As healthcare leaders – founders, clinicians, and operators – we invest decades building our most valuable asset: patient trust.
But what if that trust is being silently compromised by a simple website setting you don’t even know about?
According to cybersecurity professional Jacob Zammit, Technical SEO Officer at Splice Marketing and holder of the (ISC)² Certified in Cybersecurity (CC) credential, the problem isn’t a sophisticated hack – it’s a default feature in the world’s most popular website platform, WordPress.
“We’ve audited hundreds of healthcare websites over the past few years,” Zammit says. “In more than half, patient referral data, NDIS information and even children’s details were being stored directly inside the site’s backend. It’s not malicious activity, it’s just never been configured properly.”
The million-dollar risk hiding in your “Contact Us” form
When a web developer builds a form on a WordPress site, the plugin (such as Gravity Forms, Forminator or Contact Form 7) often defaults to Save all submissions to the database.
“For a plumber, that’s convenient,” Zammit explains. “For a medical clinic, it’s a compliance catastrophe.”
This single setting can create a “data honeypot” – a database containing every form submission, including referrals, medical histories and patient identifiers. Anyone with website-admin access such as staff, agencies or hackers exploiting weak passwords, can see it all.
This isn’t just PII. It’s a data profile.
Across audits, Zammit has uncovered:
- Full patient and GP referrals: Including detailed medical histories, symptoms, and private health information.
- Vulnerable-patient data: NDIS status, details of social disadvantage, and whether clients identify as Aboriginal and/or Torres Strait Islander peoples.
- Children’s data: Full names, dates of birth, and sensitive parental information from paediatric and allied health intake forms.
- Financial and ID data: Medicare numbers, private health fund details, and even partial credit card numbers.
- Publicly accessible files: In the most severe cases, uploaded patient referrals and job applicant resumes were found to be saved with a publicly accessible URL. Anyone with the direct link could download these confidential files.
“Storing that mix of information in one place,” he warns, “is like leaving your clinic’s filing cabinet unlocked in a public park.”
Why this is a governance failure, not an IT problem
This isn’t just bad practice; it’s a critical failure of business governance and a likely breach of your legal obligations under the Privacy Act 1988.
Zammit points to two common violations:
- APP 11 (Security): Storing unencrypted health data on a public webserver fails the test of “reasonable steps” to protect personal information.
- APP 8 (Data Sovereignty): Forwarding submissions to Gmail or Google Sheets often means data is stored overseas without consent.
“Clinic owners sometimes assume this is their developer’s responsibility,” he says. “But under Australian privacy law, the business owner is accountable. Delegating doesn’t remove liability.”
Your three-step action plan
The good news is this is fixable. Here is your urgent action plan.
1. Ask your web team this one question today.
Email your website developer or marketing agency right now. Ask them this specific question:
“When a user submits a form on our website, where is that data being stored? Is a copy of the submission saved inside the WordPress dashboard or on the webserver?”
If the answer is “yes,” “on the website,” or “in the wp-admin,” you have a critical vulnerability that you must remediate immediately.
2. Conduct an urgent data flow audit
You must know what data you are collecting and where it is going.
- Check every form: This includes your main contact form, new patient intake forms, GP referral forms, and even job application forms.
- Turn off “Save Submissions” or “Retain Entries” on every single form.
- Securely delete any existing data and permanently purge from the server database.
3. Implement a secure, compliant pathway
“Your website should be a conduit, not a container,” Zammit explains. “Sensitive data should flow directly into a secure, compliant system — never come to rest on the website itself.”
A secure pathway means the form submission is encrypted and sent directly into a compliant platform such as your practice management software (PMS), referral management system (RMS), or dedicated communications platform.
If you’re unsure whether that connection exists, speak with your RMS or PMS provider to confirm whether secure integrations are available and compliant with Australian privacy standards.
Stronger businesses don’t leak data
“A clinic that unknowingly leaks patient data isn’t just non-compliant – it’s at risk of losing the trust it’s built over decades,” Zammit says. “Fixing this takes minutes once you know it exists.”
Digital trust isn’t just an IT issue – it’s the foundation of modern healthcare leadership.By taking ownership of data governance, healthcare leaders protect not only patient privacy but also the integrity of their businesses.
Next steps
If you’re concerned about potential vulnerabilities in your clinic’s website or data-handling processes, Splice Marketing offers a complimentary security audit for healthcare organisations.
Chat with the team at splicemarketing.com.au/free-consultation to identify risks and strengthen your clinic’s digital defences.





Clinical & consumer healthMarket intelligence & industry trendsPolicy reformsPolicy, compliance & governance
Building pressure: what’s straining Australia’s hospitals and how to build resilience