News|Articles|September 4, 2026

Patients trust fake physician reviews more than real ones, study finds

Fact checked by: Keith A. Reynolds
Listen
0:00 / 0:00

Key Takeaways

  • Deceptive reviews contained more symptoms, diagnoses, medications, and treatment narratives, exploiting readers’ preference for story-like clinical detail that authentic patients rarely share.
  • Verified impersonation involved providers and clinic staff leveraging a security flaw in appointment-invite workflows, yielding 8,313 fake reviews within 35,000 collected (India, 2015–2017).
SHOW MORE

Researchers verified thousands of fake reviews posted by providers and clinic staff and found them longer, more clinically detailed and better received than the real thing. HIPAA leaves physicians very little room to respond.

Fake physician reviews collected more helpful votes and scored higher on perceived trustworthiness than genuine patient reviews, according to a study of 5,000 online physician reviews published in Internet Research.

The fakes were longer, and they said more about symptoms, diagnoses, medications and treatment. Genuine reviewers rarely offer that much.

"Patients naturally want detailed information when they're choosing a health care provider. A real patient might simply say a doctor was helpful, while a fake review tells a detailed story about symptoms, diagnosis and treatment," said Aishwarya Deep Shukla, Ph.D., associate professor of management information systems at Simon Fraser University's Beedie School of Business and the study's lead author, in a news release.

"People are drawn to stories. Unfortunately, these deceptive reviews have the kind of information real patients don't usually share publicly and can influence decisions about who people trust with their care."

Where the fake reviews came from

The dataset holds 35,000 reviews collected in India between 2015 and 2017, spanning specialties from family medicine to dentistry and dermatology.

Researchers verified 8,313 of them as fake, posted by health care providers and clinic staff who exploited a security flaw in a platform that invited patients to review their appointments. Some of the posters impersonated patients. The paper counts a review as fake when it is written to deceive patients through impersonation.

Helpful votes were real user behavior recorded by the platform. The trustworthiness score was not. Shukla and co-authors Jie Mein Goh and Laksh Agarwal used large language models to generate it, citing marketing research finding that model responses can approximate actual survey respondents, and acknowledging in the paper that such models carry risks of bias and hallucination.

What it can and can't tell a U.S. physician

The data are Indian, roughly a decade old, and drawn from one platform. The paper's own limitations section says the results may not generalize beyond online physician reviews.

Shukla said the tactics have not gone away, and that generative artificial intelligence cuts in both directions. "When I look at reviews now, I see the same patterns of length and detail," he said in the release. "The double-edged sword of AI is that it's helping real people write more complete and useful reviews, but it's also helping bad actors produce detailed fake reviews at scale."

Patients are already acting on what they read

In a June survey of nearly 1,000 adults, 55% said they had walked away from at least one physician because of what they read online, up 15 percentage points from a year earlier, according to reputation management vendor rater8's 2026 Patient Choice Report. Three-quarters said they would not book with a physician rated below 4.0 stars.

"It isn't always a fair situation when someone can take to the internet for free on a fake account, behind the protection of anonymity, and in a matter of minutes post something online that then reverberates through this physician's and health care practice's entire operation, from the top to the bottom, from business to personnel to profit and losses," said Michael Pelagalli, J.D., a partner at Minc Law, a Cleveland firm that works exclusively on internet defamation and online reputation matters, in an interview with Medical Economics.

The first move is documentation, not a reply

"When a practice or a physician or a practice manager at a medical facility sees a false review or a problematic review, the first thing they need to do is document it, by way of screenshots, by way of a contemporaneous note or an email to someone else at the practice," Pelagalli said. Fake reviews come down as fast as they go up, either because the poster deletes them or the platform does, and what isn't preserved is gone.

A review left by someone who never appears in the practice's records is the cleanest case.

Pelagalli said practices that check their charts and then tell the platform the name matches no patient, no family member and no visit have had success getting those reviews removed, particularly when they report repeatedly, a couple times a week, and from more than one account at the office.

"The difficulty with that is it's completely up to the platform," he said. "There is no deadline or time constraint on the platform to take action if they see fit."

Where the reviewer was an actual patient, and some of what they wrote is true, Pelagalli said the call is to a lawyer before anything happens privately and well before anything happens publicly.

HIPAA leaves almost nothing to say publicly

Physicians can post a general reply inviting the reviewer to call the office. That is close to the whole menu.

"Unfortunately, the prohibitions set under HIPAA preclude physicians from meaningfully responding," Pelagalli said. A practice cannot name the reviewer, describe what it did or did not do, or confirm that the person was ever a patient, even after the reviewer has said so publicly under their own name.

The Office for Civil Rights collected $30,000 from a New Jersey psychiatric practice in 2023 after it answered four patients' negative Google reviews with information about their diagnoses and mental health treatment.

A North Carolina dental practice drew a $50,000 civil money penalty, announced in 2022, for naming a patient three times in a reply to a one-star Google review.

A Dallas dental practice paid $10,000 in 2019 after responding to a Yelp reviewer with her last name, treatment plan, insurance and cost information.

"This is different from clients of mine who run large restaurant chains, who have numerous Google Business Profile pages and are assaulted with different types of attacks all the time, who can publicly respond with screenshots of security footage showing exactly when a patron came and left," Pelagalli said.

An advocacy campaign called the RESPOND Act is pushing a narrow HIPAA amendment that would let a physician answer in proportion to what a patient has already disclosed publicly. No bill has been introduced, and the campaign's proposed amendment language, legislative brief and provider survey are all listed on its site as in preparation.

When the reviewer is a competitor

Pelagalli represented a family physician who woke up to dozens of fake reviews across several platforms. Subpoenas traced them to a family physician one county over.

"There really wasn't even any personal animus that our client could recall between them," he said. "I think it was just a really bad idea for trying to get new patients."

That changes the claims available. Unfair competition and tortious interference become viable, and a case in federal court can reach the Lanham Act or fake review statutes.

"It certainly opens the door to more arguments for actual malice and intentional misconduct," Pelagalli said.

It also runs into the Federal Trade Commission (FTC)'s rule on consumer reviews and testimonials, effective Oct. 21, 2024, which bans fake reviews and insider reviews written without disclosure, and lets the agency seek civil penalties against knowing violators. The 8,313 verified fakes in the SFU study were written by providers and their own clinic staff.

Shukla's proposed fixes sit with the platforms rather than with physicians: appointment-linked review systems, authenticated anonymous reviews, stronger moderation, and eventually verified systems run by health care organizations or public agencies that confirm a patient relationship without exposing the patient.

Until something closes the detail gap, the most persuasive review on a physician's profile may be the one nobody wrote.

What is inside a practice's control is the clock. "The sooner we are able to make contact with that patient relative to the review being published, the sooner we're able to make that touch point, have that human conversation on the phone," Pelagalli said, "the chances of success go way up."