Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
Compliance and security

HIPAA and social media: What you can and can’t post

Avatar photo Lucy Galloway
Last Updated: September 22, 2026
Reviewed by: Avatar photo Lucy Galloway

HIPAA and social media meet at a single rule. A post becomes a violation the moment a patient can be identified from it. Identified does not mean named. A cropped photo, a review reply or a visible room number can all do it.

HIPAA names no platform, so what governs your feed is the Privacy Rule and its protection of protected health information, known as PHI. This guide covers the rules, the penalties OCR has issued and the Pre-Post PHI Check we run before a clinical post goes live.

Key takeaways
Found our content helpful?

Key takeaways

A post breaks HIPAA the moment a patient is identifiable from it, even if you never use a name.

Authorization has to be written, specific to social media and stored on the patient record, and a patient can withdraw it later.

OCR has penalized practices between $10,000 and $182,000 for putting patient information online.

Tattoos, jewelry, wall art, a reflection and the photo’s own metadata survive a crop and still identify the patient.

The Pre-Post PHI Check puts five gates between the person holding the phone and the publish button.

Is posting on social media a HIPAA violation?

Yes, if a patient can be identified from the post, directly or indirectly, and you do not hold their written authorization to share it.

That is the whole test, and the word doing the work is identifiable. A hospital employee posts about a difficult shift and names nobody. The post is still a disclosure if their bio names the employer and the case is unusual. So is a lip filler result cropped to the mouth, when the patient’s own comment sits underneath it.

Three questions decide whether a clinical post is safe to publish. Run them before the post goes live:

  • Can anyone be identified from the image, the caption, the tags or the comments?
  • Do you hold a signed authorization that names social media as the use?
  • Does the thread underneath confirm that a named person is a patient?

Privacy settings do not change the answer. A closed Facebook group, a story that expires in 24 hours and a profile set to friends-only are all disclosures to people outside the practice.

What HIPAA social media rules actually say

There is no social media chapter in the law. HIPAA stands for the Health Insurance Portability and Accountability Act, and it was enacted in 1996. The HIPAA social media rules a practice follows are the Privacy Rule applied to a feed.

Two parts of the Privacy Rule do almost all the work. The first is the ban on impermissible disclosure: PHI leaves the practice only for treatment, payment, health care operations, or with the patient’s written authorization. Marketing is none of the first three.

The second is the minimum necessary standard. Even where a disclosure is allowed, you share the least information that does the job.

Applied to your own posting guidelines, that means a case study carries the clinical detail and stops there. The patient’s age, town and treatment date add little to the post and plenty to the risk.

What counts as PHI in a social media post

PHI is any health information that can be tied to a person through one of the 18 identifiers HIPAA lists. Those run from a name or a date of service to a photograph.

The safe harbor method of de-identification lists all 18. The ones that turn up in posts look like this:

  • Names, including a first name in a reply or a tag.
  • Geographic detail smaller than a state, which includes a location tag on a story.
  • All dates tied to the patient: birth date, treatment date, admission or discharge.
  • Phone numbers, email addresses, and social handles used as contact details.
  • Medical record numbers, account numbers and health plan numbers, often visible on a screen in the background.
  • Full-face photographs and any comparable image, which covers most before-and-after work.
  • Any other unique identifying number, characteristic or code. A tattoo or a birthmark falls under that catch-all.

Safe harbor only holds if every identifier is gone and you have no reason to believe the person could still be recognized. On a public feed, the second half of that sentence is the hard part.

What the 2025 to 2026 HIPAA updates change for social media

No rule in force has changed what you may post. The Privacy Rule still governs what you publish, and the headline update of the past two years is still a proposal.

OCR issued a notice of proposed rulemaking on the HIPAA Security Rule on December 27, 2024. The notice appeared in the Federal Register on January 6, 2025, and the comment period closed on March 7, 2025. As of September 2026 no final rule has been issued, and HHS says the current Security Rule stays in effect while the rulemaking runs.

It still matters for your marketing. The proposal would drop the distinction between required and addressable safeguards, and it would require written policies that are reviewed and tested on a schedule. The phones your team shoots on and the tools that hold the photo library sit inside that scope.

Who is subject to HIPAA and social media rules

Covered entities and their business associates are bound: your practice, anyone on its workforce, and every outside company that handles patient data on your behalf.

A covered entity is a health care provider that bills electronically, a health plan or a clearinghouse. Most med spas, dental offices and independent practices are covered entities. If you are unsure which parts of the law reach yours, start with our guide to HIPAA compliance.

A business associate is any outside party you hand data to so it can work for you. That covers the marketing agency, the photo-editing freelancer and the scheduling tool. Each one needs a business associate agreement before it touches a patient record.

Employees are the part that confuses people. A receptionist’s personal Instagram account is not itself a covered entity. The practice is still answerable for what its workforce discloses, and the employee can face dismissal, license action and state privacy claims.

On personal use of social media and PHI, the answer is simple. No patient information may be posted from a personal account without written authorization. A pseudonym, a private setting and a deleted post do not cure the disclosure.

Platforms are not business associates. Meta, TikTok and Google sign no agreement with your practice and owe your patients no duty under HIPAA. Whatever you publish there, you published.

Examples of HIPAA violations on social media

Most examples of HIPAA violations on social media are review replies, patient photos, staff pictures with a screen in shot, and venting about a case.

Review replies are the most common, because they feel like a conversation rather than a disclosure. The moment you answer a reviewer with details of their visit, you have confirmed in public that they are a patient. That holds even when they posted under a nickname and told the story first.

The rest of the violations a practice runs into look like this:

  • A treatment photo posted without written authorization, or with authorization that only covered the patient record.
  • A team photo where a monitor, a whiteboard or a sticky note is readable behind the smiling faces.
  • A story that tags the practice location while a patient is recognizable in the frame.
  • A post about an unusual case, written with no name and every other detail intact.

The employer detail is what usually breaks the anonymity. A nurse at a Texas children’s hospital was fired after posting about a child with measles. She named nobody. Her profile named the hospital, and the hospital had one such case.

HIPAA violations on social media that reached enforcement

The cases below are HIPAA violations on social media and public websites that reached a published settlement or penalty, with the figure OCR collected.

CaseYearWhat was postedPenaltySource
Elite Dental Associates, Texas2019A reply to a patient’s online review naming her and describing her treatment and insurance$10,000HHS OCR
Dr. U. Phillip Igbinadolor, D.M.D. & Associates, North Carolina2021A reply on the practice’s Google page naming a reviewer who had used a pseudonym$50,000HHS OCR
New Vision Dental, California2022Yelp replies giving patients’ full names, visit details and insurance information$23,000HHS OCR
St. Joseph’s Medical Center, New York2023Three patients observed and photographed by a news reporter without authorization$80,000HHS OCR
Cadia Healthcare Facilities, Delaware2025Patient “success stories” with names and photos published on the website, 150 patients in total$182,000HHS OCR

Every figure above comes from the OCR resolution agreements and penalties published by HHS. Three of the five are dental practices answering reviews, which tells you where the everyday risk sits.

What a HIPAA breach on social media costs

A single post can carry a penalty of $145 to $73,011, rising to $2,190,294 a year where a practice knew and did nothing.

Penalties run in four tiers set by what the practice knew. The amounts are adjusted for inflation each year and published at 45 CFR 102.3. The table below carries the current figures.

TierWhat it meansPer-violation rangeCalendar-year cap
1. Did not knowThe practice could not reasonably have known about the violation$145 to $73,011$2,190,294
2. Reasonable causeThere was a reason for it, but not willful neglect$1,461 to $73,011$2,190,294
3. Willful neglect, correctedWillful neglect, put right within 30 days of discovery$14,602 to $73,011$2,190,294
4. Willful neglect, not correctedWillful neglect left uncorrected after 30 days$73,011 to $2,190,294$2,190,294

Treat the table as the ceiling rather than the likely bill. OCR said in 2019 that it would apply lower annual limits to the first three tiers while it considers a rule change. The five social media cases above all settled between $10,000 and $182,000.

The money is rarely the worst part. A clinician can lose their license or their job over one post. The practice ends up in OCR’s published enforcement record, and the corrective action plan that follows runs for years. Patients read all of it.

Staff posts are also not the only exposure. An investigation in 2022 found the Meta Pixel running on the websites of 33 of the 100 largest US hospitals. At seven of them it was sending patient information to Facebook, and Meta was sued over it. Marketing code on your own site can disclose as surely as a photo can.

HIPAA photography policy: What happens when a treatment photo goes public

A cropped treatment photo still identifies the patient through tattoos, jewelry, the room behind them, and the metadata inside the file itself.

A HIPAA photography policy earns its keep here, and it matters most in aesthetics. For a med spa, the highest-risk post type is also the best marketing asset the practice owns. Treatment photos on Facebook trip up more injectors than any other scenario we see. Cropping feels like de-identification, but it leaves the patient recognizable.

Here is what survives a crop:

  • Tattoos, scars, moles and birthmarks, which are unique identifying characteristics in HIPAA’s own wording.
  • Jewelry, a watch, a wedding ring, nail polish and a distinctive manicure.
  • Clothing, a lanyard, a uniform from the patient’s own job.
  • The treatment room behind them: wall art, a chair, a window view, a room number.
  • A name badge, a monitor or a printed schedule caught in the frame.
  • A reflection in a mirror, a window or a glass cabinet door.
  • The EXIF data the camera writes: the geotag, the exact timestamp and the device.
  • The location tag, the practice hashtag and a caption that dates the appointment.
  • The patient’s own reply in the comments, which names them for you.

Jessica Ellis-Wilson, FACMPE, a former HIPAA Privacy Officer and compliance consultant, sees the same slip in practice after practice. “It’s easy to snap a couple pictures of smiling staff, and forget to zoom in on every area of the picture,” she says.

Authorization is the other half of this section, and it is not permanent. A patient can withdraw it in writing at any time, and the practice has to stop the use from that point on.

What no practice can do is unshare a post. By then the image may have been screenshotted, reposted and indexed by search engines. The decision to publish deserves more care than the decision to take the photo.

HIPAA do’s and don’ts for social media

The HIPAA do’s and don’ts below cover the situations a practice team meets weekly. Each one is a decision someone makes on a phone, usually in under a minute.

Do think about your personal accounts

Following a patient is not a HIPAA violation on its own. Confirming that someone is a patient is, and a public reply, a tag or a comment can do exactly that.

The same goes for direct messages. A patient may message you about their treatment whenever they like, because the rule binds the practice and not them.

Your reply is a disclosure, so it stays clinical, stays inside a channel the practice controls, and gets recorded against the patient file. Steer questions about their care to a phone call or the patient portal.

Don’t discuss patients online, even anonymously

Closed professional groups feel safe and are not. A post describing an unusual presentation, a difficult consultation or a complication is a disclosure the moment anyone can work out who it was. Small specialties and small towns make that far easier than the person posting expects.

Do get written authorization first

Written authorization has to name social media as the use before a patient photo goes anywhere near a feed. Verbal agreement in the treatment room does not count.

Check the wording you already hold. A consent to photograph for the medical record is not a consent to publish. A form signed three years ago for a website gallery does not cover a new platform. Store the signed authorization with the images it covers, so the person scheduling the post can see it.

Don’t reply to comments about a patient’s care

A reply that engages with someone’s treatment confirms they were treated, which is a disclosure on its own. Thanking a patient by name under their comment confirms it just as plainly.

Agree one line the team can use every time, such as “thank you for getting in touch, please call the practice so we can help”. The reply helps without confirming that anyone was treated.

Do answer reviews without confirming anyone is a patient

You can answer a negative review, as long as the reply says nothing about the reviewer’s care, their visit or their insurance. Neither the practice’s version of events nor a correction is worth the penalty.

A safe reply states the practice’s standards, invites the person to make contact offline, and stops. Three of the five enforcement cases in the table above began with a reply that went further than that.

The Pre-Post PHI Check

The Pre-Post PHI Check is five gates the person holding the phone answers before any clinical post goes live. A no at any gate stops the post.

The check is written for a front-desk coordinator or an injector shooting between patients, not for a compliance officer with an afternoon free. The whole run takes about a minute once the team knows it.

Five-gate flow of the Pre-Post PHI Check: 1 is a patient in this, 2 do we hold written authorization, 3 what survives the crop, 4 what do the file and caption carry, 5 who approved it and where is that logged
The Pre-Post PHI Check runs top to bottom, and a no at any gate stops the post. The identifier list follows HIPAA safe harbor at 45 CFR 164.514.
  1. Is a patient in this at all? A photo, a case detail, a date, a reply or a tagged story all count. If no patient appears anywhere in the post, publish and skip the rest.
  2. Do we hold written authorization? It has to be signed, name social media as the use, sit on the patient record, and still be in force.
  3. What survives the crop? Open the image at full size and sweep the identifier list above, corner by corner. Tattoos, jewelry, wall art, a badge, a screen and a reflection are the usual finds.
  4. What do the file and the caption carry? Strip the EXIF data, drop the location tag, and cut any caption detail that dates the visit.
  5. Who approved it, and where is that logged? One named approver signs off, and the authorization and approved file are stored together where an auditor can read them.

In practices we onboard, gate 3 catches the most. The find is almost always a reflection in a treatment-room mirror, or a name badge nobody had zoomed in on.

How to write a HIPAA social media policy

A HIPAA social media policy is five decisions written down: who posts, who approves, what gets checked, how staff are trained, and what you keep. Most healthcare social media policies fail on the last two.

1. Name one owner and one approver

Shared logins and a group chat full of ideas are how an unchecked post gets published at 9pm. Put one person in charge of the accounts, usually the practice manager, and name a second person who approves any clinical post. Two names, written down, with cover arranged for holidays.

2. Write the policy down before you need it

A policy that lives in the owner’s head proves nothing to an investigator. Write down the channels you use, the approval route, the Pre-Post PHI Check, and worked examples of posts that were changed or pulled. A social media policy healthcare teams actually follow is short, specific and full of examples from their own feed.

3. Train everyone who can post, not just marketing

The people who run your accounts are often the ones who never sat through privacy training. Interns, a freelance social manager and an outside agency all need it before they get access.

“The biggest mistake I see is that organizations do not conduct appropriate privacy law training for the people responsible for social media engagement,” says Ellis-Wilson. “It’s easy to cross the line into impermissible activities.”

Run it at induction and refresh it annually, and keep the attendance record. Our guide to HIPAA training for employees covers what the sessions need to include.

4. Add new platforms and formats as they appear

A policy written for Facebook says nothing useful about a live stream from the treatment room. Review it whenever the practice adopts a new channel or format, and name the formats you have decided against.

Monitoring belongs here too. Once a month, search your practice name, your branded hashtag and your location tag, then open the photos patients have tagged you in. Look for patient posts that a reply from you would confirm, and for old posts of your own that no longer hold authorization.

5. Keep records you could hand to an auditor

You prove HIPAA social media compliance with documents. Keep the signed authorizations, the approval trail for each clinical post, the training log, and an export of what you published.

Practices that maintain HIPAA compliance well keep their records in one place rather than across a drive, an inbox and a phone. Keeping the policy, the training record and the consent trail in compliance management software makes an audit request a search rather than a hunt.

What to do in the first 72 hours after a post goes wrong

Take the post down, keep a copy, and use the first 72 hours to decide whether the disclosure meets the breach notification threshold.

HIPAA gives you 60 days to notify. The 72-hour window is ours, because the evidence you need gets harder to collect with every hour the post stays up or comes down untracked.

  1. Hours 0 to 1: capture, then remove. Screenshot the post, the comments and the engagement figures first. Save the URL and the timestamps, then take it down.
  2. Hours 1 to 4: log the disclosure. Write down which patients were identifiable, what was disclosed about each, how long it was live and roughly how many people saw it.
  3. Hours 4 to 24: assess the risk. A breach of unsecured PHI is presumed unless you can show a low probability of compromise. Work through the four factors: what was disclosed, who received it, whether it was actually viewed, and how far you have mitigated it.
  4. Hours 24 to 72: decide on notification. Affected patients get notice within 60 days of discovery. A breach touching 500 or more people in one state also goes to HHS and the media inside that window. Smaller ones go on the annual log filed within 60 days of year end.
  5. Day 3 onwards: close the loop. File the assessment, retrain whoever posted, and change the approval step that let it through.

Our guide on what to do if you violate HIPAA goes further into how an OCR investigation runs.

Withdrawn authorization follows the same sequence, with one difference. No rule was broken, and the patient is entitled to change their mind. Take the post down the day the written withdrawal arrives.

Then ask any account that reposted it to remove their copy, and request removal of the cached version from search. Note the date the authorization ended on the patient record. Tell the patient what you did, because they will check.

Most of the risk in this article starts in the same place: clinical photos on a personal phone, and consent on paper in a drawer. Marketing asks for “a good before-and-after”, someone scrolls their camera roll, and nobody can say what the patient signed.

Practice management software like Pabau closes that route by keeping the photo and the authorization in one record. Photos are captured against the patient file rather than the phone’s gallery. Digital consent forms are signed before the appointment and stored on the client card, and permissions decide who can export them.

The result is a shorter Pre-Post PHI Check. Gate 2 becomes a look at the patient record instead of a question nobody can answer. Gate 5 is already done, because the system logged who opened the image and when. If a patient withdraws authorization, the record shows every image it covers.

Before-and-after treatment photos stored against a patient record in Pabau
Pabau’s before-and-after photos sit on the patient record next to the signed consent, so nobody has to post from a camera roll to find them.

Keep consent, photos and patient records in one place

Pabau stores treatment photos against the patient record with the signed consent beside them, and logs who opened or exported each one. Your team can check authorization before a post goes live instead of guessing.

Pabau clinic management dashboard

Conclusion

Read the enforcement record and a pattern stands out. Almost none of it is malice. It is a reply typed in irritation, a photo posted in a hurry, a staff picture with a monitor in shot.

A longer policy will not change that. What works is a gate between the person holding the phone and the publish button. The Pre-Post PHI Check is that gate. Train it once, put the authorization where the poster can see it, and the decision stops depending on who is on shift.

The trade-off worth remembering is that speed is what makes social media work for a practice, and speed is what breaks HIPAA. Five questions is the smallest step that buys back the difference. Book a demo to see how Pabau keeps consent, photos and patient records together so your marketing never works from a camera roll.

Continue your research

Continue your research

Need the policy document itself? HIPAA privacy policy template gives you a structure to adapt rather than a blank page.

Not sure your authorization form covers marketing? Authorization to use and disclose health information shows what a valid authorization has to state.

Training the people who post? HIPAA training for employees sets out what each session should cover and how often to run it.

Planning for the bad day? Crisis management plan template covers who speaks, who decides and what gets said when a story goes public.

Checking your records hold up? Medical chart audit walks through auditing patient documentation before someone else does it for you.

Frequently asked questions

What types of patient information count as protected health information on social media?

PHI is any health detail that can be traced back to one person. On a feed that covers names, treatment dates, photographs, location tags, and any comment that identifies the patient. A post that carries none of those is still a disclosure if the practice confirms the person was treated.

What is one reason that social media increases the risk for HIPAA violations?

Posts are published in seconds by one person with nobody reviewing them, so a disclosure goes out before anyone catches it. The casual tone compounds it. Staff write about their day without thinking of the post as a permanent record.

Does HIPAA mention social media, and what happens if a practice gets it wrong?

HIPAA names no platform, because it was enacted in 1996, but its privacy protections cover what a practice publishes. Penalties start at $145 per violation and reach $2,190,294 in a calendar year. Confirmed breaches affecting 500 or more people are also listed publicly by HHS.

What should I do if my practice has violated HIPAA on social media?

Screenshot the post and its comments for evidence, then take it down. Log which patients were identifiable and what was disclosed about each. Assess it against the breach notification threshold, notify anyone affected within 60 days of discovery, and file the assessment with your records.

Is Facebook HIPAA compliant?

No platform is, because compliance sits with your practice rather than with Meta. Facebook signs no business associate agreement with a provider, so a post there is the practice’s own disclosure to account for. Page settings and audience controls do not change that.

Is Facebook Messenger HIPAA compliant?

Messenger is not a secure channel for patient information. A patient is free to message you about their own care, because HIPAA binds the practice rather than the patient. Your reply is the disclosure, so move the clinical discussion to a phone call or the patient portal.

Photos or videos can also be PHI: True or false?

True. A full-face photograph is one of the 18 identifiers HIPAA lists, and video is treated the same way. A cropped image still counts when a tattoo, a treatment room or a reflection gives the patient away. Most Facebook photos that breach HIPAA fail on exactly that point.

Which of the following is correct regarding personal use of social media and PHI?

The correct statement is that PHI may never be posted from a personal account without the patient’s written authorization. Answers that rely on privacy settings, a pseudonym or deleting the post afterwards are wrong. The same people are subject to HIPAA and social media rules whichever account they use.

Is it a HIPAA violation to follow a patient on social media?

Following someone is not a violation by itself. The problem starts when an interaction confirms that the person is a patient. A public reply, a tag, a comment on their post or a thank-you by name all do that, so keep the contact one-way.

Found our content helpful?
×