A new enquiry comes through your website at 9pm from someone who’s finally worked up the courage to reach out, and you can often tell from what they write that it hasn’t been an easy decision.
They leave their name, their number, and a few sentences about what’s going on, perhaps the anxiety keeping them from work, the pain that hasn’t eased after surgery, or the teenager they’re worried about. It’s rarely just a quick one-liner. People tend to share a little more because they want whoever reads it to understand what they’ve been dealing with before that first phone call.
Once they hit submit, they probably don’t think much about what happens next, but it’s worth asking where that message goes and who can see it.
Let’s get into it.
Table of Contents
ToggleTL;DR (Too Long; Didn’t Read) 👇
- Enquiry forms can feel like simple admin, but the moment someone shares symptoms, history, or anything personal, you’re dealing with sensitive health information.
- Depending on how the form is set up, that submission could be visible to your web agency, hosting provider, marketing team, or anyone with old backend access.
- Most of the time, that wasn’t a conscious decision. It’s just how the form was built and who still has access.
- The basics are pretty straightforward. Encrypt the data, store it in Australia, limit who can see it, and know how long you’re keeping it.
- We built SafeSubmit because we kept seeing this exact issue, and wanted to give health practices a simpler, safer way to handle website enquiries.
The grey zone
Here’s the assumption that causes trouble. “It’s just an enquiry form, not a patient record.”
Technically, that’s true. No file has been opened, no consent form signed, and no clinical relationship established. But people often use enquiry forms to share far more than a simple request for information. They describe symptoms, name conditions, mention medications, and explain what’s happening at home because they want the practice to understand them before that first call.
So while the form itself isn’t a patient record, it can still contain exactly the kind of personal and health information the Australian Privacy Act expects to be handled with care. That responsibility applies to the information itself, regardless of whether formal intake has started, with AHPRA-registered practitioners also carrying professional obligations around privacy.
The problem is that the enquiry form is often one of the least protected places that information ever sits.
-
Whoever’s CC’d on notifications
Practices sometimes CC their marketing agency on enquiry emails to track whether campaigns are working, but those notifications can include the full submission. That means an account manager may end up seeing very personal details when all they really need to know is that a new enquiry came through. -
Your web agency and hosting company
Form submissions are often stored in the website database, where anyone with backend access may be able to read them. That can include the agency maintaining the site and the hosting provider, even though nobody deliberately decided they should have access to years of patient enquiries. -
Whoever holds the data offshore
Many standard form tools store submissions wherever their servers are located, often outside Australia, with backups copied elsewhere too. Over time, the same enquiry can end up stored in multiple places without the practice having any real idea of where it lives. -
Potentially, an attacker
If a website is compromised, old form submissions sitting in the backend can become part of the breach. In one case, a surgical clinic found more than 2,000 enquiries stored in a hacked WordPress site, including patient details and information about their conditions, with copies held across offshore backups.
None of this usually happens because someone made a conscious choice. It happens because that’s how the form was set up, and nobody thought to revisit it.
The basics your enquiry form should cover
You don’t need to turn yourself into a security expert over this, but you do need to make sure that your enquiry handling meets a few sensible standards:
- Submissions encrypted where they're stored, not sitting there in plain text for anyone to open
- Stored in Australia, not scattered across whichever servers happened to be cheapest
- Readable only by the people at your practice who need to see it, full stop, not your host, not your web agency, not whoever else got CC'd along the way
- Notification emails that tell you an enquiry has arrived, without dragging the sensitive detail along with it
- A plain answer to "how long are we keeping these, and can we get rid of them if we want to"
The idea underneath all of this is pretty simple. The people who need to know an enquiry came in aren’t always the same people who need to read what’s in it. Your team may need the full details, while everyone else usually only needs to know that a new enquiry arrived.
It’s worth making clear that this is about the enquiry form, not clinical intake. Intake belongs in your practice management system, which was built for exactly that job. The gap tends to sit a step earlier, at the marketing-facing form where someone first reaches out. Because it technically belongs to the website rather than the clinical system, it can end up in a bit of a no-man’s-land where nobody’s really claimed responsibility for how secure it is.
The five-minute audit
You don’t need a consultant for this one. Grab five minutes and run through it yourself.
- Open one of your own notification emails. Who’s on it, and does it carry the whole submission or just a heads-up that one arrived?
- Ask who has backend access to your website. Every login on that list can probably read stored submissions, needed or not.
- Ask where submissions are stored. If the answer isn’t “encrypted, in Australia,” note that.
- Check how far back your stored enquiries go, and if anyone could delete them if you asked.
- Ask the person who built your site whether submissions are encrypted at rest. If the reply is a pause, you have your answer.
If everything checks out, great. You’re already in a better position than a lot of practices. If something looks off, the fix is usually much simpler than people expect.
It’s exactly this problem that led us to build SafeSubmit, an enquiry form designed for health websites. It encrypts submissions, stores them in Australia, keeps sensitive details out of notification emails, and puts the full enquiry behind the practice’s own secure login. If a marketing agency needs to track leads, they can still see that an enquiry came through without seeing what the person actually wrote.
Either way, it’s worth knowing what happens after someone hits submit. The person sharing something deeply personal probably isn’t thinking about where that information goes. They’re simply trusting that the practice has it handled.