A quick outside look at what anyone on the internet can see about your site. The easiest way to find out whether you have a problem.
Security for dental, physio and med-spa clinics
Ontario's Personal Health Information Protection Act makes clinics accountable for the patient information they collect, including what passes through their website, booking system and intake forms.
Most clinic sites were built by an agency and haven't been reviewed since. The gaps are rarely dramatic, but they're exactly what gets found when someone goes looking.
What usually turns up
These are the gaps most often found when businesses like yours are checked from the outside.
- Staging sites or admin logins reachable from the public internet
- Booking or intake widgets loaded from third parties without integrity checks
- Missing security headers on pages that collect patient details
- No email authentication, so patient-facing email can be spoofed
Recommended services
In the order most dental, physio and med-spa clinics should take them.
Stops people from sending email that looks like it came from you. Most businesses have never set this up, and it's usually the fastest visible win.
A hands-on review of your web application, the way an attacker would approach it.
Find out where you stand
One free finding from your own site, by email, with no access needed. It's the quickest way to see whether the gaps above apply to you.