Can home care agencies ask clients for Google reviews?
The HIPAA question, answered.
Many home care agency owners have been warned off asking for reviews because someone, at some point, said it might violate HIPAA. So they do nothing, watch competitors accumulate reviews, and lose ranking ground month after month, all based on a concern that may not even apply to their agency type.
Here is what HIPAA actually says, which agency types it actually covers, and how to run a review program that is fully compliant.
This article is for informational purposes only and does not constitute legal advice. HIPAA compliance depends on the specific facts of your agency's operations, services, and billing arrangements. Consult a healthcare attorney for guidance specific to your agency before changing your review practices.
Table of Contents
The short answer
For most non-medical home care agencies providing companion care, personal care, or respite care on a private-pay basis, HIPAA does not prohibit asking for Google reviews. Most of these agencies are not "covered entities" under HIPAA and are not subject to its restrictions on Protected Health Information.
For home health agencies that provide skilled nursing, physical therapy, or other clinical services and bill Medicare or Medicaid, the situation is different. These agencies are covered entities. The rules are more specific, though asking for reviews is still not inherently prohibited. The risk is in how you respond, not in the ask itself.
The full answer depends entirely on your agency type. Keep reading.
What HIPAA actually covers (and what it does not)
HIPAA, the Health Insurance Portability and Accountability Act, applies to three categories of "covered entities": healthcare providers who transmit health information electronically (primarily those billing insurance), health plans, and healthcare clearinghouses. It also applies to "business associates," meaning vendors who handle Protected Health Information on behalf of covered entities.
The critical phrase is "transmit health information electronically." This typically means submitting claims to Medicare, Medicaid, or private insurance. An agency that invoices families directly for companion care and never files an insurance claim is almost certainly not transmitting electronic health information under HIPAA's definition.
HIPAA was not written to govern all businesses that interact with people who have health conditions. It was written to protect the flow of identifiable health information through the healthcare billing and treatment system. A non-medical home care agency that helps a senior with bathing, meals, and companionship, charges the family directly each month, and keeps simple care notes, likely falls entirely outside HIPAA's scope.
This distinction is one that many agency owners, and frankly many people who give advice to agency owners, get wrong. Repeat: HIPAA does not automatically apply to every business that works with older adults or people with health conditions. It applies to covered entities as specifically defined by the law.
Is your agency a covered entity?
Use this as a rough framework. Again, get a healthcare attorney to confirm your specific situation.
| Agency Type | Likely Covered Entity? | Notes |
|---|---|---|
| Non-medical home care (companion care, personal care, housekeeping), private pay only | Typically No | No electronic health information transmission. HIPAA restrictions likely do not apply. |
| Non-medical home care that bills Medicare or Medicaid for any services | Possibly Yes | Electronic claims submission may trigger covered entity status. Consult an attorney. |
| Home health agency (skilled nursing, PT, OT, speech therapy) billing Medicare/Medicaid | Almost Certainly Yes | HIPAA applies. See sections below for what this means for review practices. |
| Dual-service agency (personal care + skilled services under same entity) | Likely Yes | The skilled services component almost certainly triggers covered entity status for the whole organization. |
What HIPAA actually prohibits regarding reviews
If your agency is a covered entity, HIPAA's Privacy Rule prohibits you from disclosing "Protected Health Information" (PHI) without patient authorization. PHI is information that identifies a specific individual and connects them to health information. Combinations like name plus diagnosis, name plus treatment received, or name plus dates of care all constitute PHI.
Here is the key point: asking a client "Would you leave us a Google review?" does not disclose their PHI. You are not sharing their information with anyone. You are simply making a request. The act of asking is not a disclosure.
The HIPAA concern with reviews lives almost entirely on the response side. If a client leaves a review and you respond in a way that confirms they are your client or reveals anything about their care, that response can constitute an unauthorized disclosure of PHI. That is where agencies get into trouble, not in the original ask.
Sending a review request does not disclose PHI. Responding to a review in a way that confirms a care relationship or reveals health details does. Focus your compliance attention on response protocols, not on whether to ask.
What you can do (for covered entities)
If your agency is a covered entity, here is what is and is not permissible regarding review solicitation:
You can ask verbally. A coordinator saying "If you've been happy with our care, we'd really appreciate a Google review" during a call or visit is not a HIPAA violation. No PHI is being disclosed.
You can send a generic text or email with a review link. A message that says "Hi Sarah, we'd appreciate your feedback on Google" with a link is compliant, as long as the message does not reference their care, diagnosis, health status, or any specific services they received. Generic is key.
You can hand out review request cards. A physical card with your Google review link and a simple "We'd love your feedback" message carries no PHI and is fully compliant.
What you cannot do: respond to a review in a way that confirms the person is your client or reveals anything about the care they received. More on that below.
How to respond to Google reviews compliantly (for covered entities)
This is where compliance gets specific and where mistakes happen. When you respond to a Google review publicly, your response is visible to everyone. Any information you include in that response is a public disclosure.
The HIPAA-compliant approach is to never confirm or deny that the reviewer is or was your client. Even a response as simple as "Thank you for being our client, Mrs. Johnson" confirms a care relationship and constitutes a PHI disclosure without written authorization.
Instead, use generic, non-confirming language that acknowledges the feedback without confirming the relationship:
"Thank you for taking the time to share your experience. We take all feedback seriously and are committed to providing compassionate, high-quality care. Please feel free to contact us directly at [phone number] to discuss further."
And here is the response you must never write:
"Thank you, Linda! We are so glad your mother's recovery from her hip surgery went smoothly with our team. Maria loved working with her every Tuesday and Thursday." Every word after "Thank you, Linda" is a potential HIPAA violation. You have confirmed a care relationship, referenced a medical condition, and disclosed a care schedule.
The safe response formula is simple: thank the reviewer generically, express your general commitment to quality, and direct further conversation to a private channel. Keep it to two or three sentences. Say nothing that confirms, implies, or reveals a care relationship.
The Google review platform itself
Google is not a HIPAA-compliant platform and has no BAA with home care agencies. This raises a question some owners have: is the act of sending a review request via email or text, then having the client post on Google, itself a HIPAA issue?
The answer is no, for a practical reason: a client choosing to post a public review on Google is their own voluntary disclosure. They are sharing their own information in a public forum of their choosing. You did not disclose it. You did not facilitate a disclosure to a third party that had obligations to protect PHI. They made a choice as an individual to share their experience publicly.
Your HIPAA obligation does not extend to controlling what clients choose to say about their own experiences in public. Your obligation is to not disclose their PHI yourself, and to not confirm or add to what they disclose in your public responses.
Building a compliant review program
For non-medical private-pay agencies, the practical answer is: build your review program the same way any local business would. A systematic, respectful ask at the right time in the client relationship. A direct Google review link. One follow-up if no response. A personal thank-you when a review appears. Your HIPAA exposure is minimal to none.
For home health agencies and any covered entity, the practical answer is: build the same program, but apply these additional guardrails.
The bottom line is this: the HIPAA concern around Google reviews is real but narrow, and for most home care agencies it does not apply at all. Do not let a vague, unexamined worry about compliance prevent your agency from building the review volume that directly drives your Google Map Pack ranking and your inquiry volume. Understand the rules that actually apply to your agency type, apply them correctly, and build your review program with confidence.
For more on building review volume systematically, see our guide on how to get more Google reviews for your home care agency. For the broader picture of how reviews feed into your local search ranking, read our home care local SEO guide.
Frequently asked questions
Quick answers on HIPAA, reviews, and what applies to your agency type.