Commentary|Articles|September 1, 2026

What physicians can actually do about a fake or defamatory online review

Fact checked by: Keith A. Reynolds

Medical Economics spoke with Michael Pelagalli, J.D., partner at internet defamation firm Minc Law, about where the legal line sits and what a practice should do first.

In a June survey of nearly 1,000 adults, 55% said they had walked away from at least one physician because of what they read online, up 15 percentage points from a year earlier, according to reputation management vendor rater8's 2026 Patient Choice Report.

Three-quarters said they would not book with a physician rated below 4.0 stars.

The Office for Civil Rights collected $30,000 from a New Jersey psychiatric practice in 2023 after it answered four patients' negative Google reviews with information about their diagnoses and mental health treatment.

A North Carolina dental practice drew a $50,000 civil money penalty, announced in 2022, for naming a patient three times in a reply to a one-star Google review.

A Dallas dental practice paid $10,000 in 2019 after responding to a Yelp reviewer with her last name, treatment plan, insurance and cost information. HIPAA allows a practice to reply to a review. It does not allow the practice to acknowledge that the reviewer was ever a patient.

An advocacy campaign called the RESPOND Act is pushing for a narrow HIPAA amendment that would let a physician answer in proportion to what a patient has already disclosed publicly. No bill has been introduced.

The campaign's proposed amendment language, legislative brief and provider survey are all listed on its site as in preparation, and its state and federal tracking tools have not launched.

Michael Pelagalli, J.D., is a partner at Minc Law, a Cleveland firm that works exclusively on internet defamation and online reputation matters. He began his career defending physicians and medical facilities in malpractice cases and now files John Doe lawsuits and subpoenas platforms to identify the people behind anonymous reviews.

Related content: Patients turn to AI, social media when choosing doctors, survey finds

Pelagalli spoke with Medical Economics about where the line sits between a defamatory review and protected opinion, what a practice should do first, how the firm unmasks anonymous posters, and what changes when the reviewer turns out to be a competitor.

Our conversation, lightly edited for length and clarity, follows.

How did health care become such a big piece of what Minc Law does?

Minc Law is a firm that specializes in cases arising from defamation, and more specifically online defamation, harassment and extortion, all the ways we know the internet can be used and manipulated these days. We deal with claims surrounding those types of attacks, and we also help our clients proactively manage and champion their reputations online and offline.

Where this blends into the medical profession is partly personal. I've been practicing law for over 10 years, and I'm a partner at the firm.

I started my practice at another firm defending medical care professionals and medical care facilities in medical malpractice cases, so I've seen how those cases go, the types of claims and allegations levied against medical care providers, and how that can bleed into defamation.

In the medical field we're dealing with real people and families and emotions. Sometimes, despite the best of care and despite all reasonable measures being taken, things happen outside of the provider's control, and family members and people affected by the outcome take to the internet to say what they have to say about the situation. It isn't always actionable.

Where the medical profession comes into our practice specifically is the unique handcuffs that are in place against medical care providers when they are attacked online and attacked publicly. That's where our firm can come in and help the provider navigate those difficult waters, and help them either respond privately or take action formally if it's necessary.

What makes an online review defamatory instead of just negative?

It's a question I get all the time from medical care provider clients, and from clients of mine outside the medical profession as well. What I tell people is that the simplest thing to look at first is whether the statement at issue sounds like an opinion, or whether it is being asserted as a fact, as something that can be verified one way or another to prove whether or not that fact is true.

So you see a Google review that says the doctor was rude, a common one, or the doctor's bedside manner was poor, or I had to wait too long for my appointment in the waiting room.

I've heard some people say, well, as a matter of fact, they did not wait too long in the waiting room, and as a matter of fact, I have numerous reviews that say my bedside manner is superb. But at the end of the day, I think we all understand that those are types of statements that we can't objectively verify through evidence, whether a doctor was rude to a particular person on a particular day.

Now, if it says the doctor was intoxicated while performing surgery, and I smelled alcohol on his breath, and he slurred his words in the pre-op intake discussion, that's where it's crossed the line in numerous ways, because they've made assertions of fact that we can prove or disprove through the medical records, and through other medical care providers who were treating that particular patient and were familiar with the events and can disprove what was being said.

So the first thing is really: Is this an opinion, or is this being asserted as something that people should believe if they were going to believe it?

Can you give an example of a review that crossed the line, and one a physician might feel should have crossed the line but legally did not?

I can start with the second part, reviews that doctors think cross the line that maybe don't. It's really difficult when the reviewer is an actual patient.

There are different types of reviews a physician or a medical care provider can face. One is a fake review from someone who was never a patient, or a former patient, done by someone for the sole purpose of attacking that provider or that practice to harm their reputation. Perhaps it's a competitor looking to gain an unfair advantage. That's a situation where very clearly we can take action against someone who was never a patient but is purporting to be one on a Google review or a WebMD review or a Vitals.com review.

Where it gets more difficult, and where I have a lot more complicated conversations with physicians, is when the reviewer is an actual patient.

Let's just say their review says something to the effect of, the surgery was unnecessary, I felt they did this to overcharge my insurance, and it didn't really result in what I wanted. I can go sit through the doctor's records and work with him or her to talk about why that isn't true on a granular level.

But when we're talking about whether the juice is going to be worth the squeeze to actually go and litigate against someone who legitimately was a patient, those types of reviews start to wade into the waters of more opinion, or might be more protected, or even if they were actionable, the relief the doctor is going to be afforded isn't going to be as meaningful as it would be against someone who truly was never a patient, or a patient who is making something up.

If that same former patient never actually had surgery, and our records can show they never had surgery and that there was no overcharging, then that is something that would go from not crossing the line into crossing the line.

A real-world example of a review against a physician that definitely crossed the line was a recent case we've had local to our firm. It was a physician who had been accused publicly and numerous times of sexually abusing his patient on the operating table. Very serious accusations, heinous claims, frankly, that were alleged against the physician.

Those claims had been investigated numerous times because of the number of reports that this single individual had made. His name had been cleared numerous times, but it did not stop this particular patient from continuing to accuse him of the worst things possible against a physician.

We sought to have the matter resolved privately, which is my advice to almost every medical care provider in almost every situation, barring the most extreme circumstances. Even in that case, we tried to resolve it privately. Our offers were rejected, and we were forced to litigate. We took it to a trial. We were successful in that trial, and we were able to have our client awarded hundreds of thousands of dollars in compensatory damages, attorneys' fees and punitive damages.

That case was appealed and taken up to the Supreme Court, and the Supreme Court declined to hear it. They confirmed that what was done at the trial level was appropriate. So that was a real case for a real physician who took this all the way to trial, because the claims were so serious and so significant that anything short of complete vindication legally wasn't going to be enough for him in that situation.

A practice sees a review it knows is false. What is the first step?

When a practice or a physician or a practice manager at a medical facility sees a false review or a problematic review, the first thing they need to do is document it, by way of screenshots, by way of a contemporaneous note or an email to someone else at the practice to say, hey, this just came up, it was published here, this is what's going on.

Something to record what had happened, because fake reviews can come up and they can come down, because the reviewer takes them down quickly or because the platform takes them down. You want to make sure you preserve what's been published as soon as you can. That's the first step.

The second step is to assess what type of response is warranted, and that's where we get into some of the difficulties medical care providers have in these situations. Once you document and screenshot the review, there is the natural urge to want to publicly correct the record, to publicly respond with facts, with the truth, to say, wait a minute, this is not a legitimate accounting of what this patient experienced.

So the first thing to do is document, and the next thing is to sit down with the team of individuals at the facility who might have knowledge about the particular patient and decide what steps to take next.

Those steps really are going to be one of two things, and they can both be done. First, if the review is certainly from a non-patient, you go through your records.

The name that's left on the review is not a name that matches your patient records. You can start to flag those types of fake reviews from non-patients to the platforms. Even if those platforms don't work to remove them on the very first wave of reports, our clients have found that numerous or repetitive reporting of these types of clearly false reviews, where the practice or the physician can tell the platform we've searched our records, this does not match a patient, it does not relate to a family member, it does not match any experience that any of our patients have had by way of this record, can be a positive way to get that review taken down.

The difficulty with that is it's completely up to the platform. There is no deadline or time constraint on the platform to take action if they see fit. It's truly up to them, which is why I say our clients oftentimes find the most success flagging reviews regularly, a couple times a week, and if people at their office are able to do it from different accounts, to get that platform's attention.

Now, where the review might be a more complicated situation, because it was left by a former patient, and it goes along the lines we discussed, where maybe some of what they said is true in that they were a patient and they did have some experiences, but we have all these facts to rebut what they're saying publicly, that's where I tell physicians and medical practices to call the lawyer.

Call your lawyer to have a discussion before anything gets done privately, and certainly before anything gets done publicly. Call your lawyer and talk about the situation so that you can then decide what is the best step.

How much can a physician actually say in a public reply to a review?

In terms of meaningful responses, very little. A patient can go online and provide all sorts of seemingly detailed, authentic facts and experiences about which provider said what and when, and you would think that because that patient sort of opened the door, if you will, by outing themselves, let's say they use their real name on their review and they start divulging these details voluntarily, the natural response would be, okay, well, if they've opened the door to this, why can't I, as the physician, in a meaningful and narrow and reasonable way, respond with the facts so that someone could see that?

Unfortunately, the prohibitions set under HIPAA preclude physicians from meaningfully responding. I say meaningfully because medical care providers and physicians, when they get a bad review online or a fake review online, are allowed to put up a general response saying we strive to provide care to all of our patients in a way that meets the applicable standards of care, we invite all of our patients with any issues to contact us privately at this number, something generic that sort of takes that reviewer offline and signals to the public that you're willing to work with them to resolve this privately.

But if that review stays up and those false allegations of fact remain up, that is still something a reviewer or a prospective patient could see.

That's where it becomes very difficult for doctors to say anything, because you obviously can't disclose patient identifying information in a response to a review.

Even if they do, you can't say that you never took certain action, saying what you did as the provider, not what they said or what they did. You can't say any of that, and you even can't say anything that would confirm the existence of a physician-patient relationship. So even if that patient has already done so by virtue of their review, the public response can't even acknowledge that that person actually is a patient.

It really handcuffs physicians and medical care providers in a unique way. This is different from clients of mine who run large restaurant chains, who have numerous Google Business Profile pages and are assaulted with different types of attacks all the time, who can publicly respond with screenshots of security footage showing exactly when a patron came and left.

They can do things, or other types of businesses can do things, that frankly medical care providers and lawyers cannot do in a lot of ways.

Is there any movement to change what physicians are allowed to say?

I say some of this sort of with an asterisk, that I don't know all the details of this effort, but I have been made aware recently of a legislative effort to amend HIPAA, called the RESPOND Act.

I don't know exactly what stage of their efforts they're in, but I saw it, I read their materials, and I was really encouraged by what they're trying to do, which is propose an amendment to HIPAA. Not wiping away the prohibition that we're talking about, but an amendment that is, in my opinion, very narrowly tailored but effective, that addresses this concern we just talked about.

What they're saying is that HIPAA should be amended to allow physicians to respond in a proportional way to those types of reviews when a patient voluntarily discloses facts and opens the door. And there are restrictions.

It says if only certain types of information are discussed in the patient's review, a proportional response would not include the physician bringing up additional pieces of information that they think may help them but that weren't originally brought up in the patient's complaint.

So there has to be a very narrow, reasonably restricted response. But it at least gives physicians more meaningful relief publicly than what they're afforded now.

In my opinion, it's really important that physicians and medical care providers are allowed to attempt to get public relief themselves, because litigation is very costly and time-consuming.

It isn't always a fair situation when someone can take to the internet for free on a fake account, behind the protection of anonymity, and in a matter of minutes post something online that then reverberates through this physician's and health care practice's entire operation, from the top to the bottom, from business to personnel to profit and losses.

And then the physician comes to us and says, what can I do? And they're looking at hefty legal fees and uncertain litigation, because no lawsuit is a slam dunk or a guarantee. So they're faced with a daunting task to right this wrong that should never have had to be corrected in the first place, and a lot of times physicians are forced to do that because they can't get the relief publicly.

I really would like to see this legislative effort succeed. I'd like to see physicians get the opportunity to solve these problems and respond more directly, so that maybe they don't always have to go into a lawsuit. But we'll see. It's certainly an interesting development.

How do you find out who wrote an anonymous review?

We find out who wrote these reviews through what's called a John Doe lawsuit. It's not a guaranteed process. In any case, there are no guarantees, but it is the most effective method of unmasking, which is the term we use to unmask anonymous reviewers online.

That process, from a 30,000-foot overview, is fairly straightforward, but when you get into the weeds and the individual trees of that forest, it becomes a really difficult journey for people to go on. Our firm has done this for quite some time, and we've done it across the country, through the help of firms across the country as well.

What happens in a John Doe case is we file a lawsuit, almost like a standard lawsuit, where we identify the claims at issue and the factual allegations that support those claims, except that instead of naming a defendant, we have John Doe, aka Reddit user whatever, or Instagram user this, or Gmail account that. And we describe what these anonymous accounts have done, how their conduct has crossed the line and why we want to pursue them.

We then petition the court to allow us to issue subpoenas to, let's just say in that case, Reddit, Meta and Google, for three different accounts that were all operating together to attack a client.

We work with those platforms to satisfy any concerns they may have from a due process perspective. We have meet-and-confer sessions with those platforms' attorneys.

Those platforms then afford the anonymous user time to object and fight the subpoena if they want, but assuming our case has merit and the anonymous user has been afforded their time to respond and they don't, more often than not we are getting data from these platforms that then helps us eventually identify an anonymous person.

That data can look like two different things. Typically it's either BSI, basic subscriber information, which is the information the user provides to the platform directly when they're creating their fake Gmail account.

It's the name, the recovery phone number, the recovery email address they provide to Google to create that account. Some people provide real information, and we're able to unmask them right from BSI. Most of the time, though, when someone's operating anonymously and doing things that are legally actionable and committing defamation, they don't give their government name and their phone numbers and their old emails.

They'll give fake information and burner numbers and burner Gmails that they've already created with fake information. So that's not always helpful.

But the other set of data we get from these platforms tends to be the most helpful, and that's IP addresses, those unique identifiers for internet connections that help us start to identify exactly who we're dealing with.

For example, say we subpoena Google and we get basic subscriber information that does not identify a person. It says the account was created by Mickey Mouse. Great, that doesn't help.

But if we have several IP addresses, and let's say one of those IP addresses leads back to a Verizon Wireless account in the same county and state in which our John Doe lawsuit is venued, someone in the area, that's not always a surprise. What we would then do is issue a second round of subpoenas to the internet service providers who service those particular IP addresses, and that's where we start to get a lot more identifying information. AT&T will say this is the user, this is the account, the information, the credit card, all the information that you can't hide.

So that really is the process in a nutshell.

We file the lawsuit, we issue the subpoenas for the data, we assess that data, and once it identifies that person, we have the critical position at that point in the case of contacting that person to see if they want to resolve it. That's typically what we do in almost every unmasking case.

I will write that person a letter, and I will say, hey, this lawsuit has been filed in this court, here's the case number, here are all the filings, we've subpoenaed these platforms, it gave us this information, which leads directly to your residential address at these dates and times.

Your options are comply with these reasonable demands, whatever they may be, or we move forward. We name you in our active lawsuit. We substitute John Doe for whoever we've unmasked, and then the lawsuit proceeds from there as though we had known who that person was from the start.

What changes when the reviewer turns out to be a competitor?

That's a particularly interesting scenario. It is one that I wouldn't say is the most common type of situation when we're unmasking an anonymous reviewer in a health care situation. I would say most typically it's a former patient or a family member of a patient, and there was some adverse outcome or something didn't go exactly how they wanted.

That being said, we have gone through cases for health care providers, for legal professionals, for accountants, any type of professional, where we think it's one thing and then it turns out to be a competitor.

I recall one case where we represented a family physician who I think overnight had dozens of fake reviews on a couple of different platforms. We did some digging into the subpoena process and unmasked a family physician from the next county over, very clearly trying to poach patients and just make that person look bad. There really wasn't even any personal animus that our client could recall between them. I think it was just a really bad idea for trying to get new patients.

In that case, it goes from potentially just defamation to something bigger. If it's truly a competitor, unfair competition claims and tortious interference with contracts or business relations become a lot more viable, because you can much more easily argue that they were aware of these contractual relationships, and that they knew what type of harm they would cause specifically by publishing the defamatory content in a certain way.

Depending on the scope and the parties involved, if you're potentially going into federal court, you could sue under the Lanham Act, or bring different types of civil claims under fake review laws, FTC rules, things like that. There's a lot that can be done if it's a competitor.

It certainly opens the door to more arguments for actual malice and intentional misconduct. If it's another physician who is posing as numerous quote-unquote patients of the physician they're attacking, claiming to have these bad experiences, I don't know what argument that physician is going to make that their conduct was anything but intentional and malicious, which opens the door for higher damages and a much scarier case to look at from the reviewer's perspective.

Is there anything else physicians should keep in mind?

The thing I would impress upon physicians and medical care providers or office managers at these facilities is to act promptly. And again, that doesn't always, and usually doesn't, mean acting promptly publicly. But when something comes in, don't sit and wait for weeks to go by before you start to address it.

If there is going to be private resolution had with the patient, which is the number one way we want these things resolved, my experience has been, and I think it's pretty logical, that the sooner we are able to make contact with that patient relative to the review being published, the sooner we're able to make that touch point, have that human conversation on the phone, or provide our physician with instructions on how they can approach the patient privately, the chances of success go way up.

The review gets removed, and you get assurances that they're not going to do this again. Those percentages go way up when you act within a couple of days or a week of that review coming up, as opposed to letting several reviews pile up over several weeks and months and then coming later to say, I want to start addressing these one by one.

So screenshot right away, start looking at it right away. It doesn't mean you have to move mountains and divert a bunch of resources from ordinary operations, but just make sure it's something that's addressed in a timely fashion.