PATIENT TESTIMONIALS, CONFIDENTIALITY & LIABILITY
Last updated: September 15, 2026
PATIENT TESTIMONIALS & CONFIDENTIALITY
Part of our work together may include collecting and sharing patient testimonials in your marketing materials. Because you're a healthcare provider, we want to be clear about how that works and who's responsible for what.
(a) What you send us. You'll only share testimonial content with us that the patient has already agreed to make public - things like their name, photo, video, quote, or story. Please don't send us medical records, diagnoses, treatment notes, billing details, or anything else from the patient's chart. We only need the story the patient chose to share, not the underlying medical information behind it.
(b) Getting patient consent is on you. Before sending us anything, you'll need to have the patient sign a release or authorization allowing their story to be used publicly for marketing. You'll keep that signed form in your own records - we don't need a copy, and we won't store it.
(c) We'll keep it confidential. Any testimonial or patient information we do receive will be used only to write, edit, format, and prepare your marketing materials - nothing else. We won't share it with anyone outside our team without your say-so.
(d) If we ever receive more than we should. If something slips through - say, a testimonial draft that accidentally includes medical details - we'll let you know right away, won't use that information, and will delete it or send it back at your request.
(e) This isn't a HIPAA Business Associate Agreement. Because we're only working with content you've already cleared for public release, we're not handling protected health information as defined under HIPAA, so this section - and this Agreement - isn't a Business Associate Agreement. If that ever changes and we need to handle protected health information directly, we'll put a separate HIPAA agreement in place first.
(f) Governing law. This section is governed by Texas law.
PATIENT CONSENT WARRANTY & INDEMNIFICATION
Because we rely on you to handle the patient consent side of things, we want to spell out clearly what that means.
(a) You're responsible for consent. You confirm that every piece of content you give us - testimonials, images, videos, or any patient likeness - comes with a fully signed, legally valid HIPAA authorization and media release from that patient. We rely on your word that this paperwork is in place and properly executed.
(b) You own that responsibility. If a consent form turns out to be missing, invalid, or improperly obtained, that responsibility sits with you, not us. We're not in a position to verify each patient's paperwork ourselves.
(c) You'll cover us if something goes wrong. If a lawsuit, regulatory inquiry, or financial claim arises because proper consent wasn't obtained for something we published on your behalf, you agree to defend us, cover our costs, and hold us harmless from that claim.
THIRD-PARTY PLATFORMS & LIMITATION OF LIABILITY
Our marketing work runs through platforms we don't own or control, so we want to be upfront about what that means for both of us.
(a) We use third-party platforms. We manage your marketing through outside platforms and tools - including Meta Business Suite, Facebook, and Instagram, among others. These platforms are owned and operated by other companies, not us, and we can't guarantee their security or uptime.
(b) We're not responsible for what those platforms do. If something goes wrong because of hacking, phishing, a platform outage, an account takeover, or other criminal activity outside our control, we're not liable for the resulting losses - including unauthorized ad spend, data breaches, or business disruption - unless it's shown that we were grossly negligent.
(c) You'll cover us in those situations. You agree to defend us, cover our costs, and hold us harmless from claims or losses arising from these third-party platform issues, except where our own gross negligence is proven.
(d) Our liability has a cap. If we're ever found liable for a service error or security incident, the most we'd owe is capped at the total fees you paid us in the three (3) months before the incident.
Questions about this policy? Contact the SoClients team at (512) 400-4349.


