NDIS Software Tools
All Episodes
NDIS Privacy Pitfalls: Forms, SMS Leaks, and Safer Bookings

NDIS Privacy Pitfalls: Forms, SMS Leaks, and Safer Bookings

0:00|0:00

This episode unpacks the privacy risks of over-collecting sensitive details on public booking forms and explains why NDIS providers should keep early enquiries lightweight and low-pressure. It also covers lock screen SMS leaks, better reminder practices, and the importance of separating website tools from official participant records.


Chapter 1

The Data Over Collection Trap and Lock Screen Leaks

Will, EnableUs Community

If you visit an NDIS provider website and click book an initial chat, and the very first form asks for your full NDIS plan number, your primary diagnosis, and a breakdown of your budget goals, um, that feels like thorough intake, right? It feels proactive.

Winter, EnableUs Community

Yeah, like they are getting ready to help you.

Will, EnableUs Community

Except it is actually a massive privacy trap, and, er, it turns out it scares off a lot of potential participants before they even submit the form.

Winter, EnableUs Community

Wait, why? I mean, do not they need that info eventually?

Will, EnableUs Community

Eventually, sure, once a service agreement is signed. But on a public web form, when someone is just researching options? Under NDIS guidelines, participants are encouraged to compare providers, shop around, and switch if they want to. Pushing for sensitive personal details on a simple booking calendar undermines choice and control. Plus, you are dumping deeply personal health data into a basic website database that might not be built for high level security.

Winter, EnableUs Community

Oh, wow, yeah. It, it, it turns a simple enquiry into a high stakes disclosure. You do not even know if you want to work with them yet.

Will, EnableUs Community

Exactly. And it does not end with the form itself. Think about what happens after someone actually books that chat. What is the very next thing the system sends them?

Winter, EnableUs Community

An automated text reminder?

Will, EnableUs Community

Right. An SMS reminder. And this is where another huge privacy leak happens. A lot of default booking systems automatically insert the name of the service into the text message. So a participant gets a text that pops up right on their phone screen, saying something like, reminder, your Behavior Support Intake Session is tomorrow at two p m.

Winter, EnableUs Community

Oh, no.

Will, EnableUs Community

Or, reminder, Psychosocial Assessment with so and so.

Winter, EnableUs Community

On a locked screen sitting on a kitchen table or on a desk at work where anyone walking past can read it. That, that actually happened to me a few months ago, not with NDIS, but with a specialist clinic. My phone buzzed on a table during a meeting with colleagues, and the lock screen displayed the full clinical description of the appointment. I was so embarrassed. It felt like such an invasion, even though the clinic thought they were just being helpful.

Will, EnableUs Community

Yeah, it is terrible. And for NDIS participants, receiving a text that broadcasts terms like behavior support or psychosocial evaluation on a lock screen is a real breach of dignity. It destroys trust before you have even met them.

Winter, EnableUs Community

So what is the fix? How do you keep the attendance rate high without putting someone's private business on display?

Will, EnableUs Community

It comes down to simple reminder hygiene. You strip the automated SMS down to the bare minimum essentials. Time, date, and a neutral organization name or doctor name. So instead of Behavior Support Consultation, the text just says, reminder, your appointment with EnableUs is tomorrow at two p m. Reply Y to confirm.

Winter, EnableUs Community

That is it. Clean, professional, completely private, and it still keeps the attendance rate right where it needs to be.

Chapter 2

Drawing the Line Between Website Forms and Official Records

Will, EnableUs Community

Now, where does that information actually go once the participant clicks submit on your website?

Winter, EnableUs Community

Well, usually it goes to someone's email inbox, right? Or sits inside the plugin dashboard on WordPress or Wix or whatever.

Will, EnableUs Community

And that creates what we call the shadow database hazard. You have sensitive enquiry details, names, phone numbers, family notes, sitting across three different staff email inboxes and unencrypted web host servers. When audit time comes around, the NDIS Quality and Safeguards Commission wants clear, complete, and secure records. Having loose participant data sitting around in web form logs is a major compliance vulnerability.

Winter, EnableUs Community

So your public website should never be your participant database.

Will, EnableUs Community

Never. You have to draw a strict boundary between public web tools and official record management. And that starts with how you frame the booking in the first place. You do not call it a service intake booking. You call it an introductory chat or an exploratory call. You make it clear to the participant that this meeting is non binding and completely preliminary.

Winter, EnableUs Community

Right, because NDIS guidance explicitly says participants have the right to switch providers and compare options without pressure. So calling it an exploratory chat signals that they are in control, not locked into a contract.

Will, EnableUs Community

Spot on. And setting up this clear boundary right now is especially critical because of what is coming down the track. In the second half of 2026, the NDIS Commission is rolling out its new provider portal for registration, reportable incidents, and behavior support plans. While that portal is separate from your website, it signals a much tighter digital environment across the entire NDIS ecosystem.

Winter, EnableUs Community

So providers who clean up their data boundaries now will be way better prepared when those strict portal rules kick in late 2026.

Will, EnableUs Community

Exactly. So here is the three step workflow rule every provider should follow for their website booking setup.

Winter, EnableUs Community

Okay, step one?

Will, EnableUs Community

Step one, collect only minimal contact details on the web form. Name, preferred contact method, and a general topic box. No plan numbers, no clinical histories.

Winter, EnableUs Community

Got it. Step two?

Will, EnableUs Community

Step two, route that data directly out of the website and into your secure, approved NDIS CRM or participant management system immediately. Do not leave it sitting in email threads.

Winter, EnableUs Community

And step three?

Will, EnableUs Community

Step three, set an automated purge rule on your website server that permanently deletes web form submissions every 30 days. That way, even if your website host ever suffers a security breach, there is no shadow database of participant enquiries sitting there to be stolen.

Winter, EnableUs Community

That makes total sense. Minimal collection, direct CRM routing, automatic purging. Simple, secure, and respectful.

Will, EnableUs Community

Alright, good chat today. Talk soon!

Winter, EnableUs Community

Talk soon!