this post was submitted on 24 Jul 2026
-5 points (35.3% liked)
Privacy
10466 readers
20 users here now
A community for Lemmy users interested in privacy
Rules:
- Be civil
- No spam posting
- Keep posts on-topic
- No trolling
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Address and phone number is not essential. They can inform you with email
No
Depending on local laws they may not due to, ironically enough, privacy and sensitive information laws. In fact beyond appointment scheduling I’ve yet to go to a practice that used email in any meaningful way. Even getting my health summary info to transfer between practices, I had to do a whole song and dance that essentially equates to “we’re sending you all this but if it gets lost, intercepted or misdirected, you agree that’s your problem because we told you email is bad”.
They usually need an address to verify who you are (Medicare, benefits, script confirmation, patient differentiation) and a number so they can contact you regarding follow up’s (again to come in, not to discuss meaningful information). Keep in mind, practices, hospitals, etc also deal with drug seekers and mentally unwell individuals.
Beyond personal/sensitive information laws; they also want you to come in for any follow up/results because healthcare professionals like being paid for their time and up until Telehealth, couldn’t typical bill for phone calls. I get desiring privacy but given you’re going to be discussing and sharing personal health information with a clinician, this all seems a bit pointless tbh. Hence ol mate thinking this is a troll question I would guess.
When I worked for a family medical practice, many moons ago, if a patient refused to provide “demographic” information like this, we likely would just decline them as a patient, for liability reasons if nothing else.
Why would email get lost, intercepted, or misdirected (compared to SMS)?
In my experience, they don't seem to verify or identify a patient by address. Even if I give them a fake one, they accept it. If they ever need to send something later, they'll just confirm the address with you again. So I'd rather give them somewhere to send it, like a PO box, when they actually need it.
It's about keeping unnecessary people from knowing unnecessary information when there's a perfectly good alternative like email.
In your experience, do they share a patient's address, phone number, and medical info with any third party? Or does it stay within that practice permanently?
Email is not a very secure means of communicating. Generally emails are encrypted between each relay, but at them, they sit there until it’s encrypted again for the next hop. Email in general is not super secure unless you set up some form of encryption, like openpgp for example. The clinic also can’t necessarily determine if you’ve have the account one day, or whether it’s been compromised the next.
If you use email in a browser, that’s a whole new set of potential attack vectors (MiTM for example). Healthcare providers pay out the nose for secure messaging and email services (so your specialist can transmit results/findings to your GP for example). Which requires both parties to have specialised paid software.
I would caution anyone about providing false information to healthcare providers. They may not necessarily immediately work it out but if your information is checked against a third party (certain medications are checked against a database or governing body if they’re scheduled/have high abuse potential) and found not to match, issues may arise. Like important medication scripts being cancelled. Still got that medication? You now possess a controlled substance without legal justification. This one of a myriad of reasons this is a bad idea.
I don’t live in the capitalism funhole that is the US as a disclaimer. From my understanding, not without your permission (I.e. a GP suggest you see a specialist, you accept, they then coordinate and potentially, with your consent, send the referral). The only exception I can think of is providing information to law enforcement if you break the law at the practice (e.g. threaten staff, become violent etc). Breaching confidentiality is a big deal in the healthcare profession.
Generally they’ll retain your records while you’re an active patient and a minimum time after. When you become inactive, you can request a copy of your patient summary information. Though here I believe after a certain time, lacking any instruction, they’re obligated to de-identify and destroy patient records.
Long version
https://avant.org.au/resources/medical-records-the-essentials
From a medical indemnity providers site. Aka lawyers for doctors.
Thank you, this is very informative.
Though I have to argue that email is better than SMS, since SMS messages aren't encrypted at all.
Email isn't really encrypted either, depending.
You have no more control or assurance email will be encrypted than you do SMS. Neither one is - in any way - a secure communication channel.
Which is why no medical provider I've dealt with in the last 10 years sends anything sensitive via email (or sms).
They send an email/sms letting you know there's a message for you, and to go login to their system to retrieve the message or test result.