Your Social Feed Widget Is Republishing Banned Testimonials
A live Instagram or Facebook feed widget on a clinic website pulls in captions, tagged photos and comment threads automatically, and any of those can carry a patient's clinical statement. Section 133 of the National Law bans testimonials in advertising a regulated health service, and AHPRA's cosmetic guidelines treat that republished content the same as a testimonial the clinic wrote.

Key Takeaways
- Section 133 of the Health Practitioner Regulation National Law bans testimonials referring to a clinical aspect: an outcome, a recommendation, or a practitioner’s skill
- AHPRA’s cosmetic procedure advertising guidelines, in effect since 2 September 2025, apply to that ban and to the newer higher risk non-surgical cosmetic category specifically
- A live feed widget republishes whatever exists on the source platform the moment it loads, including comment threads no one at the clinic has read
- AHPRA’s position is that sharing, replying to or otherwise amplifying patient content on a channel the clinic controls is using a testimonial in advertising
- AHPRA’s own guidance suggests practitioners can reduce this exposure by disabling reviews, comments or tagging functions on their social platforms
- The maximum penalty under section 133 is $60,000 for an individual and $120,000 for a body corporate, per offence
- No published AHPRA determination names a feed-embed widget specifically. The regulator’s posture on amplified patient content is on the record; a case naming this exact mechanism is not
A live Instagram or Facebook feed embed on a clinic website pulls in captions, tagged photos and comment threads automatically, and any one of those can carry a clinical statement, a patient’s comment describing how their filler turned out, a caption naming a treatment result. AHPRA’s guidelines for advertising higher risk non-surgical cosmetic procedures, in effect since 2 September 2025, treat republished patient content the same as a testimonial the clinic wrote itself once it is amplified on a channel the clinic controls. A widget has no way to check a comment before it renders it. As at 18 August 2026, that gap between what a feed widget does and what the advertising rules require is the actual exposure, not the underlying Instagram post.
What AHPRA’s Guidelines Say
The relevant source is AHPRA’s Guidelines for advertising higher risk non-surgical cosmetic procedures, in effect since 2 September 2025. They sit alongside section 133 of the Health Practitioner Regulation National Law, which bans testimonials in advertising a regulated health service generally, and apply specifically to the higher risk category the guidelines name: injectables, dermal fillers, thread lifts and similar procedures.
Three things the guidance sets out matter for a feed embed specifically.
First, scope. The ban binds registered health practitioners, non-registered individuals, and businesses, partnerships and corporate entities that advertise these procedures. A clinic company installing a widget is squarely inside that scope, the same way a practitioner posting directly is.
Second, what counts as a testimonial in this context. Guidance summarising the AHPRA text describes a clinical aspect as a positive statement about the experience of, the reason for, or the outcome of a procedure, or a statement about a practitioner’s skill or experience. That description covers a huge share of what patients write, unprompted, in comments under a clinic’s own posts.
Third, and most directly relevant here, the interaction rule. AHPRA’s guidance is explicit that a practitioner does not become responsible for a testimonial simply because a patient posted one, unprompted, on a platform the practitioner does not control. Responsibility begins with amplification, sharing, reposting or otherwise bringing that content onto a channel the clinic does control. Guidance built from the source material puts it plainly: the moment a clinic shares, reposts or amplifies patient content endorsing a clinical outcome, it has used a testimonial in advertising. AHPRA’s own material on minimising this risk points practitioners toward disabling reviews, comments or tagging functions on their social platforms, precisely because those functions are where uncontrolled patient content accumulates.
A live feed widget does the amplifying automatically. It has no setting for “only republish the compliant comments.”
The figures above are an illustrative model of how much a clinic reviews before each content type reaches its own site, not a measured audit. The point they encode holds regardless of the exact numbers: a caption is something the clinic wrote and can check. A comment thread is something a stranger wrote five minutes ago, and a live widget publishes it with nobody in the loop.
What That Means for the Build
A feed embed is usually a third-party script or iframe, tools like Elfsight, SnapWidget, Curator.io, or Meta’s own oEmbed and Graph API feed plugins, dropped into a page template and left running. Fixing the compliance gap is a configuration and architecture decision, not a content decision made after the fact.
Turn off comment rendering in the widget’s settings first. Every mainstream feed embed tool has a toggle to show or hide comments and likes counts alongside each post. This is the single highest-value change because it removes the content type the clinic has zero pre-publication control over.
Check whether the widget also pulls tagged photos or a hashtag search, not just the account’s own posts. Some feed plugins default to a combined view: your posts, photos you’re tagged in, and posts using a branded hashtag. A tagged photo can be a patient’s own after photo with a caption describing their result, published without the clinic ever seeing it first.
Route the feed through a moderation queue if you need comments visible for engagement reasons. A small number of tools support an approval step before a post (and its comment count) goes live. If genuine interactivity matters more than the aggregate rating pattern used elsewhere on the site, this is the build that keeps it defensible: nothing renders without a human decision recorded against it.
Cache the feed rather than rendering it live client-side, if you keep it at all. A server-side fetch on a schedule, once daily, gives a person a window to review what changed before the next publish, instead of a visitor’s browser pulling straight from the platform’s live API on every page load.
Audit the account the widget points at, separately from the site. If the source Instagram account has comments enabled and the clinic account interacts with patient comments there (a like, a reply, a heart emoji), that interaction is itself inside the ban regardless of what the website widget does. Fixing the widget and leaving the source account’s comment behaviour unchanged only half solves it.
Exposure here is a build assessment of how much unreviewed patient content can reach the page, not a regulator’s scoring system. Comments-off still leaves captions and tagged content in the mix, which is why it sits at 55, not near zero.
Embed Setting by What Renders on the Page
| Embed setting | What patients can post | What renders on your site | Build effort to fix |
|---|---|---|---|
| Live feed, comments and tagging on | Anything, in a comment, on a tagged photo | Everything, unmoderated, live | Low, it’s a toggle |
| Live feed, comments off, tagging on | Comments hidden; tagged photos still flow through | Captions and tagged photos only | Low, same toggle set |
| Live feed with moderation queue | Anything, held for review before publish | Only what’s been approved | Medium, needs a review step in the workflow |
| Curated manual grid | Nothing automatically; posts chosen and copied in by hand | Only what a person selected | Medium, ongoing manual maintenance |
| Link out to the Instagram profile | Anything, but it stays on Instagram | Nothing republished on your site | Low, it’s a link, not an embed |
A Worked Example
Cosmetic clinic. A Perth injectables clinic ran a “Follow us” feed widget on its homepage showing the last twelve Instagram posts with comments visible. Three of the most-liked posts had comment threads that included variations of “you look amazing, best filler I’ve ever had done” from patients tagged in the photo. None of it was written by the clinic. All of it was rendering, live, on the clinic’s own homepage, twenty-four hours a day. Turning off comment display in the widget’s settings panel took under five minutes and removed the highest-risk content immediately, without touching the Instagram account itself or asking any patient to take anything down.
The clinic then separately reviewed its Instagram account’s own comment behaviour and found staff had liked several of those same comments from the account, which is its own exposure regardless of what the website widget shows. Both fixes were needed. Neither one covered the other.
A quarter of the posts on that one clinic’s feed carried a comment thread worth flagging, on a widget that was rendering all twelve live and unmoderated. That ratio is specific to this worked example, not a claimed industry average, but it shows how little content needs to be risky before an entire feed is exposed.
What to Check on Your Own Site
- Find every page running a social feed widget, including the footer and any landing page built for a specific procedure.
- Open the widget’s settings and check whether comments, likes and tagged content are set to show or hide.
- Read the comment thread under your ten most recent displayed posts. Does any comment describe a symptom, a treatment or a result?
- Check whether the widget is pulling a hashtag search or a tagged-photos feed as well as your own account’s posts.
- Check your source Instagram and Facebook accounts for staff likes or replies on patient comments, separately from the widget.
- Confirm whether the widget renders live in the visitor’s browser or from a cached, server-side fetch you can review on a schedule.
The Enforcement Anchor
AHPRA’s guidelines state that National Boards and AHPRA deal with non-compliant advertising through Board disciplinary processes where conduct is considered unsatisfactory, and through prosecuting breaches of the National Law’s advertising provisions via the court system where prosecution guidelines are met. AHPRA has also stated publicly, in announcing the cosmetic procedure guideline package, that the sector is on notice and that the regulator would act where practitioners were found prioritising profit over patient care.
That is the enforcement mechanism and posture on the record. A published Australian determination turning specifically on a live feed embed widget, as opposed to a manually posted testimonial or a reviews widget, is not something we can point to. Reporting that honestly, rather than dressing up a general posture as a specific case, is the point of this category.
Both figures are the statutory ceiling per offence, not a typical or an average fine. A body corporate’s exposure runs to double an individual’s, on the same section of the same National Law, for the same republished comment.
Where This Gets Hard
The commercial logic behind these widgets is real. A live feed makes a site feel current, patients do genuinely comment enthusiastic things unprompted, and disabling comments feels like muting your own happiest patients. None of that changes what section 133 restricts, and a clinic weighing “should I keep this feature” against “what does the rule say” is making a business decision layered on top of a compliance one, not instead of it.
There is also a technical honesty point. Some widget vendors advertise “moderation” features that filter by keyword or sentiment rather than by clinical content specifically. A sentiment filter will happily pass “you’re the best!!” straight through, and that comment, sitting under a photo of a treatment, can still be exactly the kind of clinical endorsement the guidelines target. Do not treat a generic content filter as a compliance filter without checking what it is matching on.
The regulator says advertising a regulated health service must not use testimonials referring to a clinical aspect, and that amplifying patient content on a channel you control counts as using one; the build consequence is that a live, unmoderated feed widget has to be reconfigured, cached, or replaced with something a person reviews before it publishes; whether your specific widget configuration and account behaviour together discharge that obligation is a question for your medical defence organisation or your lawyer.
Status
In force. Section 133 of the Health Practitioner Regulation National Law is current legislation, and AHPRA’s guidelines for advertising higher risk non-surgical cosmetic procedures carry an effective date of 2 September 2025 and remain in effect as at 18 August 2026. Nothing in this post concerns a proposal or a provision pending commencement.
Frequently Asked Questions
Does embedding an Instagram or Facebook feed on my clinic website count as advertising?
Yes, if the widget displays content relating to a regulated health service on a channel the clinic controls. AHPRA’s guidance treats sharing, reposting or amplifying patient content on your own channels as using a testimonial in advertising, and a live feed widget performs that act automatically every time it refreshes.
Can I keep the feed running if I just hide the comments?
Hiding the comment thread removes the highest-risk surface, since a patient’s own comment is the content the clinic has the least control over before it renders. It does not clear the caption if the clinic wrote language describing an outcome, and it does not clear a tagged photo showing a result, so hiding comments is a partial fix, not a complete one.
Does the testimonial ban apply to a patient’s own Instagram comment if the clinic never asked for it?
The comment itself, sitting on Instagram, is not the clinic’s advertising. AHPRA’s guidance draws the line at interaction, liking, replying to or republishing that comment on a channel the clinic controls is what brings it inside the ban. A live feed widget performs that republishing step without a person deciding to do it.
What is the actual penalty if a feed embed republishes a testimonial?
Section 133 of the Health Practitioner Regulation National Law sets a maximum penalty of $60,000 for an individual and $120,000 for a body corporate per offence, the same maximum that applies to any other advertising breach of that section, including a written or video testimonial.
Get Your Social Widgets Audited
Get in touch with RockingWeb to check every feed widget, review plugin and footer embed on your site against the testimonial rule, and get a report on which settings are safe to leave running and which need to change.
Sources
- AHPRA - Guidelines for advertising higher risk non-surgical cosmetic procedures, in effect since 2 September 2025, including scope, the testimonial and interaction rules, and dealing with non-compliance. Checked 18 August 2026.
- AHPRA - Booming billion-dollar cosmetic industry on notice with new cosmetic procedures guidelines, 3 June 2025. Checked 18 August 2026.
- Federal Register of Legislation - Health Practitioner Regulation National Law, section 133, testimonial prohibition and maximum penalties. Checked 18 August 2026.
Related reading: Why you cannot embed a reviews widget on a health website and what clinics can post on Instagram under AHPRA’s guidelines.
Last reviewed: 18 August 2026.

Vikas Thakur
Founder of RockingWeb. 16 years building for companies like TPG, iiNet and Monadelphous, now focused on websites and marketing that comply with AHPRA's advertising guidelines and still book patients.





