The rule change most agencies are ignoring

The "pre-screen" is dead. The compliant ask is alive.

FTC 16 CFR Part 465. Civil penalties: $51,744 per violation. The tactic it targets: routing patients to leave a review only if they pre-rate you 4★+. That is the default in Birdeye and Podium. We rebuilt the flow to be compliant from the first SMS.

What the service includes

Six things we run, every month.

Same-day SMS review ask

Triggered from your PMS export — Dentrix, Open Dental, Eaglesoft — within 4 hours of the appointment. Same-day asks have a 3–5x reply rate versus 7-day-delayed asks. SMS open rates are 98% in healthcare versus 21% for email.

FTC-compliant ask copy

No pre-screening, no incentives tied to sentiment, no "tell us privately first" fork. One ask, one link, your patient picks the platform. We A/B test the copy quarterly — the published winners are in the public client work log.

HIPAA-safe response handling

Responses written from templates that never confirm a patient relationship, never reference a clinical detail, and never name the patient. Three OCR settlements against dental practices since 2022 — Manasa Dental, Elite Dental, New Vision Dental — were driven by exactly the response mistakes most agencies still make.

Crisis SOP for negative reviews

A documented playbook for three scenarios — a review that exposes PHI, a defamatory or clearly false review, and a coordinated attack (3+ 1-stars in 24–72 hours). Same-day response, escalation path, deletion-request workflow, and breach-record protocol if PHI was disclosed.

Review schema and AggregateRating

Reviews surface inside Google, AI Overviews, and Perplexity citations only when the schema is present and structured correctly. We wire AggregateRating to the homepage and per-provider pages, with the source linked back to Google or Healthgrades so it survives Google's review-snippet guidelines.

Weekly monitoring across 7 platforms

Google, Healthgrades, Vitals, Zocdoc, Yelp, Facebook, RateMDs. Sentiment triage by a real person, not an algorithm scoring 3-stars as 5. Every new review responded to within 48 hours on Growth.

The compliance math

What the FTC rule and HIPAA actually cost when you get it wrong.

$51,744 per-violation FTC civil penalty for fake or suppressed reviews (2026 figure)
$10K–$50K typical OCR settlement range for HIPAA disclosure in a review response
98% SMS open rate in healthcare — versus 21% for email asks
3–5x reply lift on same-day asks versus 7-day-delayed asks
Why we built our own stack

We don't resell Birdeye, Podium, or Weave.

Birdeye and Podium charge $299-$899/mo for software where you still do the writing. Our stack runs on Twilio + SendGrid + Notion. Cost per client ~$35/mo — which is why reputation runs as $297/mo standalone or bundled into the $997 Growth tier.

Pricing

One simple choice. Month-to-month.

No contracts. No setup fees on Foundation or Growth. You own your assets from day one.

Foundation

For: AEO baseline + local visibility
$597 /month
  • AEO citation tracking · 4 AI engines
  • Schema deployment (one-time)
  • Google Business Profile management · 4 posts/mo
  • 2 blog posts / month (dentist-reviewed)
  • Review acquisition · 25 outreaches/mo
  • AI Visibility Score · monthly
  • AI Growth Simulator · view-only
  • Month-to-month — own everything
Most chosen

Growth

For: Our most chosen tier
$997 /month
  • Everything in Foundation, plus:
  • +4 long-form blog posts / month
  • +8 GBP posts + 12 social posts / month
  • AI Visibility Score · weekly
  • Schema audit + ongoing optimization
  • Reputation outreach · 50/mo
  • AI Growth Simulator · full
  • AI Multi-Language Outreach · drafts
  • AI Practice Valuation Tracker
  • AI Daily Huddle Brief · 7am email
  • AI Weekly Business Review · Monday 6am
  • Quarterly strategy call
  • Month-to-month
  • You own everything
  • HIPAA-aware on day one of registration

Not ready to commit? Start with the free 50-point AEO audit or the $497 deep audit.

Our promise

The Thorli Bill of Rights

Ten things every dental practice should demand from a marketing agency. Most won't put these in writing. We do — every engagement letter.

  1. 01 Month-to-month. Cancel anytime. No cancellation fee.
  2. 02 You own your domain. Always.
  3. 03 You own your Google Business Profile, social accounts, and all content.
  4. 04 No long-term contracts. Ever.
  5. 05 No setup fees on Foundation or Growth tiers.
  6. 06 Transparent pricing — published on the site, not hidden behind a sales call.
  7. 07 Monthly transparency report — every change, every shipped asset, every AI citation.
  8. 08 A signed BAA with every client. HIPAA by default.
  9. 09 No AI-generated medical content without licensed dentist review.
  10. 10 Clean handoff if you leave — all assets transferred within 7 days.
FAQ

Questions, answered.

Is the Birdeye/Podium pre-screen actually illegal now?

It is at minimum a regulatory risk the FTC has named in the 16 CFR Part 465 rule-making comments. No federal court case has tested it yet, but the FTC's enforcement priorities are explicit. The defensible position is to not run a pre-screen at all — give every patient the same ask. That's how we run it.

Can I incentivize reviews?

You can offer a small thank-you to anyone who leaves a review, but it cannot be conditioned on sentiment, you must disclose the incentive in the ask, and the incentive cannot create a "material connection" that biases the review. We default to no incentive — the legal surface area is not worth it, and same-day SMS asks already produce industry-leading reply rates without one.

What about HIPAA — can I respond to a review at all?

Yes, but you cannot confirm a patient relationship or reference any clinical detail without a signed HIPAA Authorization on file. The templates we use respond to the substance of the review without ever acknowledging the writer was a patient. Three OCR fines against dental practices since 2022 came from agencies and dentists getting this wrong. We will not let you make the same mistake.

What if we get a coordinated attack — multiple 1-stars overnight?

The crisis SOP triggers within hours: screenshot every review, file deletion requests where the platform allows it (Google specifically allows reporting for off-topic, fake, or terms-violating reviews), respond to legitimate-looking ones with the HIPAA-safe template, and freeze incentive campaigns while we triage. Growth clients get same-day triage during business hours.

Do reviews actually move AI citations?

Yes. AggregateRating schema is one of the signals AI engines use to decide which practice to quote when a user asks "best dentist in [city]." Practices with 200+ Google reviews and proper schema get cited more often than practices with 50 reviews and no schema, even when the smaller practice has stronger SEO otherwise. Reviews are an AEO input, not just a trust signal on your site.

Want to know what AI says about your practice?

Free 50-point AEO audit. Delivered in 48 hours. No card. No call required.