• About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Disclaimer
  • Sitemap
Tuesday, September 15, 2026
The AUSTRALIAN BUSINESS JOURNAL
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech
No Result
View All Result
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech
No Result
View All Result
Australian Business Journal
No Result
View All Result
Home Featured

The Healthcare Privacy Risk Hiding in an Ordinary Website Contact Form

by ABJ Staff
September 14, 2026
in Featured
0
Share on FacebookShare on Twitter

Someone looking for a psychologist might use a website enquiry form to explain their anxiety. A prospective patient contacting a specialist could describe a medical condition, symptoms, or treatment history. Another person might include details about their family, mental health, or circumstances because they assume the information is going directly to the practitioner they are trying to reach.

What they probably aren’t thinking about is who else can read it.

That question led Brisbane digital agency Excite Media to develop SafeSubmit, an Australian SaaS platform designed specifically to protect sensitive information submitted through healthcare websites.

The idea emerged from something the Excite Media team was encountering in its everyday work with health practices: general-purpose website forms could leave deeply personal information accessible in places, and to people, that neither the patient nor the practice necessarily expected.

For SafeSubmit’s Co-Founder, Scott Maynard, the problem raised a straightforward question about how access to personal data is handled.

“The practices trust us to manage their websites and marketing, but we don’t need to read someone’s private story to know a real enquiry has come through,” he says. “Those details aren’t ours to see.”

What Happens After Someone Clicks Submit?

Contact forms are among the most ordinary features on the internet, which is partly why their privacy implications can be easy to overlook.

A standard form may send the complete submission to a practice by email. A copy can also remain in the website database and subsequently appear in backups. Depending on how the site is configured, people with administrative or technical access, including web developers, agencies, hosting providers and software suppliers, may potentially encounter the information.

For a restaurant booking or general retail enquiry, that might involve relatively mundane details. Healthcare changes the stakes.

People frequently provide information well beyond their name and phone number when trying to explain why they need an appointment. Medical conditions, mental health concerns and sensitive personal circumstances can enter the system before the individual has ever spoken to the practice.

That makes the enquiry form an unusual point in the healthcare journey. The person isn’t yet an established patient whose information is sitting within a dedicated practice management system, but they may already be disclosing information that deserves a comparable level of care.

Finding the Gap Between Two Systems

SafeSubmit was developed by Excite Media around that specific gap.

Practice management platforms are designed to manage established patient relationships, including appointments, clinical records and billing. Website platforms such as WordPress, Wix and Squarespace serve a different purpose and their general-purpose form functionality isn’t necessarily designed around sensitive healthcare information. SafeSubmit sits between the two.

Rather than allowing the full contents of an enquiry to travel through the usual chain in plain text, submissions are encrypted and stored in Australian data centres. Authorised members of the healthcare practice access the complete information through a secure portal using a PIN controlled by the practice.

Other parties involved in maintaining the website can know an enquiry has arrived without seeing the person’s identifying details or the private information contained within it.

“The people responding to an enquiry may need the full context,” Maynard says. “Everyone else only needs to know that it has arrived.”

Healthcare’s Data Problem Extends Beyond Hackers

The timing is significant. Australian health service providers have consistently ranked among the sectors reporting the greatest number of data breaches. In 2025, the Office of the Australian Information Commissioner (OAIC) received a record 1,205 breach notifications across all sectors. Health service providers accounted for 225, or 19 per cent, making healthcare the most commonly affected sector.

Cyberattacks remain the dominant cause nationally, but the figures also highlight a less dramatic source of privacy risk: ordinary human and operational mistakes.

In the second half of 2024, for example, health service providers reported 45 breaches attributed to human error, alongside 72 caused by malicious or criminal attacks.

That distinction matters because improving privacy cannot depend entirely on stopping sophisticated attackers. It also involves examining where information is collected, how many copies exist, who can access them and whether those people genuinely need that access.

SafeSubmit approaches the problem from that direction: reduce the number of places sensitive information is exposed in the first place.

Designing Around What People Actually Write

The platform retains some of the functionality practices expect from an enquiry-management system. Its portal includes anonymised summaries, spam detection, enquiry scoring and a pipeline for moving enquiries through stages such as new, processing, follow-up and booked.

The difference lies in separating useful operational information from personally identifiable information.

That distinction also reflects how SafeSubmit came about. It wasn’t developed from a theoretical cybersecurity problem, but from Excite Media’s experience managing healthcare websites and seeing what prospective patients actually typed into forms.

Website designers may intend a field labelled “How can we help?” to collect enough information to route an enquiry. Someone experiencing a difficult or highly personal situation may interpret that invitation very differently.

Once submitted, their story becomes data. The question then becomes whether every system and organisation involved in delivering the website should be able to see it.

Privacy Before Someone Becomes a Patient

SafeSubmit’s development points to a broader issue in digital healthcare: privacy begins earlier than the clinical relationship.

A person’s first interaction with a practice may happen through Google, a website and an enquiry form long before they enter a consulting room or patient management system. Yet those first few minutes can involve some of the most personal information they will share.

The OAIC’s figures make the consequences of poor information handling increasingly difficult for healthcare organisations to ignore. Health service providers have remained among Australia’s most frequently affected sectors since the Notifiable Data Breaches scheme began.

SafeSubmit’s answer is not to redesign the entire patient journey. It focuses on one comparatively small stage that its founders believe has received too little attention.

That may ultimately be the more interesting story behind the platform. A privacy problem doesn’t have to begin with a dramatic cyberattack or a compromised clinical database. Sometimes it starts much earlier, with an ordinary box on a website and a person trusting that whatever they type into it will only be read by the people they intended to tell.

To learn more about SafeSubmit, visit safesubmit.com.au. 

ABJ Staff

ABJ Staff

The ABJ Staff cover a variety of stories from Australia and beyond. The ABJ Staff enjoy highlighting the work of entrepreneurs, thought leaders, business owners, and creatives with branded content.

Please login to join discussion

Popular News

  • Beyond Orthotics: Advance Foot Clinic Brings New Technology Into Everyday Podiatry

    0 shares
    Share 0 Tweet 0
  • 10 Australian Strategy Consultants Leading Change in 2026

    0 shares
    Share 0 Tweet 0
  • Marketing Bee Strengthens Its Position as a Global Growth Partner for Leading Asian & International Brands

    0 shares
    Share 0 Tweet 0
  • Centrelink May 2025 Payment Changes: New Rates, Key Dates & Eligibility Explained

    0 shares
    Share 0 Tweet 0
  • National Cabinet Agrees to New Rules for AI Data Centres

    0 shares
    Share 0 Tweet 0
  • About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Disclaimer
  • Sitemap

© 2021 The ABJ -The Australian Business Journal. All Rights Reserved.

No Result
View All Result
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech

© 2021 The ABJ -The Australian Business Journal. All Rights Reserved.