Can doctors, dentists and therapists use AI to write blog posts?
Yes. Nothing in either rulebook asks who typed it.
A page on your practice’s website is judged on what it claims and on who can be recognised in it. Neither test changes because software wrote the first draft.
Two rulebooks reach one. HIPAA governs what you may say about the people you treat. The FTC governs what you may promise about a treatment. Neither asks who held the pen, and neither moves an inch of the answering off the practice.
Draft · What a first appointment actually involves
Most people arrive braced to explain everything at once. The first visit is mostly the other way round: working out what you want to be different, and whether this is the right room for that.
Bring nothing. If you keep a list of your medications, have it on your phone.
Strong · one thing to look at
Overall 89 · publishable bar 80
Three things do not move, whoever does the typing.
A clinician answers for it
A post about a condition is a clinical statement about it. No vendor and no tool takes that on for you.
Patients stay out of it
Unless one signed an authorization for this exact use. There is no version of this rule that ends in “probably fine”.
Someone reads it first
Before it is live, and not whoever holds the website login. So the useful thing is to make it quick and hard to skip.
Name the person, and make them clinical.
This reads as obvious until you try to name them. A post that says what a procedure feels like, how long recovery takes, or when a symptom is worth worrying about is a clinical judgement, so whoever approves it has to be able to defend it out loud. In a group that is the clinician who owns the service line.
The usual failure is not a practice letting software publish unread. It is the sign-off drifting to whoever runs the website, because they hold the login. Right person to press the button, wrong person to decide the recovery timeline is right.
You can tell that story out loud. Publishing it is a different act.
The case you would describe at a study club, name left out, is the same case a blog post turns into a disclosure. A published page is permanent, searchable and open to everyone, and the details that make a story worth reading are the ones that identify the person. A town, an age, an unusual presentation, the month. Three of those together is a patient.
What has to be true first
- The patient signed an authorization.
- Written for this use, not the intake pack.
- Filed where you can find it again.
- They can revoke it, and you can take the page down.
Four lines, and the reason most practice blogs should hold no patients at all.
What practices reach for instead
- “I changed the details.” Stripping identity is a defined standard, not an edit. A changed name beside the same town, age and procedure changes nothing.
- “They were happy for me to.” Said in the chair is not signed for this. The rule wants a signature covering the use you are making.
- A review they left you. They chose to publish that. Repeating it beside what you treated them for is you publishing it.
- A photo with the face cropped. The crop takes the face. It leaves the tattoo, the ward, the window, the date stamp.
None of this is new, and none of it is caused by software. What software changes is how easily a patient reaches a draft at all, because the fastest way to make a post feel specific is to reach for a real case.
The third one is the only one software takes work off.
The first two are yours and stay yours. The third is a reading job, which is where Verand comes in and the only place it does. It drafts the post from what your practice has told it, checks it against the rules you are subject to, marks what would be a problem and hands it to a clinician. It cannot publish, and no setting changes that.
Read it as a clinician
Is it right, current, and something you would say in the room? Nothing outside your practice can answer that.
Hunt for the patient
Any case, any photograph, any “a patient of ours”. If one is there on purpose, the authorization is filed first.
Every figure to a source
And a date beside it. A superseded recommendation reads exactly like a current one.
Read the promises sideways
Cut anything guaranteeing an outcome, calling a result permanent, or calling a procedure painless.
Disclaimer on the live page
Confirm it appears as the page will publish, not only in the draft.
Approve, file, publish
In that order, by name and date. Afterwards it stops happening.
Four ways a health draft goes wrong, and where to look.
A patient who was never there
Ask for a specific example and you get one: an age, a presentation, an outcome. Nobody real is in it, so it is not a privacy problem. It is an invented clinical claim under a clinician’s name, which is the other one.
Outcome language nobody chose
Models have read a great deal of clinic marketing, most of it by people your board does not reach. So absolutes arrive in a draft about a routine procedure, in a sentence nobody wrote on purpose.
Recovery is quick, and most patients get permanent results from a single visit.
Flagged for you, and on the hard tier there is no override.
Claims about your own practice
How long you have been in practice, which board certified you, how many of a procedure you have done. Software cannot verify a word of it and writes it anyway, because that is the sort of sentence that belongs there.
Guidance that has since moved
Screening intervals, age bands, dosing, the season’s vaccine advice. A draft states the version it learned with the confidence of the version in force, and on a health page that error has the longest tail.
The first three are why a clinician reads the draft. The fourth is why every figure carries a source and a date, which software is better at than people.
One limit, said plainly.
The automatic check for patient detail is narrower than you would want. It reads the finished draft for the mechanical giveaways, a Social Security number or a written-out date of birth. It cannot read a paragraph and tell you the person in it is recognisable; that needs someone who knows the patient and the town. Step two of the review above exists for exactly that reason, and we would rather write it down than let you assume otherwise. Verand does not check your state board’s own rules yet either, so what your board bans and the pack does not, you add yourself.
The four that come up every time.
Do I have to tell patients a post was drafted with AI?
Nothing in the privacy rule or the FTC’s health-claims guidance asks for a byline naming the software. Both ask whether the page is accurate, supportable and free of anyone’s health information. Plenty of practices disclose anyway; treat that as a decision for you and your counsel, not a requirement you are failing.
Can I publish a patient story if the patient is pleased about it?
Only with a signed authorization written for that use, kept six years, and only while they have not revoked it. Being pleased is not the same as having signed, and neither is a review they left elsewhere. Verand will not catch a story told in prose, so it goes in by hand after the gate.
Does a clinician have to review it, or can my practice manager?
Whoever can judge the clinical content, which means a clinician. Your practice manager can own the queue and press publish, but should not be the one deciding the recovery timeline is right. Verand hands it over with the questionable sentences marked and the sources attached, which is what turns two hours into five minutes.
Could Verand publish while I am with patients?
No, and no plan, setting or connector changes it. Every draft stops at a person at your practice. The connector cannot publish, cannot clear a compliance block and cannot delete content. If nobody reads it, it does not go live.
Two questions this page leaves to their own pages.
AI content for medical, dental and mental-health practices
What a draft is checked against before anyone can publish it.
/medical-practices The testIs a practice blog post marketing under HIPAA?
Where the line falls between educating and marketing, and what changes when a post crosses it.
/what-counts-as-advertising The checklistWhat the medical disclaimer has to say
What the block has to contain, where it sits, and why there is only ever one.
/disclaimer-requirementsSources: the HIPAA Privacy Rule’s authorization, identifier and documentation requirements, and the FTC’s health-claims guidance. Validated against HHS and FTC rules. AI-researched and operator-reviewed. Your counsel confirms applicability. Not legal advice. 45 CFR §164.508 · 45 CFR §164.514(b)(2) · 45 CFR §164.530(j)(2) · FTC Act §5 · FTC Health Products Compliance Guidance
The answer is yes. The reading stays clinical.
Seven days, every feature unlocked, one click to cancel. Your first article is drafted during setup, and it stops where this page says.
Every draft stops at a person at your practice. There is no setting that changes it.