Skip to main content

For clinics & private practices

Patient data on your booking system. Who can see it from outside?

Vantyris checks your clinic's website and booking-system domain the way an attacker would: email impersonation, exposed admin pages, a missing privacy notice, trackers that load before consent. Then it writes a plain-English report you can forward to your web host or your insurer. From $10€10£10A$15¥1,500AED 40. No contracts.

67Security score,
grade C
2Fixes for
today

Each panel mirrors a screen in your workspace, shown with our demo clinic. After your first scan, it's your sites and your findings.

The reality

What clinic owners worry about

Patient data sits on the booking system, and you have no idea who can see it from outside.

A letter from your data-protection regulator would feel impossible to answer without help.

Your insurer asked about cyber security at renewal and you didn't have a good answer.

Your website builder set up Google Analytics three years ago. You can't say whether it loads before patients accept the cookie banner.

What a typical clinic scan surfaces

One finding, shown in plain English.

Every finding in your Vantyris report is shaped the same way: what it means for your business, how to fix it, who to ask, and the technical evidence one tap below.

high

Anyone can send email pretending to be from your clinic

Your booking-system domain has no DMARC record, the DNS entry that tells receiving mail servers to reject impersonated email. Right now a scammer can send a fake appointment reminder from your clinic's address and the patient's inbox will treat it as real. It's also one of the cheapest fixes in the report.

How to fix it

Add one TXT record at _dmarc.your-clinic-domain. The report's Exact Fix section gives the text to paste, so your web host doesn't have to interpret anything. About 30 minutes, including the wait for DNS to update.

What Vantyris gives clinics

What changes after the first scan.

Plain English first, technical detail second

Every finding opens with what it means for the clinic, for example 'a scammer can send fake appointment reminders that look real to your patients'. The evidence your IT person needs (the exact DNS record, the HTTP header, the failing TLS handshake) sits one click below. Reception can follow the top line.

A one-page summary for the partner

Every verified report opens with a one-page executive summary for non-technical readers: the headline grade, the three biggest wins, the projected score after fixes, and a 'Business impact in plain English' table that maps each finding to its commercial risk. The partner reads page two. The IT contractor starts at page seven.

Monitoring that alerts on three things

Enrol the clinic's website in weekly re-scans. Vantyris emails you about three things only: a new high or critical finding, a score drop of ten points or more, or a TLS certificate within fourteen days of expiry. Nothing else lands in your inbox.

The privacy checks a regulator would start with

The Privacy category checks what a regulator notices first: trackers that load before the visitor clicks Accept, a cookie banner with no visible Reject button (an EDPB requirement), Google Consent Mode v2 missing, and no privacy-policy link in the footer. Regulators' cookie sweeps, such as the UK ICO's in 2023, went after the same patterns.

Nine categories, sorted into a Fix Roadmap

The report scores your site in nine categories. Every issue lands in Today, This Week or Later, grouped by who fixes it: web host, developer, DNS admin or domain registrar. Each person gets one list. Items that need a check rather than a fix, like a shared CDN address on a Spamhaus list, sit in a separate Acknowledged section, so the report doesn't read like an emergency.

A trust page for patients and inspectors

Switch on a public trust page at /trust/your-clinic. It shows your current grade, the nine-category grid and the controls external scanning has verified. Put the link in your privacy notice, your insurance renewal form or your next inspection file. Anyone can check it themselves instead of waiting for last year's PDF.

A PDF in three layouts

The same scan downloads as the full report, which opens with a one-page executive summary, as a single-issue work order for your web host, or as a compliance pack sized for an auditor or regulator.

Long read

12-minute read

The 12-item cyber hygiene checklist for clinics, in priority order (written for UK practices).

A plain-English playbook for clinics from the Vantyris editorial team. It takes positions, which a generic checklist won't.

Read the full playbook

FAQ for clinics

Common questions from clinic owners

Does this make my clinic GDPR or Cyber Essentials compliant?
No. Vantyris doesn't certify you against any framework. Every verified report has a Cyber Essentials A1-A5 section (the UK government's baseline scheme) showing which controls each finding touches, which is a good starting point for a conversation with your regulator or your insurer. Certification needs an assessor. Vantyris shows what an external scan can speak to and what needs internal evidence.
Will the scan slow my booking system down?
No. It reads what your site already shows the public: DNS records, response headers, certificates and a short list of common paths, with time-limited requests. It doesn't try to log in, doesn't probe for hidden services, and doesn't brute-force or fuzz anything.
Can I show this to my professional indemnity insurer?
Yes, three ways. Email them the PDF (the compliance-pack layout is sized for this). Send a time-limited share link they open in a browser, watermarked with their name if you like. Or give them the address of your public trust page. If your policy asks for evidence of an external scan in the past 12 months, any of the three gives you something dated to send.
What about cookie-consent sweeps? Does Vantyris check for that?
Yes. The Privacy category checks for trackers loading before consent, reject parity on the cookie banner (the EDPB rule that rejecting must be as easy as accepting), Google Consent Mode v2 when Google trackers are present, and a visible privacy-policy link. Regulators run sweeps on exactly these patterns (the UK ICO's 2023 sweep covered the top 100 UK sites) and follow up with smaller organisations when someone complains.
What if a regulator asks about a specific control?
Open the verified report, go to the Cyber Essentials section and find that control's row. It lists every finding that touches the control, with its severity. It also says whether the area is covered, has gaps, or sits outside what an external scan can see. Endpoint posture and staff training, for example, need internal evidence.
What if I don't have a 'developer'?
Most fixes happen in your web host's control panel. The report words each action plainly enough to forward to the host's support team, and includes a copy-paste snippet for the common fixes: DMARC, HSTS, blocking /readme.html, locking down the WordPress REST API user list. You can also assign a finding to your host's support address from inside the report. Vantyris keeps the audit trail of when it went out and who responded.
Full FAQ

Ready when you are.

Free account, free passive teaser, no card. A verified scan from $10€10£10A$15¥1,500AED 40. No contracts.