STAT Studio

STAT Studio · Client-facing

How we keep your marketing compliant

Healthcare marketing carries obligations that general marketing does not. These are the practices we follow on every account, what we will need from you, and where the line sits on the things that matter most.

Document

Compliance Standards

Version

2.8

Effective

September 2, 2026

Supersedes

Version 2.7 · August 28, 2026

Applies to

All client engagements

Download as PDF

Questions about any of this? Email us directly.

Patient information


1Patient information stays protected.

We never solicit or collect patient information. No identifiable patient testimonial, story, or photograph enters your materials until you provide a signed HIPAA authorization from that individual. A photo release, a model release, or a general testimonial consent form is not sufficient — a release covers right of publicity, while HIPAA requires a specific written authorization with its own required elements, including the individual's right to revoke. We keep a copy on file alongside the content for as long as the material is in use, and we stop using it immediately if an authorization is revoked.

2A Business Associate Agreement is built into your contract.

Where our work brings us into contact with protected health information, a Business Associate Agreement has to be in place first. Ours is Schedule B of the Client Services Agreement, executed by the same signature — so you sign once rather than twice, and it is written for this specific service rather than adapted from a general template.

If your compliance program requires its own form, send it and we will review it. Many practices have one, and we would rather work through yours than have you adopt ours by default.

Nothing that touches protected health information starts until one of them is signed.

3You know who touches your account.

Work is performed by STAT Studio and, for routine review responses, by a small number of contracted writers. Every person who touches a client account completes HIPAA privacy and security training for business associates before doing so, and renews that training every year. We keep the completion records. Everyone works only from the response library you have approved, and contractor access is granted individually and revoked the day their engagement ends.

Kristen Jones, who founded STAT Studio, holds that training herself — HIPAA privacy and security training completed through The HIPAA Journal · 2026.

Access and approval


4We request the least access necessary.

Google Business Profile management requires Manager access — the minimum level Google provides that permits responding to reviews and publishing posts. It does not include the ability to transfer or remove your profile, which stays with your Owner. Access is granted through delegated permissions, never shared passwords, and is revoked the day an engagement ends. We will not accept a password, even if you offer one.

5Nothing is published that you have not approved in advance.

You name a Primary and a Backup Approver. Because we publish to your Google Business Profile on your behalf, approval happens before publication rather than at the moment of it. You approve a response library in writing, and we reply only from it. Nothing we publish is improvised.

The wording is not editable. Some replies contain bracketed fields — a practice name, a department, a contact — and those are filled in with what the bracket asks for, and nothing else. Everything outside the brackets stays as written. That is the point of a prepared library: the language was settled before anyone was under pressure, and a reply that has been rewritten is a different reply.

If a reply does not fit your situation, decline it and tell us. We will use a different one, or add one written to the same standard as the rest of the library. You may withdraw the library, in whole or in part, at any time, and we stop using it that day.

You may reply to any review yourself, in your own words, whenever you like. That is your profile. This governs only what we publish on your behalf.

We do not change your practice name, address, phone number, hours, or service categories without your written approval for that specific change.

6Clinical claims are yours, not ours.

Some plans include profile content — your business description, your service names and descriptions, the text of a post. Where your Schedule A includes it, you approve everything we write before it is published, and every fact in it is yours to confirm: credentials, accreditations, licensure, and any statement about what you treat. We do not independently substantiate a medical claim, and we will not invent one to fill a gap.

Review replies carry none of this by design. A reply from your approved library never states a credential, never describes a service, and never references a condition or a course of care.

We do not publish pricing or insurance participation — not on your profile, not in a reply. Both change, and a figure that was right last quarter reads as current to the patient looking at it today. Those questions are routed to your office.

What we produce for you


7Review responses follow a library you approved.

We never confirm or deny that any person was a patient, never reference a condition, visit, course of care, or billing matter, and route anything clinical, legal, or contentious back to you instead of answering it. We monitor multiple times per week on business days — this is not real-time coverage, and you can always respond directly yourself.

8We report reviews honestly, and we do not promise removals.

We report reviews that appear to violate platform content policy, up to the monthly cap in your Schedule A. The platform decides whether a review comes down, not us, and most reviews are not removable. Google permits one report and one appeal per review, so the reporting category is a matter of judgment rather than a guaranteed outcome. Anything that threatens harm or litigation is escalated to your designated contact rather than answered.

9Our written products are educational, not legal advice.Digital products

The guide, the response templates, and the interactive tool we sell are educational resources. They are not legal advice and do not replace your own counsel or compliance program. Legal language has been reviewed by a healthcare compliance attorney and tone and clinical realism have been reviewed by practicing licensed clinicians. These are two separate reviews, completed before anything is offered for sale, and clinician review is never presented as compliance authority.

How we operate


10Your materials are stored securely.

Client files are held in access-controlled cloud storage with multi-factor authentication, retained for the term plus twelve months, and deleted on request.

11We notify you within two business days.

Any suspected exposure of patient information is reported within two business days of discovery — to the privacy or compliance contact you designate at onboarding, not only your marketing contact. That commitment is considerably stricter than the law requires of a business associate, which is allowed up to sixty days. Anyone working on your account under contract owes us that report within twenty-four hours, so the time is spent establishing facts rather than waiting. The notice tells you what we know so far; the breach determination and any patient notification remain yours as the covered entity.

12We carry professional liability insurance.

Professional liability (errors and omissions) coverage is in force, with a limit of $1,000,000. A certificate of insurance is available on request.

13How we use AI.

We use AI tools the way most writers now do — to help draft and edit our own materials. Everything we publish or sell is then reviewed and edited by a person, and your response library is approved by you in writing before a single reply goes out.

Two limits we hold to. No patient information is ever entered into an AI tool. And no AI system publishes to your profile — a person does, from the library you approved.

Most of this comes down to one idea: the practice owns the patient relationship, and the marketing should never get between you and it.

That is why clinical claims are yours to confirm, why every reply comes from a library you approved, and why we will hold a patient testimonial back rather than publish it without a signed authorization on file.

Want this reviewed before you sign anything?

Send it to your compliance officer or practice administrator. If they have questions, we will answer them in writing — before there is any agreement on the table.

[email protected]

This page describes STAT Studio's operating practices. It is not legal advice, and it does not replace your practice's own HIPAA policies or compliance counsel. HIPAA does not certify vendors; no marketing company can be “HIPAA certified.” These standards are reviewed at least annually and on any material change to our services.

Scroll to Top