Attending Digital Health Festival? Click here.
The voice of business news for healthcare
A cybersecurity professional at a desk in front of computer screens smiling and explaining data security

Data security in healthcare marketing

×

Share this article

read time 3 min

Key takeaways

  • Thousands of Australian healthcare websites are unknowingly storing sensitive patient data because of a default WordPress setting.
  • Data saved in website form plugins often breaches the Privacy Act 1988, particularly APP 11 (Security) and APP 8 (Data Sovereignty).
  • This is a governance issue, not just an IT problem — business leaders remain legally responsible for protecting patient information.
  • A simple audit and reconfiguration of website forms can remove the vulnerability within minutes.
  • Secure alternatives such as referral-management and practice-management systems provide compliant pathways for patient data.
Partnered Content
This article was produced by Splice Marketing in collaboration with Veri Health as part of our Partner Content series, which showcases expert-led insights shaping the business of healthcare in Australia.

As healthcare leaders – founders, clinicians, and operators – we invest decades building our most valuable asset: patient trust.

But what if that trust is being silently compromised by a simple website setting you don’t even know about?

According to cybersecurity professional Jacob Zammit, Technical SEO Officer at Splice Marketing and holder of the (ISC)² Certified in Cybersecurity (CC) credential, the problem isn’t a sophisticated hack – it’s a default feature in the world’s most popular website platform, WordPress.

“We’ve audited hundreds of healthcare websites over the past few years,” Zammit says. “In more than half, patient referral data, NDIS information and even children’s details were being stored directly inside the site’s backend. It’s not malicious activity,  it’s just never been configured properly.”

The million-dollar risk hiding in your “Contact Us” form

When a web developer builds a form on a WordPress site, the plugin (such as Gravity Forms, Forminator or Contact Form 7) often defaults to Save all submissions to the database.

“For a plumber, that’s convenient,” Zammit explains. “For a medical clinic, it’s a compliance catastrophe.”

This single setting can create a “data honeypot” – a database containing every form submission, including referrals, medical histories and patient identifiers. Anyone with website-admin access such as staff, agencies or hackers exploiting weak passwords, can see it all.

This isn’t just PII. It’s a data profile.

Across audits, Zammit has uncovered: 

  • Full patient and GP referrals: Including detailed medical histories, symptoms, and private health information.
  • Vulnerable-patient data: NDIS status, details of social disadvantage, and whether clients identify as Aboriginal and/or Torres Strait Islander peoples.
  • Children’s data: Full names, dates of birth, and sensitive parental information from paediatric and allied health intake forms.
  • Financial and ID data: Medicare numbers, private health fund details, and even partial credit card numbers.
  • Publicly accessible files: In the most severe cases, uploaded patient referrals and job applicant resumes were found to be saved with a publicly accessible URL. Anyone with the direct link could download these confidential files.

“Storing that mix of information in one place,” he warns, “is like leaving your clinic’s filing cabinet unlocked in a public park.” 

Why this is a governance failure, not an IT problem

This isn’t just bad practice; it’s a critical failure of business governance and a likely breach of your legal obligations under the Privacy Act 1988.

Zammit points to two common violations:

  • APP 11 (Security): Storing unencrypted health data on a public webserver fails the test of “reasonable steps” to protect personal information.
  • APP 8 (Data Sovereignty): Forwarding submissions to Gmail or Google Sheets often means data is stored overseas without consent.

“Clinic owners sometimes assume this is their developer’s responsibility,” he says. “But under Australian privacy law, the business owner is accountable. Delegating doesn’t remove liability.”

Your three-step action plan

The good news is this is fixable. Here is your urgent action plan.

1. Ask your web team this one question today.

Email your website developer or marketing agency right now. Ask them this specific question:

“When a user submits a form on our website, where is that data being stored? Is a copy of the submission saved inside the WordPress dashboard or on the webserver?”

If the answer is “yes,” “on the website,” or “in the wp-admin,” you have a critical vulnerability that you must remediate immediately.

2. Conduct an urgent data flow audit

You must know what data you are collecting and where it is going.

  • Check every form: This includes your main contact form, new patient intake forms, GP referral forms, and even job application forms.
  • Turn off “Save Submissions” or “Retain Entries” on every single form.
  • Securely delete any existing data and permanently purge from the server database.

3. Implement a secure, compliant pathway

“Your website should be a conduit, not a container,” Zammit explains. “Sensitive data should flow directly into a secure, compliant system — never come to rest on the website itself.”

A secure pathway means the form submission is encrypted and sent directly into a compliant platform such as your practice management software (PMS), referral management system (RMS), or dedicated communications platform.

If you’re unsure whether that connection exists, speak with your RMS or PMS provider to confirm whether secure integrations are available and compliant with Australian privacy standards.

Stronger businesses don’t leak data

“A clinic that unknowingly leaks patient data isn’t just non-compliant – it’s at risk of losing the trust it’s built over decades,” Zammit says. “Fixing this takes minutes once you know it exists.”

Digital trust isn’t just an IT issue – it’s the foundation of modern healthcare leadership.By taking ownership of data governance, healthcare leaders protect not only patient privacy but also the integrity of their businesses.

Next steps

If you’re concerned about potential vulnerabilities in your clinic’s website or data-handling processes, Splice Marketing offers a complimentary security audit for healthcare organisations.

Chat with the team at splicemarketing.com.au/free-consultation to identify risks and strengthen your clinic’s digital defences.

 

Partnered Content
This article was produced by Splice Marketing in collaboration with Veri Health as part of our Partner Content series, which showcases expert-led insights shaping the business of healthcare in Australia.
Splice Marketing

Contributor

Splice Marketing is an Australian healthcare marketing and growth agency specialising in strategy, communications and digital solutions for healthcare providers. The team partners with medical, allied health and aged care organisations nationwide to help them grow ethically, communicate with impact and build patient-trusted digital foundations.

Jacob Zammit is Splice Marketing’s Technical SEO Officer and an (ISC)² Certified in Cybersecurity (CC) professional. He has conducted digital audits across hundreds of healthcare websites, helping clinics strengthen compliance, safeguard data and maintain patient trust online.

×

Share this article

Related business