Free privacy check

Does your website meet privacy obligations for NDIS and healthcare enquiries?

Free external website privacy & security check for NDIS providers, allied health clinics and medical practices. Find publicly visible risks in about a minute.

Free healthcare website privacy scanner — check forms, privacy policies, security headers and data handling
Why scan

Does your website collect client information in a way that creates privacy or security risk?

Healthcare and NDIS websites often collect sensitive information before anyone realises where it goes. Our free scanner looks at the public-facing parts of your site to identify what should be fixed or what needs a deeper technical review.

What we check

What the scanner checks publicly

Forms & data fields
Enquiry forms, date-of-birth fields, Medicare or health identifiers, unrestricted message boxes, and any fields that capture sensitive client data.
Privacy notices & policies
Whether a privacy policy and notice exist, what they cover, and whether visitors are told how information is collected and used.
Security basics
HTTPS, security headers, WordPress and form technology in use, SPF/DMARC email records, and visible tracking scripts.
Data destination clues
Where form data appears to be processed — including embedded third-party forms, marketing tools, and overseas service providers.
Start the free scan
What we cannot prove

The scanner is honest about its limits

From outside the website we usually cannot prove the things that matter most. The free report flags these so you can verify them internally or with our technical review.

  • Whether form submissions are stored in WordPress
  • Whether the website emails the full enquiry
  • Whether SMTP is encrypted
  • Who can access the receiving mailbox
  • How long submissions are retained
  • Whether old staging copies contain client data
The next stage

From free scan to managed security

The scanner is a door opener. The real protection comes from understanding how client information moves through your whole organisation — then fixing the gaps.

Technical privacy review
Website → WordPress → SMTP → Microsoft 365 → mailbox permissions → staff computers → firewall/network → backups → security controls.
Remediation
Fix form workflows, secure email, remove stale data, configure access controls, and document what needs to change for compliance.
Managed security / MSP
MFA and Conditional Access, EDR and threat hunting, application allowlisting and ring-fencing, managed firewall, secure remote access, backup and recovery, ongoing monitoring.
Book a technical privacy review

Common questions

What does the free healthcare website privacy scanner check?
It checks enquiry forms, sensitive data fields, privacy notices and policies, HTTPS, security headers, tracking scripts, WordPress and form technology, SPF/DMARC records, and where form data appears to be processed.
Is it safe to use?
Yes. The scanner only looks at publicly available information. It does not submit forms, run exploit tests, or log into your website.
What can it NOT see?
It cannot confirm whether submissions are stored in WordPress, whether enquiries are emailed in full, whether SMTP is encrypted, who can access the receiving mailbox, how long data is retained, or whether old staging copies contain client information.
Who is it for?
NDIS providers, allied health clinics, medical practices, dental clinics, psychology practices, community organisations and any healthcare business that collects sensitive client information online.
What happens after the scan?
You get a plain-English report with fix-now items, items to verify internally, and things to consider. You can then book a deeper technical privacy review with Tech Troubleshooters.

Scan your healthcare website now

It takes about a minute and gives you an honest, public-facing privacy assessment you can act on immediately.