Compliant review collection for private practice
We build and document a review collection process that stays inside the code your license sits under.
You were told you cannot ask. That is one sentence of the rule.
Most practice owners land here having already read that they cannot ask clients for reviews. That part is true, and it is where nearly every article on the subject stops.
It is also only the first sentence of the rule. Your code governs solicitation from clients. It does not govern whether your practice can have a credible public presence, and the gap between those two things is where a compliant process lives. The work is knowing exactly where your board draws its line, then building a repeatable process that stays on the correct side of it and leaves a record.
That is what this is. Not a promise that we can make your practice compliant, because we cannot. Compliance is your board's call and your responsibility. What we do is implement a process your own governing body already permits, and document it well enough that you can defend it.
What your governing body actually permits
Four bodies, four different positions. The differences are not cosmetic. A process that is fine for an LPC in Texas can be a standards breach for a Registered Psychotherapist in Ontario.
| Governing body | Ask a current client | Ask a former client | Use a review you never asked for | Promote reviews on your own site |
|---|---|---|---|---|
| APA Standard 5.05 | No | Not named. The "vulnerable to undue influence" clause is the catch, and most ethics consultants read it as no | Not addressed anywhere in the code | Not addressed |
| ACA Standard C.3.b | No | No, named explicitly, with no waiting period | Yes, after you discuss the implications with the client and obtain permission | Permitted once that permission is documented |
| NASW Standard 4.07(b) | No | Not named. The vulnerability standard still applies | No. The code bans soliciting consent to use a prior client statement, so the permission conversation itself is closed | Effectively no, for anything client-sourced |
| CRPO Standard 6.2 | No | No, former clients named explicitly | A client may post on a third-party site, provided you did not request it and do not influence what gets published | No. Registrants are expected not to advertise or promote third-party reviews about them |
Two things in that table catch most practices out.
ACA is the only one of the four with a documented path. Its 2014 revision added a second sentence the others do not have, requiring that counselors discuss the implications of a testimonial and obtain permission before use. That makes an unsolicited review usable for an LPC or LMHC. It does not make it usable for a social worker, because NASW closed the same door in the opposite direction.
CRPO restricts display, not just asking. Ontario registrants are expected not to advertise or promote third-party reviews at all. A reviews widget on the homepage, a five-star badge in the footer, a "see our Google reviews" link: all of that is a standards problem in Ontario and completely unremarkable in most of the United States. This is the single most common thing we find on a Canadian practice site that was built from an American template.
One live caveat we track for you. The ACA Code of Ethics is mid-revision. Board adoption is scheduled for September 2026 and publication in the fall, and until that happens the 2014 Code remains the operative version. C.3.b's wording could move. If your practice is ACA-governed, the process we build gets re-checked against the new text when it lands.
The alternatives that actually work
Your professional network is not in a clinical relationship with you, which is the entire reason the prohibition exists. Remove the power imbalance and the concern goes with it.
Colleagues, referral partners and supervisors.
Consultation group members, the psychiatrist who sends you referrals, a former supervisor. They can speak to your clinical thinking and your reliability without any of them being vulnerable to undue influence. This is the largest untapped source of credible public feedback in almost every practice we look at.
Workshop and CE attendees.
Someone who sat through a training you delivered has no ongoing dependency on you. A current supervisee accruing licensure hours does, which is where that line sits.
Aggregate, anonymized outcome data.
Intake and exit measures reported across your caseload demonstrate effectiveness without a single identifiable person in the copy. For NASW and CRPO practices, where client-sourced material is largely closed off, this does the work testimonials do elsewhere.
A complete Google Business Profile.
Review count is one input among many. Categories, service areas, hours, attributes, photos and posts are all ranking signals you control outright, and most practice profiles are half-filled. This is usually the fastest visible movement available to a practice that cannot solicit.
Your privacy stance, said out loud.
A short line explaining that you do not solicit or respond to reviews because client confidentiality outranks marketing is a trust signal in its own right. Prospective clients read it correctly.
How we set it up
Two halves, and the first one carries the actual risk.
What comes out
Almost every practice we look at is already doing one or two of these, usually inherited from a template, a reputation tool, or an EHR default nobody chose.
What goes in
The reviews you already have
Most practices arrive with something already sitting on Google, and usually with a decision to make about it.
An unsolicited positive review.
You did not solicit it, so you have not breached anything. What you do next is the question, and the answer is different for every one of the four bodies. Under ACA you may be able to use it after a documented permission conversation. Under NASW that conversation is itself off limits. We tell you which applies to you before anything gets touched.
Replying in public.
A review with identifying detail in it.
A negative one.
A widget you inherited.
What this costs
Compliant review collection, two ways in
- The removals half. A dated findings document naming every item, the specific fix, and the rule it comes from.
- None. The document is yours to act on.
- A practice that wants to know where it stands before committing to anything.
- Everything in the audit, implemented, plus the full build and the written policy.
- Done for you.
- A practice that wants this finished and documented.
Common questions
Need help with Website Design + Build?
Learn more about Website Design + Build here
Too busy to manage follow-up and admin workflows?
Learn more about Automation for Workflows here
