Secure enquiry forms for Australian health practices

Your patient enquiries pass through more hands than you think.

An ordinary form emails the whole enquiry to everyone it's set to notify, and keeps a copy forever. With SafeSubmit, the email is masked and the full enquiry stays encrypted, in Australia, for your staff only.

SafeSubmit works with the enquiry form already on your website, on WordPress, Wix, Squarespace and most other platforms. Patients see nothing different.

What changes
Before Ordinary form
Search mail
Inbox14 Starred Sent Drafts
New enquiry: Sarah Mitchell
W
WordPress <[email protected]>
to me, reception, marketing@youragency, support@yourhost
NameSarah Mitchell Phone0491 570 156 Email[email protected] MessageHi, since my marriage ended I've been drinking more than I should and I'm not coping at work. My GP suggested I talk to someone. Do you have anything in the next few weeks?
  • Full enquiry in plain text
  • Read by staff, and outsiders like IT and marketing
  • Not encrypted where it's stored
  • Stored in multiple locations, possibly overseas
  • Kept forever
After Secured by SafeSubmit
Search mail
Inbox14 Starred Sent Drafts
New enquiry: S•••• M•••••••
SafeSubmit <[email protected]>
to me
NameS•••• M••••••• Phone•••• ••• •56 SummaryNew client, GP referral, asking about availability in the next few weeks.
Enter PIN to view the full enquiry
  • Masked in the email
  • For your staff only
  • Encrypted where it's stored
  • Held in an Australian data centre
  • Gone when you say so

Why it matters

Your enquiry form could be leaking private  patient information.

On a psychology, surgery or allied-health website, people routinely type deeply personal details into the contact form - conditions, symptoms, medications - right next to their name and phone number. On a typical WordPress, Wix or Squarespace site, here is what actually happens to it.

A typical website form
  • Emailed in plain text - readable by anyone in the inbox or mail server it passes through
  • Saved in the website database unencrypted, and kept there indefinitely
  • Visible to your web agency, hosting company and plugin providers
  • Copied into automatic backups, scattered across multiple servers
  • A prime target for hackers - health data is among the most valuable to steal
  • Often processed or stored overseas, outside Australian jurisdiction
With SafeSubmit
  • Encrypted the instant it’s submitted
  • Stored encrypted in a secure Australian data centre - never in plain text
  • Only you, the business owner, can unlock the submissions
  • Your agency, your host - even our own team - never see the contents
  • Nothing legible sits in databases, inboxes or backups to be stolen
  • Built to align with the Privacy Act and AHPRA record-keeping guidance

The hidden trail

One enquiry. Look how far it travels.

A patient fills in your form once, meaning it for you. But on an ordinary website that single submission is copied, forwarded and stored in places most practices never see. Every copy is another set of eyes on information you’re obligated to protect.

1 patient enquiry

“Hi, I’ve been managing depression and would like to book…”

Name · phone · email · health details

  • Your web agencyfull admin & database access
  • The hosting companyreads the raw database
  • Email servers en routeplain text, each hop
  • Form & plugin vendorsthird-party tools
  • Automatic backupsretained for years
  • Servers overseasoutside Australian law
6+ parties and places can quietly read a single enquiry - often many more, and none of it under your control
1 with SafeSubmit, only you can read it - unlocked with your passcode, and no one else’s

How it works

Private by design - not by policy.

SafeSubmit isn’t another form builder - it’s a secure form processor. Your website keeps an enquiry form that looks and works the way it does now; SafeSubmit takes over the moment someone presses send, so the security lives where it actually matters - in what happens to the data.

1

A patient submits

Their name, contact details and message are encrypted before they are sent, and they remain encrypted when they are stored.

2

Stored safely in Australia

The encrypted enquiry rests in a secure Australian data centre. Even if someone accessed the submission, it would be unreadable noise.

3

Only you can read it

You unlock enquiries with your own passcode. No agency, host or third party - including us - can view them.

Works with your website

Compatible with virtually every website platform.

SafeSubmit isn’t a form builder or a plugin you have to hope exists for your platform. It’s a form processor - any standard HTML form can send its submissions straight to your secure SafeSubmit endpoint, whether that’s the form your site already has or a simple like-for-like replacement. So it works on virtually every website platform.

…and every other platform that can host a standard HTML form - including fully custom-built websites.

Why we built this

Too many times we saw patient enquiries exposed.

SafeSubmit grew out of an uncomfortable truth we kept running into at our agency. Too many times we saw health practice websites that didn't treat initial patient enquiries with an appropriate level of privacy. Every time a patient filled in a contact form, those enquiries were being stored in plain-text for anyone who manages the website to see (not just the practice owner).

Full names. Phone numbers. Detailed explanations of mental health conditions. Information that was meant only for the clinician. And yet, many other parties (including us as the agency) were being granted access to that information.

It didn't feel right. And the more we noticed this happening, the more we realised most of our clients were completely unaware there was even an issue - let alone that it made them genuinely non-compliant. Even initial enquiries count as sensitive health information under the Privacy Act and AHPRA guidelines, and ordinary contact forms simply aren't built to handle that.

Platforms like WordPress make this worse. They're powerful, but they're inherently open - your web agency, your host, your plugin providers and your backup services all have varying degrees of access to everything that comes through. While that might be fine for a café booking. It's not fine for a patient disclosing their mental health history.

So we built SafeSubmit. With it, we still support the clinics we work with - but now we only see a high-level summary of enquiries (enough to gauge enquiry relevance), never the personal details that aren't ours to read. And more importantly, neither does anyone else.

"We saw countless health practice websites unknowingly giving away access to their patient enquiries - including full names, explanations of mental health conditions - and it didn't feel right."

The team that built SafeSubmit

With SafeSubmit, your agency can still support you - but they only see a summary, never the personal details that aren't theirs to read.

Built for Australian obligations

Helping you meet the Privacy Act and AHPRA expectations.

Health practitioners are held to a high standard for handling personal and health information. Collecting sensitive details through an ordinary, unprotected form can put your practice at risk of non-compliance. SafeSubmit is designed from the ground up to keep that information confidential, in Australia, and under your control.

  • Australian Privacy Principles Sensitive information is encrypted, access-controlled and kept onshore.
  • AHPRA & health records guidance Confidential handling of patient information from the very first contact.
  • Data sovereignty Stored in Australian data centres.

Free form check

See if your current form complies with patient privacy requirements.

Send us your website address and we’ll review the enquiry form you’re using now to identify any privacy issues. We'll show you what’s exposed, where it ends up, and how SafeSubmit would close the gaps.

  • A plain-English review of your existing form
  • What it means for the Privacy Act & AHPRA
  • We reply within one business day
We’ll never share your details.