce training that specifically includes marketing staff, and notification to every affected individual.

Two things stand out. First, the harm was not a hack or a stolen laptop, it was a marketing program running exactly as designed. Second, the corrective action plan names marketing staff, which tells you where OCR thinks the gap usually is. Nine years earlier, in 2016, OCR settled with a Los Angeles physical therapy provider for $25,000 over patient testimonials posted to its website without authorization, so this is a consistent enforcement position rather than a new one.

Revocation, and what happens to a published video

A patient can revoke an authorization in writing at any time. The revocation is not retroactive for actions you already took in reliance on it, which is why the Rule requires that exact caveat in the form. Practically, though, revocation means you take the testimonial down: off the website, out of the ad rotation, out of the next email. You cannot recall the copies that already circulated, and you should not pretend otherwise to the patient.

This is a workflow problem more than a legal one. If your authorizations live in a filing cabinet and the videos live with an agency, nobody can answer "which patients have current authorizations" on the day it matters. Keeping the signed authorization attached to the testimonial itself, captured at the same moment, is what makes takedown a one-click action instead of an archaeology project. Teams that collect testimonials through a request link can capture the consent language on the same screen as the recording, so the record and the content never separate. Larger organizations running several sites usually end up needing something that tracks each obligation against the control that satisfies it, because HIPAA is not the only regime touching the same marketing assets.

Does HIPAA apply to my practice at all?

Only covered entities and their business associates are bound by HIPAA. Covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction, which in practice means almost any provider that bills insurance.

That leaves a real gray zone. A cash-only med spa that never bills insurance, a personal trainer, a wellness coach, or a cosmetic practice that takes no third-party payment may well not be a covered entity, and HIPAA may not reach their testimonials at all. That is not permission to skip consent. Three other things still apply: state privacy and medical records laws, which in several states are stricter than HIPAA and are not limited to covered entities; basic rights of publicity, which govern using someone's face and name commercially; and the FTC, which treats a testimonial as a claim the advertiser is making directly. If your marketing shows a before-and-after or quotes an outcome, the FTC substantiation rules bite regardless of your HIPAA status, which is the same trap fitness businesses hit on gym testimonials. Our guide to the FTC rules on reviews and testimonials covers the advertising side, and if you are unsure whether you are a covered entity, that is a question for your own counsel rather than a blog post.

What you can still legally publish

The rules are strict but they are not a ban, and practices that read them carefully end up with better proof than the ones that avoid the topic:

  • Fully authorized patient stories, including video and full names, when the authorization covers what you actually publish.
  • De-identified content, though be careful: removing the name is not enough if the photograph, the rare condition, or the small town makes the person identifiable.
  • Reviews about non-clinical experience, such as scheduling, staff, parking, and billing, which carry far less PHI when they avoid naming a condition or procedure.
  • Testimonials from people who are not patients, such as referring physicians, employers, or partner organizations.
  • Responses to online reviews, as long as you never confirm the person is a patient or reference any clinical detail. This is the single most common HIPAA mistake in practice marketing: a defensive reply to a one-star review that describes the visit is a disclosure, and the fact that the patient posted first does not waive anything.

Frequently asked questions

Can you use patient testimonials on a website?

Yes, if you are a covered entity and you have a valid HIPAA authorization signed before you publish. The authorization must specifically describe the information, the audience, and the purpose, carry an expiration, and tell the patient they can revoke it and that treatment is not conditioned on signing. Publishing first and collecting paperwork later is the pattern OCR has repeatedly penalized.

Is a patient testimonial a HIPAA violation?

It is a violation when a covered entity publishes it without a valid authorization, because the post discloses that an identifiable person is your patient. It is not a violation when a proper authorization is in place, or when the patient posts about themselves on their own account. The obligation sits with the practice, never with the patient.

What is the difference between a consent form and a HIPAA authorization?

Consent, in HIPAA terms, is a general permission for treatment, payment, and health care operations, and it is optional for providers to obtain. An authorization is a specific, written permission for a use or disclosure that the Rule does not otherwise allow, and it is mandatory for marketing. A signed consent to treat, a notice of privacy practices acknowledgment, and a photo release from your general intake packet are none of them authorizations.

Does a photo release cover a patient testimonial?

Usually not, on its own. A standard photo or media release addresses image rights, but it rarely contains the elements 164.508 requires: the specific description of health information, the named recipients, the expiration, the revocation statement, the no-conditioning statement, and the redisclosure warning. You can combine them into one document, but the HIPAA elements have to be present.

How long does a HIPAA marketing authorization last?

As long as the expiration date or event you wrote into it, which the Rule requires you to specify. Many practices use a fixed term such as three years, or tie it to an event like "until I revoke this authorization in writing." An authorization with no expiration at all is defective, and once it expires you have to stop using the material and re-authorize to keep it up.

Can a patient ask you to take down a testimonial?

Yes. The patient can revoke the authorization in writing at any time, and once they do you must stop using the testimonial going forward. The revocation does not reverse uses you already made in reliance on the authorization, so copies already printed or already shared cannot be recalled, but the live page, the ad, and the video should come down promptly.

Bottom line

Patient testimonials are among the most persuasive assets a practice can own, and the compliance work is a form, not a prohibition. Write one authorization that carries all nine requirements, capture it at the same moment as the story rather than chasing it afterward, keep it attached to the recording, and honor revocations quickly. Practices that build this into the collection flow publish more patient proof than their competitors, not less, because they stop treating every testimonial as a legal risk to be avoided. If you want the practice-side workflow, our patient testimonials page covers collecting video with consent captured on the same screen, and the testimonial release form guide covers the wording for businesses outside HIPAA's reach.

This article is general information about the HIPAA Privacy Rule, not legal advice. Regulations change and state law varies. Confirm your own obligations with counsel before publishing patient content.

Collect proof without chasing

Send one link, your customers record a video or text testimonial in seconds with no login, and you embed a beautiful Wall of Love in minutes. Text and video, unlimited, at one flat price.