How Amazon, Glassdoor, and Zocdoc Verify Reviews Differently
Drash Eldetron
Writes about digital privacy, reputation, and online presence.
September 3, 2026
“Report this review” sounds like the same button everywhere. What a platform actually checks before it does anything about it almost never is — Amazon alone blocked over 250 million suspected fake reviews in a single year, using a verification system that has nothing in common with how a healthcare or employer-review site checks anything.
Here's what four different categories of review platforms are actually verifying, and why that changes what a removal request needs to prove.
Quick overview
- Amazon verifies a real purchase; it doesn’t need to verify who you are.
- Glassdoor and Indeed do the opposite — they’re built to protect anonymity, and courts have backed that up even against legal requests to unmask a reviewer.
- Healthcare review sites vary a lot: Zocdoc requires an actual booked visit, while some competitors only confirm an email address.
- TripAdvisor looks for coordinated fake-review networks rather than checking any single transaction.
E-Commerce: Verified Transactions
Amazon’s “Verified Purchase” badge confirms one specific thing: that the reviewer bought the product on Amazon at a price generally available to other buyers. It doesn’t confirm anything about who the person is — it’s a transaction check, not an identity check, because Amazon’s own systems already hold the purchase record needed to verify it.
The scale of enforcement behind this is real: Amazon reports blocking or removing over 250 million suspected fake reviews in a single year, with more than 99% of reviews seen by customers assessed as authentic, backed by roughly 15,000 employees dedicated to store protection, legal action against more than 150 bad actors, and the takedown of 75 fake-review broker websites by mid-2024. All of that machinery exists to protect one specific claim — that the transaction behind the review is real.
Employer Reviews: Anonymity Is the Point
Employer-review platforms are built around the opposite priority. Indeed’s policy is explicit that reviews and Q&A content are anonymous, and employers are barred from trying to identify who wrote one. Glassdoor goes further: it has successfully protected reviewer anonymity in more than 100 legal cases, even when a company demands to know who wrote a review, by requiring the requesting party to establish a “prima facie” case before a court will even consider ordering disclosure.
A real example: in Glassdoor, Inc. v. Superior Court (Machine Zone), a California appeals court sided with Glassdoor when an employer tried to unmask an anonymous reviewer, because the employer hadn’t met that threshold. Worth being precise about what this case is actually about — it’s a fight over forcing a platform to reveal an identity, a different legal question from forcing a platform to remove content, which is the Section 230 territory covered in our separate piece on the legal reality behind review removal.
The reason the two platform types diverge so sharply comes down to what each business model depends on. Employees generally won’t write honestly about a workplace under their real name, so the platform’s entire value proposition rests on protecting anonymity.
E-commerce reviews depend on the opposite: proving the transaction actually happened.
Healthcare Reviews: Verification Varies More Than You’d Think
Even within one category, verification isn’t consistent. Zocdoc’s reviews come exclusively from patients who booked and attended an appointment through Zocdoc itself — a “hard” verification tied to its own scheduling system, with every review passing human moderation before it’s published. Healthgrades takes a lighter approach: it confirms a reviewer through an automated email or text message, which verifies contact information, not that the person was actually a patient at that specific practice. Vitals’ own public FAQ doesn’t describe a verification step for new reviews at all — worth noting as something not publicly specified, not evidence that no check exists.
One clarification worth making precisely: HIPAA does not apply to review platforms — they aren’t “covered entities” under the law.
What HIPAA actually restricts is the doctor or practice’s own response: a provider can’t confirm that someone was a patient, or discuss treatment details, in a public reply to a review, even if the patient brought it up publicly themselves. That’s a constraint on the practice responding, not on how the platform verifies the review in the first place — two different mechanisms people often blur together.
Travel and Hospitality: Fraud-Network Detection
TripAdvisor’s most recent transparency report describes a detection system built around neither transactions nor identity, but patterns: it reports preventing 2.7 million fraudulent reviews in a single year, with roughly 88% of submitted reviews clearing automated checks, about 7% automatically rejected, and the rest flagged for its Trust & Safety team, which manually reviewed over 4 million reviews that year.
The largest category of fraud it detects is “review-boosting” — coordinated campaigns of fake positive reviews meant to manipulate a listing’s ranking — accounting for more than half of everything flagged.
In enforcement terms, that meant warning around 9,000 businesses, removing 360,000 reviews tied to employee-incentive schemes, and flagging over 200,000 AI-generated reviews. None of that depends on verifying a single purchase or a single identity — it depends on spotting coordinated behavior across many accounts at once.
So What Does This Mean When You Report a Review
Four platform categories, four different questions being asked behind the scenes: did you really buy this, are you really an employee without being identifiable, were you really a patient, or is this part of a coordinated network? That’s why a generic “this review is fake, please remove it” request lands so differently depending on where it’s sent — the platform isn’t ignoring the request, it’s running it through whichever of these four checks actually applies to that category.
If Google is the platform in question, its own flagging, appeal, and escalation process is worth knowing in more detail than the transaction-versus-identity question covered here — see our 5-method Google review removal walkthrough.
Dealing with a specific platform? Get a free assessment of what a removal request would actually need to show in your case.
Frequently asked questions
Can a doctor confirm in a public review reply that someone was actually their patient?
No. HIPAA restricts the provider's own response, not how the platform verifies reviews. A doctor or practice can't confirm someone was a patient or discuss treatment details in a public reply, even if the patient brought it up publicly themselves.
What legal standard does a company have to meet to unmask an anonymous Glassdoor reviewer?
A "prima facie" case — meaning the company has to establish real evidence before a court will even consider ordering disclosure. In Glassdoor, Inc. v. Superior Court (Machine Zone), a California appeals court sided with Glassdoor because the employer hadn't met that threshold.
What's the most common type of fake review TripAdvisor's system catches?
"Review-boosting" — coordinated campaigns of fake positive reviews meant to manipulate a listing's ranking — accounts for more than half of everything TripAdvisor's Trust & Safety team flags.
How many fake reviews has Amazon actually taken action on?
A lot — Amazon reports blocking or removing over 250 million suspected fake reviews in a single year, backed by roughly 15,000 employees dedicated to store protection and legal action against more than 150 bad actors.
Prefer not to do this yourself?
We can take it from here
If the steps above don't get you the result you need, tell us what's going on and we'll take a look.
Get in touch