Security for dental, physio and med-spa clinics

Ontario's Personal Health Information Protection Act makes clinics accountable for the patient information they collect, including what passes through their website, booking system and intake forms.

Most clinic sites were built by an agency and haven't been reviewed since. The gaps are rarely dramatic, but they're exactly what gets found when someone goes looking.

What usually turns up

These are the gaps most often found when businesses like yours are checked from the outside.

  • Staging sites or admin logins reachable from the public internet
  • Booking or intake widgets loaded from third parties without integrity checks
  • Missing security headers on pages that collect patient details
  • No email authentication, so patient-facing email can be spoofed

Recommended services

In the order most dental, physio and med-spa clinics should take them.

Find out where you stand

One free finding from your own site, by email, with no access needed. It's the quickest way to see whether the gaps above apply to you.

Connect on LinkedInSee the code on GitHub

Opens your email app with this filled in.