5 Steps to a Secure Website

Jules Roebbelen • August 4, 2020

Please do not send any personal health information through this form. 


Email communication is not secure. Do not share your health information via email.


No matter how it’s worded, even in giant blinking letters, whenever there is an opportunity to type text into a message area, people will, without fail, share personal information through website Contact Us forms. This likely triggers a whole process of information deletion at the receiving end, and is a constant privacy concern for security officers. It is the responsibility of health care providers to ensure that information is handled properly, even if it was improperly sent through your website. 


There are hundreds of available website Content Management Systems (CMS), but few are optimized for displaying health care services or gathering Personal Health Information (PHI) from patients and clients. Caredove takes your website security seriously, and we have a few tips to help boost your site's integrity and improve the management and security of PHI.


1. Secure your website with an SSL certificate.

This turns the "http" at the beginning of your URL to "https" which encrypts requests and responses between your website and the website viewer. This also makes your website harder to hack, protecting your information and any client information that might be held in your website. Having a site secured with an SSL certificate is the bare minimum of security measures you should implement on your website, especially if you are promoting healthcare security and privacy standards in your workplace. It is the most standardized "stamp of approval" for a website's authenticity and trustworthiness. Depending on your website provider, you can get free or low cost SSL certificates that are simple to implement.


2. Remove your general inbox email address from your site.

Hacker bots can scan thousands of web pages every day looking for an exposed email address. These email addresses are then victim to higher volumes of spam and junk mail, which can be an insidious way for hackers to gain access to your private information through a scam process called phishing. If a team of receptionists or front desk staff are sharing access to a general email inbox, any one of them could fall victim to a phishing scam, where they are tricked into entering passwords or credit card information into a fake form, handing over the keys to their virtual lives to an unknown hacker.


3. Secure your contact form.

Contact forms are an excellent way to gather leads and handle incoming inquiries from your website. But there are several reasons why a contact form is NOT the best way to gather information about your clients. Contact form submissions likely land in a general email inbox for your organization, managed by multiple front desk staff. Overall, email is NOT a secure place to hold patient information.


  • Are you 100% sure that you know all the people that have access to that email inbox?
  • When was the last time the password was changed?
  • What country is your email server hosted in?
  • What if the email server fails? How do you access your messages?
  • Does your staff have access to this email from home?
  • What if their home computer gets a virus? Do they have proper malware in place?
  • How do you know that your staff aren't forwarding PHI on to other parties?
  • What sort of workflow do you have in place to action these inquiries to make sure they aren't being lost in the shuffle?
  • If PHI is sent through these forms, what steps do you take to destroy that information?


If your contact form is NOT going to a general email inbox, that means that the data is stored directly in your CMS. The top five website Content Management Systems under attack in 2018 were:


  1. WordPress (while WordPress does offer a substantial security program, most breaches are because the WordPress website was improperly set up by the user, due to old plugins not being updated and missing SSL certificates)
  2. Joomla
  3. Drupal
  4. Magento
  5. Sharepoint
    Source


These CMS are at risk of compromising any PHI you have stored in your website. Many CMS have servers all over the world, which means your client PHI could be travelling to countries with much less strict privacy standards than Canada. Storing PHI outside of Canada might be in breach of your organization's privacy and security standards.


4. Ensure any contact form integrations are compliant with your national healthcare privacy standards.

Contact forms can be integrated to lead pipeline software like Hubspot or Salesforce, making it easy for your sales team or intake staff to action leads without living in an email inbox. Even if you have an integration to one of these softwares, which ensures leads and PHI does not land in an email inbox, many of these lead tracking softwares are not PIPEDA and HIPAA compliant, meaning they do not meet Canadian and American healthcare privacy and security standards. If you are handing PHI in one of these systems, make sure that they are meeting the healthcare standards necessary to properly handle your client information. 


5. Choose a contact form process that aligns with your organization's values to provide the best and most secure access to care for your clients and patients.

You will likely be able to make things clearer if you manage service requests in a compliant system like Caredove.


  • Caredove has a 99.9% uptime with AWS servers hosted in Montreal. No patient health information ever leaves Canada.
  • Caredove terms and conditions means we take responsibility for storing this information securely.
  • Our data is encrypted end to end.
  • We are experts in health information privacy and security, so you don't have to worry.



Caredove can embed a secure contact form on your site, or build and host your entire website if you are concerned about your site's overall security. We guarantee a secure, responsive and beautiful website, with all your Caredove services and contact forms seamlessly integrated, making it easy for patients and clinicians to send service requests from their computer, tablet or phone. Learn more about our WebBuilder, and how we can improve your website security and your client experience.


Crown made of silhouetted people holding hands, yellow background, radiant lines.
By Jeff Doleweerd June 27, 2024
A truly effective central intake hub is not merely a team of staff manually routing referrals behind a veil of complexity; it is an integrated system that dynamically combines public accessibility, algorithmic precision, real-time capacity management, and seamless communication to ensure patients receive timely and appropriate care.
Three people collaborating around a laptop, one holding a mug. Light teal background.
By Jeff Doleweerd May 14, 2024
Access to community healthcare is paramount for individuals across various stages of life — from seniors desiring to age gracefully in their own homes, to new parents seeking care for their infants and individuals in need of mental health and addiction support. Traditionally, when we mention referrals, the image of a physician sending a document to a specialist comes to mind. However, the landscape of healthcare referrals is evolving, and it's time to redefine our approach. Gone are the days when referral management systems solely relied on healthcare professionals. Take Caredove, for example. What was once considered a referral management system has transformed significantly to a multichannel access management platform. Surprisingly, 43% of referral activity now stems from direct public sign-ups. This shift is monumental, with a staggering 70-fold increase in public service requests compared to pre-pandemic levels in 2019. Clinician referrals will be the minority of service requests activity in our platform by the end of 2024. Why this paradigm shift? During the pandemic, communities learned the importance of direct access to essential services. The notion of gatekeeping community services in any manner like specialist services became obsolete. The crisis strengthened the muscles of direct access, emphasizing the significance of preventive health through social and other services that keep people out of hospitals and other care facilities. Moreover, primary care is under immense strain, with 15% of Canadians lacking consistent access to ongoing primary care. In such a scenario, burdening already stretched healthcare professionals with more referral duties is not sustainable. Accessing services directly not only expedites the process but also empowers individuals to take charge of their own health journey. It signifies readiness for change and recovery, without the artificial requirement of seeing a physician solely for a referral. Primary care remains crucial, and it's imperative to equip them with resources available at their fingertips, enabling them to navigate the healthcare landscape autonomously. After all, patients trust their primary care providers, and we should harness this trust. We also need to foster a culture of self-advocacy and consumer empowerment as part of a broader solution. Community agencies are champions of a healthcare system where individuals are empowered to take control of their health, supported by a network of trusted professionals. In an era of putting patients before paperwork, it is time to embrace direct access and take every bit of unnecessary administrative burden off family doctors and nurse practitioners, in the process.
Two people communicating using string phones, standing on separate rooftops over a gap.
May 10, 2024
In the landscape of mental health support, a new trend is emerging: rapid access low-barrier walk-in counseling. This innovative approach is reshaping how individuals access mental health services, providing immediate support without the traditional hurdles of scheduling. At Caredove, we're witnessing the transformative power of collaboration among organizations delivering these services. Let's delve into why this trend is not just groundbreaking but essential. Immediate Suppo rt : Imagine being able to get the help you need right when you need it, without waiting weeks for an appointment. That's the promise of rapid access low-barrier walk-in counseling. It ensures that no one falls through the cracks during times of crisis. Reduced Stigma : By offering low-barrier access, we're sending a powerful message: seeking therapy for mental health concerns is not only acceptable but encouraged. This approach helps break down the stigma surrounding mental health, making support readily available and easily accessible. Increased Accessibility : Not everyone has the means to access traditional counseling services. Some regions have been able to eliminate cost barriers, thereby ensuring that everyone, regardless of financial situation, can access the support they need to thrive. Community Building : Low-barrier walk-in counseling centers can become community hubs, fostering a sense of belonging and support. Preventative Approach : By addressing mental health concerns early and proactively, these services can prevent more serious issues from developing later on. Empowerment : Rapid access low-barrier counseling empowers individuals to take charge of their mental health. By providing immediate support and resources, we're giving people the tools they need to overcome challenges and live fulfilling lives. Cost Savings : While offering these services may seem like a costly investment, it can actually save money in the long run. By addressing issues early, we can reduce the need for more expensive interventions down the line. No physician burden : Rapid access counseling requires no physician referral so does not tap the resources of overextended primary care, or present barriers for unattached patients. Progressive Approach : Embracing rapid access low-barrier walk-in counseling reflects a progressive mindset in healthcare. It's about prioritizing the well-being of all in the community. Stepped Care approach : Rapid access can operate in a stepped care model. During the session, if more specialized services are identified as necessary, individuals can be seamlessly referred to these services by their therapist. Rapid access low-barrier walk-in counseling represents a seismic shift in how we approach mental health support. By embracing collaboration, we can amplify its impact, ensuring that everyone has access to the help they need, when they need it. Together, we're not just changing lives; we're changing the conversation around mental health..
Show More