---
title: "A review workflow for medical practice social media"
description: "How to run drafting, clinical review and approval for a medical practice's social media — and where Bolta fits. Workflow only; not legal or compliance advice."
canonical_url: "https://bolta.ai/for/medical-practices/compliance"
markdown_url: "https://bolta.ai/for/medical-practices/compliance.md"
last_updated: "2026-07-28"
content_type: "industry"
publisher: "Bolta"
---

# A review workflow for medical practice social media

Source: https://bolta.ai/for/medical-practices/compliance
Last updated: 2026-07-28

How to run drafting, clinical review and approval for a medical practice's social media — and where Bolta fits. Workflow only; not legal or compliance advice.

## Summary

This describes an operating workflow — who drafts, who reviews, what gets checked, what gets recorded. It is not legal, regulatory or clinical advice and it does not describe what your practice is required to do.

## Who this is for

- Medical Practices

## Core capabilities

- Confirm written publication permission for every image of a person: Specific to publication, specific to the platform, and current. Treatment consent does not cover it and a lobby-album release does not cover Instagram. If you cannot point at the document, the post does not go. Keep an easy path for someone to withdraw permission later and honour it the same day.
- Check the clinical accuracy of every statement: What the treatment does, what it does not do, the timeline, the mechanism. This is the item that requires the clinician and it is the reason review cannot move to marketing. Check it against what you would say in a consultation, not against what reads well.
- Run the claims stop list: Guarantees, superlatives, comparisons to other practices, implied typical results, anything with the word best or safest. Maintain the list in writing and give it to whoever drafts, including Bolta's agents, so the same correction is not made every week.
- Check for anything that could identify a patient: Not just names. Recognisable detail, distinctive features in frame, a location, a date, a case described specifically enough that a colleague or a family member would know. The test is whether someone close to them would recognise it, not whether a stranger would.
- Confirm no protected health information reached the tool: Periodically check what has been entered into Bolta — context, prompts, uploads. It should describe treatments and the practice, never an individual. This is a habit rather than a one-time setup, because the drift happens when someone new starts drafting.
- Check the image matches the caption and the platform: Wrong procedure, wrong stage, an image reused from a post with different permissions attached. Scheduled queues drift, and a mismatch on a medical account is worse than careless — it can make a caption into a claim about the wrong thing.
- Read every public reply before it is sent: Anything that confirms someone is a patient is a disclosure, including a denial. Decide the neutral reply in advance, use it every time, and move everything substantive to the office. Never let a public reply be composed by someone who is annoyed.
- Review your own edits monthly: Once a month, look at what the clinician changed most often across approvals. That pattern is a stop-list entry or a voice rule that has not been written down. Add it. In Bolta those edits also feed the voice model directly, so the pattern gets absorbed rather than repeated.

## Limitations and boundaries

- This page is general information about publishing workflow. It is not legal, regulatory, compliance or clinical advice, and it does not describe what any particular practice, clinician or facility is required to do. Bolta is not a HIPAA business associate, does not offer a business associate agreement, and makes no claim that using its product satisfies any legal, regulatory or professional requirement. Do not put protected health information into Bolta. Consult your own counsel, compliance officer and professional body, and follow the policies your practice already has.
- This page is general and educational. It is not legal, financial, medical, or regulatory advice for practices.
- Generated content can be incorrect and should be reviewed before publication.
- Availability depends on the current Bolta plan, connected network, account permissions, and integration coverage.
- Current prices and plan limits must be verified on the Bolta pricing page.

Every practice that markets already has a review expectation, even if it was never written down: the doctor reads it before it goes out. The problem is that the expectation was formed when marketing meant a handful of items a year, and social media produces a hundred and fifty. The volume breaks the process, not the medium.

What follows is a workflow built for that volume. Make drafting cheap so it is not the bottleneck. Keep clinical review mandatory and make it fast enough that a booked clinician will actually do it. Record who approved what, so a question six months later has an answer. And keep patient information out of the marketing stack entirely, which is the one line that should never be a judgement call.

None of this changes who decides what your practice publishes, and none of it makes a practice compliant with anything. It is a way of running a queue.

## Separate drafting from judgement, and be honest about which is which

The single most useful move a practice can make is to stop treating social media as one job. It is two, and they need different people.

Drafting is writing, formatting, scheduling and image handling. It does not require clinical training and it should not consume clinical time. A coordinator, an agency or an AI agent can do it, and the difference between those options is cost and turnaround rather than kind.

Judgement is deciding whether a post is accurate, whether an implied claim is defensible, whether an image may be published, and whether the practice wants to say this at all. It is a clinical decision and it cannot be delegated to marketing — not because of any rule this page is describing, but because the person who can answer those questions is the person who does the procedure.

When practices get into trouble, it is almost always because these two jobs got merged. Either a clinician was doing both and simply stopped posting, or a coordinator was doing both and published something that had to come down. The workflow that survives is the one where drafting runs continuously and judgement happens in short, batched sittings.

Bolta is built for that split. Agents and coordinators fill the queue; a clinician clears it. There is no mode in which the product publishes without a person acting.

## What gets checked at approval, and by whom

A review step that checks everything checks nothing, because it will not get done. The practices that sustain this have a short list and run it every time.

The first item is always permission. Does an image in this post have specific written publication permission that covers this platform, and is that permission still current? A media release from three years ago for a lobby album does not cover an Instagram post today. If the answer is not clearly yes, the post does not go.

The second is accuracy. Is what this says about the treatment correct, and is the implied result defensible? This is the item that genuinely needs the clinician, and it is why review cannot move downstream.

The third is claims language. Superlatives, guarantees, comparisons to other practices, and anything that implies a typical outcome. Most practices maintain a short stop list of words they have decided not to use. Writing that list once and giving it to whoever drafts — including an AI agent — is the highest-return ten minutes available, because it stops the same correction being made weekly.

The fourth is patient identifiability, which is broader than names. A case description specific enough to be recognisable, a location detail, a distinctive tattoo in frame, a date that pins something down. The test is not whether a stranger could identify the person; it is whether their sister could.

The fifth is tone in context. Is anything scheduled that would land badly given what is happening right now — locally, in the practice, or in the field?

Bolta shows the reviewer the exact post, platform, image and scheduled time on one screen, which is what makes running a five-item list in ninety seconds realistic.

## What is recorded, what is not, and a limitation to plan around

Bolta keeps an operational record of your workflow. Approvals and rejections are stored with the acting user and a timestamp, alongside post activity — created, updated, submitted, approved, rejected, commented — and an admin or owner can export that activity as JSON through the workspace audit log, filtered by date range or by actor. That is genuinely useful when someone asks in six months who signed off on a post.

Be precise about what it is not. It is a record of your own process, not a compliance certification, and no retention period is guaranteed — do not describe it to anyone as an archive with a defined lifetime. There is no CSV or PDF export of approval history. And on older records the role of the person who reviewed may be blank, which means unknown rather than anything else.

The limitation worth planning around: Bolta does not enforce roles on approval. Any member of a workspace can approve any draft, including one they drafted themselves. There is no review-only seat and no way to stop a drafter approving their own work. If your practice wants drafting and approving separated — and most do — that separation is a working arrangement you adopt and audit after the fact using the stored record. It is not a permission the product enforces. Two practical consequences: keep the workspace membership small and deliberate, and if an agency drafts for you, understand that adding them to the workspace gives them the technical ability to approve.

The other boundary is data. Bolta is not a HIPAA business associate and no business associate agreement is offered, so protected health information must not go into it. In practice that means the product knows what treatments you offer and how you talk, and knows nothing about any individual patient. Most practices find that is all it needs.

## Human review checklist

- **Confirm written publication permission for every image of a person** — Specific to publication, specific to the platform, and current. Treatment consent does not cover it and a lobby-album release does not cover Instagram. If you cannot point at the document, the post does not go. Keep an easy path for someone to withdraw permission later and honour it the same day.
- **Check the clinical accuracy of every statement** — What the treatment does, what it does not do, the timeline, the mechanism. This is the item that requires the clinician and it is the reason review cannot move to marketing. Check it against what you would say in a consultation, not against what reads well.
- **Run the claims stop list** — Guarantees, superlatives, comparisons to other practices, implied typical results, anything with the word best or safest. Maintain the list in writing and give it to whoever drafts, including Bolta's agents, so the same correction is not made every week.
- **Check for anything that could identify a patient** — Not just names. Recognisable detail, distinctive features in frame, a location, a date, a case described specifically enough that a colleague or a family member would know. The test is whether someone close to them would recognise it, not whether a stranger would.
- **Confirm no protected health information reached the tool** — Periodically check what has been entered into Bolta — context, prompts, uploads. It should describe treatments and the practice, never an individual. This is a habit rather than a one-time setup, because the drift happens when someone new starts drafting.
- **Check the image matches the caption and the platform** — Wrong procedure, wrong stage, an image reused from a post with different permissions attached. Scheduled queues drift, and a mismatch on a medical account is worse than careless — it can make a caption into a claim about the wrong thing.
- **Read every public reply before it is sent** — Anything that confirms someone is a patient is a disclosure, including a denial. Decide the neutral reply in advance, use it every time, and move everything substantive to the office. Never let a public reply be composed by someone who is annoyed.
- **Review your own edits monthly** — Once a month, look at what the clinician changed most often across approvals. That pattern is a stop-list entry or a voice rule that has not been written down. Add it. In Bolta those edits also feed the voice model directly, so the pattern gets absorbed rather than repeated.

## Is Bolta HIPAA compliant for a medical practice?

Bolta is not a HIPAA business associate and does not offer a business associate agreement, so protected health information must not be put into it. Use it for treatment education, practice information and general content. Keep patient names, identifiers, chart details and images tied to a record in your clinical systems. Ask your own counsel about your obligations.

## Who should approve social media posts in a medical practice?

A clinician, because the substantive checks — accuracy, defensible implied results, whether an image may be published — are clinical judgements. Drafting can and should sit elsewhere: a coordinator, an agency or an AI agent. Merging the two roles is the reliable way to end up either posting nothing or taking something down.

## Can Bolta stop a coordinator approving their own drafts?

No. Bolta does not enforce roles on approval — any workspace member can approve any draft, including one they wrote. There is no review-only seat. Separation of drafting and approving is a working arrangement you adopt and audit after the fact using the stored record of who approved what, not a permission the product enforces.

## What record does Bolta keep of approvals?

Approvals and rejections are stored with the acting user and a timestamp, alongside post activity such as created, updated, submitted, approved and rejected. An admin or owner can export that as JSON from the workspace audit log, filtered by date or actor. Treat it as an operational record of your own workflow, not a compliance certification, and note that no retention period is guaranteed.

## How should a practice handle a patient comment on a public post?

With a short neutral reply inviting them to contact the office, decided in advance and used every time. Never include clinical detail and never confirm or deny that someone is a patient, because the confirmation is itself a disclosure. Move everything substantive to a private channel that your practice already uses for patient communication.

## Does using Bolta make our marketing compliant?

No, and any tool that says otherwise is overselling. Bolta makes drafting cheap and keeps a named human in the publishing path with a record of who acted. What is permissible for your practice to publish is governed by your own counsel, your professional obligations and your regulators, and none of that changes because of the software you draft in.

## Relevant links

- [Social media for medical practices, drafted by AI and approved by you](https://bolta.ai/for/medical-practices)
- [LinkedIn for medical practices: referrals, recruiting and reputation](https://bolta.ai/for/medical-practices/linkedin)
- [Content ideas for medical practices that survive review](https://bolta.ai/for/medical-practices/content-ideas)
- [Medical practice social media examples, rewritten before and after](https://bolta.ai/for/medical-practices/examples)
- [Related page: /for](https://bolta.ai/for)
- [Bolta pricing](https://bolta.ai/pricing)
