Why the clinician carries the risk, not the page
The regulatory exposure from a hospital social media account lands on the registered practitioners who appear in it, not on the account. A state medical council disciplines individuals under the ethics code; it has no jurisdiction over a marketing agency and no interest in your content calendar. So the first thing to fix in a hospital social media policy is the reporting line. A clinician must be able to refuse a post about their own practice, and that refusal must be final. Policies that give marketing the last word on clinical content misallocate a liability marketing cannot carry.
The second thing to fix is scope. Most hospitals write a policy for the official handles and ignore the personal accounts where the real risk sits. A consultant with a large following who posts case images from your operation theatre is creating exposure for themselves, for the patient, and for the hospital as data fiduciary under the DPDP Act, 2023. The policy has to cover clinical content posted anywhere, by anyone employed or empanelled, whether or not the hospital is tagged and whether or not the account carries your branding.
Being clear about what the policy is for helps adoption enormously. It is not there to stop doctors having a public voice. Public health communication by credible clinicians is genuinely valuable, and the alternative is that the space fills with people who have no registration to lose. The policy exists so that a clinician can post confidently, knowing where the line runs, rather than posting nothing at all or posting something that ends in a complaint. Frame it that way when you roll it out, or it will be read as a gag order.

The four content tiers your policy needs
Sorting content into tiers is what makes the rest of the SOP operable. Tier one is general health education with no patient involved and no claim about your own results: what a symptom might indicate, how a screening test works, what recovery after a procedure generally involves. This carries the least risk and should be the bulk of what you publish. It also happens to perform best over time, because it answers the questions people are genuinely searching for rather than the ones you wish they were asking.
Tier two is institutional and factual: new equipment, a new department, revised OPD timings, a camp announcement, an accreditation outcome, a recruitment notice. Tier three is anything featuring an identifiable patient, including images, video, direct quotes, case histories detailed enough to identify, and reviews reshared from other platforms. Tier four is anything asserting a result, a rate, a comparison or a first, whether about a doctor, a department or the hospital. The tier determines the approval path, not the tone or the format.
The value of tiering is that most content stops needing individual sign-off. Tier one and tier two run on pre-approved templates and a single editorial check. Tier three cannot enter the drafting queue at all until a consent record exists. Tier four requires the medical superintendent, and in most hospitals should simply be refused. If your content calendar turns out to be mostly tier three and tier four, the calendar is the problem and no approval process will fix it.
What each tier requires before publication
- Tier one: editorial fact-check against a citable clinical source
- Tier two: confirmation from the department that the facts are current
- Tier three: signed, scope-specific patient consent on file before drafting
- Tier four: written substantiation plus medical superintendent sign-off
- All tiers: the named clinician featured has seen and approved the final asset
Patient-identifiable content and the consent that stands up
A generic admission consent form does not authorise marketing use. Under the DPDP Act, 2023 consent must be free, specific, informed, unconditional and unambiguous, given for a stated purpose, and withdrawable as easily as it was given. A clause saying the hospital may use patient information for its own purposes fails nearly every one of those tests. Marketing use of a patient image or story needs its own consent, taken separately from clinical consent, describing the channels, the duration and the withdrawal route in language the patient reads.
Identifiability is much broader than a face. A tattoo, a wristband with a legible UHID, a rare diagnosis in a small town, a village name alongside an age and an occupation. Radiology images carry patient identifiers in DICOM headers that survive a screenshot more often than people expect, and a burned-in annotation survives everything. Anonymisation is a technical task with a checklist, not a matter of cropping tightly. Assign it to someone who understands the file formats involved rather than to whoever happens to be building the post.
Withdrawal is the operational part most hospitals have not built. If a patient asks you to remove their story two years later, you need to know every asset it appeared in, which platforms hold copies, whether a paid campaign is still serving it, and who has the access to take it down. That requires an asset register keyed to the consent record. Without one, your only honest answer is that you will try your best, which is not what the statute contemplates and not what the patient asked for.

What a marketing consent record must contain
- The specific asset or story, described well enough to identify later
- Named channels and platforms, and whether paid promotion is included
- Duration of permitted use and what happens at expiry
- A plain-language statement of the withdrawal route and turnaround
- The language consent was taken in, and who explained it
Testimonials, reviews and the reshare problem
Resharing a five-star review onto your own feed converts patient-authored content into hospital advertising, and the claims inside it become yours. A review saying a surgeon cured what three other hospitals could not is a comparative outcome claim the moment you publish it in a branded card. The patient wrote it freely; you chose to broadcast it. Reviewer permission is a separate question from the platform terms of use, and most hospitals ask for neither. Both are worth settling before any design work starts.
Soliciting testimonials creates a second problem. Asking a patient for a positive video while they are still under your care, still dependent on your clinicians, and possibly still holding an unsettled bill, is a consent environment that does not look voluntary from the outside and would not survive being described in a complaint. If you gather testimonials at all, do it after the episode has closed, through someone with no clinical or billing relationship to the patient, and record that separation as part of the file.
The alternative that works better in practice is aggregate and structural. Publish your actual patient satisfaction methodology and the results it produces, publish typical waiting times, publish what your grievance redressal process is and how long it takes to close a complaint. That kind of content is harder to produce and almost impossible to fabricate, which is exactly why it persuades. A wall of testimonial cards persuades nobody who has seen a wall of testimonial cards before, and it survives a regulatory reading far less comfortably.
“We stopped running patient videos entirely and started publishing our monthly average OPD waiting time instead. Enquiries did not drop. The questions on the phone got better, because people arrived already knowing what to expect.”
Claims a hospital account should never make
Some claims are wrong regardless of how carefully they are worded. Cure rates and success percentages presented without the denominator, the case mix, the follow-up period or the source. Any statement that a condition listed in the Schedule to the Drugs and Magic Remedies (Objectionable Advertisements) Act, 1954 can be cured or prevented by a treatment you sell. Firsts and onlys, which are almost never verifiable at the level of specificity claimed, and which are among the most complained-about categories in health advertising anywhere.
Softer versions carry the same exposure. Saying that patients travel from across the country implies a comparative reputation claim. Advanced technology implies superiority over local alternatives. Painless and scarless are outcome promises. Even trusted by thousands of families is a substantiation question waiting to be asked at the worst moment. The test that works at review is blunt: if a regulator asked for the evidence tomorrow morning, could you produce a document, today, that supports this exact sentence? If not, cut the sentence rather than softening it.
The trade-off is that this makes your copy plainer than a competitor who ignores all of it, and someone in the room will point at that competitor. The counter is that claim-led health advertising converts poorly with the audience segments that matter most, and it remains a standing liability for as long as the asset exists. Publish specifics instead: which procedures, which equipment by name and model, which accreditations with validity dates, which insurers and schemes you accept. Specificity reads as confidence; adjectives read as filler.
Refuse these at draft stage, before design work starts
- Any success, cure or complication rate without a documented source
- First, only, best, leading, most advanced, world-class
- Claims to treat or prevent conditions listed in the DMR Act Schedule
- Before-and-after images without a typicality statement and consent
- Countdown pricing attached to any clinical procedure
The approval workflow, step by step
Run it as a queue with defined states, not as an email thread. A post enters as a brief containing the tier, the claim list, the assets, the clinician featured and the intended channels. Editorial checks facts and language. The featured clinician reviews their own attribution and nobody else does it for them. Tier three consent references are verified against the register rather than asserted. Tier four goes to the medical superintendent. Every state change is logged with a person and a timestamp, and nothing publishes without reaching the final state.
Two practical accelerants keep this from becoming a bottleneck. Build a library of pre-cleared tier one content by department, refreshed quarterly, so the routine calendar draws from stock rather than requiring fresh approval each week. And set standing approvals for recurring formats such as a monthly OPD timing update, where the template is fixed and only the data changes. Reserve the full path for genuinely new content, which in a well-run calendar is a small fraction of what actually goes out.
Decide in advance what happens after publication too. Comment moderation on a health post is clinical work: somebody is going to describe their symptoms in the replies and ask what they should do. The policy must state that clinical advice is never given in comments, that the responder directs the person to a consultation or an emergency number, and who is on duty to do it. Leaving that to whoever manages the account produces either silence or unregistered clinical advice given in public.

Governance: training, monitoring and the exit case
Induct on this policy the way you induct on infection control: at joining, with a signed acknowledgement, and again annually. Most breaches are not defiance, they are a resident who did not know that a theatre photograph with a monitor screen in the background carries patient data, or a department head who thought a WhatsApp status was private. A thirty-minute session using real examples from your own departments, including the near-misses you have caught, does far more than a circulated PDF. File the acknowledgement where credentialing records sit.
Monitoring should be light but real. Search your hospital name and your consultants' names monthly across the main platforms and the review sites. You are looking for three things specifically: unauthorised accounts using your brand, clinical content posted from personal accounts that breaches the policy, and old assets still circulating after a consent withdrawal. Assign it to one named person with an hour a month rather than to everyone with no time at all. An unowned monitoring task is not a control, it is a paragraph.
Finally, write down what happens when a doctor leaves. Their profile page, their content, the posts featuring them and any campaigns naming them all need a disposition rule agreed at joining rather than negotiated at exit. Continuing to advertise a consultant who no longer practises at your hospital misleads patients and creates a genuine complaint risk on both sides. HealUDoc doctor records can hold the practising status that public pages read from, so a departure updates the website rather than depending on somebody remembering.


