
Online Reputation for Doctors and Practices: Review Management Under Medical Confidentiality
§ 203 StGB (medical confidentiality), GDPR Art. 9 and the Code of Conduct of the Regional Medical Association make review management in healthcare more complex than in any other sector – and precisely for that reason, more valuable. According to the Bertelsmann Foundation, around 70% of patients research online before visiting a doctor. Anyone who ignores reviews or responds incorrectly loses patients – or risks a complaint to the Medical Association. This article explains what practice owners need to know.
Monday morning, just after eight. A general practice in Frankfurt-Bornheim opens – and the practice manager finds a new 1-star review on Google. The text describes an alleged case of mistreatment, mentions symptoms and refers to a specific medication. The patient is not named. Yet it is clear: anyone who reads the review and knows the person can identify them.
What now? Respond and correct the record? Prohibited – any substantive reply would implicitly confirm that the person was a patient. Stay silent? That costs stars and trust. Report the review? Potentially the only sensible option.
This is precisely where the real problem begins.
The 3 special rules that set healthcare apart from every other sector
A restaurateur who responds to a bad review risks, at worst, a PR misstep. A doctor risks criminal proceedings.
First: § 203 StGB – medical confidentiality. It applies absolutely. You may not confirm that a specific person was ever a patient at your practice. Not publicly, not in a response on Google, not indirectly through the context of your reply. Any statement such as "We treated you very carefully at the time" is a potential breach – because it implies a treatment relationship.
Second: the Code of Conduct of your Regional Medical Association. Most chambers have explicit rules on factual information and the prohibition on advertising. Superlatives in responses ("We are Frankfurt's best practice") can be problematic under professional regulations. Even an emotional defence against a false claim can be treated as impermissible public communication – depending on the chamber.
Third: GDPR Art. 9 – special categories of personal data. Health data enjoys the highest level of protection under European data protection law. If a review contains health information – even without a name – and you respond to its content, you are processing that data publicly. This is generally impermissible.
What many people overlook: these three rules do not apply sequentially – they apply simultaneously. A single substantive response can simultaneously breach medical confidentiality, the Code of Conduct and GDPR Art. 9.
Responding under medical confidentiality – what is permitted, what is not
Plain talk: the vast majority of response templates from general review management are unusable for medical practices.
Prohibited:
- "As I recall, your treatment on [date] was …" – confirms the treatment relationship
- "Ms X, we explained everything to you in detail at the time …" – naming plus description of the facts
- "In your case we adhered to all standards" – implies knowledge of the specific case
Permitted:
- "Thank you for your feedback. We take all responses seriously. Please feel free to contact us directly on [telephone number] for a personal conversation."
- "Our practice places the utmost importance on careful and empathetic treatment. Please get in touch with us directly so we can address your concern."
- General statements about the practice philosophy, with no personal reference whatsoever
Concretely: a response to a medical review should be a maximum of three sentences long. No details. No contradiction of the content. Always include an invitation to speak directly.
The Sternehero reply generator and the AI-assisted reply function are configurable for precisely these requirements – GDPR-compliant templates that do not imply a treatment relationship. For practices coordinating multiple locations or multiple doctors, this alone saves several hours per week.
What patients criticise – and what is reportable
Not every negative review constitutes a legal violation. This is important to understand before you invest resources in a report.
Not a violation – subjective expressions of opinion:
- "The waiting time was unbearable" – a permissible expression of opinion
- "The doctor was unfriendly" – subjective perception, protected
- "The treatment didn't help" – outcome assessment, protected as opinion
Potential violation – worth examining:
- False statements of fact: "The practice is not sterile" or "The staff misfiled my records" – if demonstrably false, the platform's policy against misleading content applies
- GDPR breach: Reviews that mention or make other patients identifiable – GDPR Art. 9, simultaneously a platform policy violation
- Conflict of interest / fake: "Was never a patient" or reviews that clearly originate from competitors
- Insults and hate speech: personal attacks on practice staff that go beyond criticism
What few people realise: GDPR violations in reviews are particularly common at medical practices. Patients inadvertently mention other patients – "While I was waiting with my mother, I heard the lady next to me say …" – and suddenly third-party health information is publicly visible online.
The Sternehero review analysis assistant helps you identify such violations systematically, before you invest time in manual review.
Jameda, Google, Sanego – the platform reality in 2026
Jameda remains the most widely used medical review platform in Germany – with an estimated 11 million reviews and its own reporting procedure that requires extensive documentation. Sanego is smaller, but disproportionately active in certain specialities (dermatology, psychiatry). Google Business Profile is the platform with the greatest influence on the Local Pack – and therefore on the actual discoverability of the practice in search results.
Sternehero currently covers the Google channel. For questions about platform expansion and the product roadmap, the FAQ is worth a look. For Jameda reports: the platform's own procedure is known for long processing times and high documentation requirements – often four to eight weeks until a decision is reached.
The mandatory GDPR workflow for medical reviews
Every practice that uses an external tool to process reviews needs a data processing agreement (DPA) under GDPR Art. 28. Full stop. No DPA, no tool – it is that straightforward from a compliance perspective.
Concretely, this means for your workflow:
- Sign a DPA with every provider that processes review texts (even if only read, not stored)
- Records of processing activities (GDPR Art. 30): add the entry "review management"
- Data minimisation: do not store complete review texts with patient references for longer than necessary
- Technical and organisational measures (TOMs): access to review dashboards restricted to authorised staff only
Sternehero provides the DPA on request. The infrastructure runs on German servers; data does not leave the DACH region – for practices handling health data, this is not a nice-to-have, it is a basic requirement.
Act now: GDPR-compliant review management for your practice. → View pricing & credits
Acquiring reviews in practice – what is permitted, what creates legal risk
Getting more positive reviews is the legitimate goal of every practice. But the path there is narrower for healthcare professionals than for other sectors.
QR code at reception: Legally unproblematic. The patient decides for themselves whether to scan. No pressure, no consent required. Works well – a dentist in Cologne-Ehrenfeld doubled their review count from 31 to 58 reviews in four months using this approach.
Active request directly after treatment: Sensitive. Not categorically prohibited, but the context must be right. No pressure, no implicit "it would be nice for the practice" framing. The Medical Associations view this critically when it appears systematic.
Incentives for reviews: Prohibited. No discount, no small gift, no prize draw. This violates the Code of Conduct and § 5 of the German Act Against Unfair Competition (UWG) (unfair advertising). Anyone who does this risks a cease-and-desist notice – not from the chamber, but from competitors.
Review reminders by email: Only with GDPR-compliant consent. This must be documented, revocable at any time and must not be linked to the treatment.
Multi-practice reality: MVZ, practice networks, clinic chains
In a medical care centre (MVZ), legal responsibility for maintaining reviews rests with the practice owner – not the MVZ operator. That may sound like a minor detail. It is not. Anyone operating 8 locations under one MVZ umbrella needs a scalable workflow that documents and attributes reports and responses location by location.
Sternehero addresses this via the white-label confirmation workflow: each location is set up separately, reports are attributed to the respective owner, and reporting is evaluable per location. More on this in the piece on multi-location review management.
Use case: dermatology practice in Düsseldorf-Bilk
A dermatology practice in Düsseldorf-Bilk, 23 Google reviews, average 3.8 stars. Four reviews contained clear GDPR violations: other patients were mentioned, in two cases with recognisable health details. The practice owner had been ignoring the reviews for months – out of uncertainty about how to handle them.
Via Sternehero, all four reviews were submitted for reporting. Documentation, violation category, screenshot – everything in under 20 minutes. The platform removed three of the four reviews within 6 days. The average rose from 3.8 to 4.2 stars. Visibility in the Local Pack for "dermatologist Düsseldorf": from position 6 to position 3.
For practices with similar issues: Sternehero for businesses provides an overview of the workflow.
Act now: Report unlawful reviews systematically. → Start for free
Use case: practice marketing agency with 22 clients
A marketing agency from Munich specialising in healthcare professions manages 18 GP practices and 4 dental practices. Until recently, the team handled review management manually – one member of staff, 22 Google Business Profile profiles, no uniform reporting. Problems: responses without GDPR review, no documentation of reports, practices received no reporting.
Since switching to Sternehero, the multi-client workflow runs via a central agency account. Each practice has its own profile, GDPR-checked response templates are stored, and reporting is exported automatically per client. The member of staff saves around 6 hours per week – the agency has the same headcount but manages 30% more clients.
From our experience with agencies across the DACH market, we consistently see that specialist medical agencies underestimate the documentation burden – until a data protection officer at one of the practices asks questions. At that point it becomes costly. More on the agency workflow under Sternehero for agencies.
Further reading
Anyone wanting to understand the mechanics of platform policy violations in more depth will find the necessary detail in these pieces: Responding correctly to Google reviews and Reporting a review for a policy violation. Common questions about reporting processes and platform coverage are answered in the Sternehero FAQ.
Conclusion: review management in healthcare is not marketing – it is compliance
Medical confidentiality, GDPR Art. 9 and the Code of Conduct of the Regional Medical Association are not bureaucratic obstacles. They are the legal framework within which every practice must manage its online reputation. Anyone who ignores this risks not only poor reviews – but a chamber complaint, a GDPR fine and reputational damage from poorly worded responses.
Honestly: most practices have neither the time nor the legal expertise to set up this workflow correctly. That is not a criticism – it is the reality of a practice with a full waiting room.
Sternehero offers you the GDPR-compliant workflow on German hosting, DPA included, with transparent credit billing and no hidden follow-on costs. No guarantees of success – but a clean, documented process that withstands a data protection inspection.
Act now: Start for free – no credit card required. → Create account now
This article does not replace legal, data protection or professional regulatory advice. The specific interpretation of § 203 StGB (medical confidentiality), the Code of Conduct of the relevant Regional Medical Association, § 5 of the German Act Against Unfair Competition (UWG) and GDPR Art. 9 in individual cases should be clarified with a professionally qualified lawyer or the practice's data protection officer. Sternehero is a software tool and does not provide legal services within the meaning of the German Legal Services Act (RDG). The decision to remove or retain a review rests solely with the respective platform; removal cannot be guaranteed by anyone. The use-case figures cited (3 of 4 reviews removed, 6 hours saved per week, 30% client growth) are illustrative and do not constitute a promise of success.

