Who’s reading your patient enquiries, and what happens to them after?

Time to read: 5 minutes

A new enquiry comes through your website at 9pm from someone who’s finally worked up the courage to reach out, and you can often tell from what they write that it hasn’t been an easy decision.

They leave their name, their number, and a few sentences about what’s going on, perhaps the anxiety keeping them from work, the pain that hasn’t eased after surgery, or the teenager they’re worried about. It’s rarely just a quick one-liner. People tend to share a little more because they want whoever reads it to understand what they’ve been dealing with before that first phone call.

Once they hit submit, they probably don’t think much about what happens next, but it’s worth asking where that message goes and who can see it.

Let’s get into it.

The grey zone

Here’s the assumption that causes trouble. “It’s just an enquiry form, not a patient record.”

Technically, that’s true. No file has been opened, no consent form signed, and no clinical relationship established. But people often use enquiry forms to share far more than a simple request for information. They describe symptoms, name conditions, mention medications, and explain what’s happening at home because they want the practice to understand them before that first call.

So while the form itself isn’t a patient record, it can still contain exactly the kind of personal and health information the Australian Privacy Act expects to be handled with care. That responsibility applies to the information itself, regardless of whether formal intake has started, with AHPRA-registered practitioners also carrying professional obligations around privacy.

The problem is that the enquiry form is often one of the least protected places that information ever sits.

None of this usually happens because someone made a conscious choice. It happens because that’s how the form was set up, and nobody thought to revisit it.

The basics your enquiry form should cover

You don’t need to turn yourself into a security expert over this, but you do need to make sure that your enquiry handling meets a few sensible standards:

The idea underneath all of this is pretty simple. The people who need to know an enquiry came in aren’t always the same people who need to read what’s in it. Your team may need the full details, while everyone else usually only needs to know that a new enquiry arrived.

It’s worth making clear that this is about the enquiry form, not clinical intake. Intake belongs in your practice management system, which was built for exactly that job. The gap tends to sit a step earlier, at the marketing-facing form where someone first reaches out. Because it technically belongs to the website rather than the clinical system, it can end up in a bit of a no-man’s-land where nobody’s really claimed responsibility for how secure it is.

Geoff collaborating with a colleague during a strategy session at the Excite Media office.

The five-minute audit

You don’t need a consultant for this one. Grab five minutes and run through it yourself.

  1. Open one of your own notification emails. Who’s on it, and does it carry the whole submission or just a heads-up that one arrived?
  2. Ask who has backend access to your website. Every login on that list can probably read stored submissions, needed or not.
  3. Ask where submissions are stored. If the answer isn’t “encrypted, in Australia,” note that.
  4. Check how far back your stored enquiries go, and if anyone could delete them if you asked.
  5. Ask the person who built your site whether submissions are encrypted at rest. If the reply is a pause, you have your answer.


If everything checks out, great. You’re already in a better position than a lot of practices. If something looks off, the fix is usually much simpler than people expect.

It’s exactly this problem that led us to build SafeSubmit, an enquiry form designed for health websites. It encrypts submissions, stores them in Australia, keeps sensitive details out of notification emails, and puts the full enquiry behind the practice’s own secure login. If a marketing agency needs to track leads, they can still see that an enquiry came through without seeing what the person actually wrote.

Either way, it’s worth knowing what happens after someone hits submit. The person sharing something deeply personal probably isn’t thinking about where that information goes. They’re simply trusting that the practice has it handled.

Nathanael Hubbard
AUTHOR

Nathanael Hubbard

Managing Director | Founder

Nathanael is the co-CEO and Co-Founder of Excite Media, which he founded alongside Scott Maynard in the early 2000s. He holds a Bachelor of Popular Music from the Queensland Conservatorium of Music and a Masters of Information Technology from the University of Queensland. Passionate about helping people (and businesses) discover what they want, why they want it, and how to achieve it, Nathanael leverages his diverse skill set to drive success in the digital marketing landscape.

Ready to chat with us?

google icon
5 stars

200+ 5-star reviews