I am writing this review with the sincere hope that it can eventually be updated following…read morecorrective action.
Thirty days ago, I scheduled new patient appointments online for both my spouse and myself. I received an email confirmation at the time of booking, followed by an automated reminder shortly before the appointment date. When I arrived--on time--for the first of the two appointments, I was informed that I was not on the schedule at all.
The receptionist initially asked whether I might be at the wrong location. I showed her the confirmation email from their own online booking system, at which point she acknowledged that their online scheduling system does not work. This is not disclosed anywhere on their website, and the system presents itself as fully functional: accepting appointments, sending confirmations, and issuing reminders, creating a reasonable expectation that the appointment has been properly recorded.
While the receptionist was courteous and apologetic and did reschedule me, a more serious concern arose during intake.
When intake questions began, I asked whether the forms I had already completed online, including extensive personal, insurance, and medical history information, were available in my chart. I was told no, because the website does not track or transmit that information to the office.
At that point, I had to stop the process.
The intake forms required the upload of significant amounts of personally identifiable information (PII) and protected health information (PHI): data that is protected under both federal and Texas law. The staff could not tell me:
where that information is stored,
whether it was transmitted securely,
who has access to it, or
whether it is retained, audited, or properly safeguarded at all.
Given these uncertainties, I formally requested that a manager and/or the organization's privacy officer contact me. When an organization invites patients to submit legally protected data through its systems, it has a legal obligation to know where that data resides and how it is protected. Failing to do so raises serious concerns about privacy compliance and patient trust.
This review reflects concern, not hostility, and I am hoping the organization takes this feedback seriously, addresses the operational and privacy gaps, and demonstrates compliance with applicable law so this review can be updated accordingly.