Went to a new clinic today. They asked for my residential address and said they don’t use email, just phone number for contact. I’m uncomfortable giving out my real details.
A couple of questions:
- Can they refuse to treat me if I don’t provide an address?
- Can they refuse to treat me if I don’t provide a phone number?
- Can they refuse to treat me if I insist to provide an email instead of a phone number?
Keen to hear what others in Aus do. Thanks.


Why would email get lost, intercepted, or misdirected (compared to SMS)?
In my experience, they don’t seem to verify or identify a patient by address. Even if I give them a fake one, they accept it. If they ever need to send something later, they’ll just confirm the address with you again. So I’d rather give them somewhere to send it, like a PO box, when they actually need it.
It’s about keeping unnecessary people from knowing unnecessary information when there’s a perfectly good alternative like email.
In your experience, do they share a patient’s address, phone number, and medical info with any third party? Or does it stay within that practice permanently?
Email is not a very secure means of communicating. Generally emails are encrypted between each relay, but at them, they sit there until it’s encrypted again for the next hop. Email in general is not super secure unless you set up some form of encryption, like openpgp for example. The clinic also can’t necessarily determine if you’ve have the account one day, or whether it’s been compromised the next.
If you use email in a browser, that’s a whole new set of potential attack vectors (MiTM for example). Healthcare providers pay out the nose for secure messaging and email services (so your specialist can transmit results/findings to your GP for example). Which requires both parties to have specialised paid software.
I would caution anyone about providing false information to healthcare providers. They may not necessarily immediately work it out but if your information is checked against a third party (certain medications are checked against a database or governing body if they’re scheduled/have high abuse potential) and found not to match, issues may arise. Like important medication scripts being cancelled. Still got that medication? You now possess a controlled substance without legal justification. This one of a myriad of reasons this is a bad idea.
I don’t live in the capitalism funhole that is the US as a disclaimer. From my understanding, not without your permission (I.e. a GP suggest you see a specialist, you accept, they then coordinate and potentially, with your consent, send the referral). The only exception I can think of is providing information to law enforcement if you break the law at the practice (e.g. threaten staff, become violent etc). Breaching confidentiality is a big deal in the healthcare profession.
Generally they’ll retain your records while you’re an active patient and a minimum time after. When you become inactive, you can request a copy of your patient summary information. Though here I believe after a certain time, lacking any instruction, they’re obligated to de-identify and destroy patient records.
Long version
https://avant.org.au/resources/medical-records-the-essentials
From a medical indemnity providers site. Aka lawyers for doctors.
Thank you, this is very informative.
Though I have to argue that email is better than SMS, since SMS messages aren’t encrypted at all.
Email isn’t really encrypted either, depending.
You have no more control or assurance email will be encrypted than you do SMS. Neither one is - in any way - a secure communication channel.
Which is why no medical provider I’ve dealt with in the last 10 years sends anything sensitive via email (or sms).
They send an email/sms letting you know there’s a message for you, and to go login to their system to retrieve the message or test result.