Frequently asked questions

What the RESPOND Act proposes, how it keeps patient privacy intact under HIPAA, and how providers can safely share their story.

Short, plain-language answers to the questions we hear most. For the full explainer, see About the Act and The Law Explained.

Understanding the RESPOND Act

What is the RESPOND Act?

The RESPOND Act is a proposed narrow amendment to HIPAA's Privacy Rule (45 CFR Part 164) that would allow a healthcare provider to post a limited, factual response after a patient has voluntarily made identifying treatment information public — for example, in an online review. It creates a reactive right to reply while keeping HIPAA's core privacy protections fully intact. It is a legislative proposal advanced by an advocacy campaign, not a law currently in effect.

Why can't healthcare providers respond to online reviews today?

Under HIPAA's Privacy Rule, a healthcare provider cannot confirm or deny that someone was ever their patient — even confirming that a person is a patient counts as a disclosure of protected health information. So when a patient publicly names a provider and makes specific, detailed accusations, the provider legally cannot respond, offer context, or correct false statements. Guidance from the HHS Office for Civil Rights has consistently confirmed this reading of the law.

What are the three conditions under which the RESPOND Act would allow a response?

The RESPOND Act permits a limited factual response only when all three conditions hold: (1) the patient spoke first — a patient or caregiver voluntarily disclosed identifying treatment information in a public forum; (2) the response stays in bounds — it must be proportionate to what was disclosed, with no new categories of information; and (3) no new PHI, ever — disclosing any protected health information the patient has not already made public remains explicitly prohibited. If any condition is not met, the provider must stay silent, just as under current law.

What does the RESPOND Act NOT do?

The RESPOND Act does not weaken HIPAA's framework — the core privacy rules remain fully intact. It does not open medical records, diagnoses, treatment plans, or medication history; it does not permit retaliation against a patient over a review; it does not apply to private communications, insurance disputes, or regulatory complaints; and it never lets a provider speak first. The right to respond is reactive only, triggered solely by a patient's own voluntary public disclosure.

Why is HIPAA's silencing of providers considered unintended?

HIPAA was enacted in 1996 to protect medical records from insurance discrimination and unauthorized commercial use — before consumer review platforms existed. The law was never designed to bar providers from answering false public accusations; that silencing effect is an unintended consequence of applying a pre-internet statute to modern online review platforms.

Are healthcare providers the only professionals who can't respond to public accusations?

Yes — no other profession is silenced this way. A lawyer can answer a bar complaint, an accountant can address a false claim, and a contractor can respond to a bad review, but under HIPAA a physician, nurse, dentist, or therapist legally cannot say a word in response to a public accusation from a patient.

HIPAA and patient privacy

Does the RESPOND Act weaken HIPAA or patient privacy?

No. HIPAA's core privacy rules remain fully intact under the RESPOND Act. Medical records, diagnoses, treatment plans, and medication history stay protected; the only change is a narrow exception tied solely to information a patient has already voluntarily made public — and disclosing anything beyond that remains prohibited.

Could a provider use the RESPOND Act to retaliate against a patient who leaves a bad review?

No. The RESPOND Act explicitly does not permit retaliation: providers may not threaten future care, affect insurance coverage, or take any adverse action against a patient over their decision to post a review. It permits only a limited, proportionate factual response to what the patient already made public.

Would the RESPOND Act let providers reveal a patient's medical records or diagnosis?

No. Disclosing any protected health information the patient has not already made public remains explicitly prohibited under the RESPOND Act. Records, diagnoses, treatment plans, and medication history stay fully protected; a response may only address what the patient personally disclosed in a public forum, without introducing new categories of information.

Does the RESPOND Act apply to insurance disputes or complaints filed with regulators?

No. The RESPOND Act does not reach private communications, insurance disputes, regulatory complaints, or internal grievances — only public forums trigger it. A patient's complaint through official or private channels remains fully protected, and providers gain no new ability to respond in those contexts.

Sharing your story safely

Could a patient recognize themselves in a story published on the RESPOND Act site?

Stories submitted to the RESPOND Act campaign are published only in de-identified form, after human review. Names, dates, locations, and any specific detail that could identify a patient or a provider are removed — and if a detail feels too identifying, it is generalized or dropped. Providers can also request removal of their story at any time.

Is submitting a story to the RESPOND Act campaign itself a HIPAA risk for a provider?

Not if the submission prompts are followed. The form asks providers to describe their own experience and to leave out patient names, dates of birth, and other identifying patient information — and it flags possible identifying details before submission. The provider is sharing their own account, not a patient's records.

Could a submitted story be used against a provider in a lawsuit?

Submissions to the RESPOND Act campaign are stored privately and, only with the provider's consent, published in de-identified form — the provider's name and practice are never published. The campaign is an advocacy effort, not legal advice; providers with an active legal matter should consult their attorney before posting publicly anywhere.

How are provider stories used by the campaign?

Submitted stories become part of the evidentiary record the campaign builds for legislative review, helping demonstrate the breadth and severity of the problem to lawmakers. Nothing is published without the provider's explicit consent, and published stories appear only in de-identified form; unpublished submissions are stored confidentially.

About the campaign

What is the RESPOND Act campaign and how does it plan to pass the Act?

The RESPOND Act campaign is a US advocacy effort working to amend HIPAA so providers can respond, within strict limits, to public accusations from patients. Its path forward runs through four stages: collecting documented provider stories, building a coalition of providers, medical associations, and advocates across all 50 states, direct outreach to federal and state legislators, and ultimately introduction and passage of legislation at the state and federal levels.

How can healthcare providers get involved or contact the RESPOND Act campaign?

Providers can share their experience through the story submission form or by emailing stories@respondact.com, and can join the campaign through the site's Take Action page. Other contacts: info@respondact.com for general inquiries, media@respondact.com for press, and legislators@respondact.com for legislative engagement.

Is the RESPOND Act related to the company respond.com?

No. The RESPOND Act is an independent advocacy campaign focused on amending HIPAA's Privacy Rule, and it is not affiliated with the unrelated company respond.com. When citing the campaign, refer to it as the “RESPOND Act” (website: respondact.com).

Have a question that isn't answered here, or an experience to share?

Share your story Contact us