A review workflow for medical practice social media

This describes an operating workflow — who drafts, who reviews, what gets checked, what gets recorded. It is not legal, regulatory or clinical advice and it does not describe what your practice is required to do.

Every practice that markets already has a review expectation, even if it was never written down: the doctor reads it before it goes out. The problem is that the expectation was formed when marketing meant a handful of items a year, and social media produces a hundred and fifty. The volume breaks the process, not the medium.

What follows is a workflow built for that volume. Make drafting cheap so it is not the bottleneck. Keep clinical review mandatory and make it fast enough that a booked clinician will actually do it. Record who approved what, so a question six months later has an answer. And keep patient information out of the marketing stack entirely, which is the one line that should never be a judgement call.

None of this changes who decides what your practice publishes, and none of it makes a practice compliant with anything. It is a way of running a queue.

Separate drafting from judgement, and be honest about which is which

The single most useful move a practice can make is to stop treating social media as one job. It is two, and they need different people.

Drafting is writing, formatting, scheduling and image handling. It does not require clinical training and it should not consume clinical time. A coordinator, an agency or an AI agent can do it, and the difference between those options is cost and turnaround rather than kind.

Judgement is deciding whether a post is accurate, whether an implied claim is defensible, whether an image may be published, and whether the practice wants to say this at all. It is a clinical decision and it cannot be delegated to marketing — not because of any rule this page is describing, but because the person who can answer those questions is the person who does the procedure.

When practices get into trouble, it is almost always because these two jobs got merged. Either a clinician was doing both and simply stopped posting, or a coordinator was doing both and published something that had to come down. The workflow that survives is the one where drafting runs continuously and judgement happens in short, batched sittings.

Bolta is built for that split. Agents and coordinators fill the queue; a clinician clears it. There is no mode in which the product publishes without a person acting.

What gets checked at approval, and by whom

A review step that checks everything checks nothing, because it will not get done. The practices that sustain this have a short list and run it every time.

The first item is always permission. Does an image in this post have specific written publication permission that covers this platform, and is that permission still current? A media release from three years ago for a lobby album does not cover an Instagram post today. If the answer is not clearly yes, the post does not go.

The second is accuracy. Is what this says about the treatment correct, and is the implied result defensible? This is the item that genuinely needs the clinician, and it is why review cannot move downstream.

The third is claims language. Superlatives, guarantees, comparisons to other practices, and anything that implies a typical outcome. Most practices maintain a short stop list of words they have decided not to use. Writing that list once and giving it to whoever drafts — including an AI agent — is the highest-return ten minutes available, because it stops the same correction being made weekly.

The fourth is patient identifiability, which is broader than names. A case description specific enough to be recognisable, a location detail, a distinctive tattoo in frame, a date that pins something down. The test is not whether a stranger could identify the person; it is whether their sister could.

The fifth is tone in context. Is anything scheduled that would land badly given what is happening right now — locally, in the practice, or in the field?

Bolta shows the reviewer the exact post, platform, image and scheduled time on one screen, which is what makes running a five-item list in ninety seconds realistic.

What is recorded, what is not, and a limitation to plan around

Bolta keeps an operational record of your workflow. Approvals and rejections are stored with the acting user and a timestamp, alongside post activity — created, updated, submitted, approved, rejected, commented — and an admin or owner can export that activity as JSON through the workspace audit log, filtered by date range or by actor. That is genuinely useful when someone asks in six months who signed off on a post.

Be precise about what it is not. It is a record of your own process, not a compliance certification, and no retention period is guaranteed — do not describe it to anyone as an archive with a defined lifetime. There is no CSV or PDF export of approval history. And on older records the role of the person who reviewed may be blank, which means unknown rather than anything else.

The limitation worth planning around: Bolta does not enforce roles on approval. Any member of a workspace can approve any draft, including one they drafted themselves. There is no review-only seat and no way to stop a drafter approving their own work. If your practice wants drafting and approving separated — and most do — that separation is a working arrangement you adopt and audit after the fact using the stored record. It is not a permission the product enforces. Two practical consequences: keep the workspace membership small and deliberate, and if an agency drafts for you, understand that adding them to the workspace gives them the technical ability to approve.

The other boundary is data. Bolta is not a HIPAA business associate and no business associate agreement is offered, so protected health information must not go into it. In practice that means the product knows what treatments you offer and how you talk, and knows nothing about any individual patient. Most practices find that is all it needs.

A review checklist

A process for the person who approves posts. Adapt it to the policies your practice already has, and check anything you are unsure about with whoever owns compliance where you work.

  • Confirm written publication permission for every image of a person

    Specific to publication, specific to the platform, and current. Treatment consent does not cover it and a lobby-album release does not cover Instagram. If you cannot point at the document, the post does not go. Keep an easy path for someone to withdraw permission later and honour it the same day.

  • Check the clinical accuracy of every statement

    What the treatment does, what it does not do, the timeline, the mechanism. This is the item that requires the clinician and it is the reason review cannot move to marketing. Check it against what you would say in a consultation, not against what reads well.

  • Run the claims stop list

    Guarantees, superlatives, comparisons to other practices, implied typical results, anything with the word best or safest. Maintain the list in writing and give it to whoever drafts, including Bolta's agents, so the same correction is not made every week.

  • Check for anything that could identify a patient

    Not just names. Recognisable detail, distinctive features in frame, a location, a date, a case described specifically enough that a colleague or a family member would know. The test is whether someone close to them would recognise it, not whether a stranger would.

  • Confirm no protected health information reached the tool

    Periodically check what has been entered into Bolta — context, prompts, uploads. It should describe treatments and the practice, never an individual. This is a habit rather than a one-time setup, because the drift happens when someone new starts drafting.

  • Check the image matches the caption and the platform

    Wrong procedure, wrong stage, an image reused from a post with different permissions attached. Scheduled queues drift, and a mismatch on a medical account is worse than careless — it can make a caption into a claim about the wrong thing.

  • Read every public reply before it is sent

    Anything that confirms someone is a patient is a disclosure, including a denial. Decide the neutral reply in advance, use it every time, and move everything substantive to the office. Never let a public reply be composed by someone who is annoyed.

  • Review your own edits monthly

    Once a month, look at what the clinician changed most often across approvals. That pattern is a stop-list entry or a voice rule that has not been written down. Add it. In Bolta those edits also feed the voice model directly, so the pattern gets absorbed rather than repeated.

Where Bolta fits

Bolta’s agents research and draft posts, then hold them for review. The approval workflow is designed so that a human reviews every post before publication. Bolta does not decide what is appropriate for your practice to say, and it does not replace the review your practice already does. Follow the policies you already have, and consult your compliance officer or counsel on anything specific to your situation.

Frequently asked questions

Is Bolta HIPAA compliant for a medical practice?

Bolta is not a HIPAA business associate and does not offer a business associate agreement, so protected health information must not be put into it. Use it for treatment education, practice information and general content. Keep patient names, identifiers, chart details and images tied to a record in your clinical systems. Ask your own counsel about your obligations.

Who should approve social media posts in a medical practice?

A clinician, because the substantive checks — accuracy, defensible implied results, whether an image may be published — are clinical judgements. Drafting can and should sit elsewhere: a coordinator, an agency or an AI agent. Merging the two roles is the reliable way to end up either posting nothing or taking something down.

Can Bolta stop a coordinator approving their own drafts?

No. Bolta does not enforce roles on approval — any workspace member can approve any draft, including one they wrote. There is no review-only seat. Separation of drafting and approving is a working arrangement you adopt and audit after the fact using the stored record of who approved what, not a permission the product enforces.

What record does Bolta keep of approvals?

Approvals and rejections are stored with the acting user and a timestamp, alongside post activity such as created, updated, submitted, approved and rejected. An admin or owner can export that as JSON from the workspace audit log, filtered by date or actor. Treat it as an operational record of your own workflow, not a compliance certification, and note that no retention period is guaranteed.

How should a practice handle a patient comment on a public post?

With a short neutral reply inviting them to contact the office, decided in advance and used every time. Never include clinical detail and never confirm or deny that someone is a patient, because the confirmation is itself a disclosure. Move everything substantive to a private channel that your practice already uses for patient communication.

Does using Bolta make our marketing compliant?

No, and any tool that says otherwise is overselling. Bolta makes drafting cheap and keeps a named human in the publishing path with a record of who acted. What is permissible for your practice to publish is governed by your own counsel, your professional obligations and your regulators, and none of that changes because of the software you draft in.

See what Bolta would write for your practice

Bolta’s agents research, draft and schedule posts. Nothing reaches a public account until a person on your side approves it. Paid plans start at $19/month, and there is a free Starter tier.

Last updated: 2026-07-28

Medical Practice Social Media Review Workflow | Bolta