Chiropractic Websites and the Not Secure Warning Patients See

91.8% of chiropractic sites load securely, which puts the trade 42nd of the 47 I ranked. A new patient meets that gap before she meets you.

Chiropractic Websites and the Not Secure Warning Patients See

I let the certificate on my own website lapse once. I sell websites for a living.

A client told me about it, very kindly, which somehow made it worse. So I’m not standing above any chiropractor here. I have been in this exact puddle.

The difference is what my visitors were about to type, and what yours are.

Sunday night, and a woman can’t turn her head.

She’s on the couch with her phone a foot from her face, typing “chiropractor open Monday” with one thumb, because lifting the other arm is the whole reason she’s searching.

Your clinic comes up. She taps it.

Before she reads a single word about you, her browser puts a note beside your address saying the connection isn’t private, and that someone may be able to see and change the information she sends through the site.

Then your new patient form asks for her name, her phone number and what hurts.

Would you fill that in? At nine at night, about your own body, on a website you’d never heard of twenty seconds earlier?

The number I keep re-reading

91.8% of chiropractic websites load over a secure connection, and my national number is 94%.

A couple of points apart. Sounds like nothing at all, so why has it bothered me for a month?

Because of what your pages ask people for. Chiropractors, who come out 42nd of the 47 trades I ranked on that one, are asking a stranger for her name, her phone number and the part of her body that has gone wrong.

Nearly every other trade I ranked sits above you on it. Most of them never ask anyone for anything more private than a delivery address, and fashion clears the same check without anyone in the trade working at it.

What the lock is doing while she types

HTTPS is the locked version of your web address, and the person who adds it is whoever you already pay to keep the site online. On every host I’ve touched it’s a switch, an afternoon, and a bill for nothing.

What the afternoon buys is a sealed line between her phone and your front desk, so what she types can’t be read or altered by anyone standing in the middle of it.

Google’s own write-up is blunt about the alternative. Without it, intruders can listen in on what moves between your site and your visitors, and tamper with it on the way through, and some of them inject their own ads into your pages while they’re at it.

Her name and phone number travelling in the open on coffee shop wifi would be bad enough on its own.

Owners wave this off by telling me they take no payments online, so there’s nothing worth protecting. I get the same sentence in Kelowna most weeks, and a form asking a stranger where she hurts is the exact thing the warning was built for.

She’s also telling you where she hurts, how long it’s been going on, and often who her insurer is.

I’m not your lawyer and I won’t pretend to know the rules that apply to your patient records. I only know what a person thinks when her browser warns her at the exact moment she’s about to hand over her health history to a stranger.

She doesn’t think “expired certificate”. She thinks these people don’t have their act together, and then she goes back to the results and taps the clinic underneath you.

Having a lock and using it are two different things

Now the second number, which I find more interesting than the first.

87.1% of chiropractic sites push insecure traffic over to the secure copy, against 88% of the sites I audited, which I have 32nd of the same 47.

A certificate only protects the people who arrive at the secure address, and I’d guess plenty of your visitors never do.

Old links in old directories. A business card someone typed in by hand. A listing you set up in 2014 that still points at the unlocked version of your domain, quietly dropping patients at the wrong door years later.

When did anybody last check where your old listings point? I ask that on every call and I have yet to hear a confident yes. Electricians taught me to count the places a web address is written down, from the van door to a directory nobody has logged into since 2016.

The fix has a boring name and takes minutes. web.dev tells you to use a permanent redirect, a 301, so every visitor gets moved onto the secure copy no matter which address they came in on.

That same page warns about a second trap I run into constantly. Leave one photo or script loading over the old insecure address on an otherwise secure page, and the browser tells your visitor the page isn’t fully secure anyway.

So you can buy the certificate, install the certificate, and still lose your lock to a single picture of a spine that someone uploaded in 2016. Fun, right?

Why it lands on your trade in particular

38.2% of chiropractic sites run WordPress, with Wix at 10.4%, Squarespace at 9.7%, GoDaddy at 4.0% and Weebly at 1.8%.

Those shares don’t add up to a whole trade, mind. A site can answer to two of them at once, and on plenty of sites my fingerprinting comes back with nothing, which tells me only that I couldn’t put a name to the platform.

The hosted builders handle this for you whether you understand it or not, which is the best thing about them. A self-hosted WordPress site built a decade ago handles nothing on its own, and a chiropractic clinic has no IT department to lean on, just a front desk with a full schedule and a phone that keeps ringing.

Clinics hand me those decade-old builds to replace most weeks, and not one of them has ever called me about the lock.

Worse, nothing tells you when it breaks. Who at your clinic would even know where to look? I refuse to be that person for a clinic, and I spent an hour with one owner explaining why the certificate needs a name inside his own building.

No alarm sounds. No email arrives. You type your own address, land straight in the admin screen you’ve used a thousand times, and the site looks perfect to you forever.

The only people who see the warning are the ones who have never met you. So when did you last open your own website the way a stranger does, from a search result, on a phone that isn’t sitting on the office wifi?

The bit that stings

Your trade has done the hard work everywhere else.

93.8% of chiropractors hold at least one Google review, and the average clinic I opened carries 100 reviews at 4.8 stars, which nobody reaches by accident.

You get to 4.8 by being good to people, one sore back at a time, for years on end, and I’ve watched clinics chase that number for a decade.

Then a browser undoes a piece of that in half a second, before a new patient has read your name properly.

Does that seem like a fair trade to you?

Most of you are already fine

Most chiropractic websites are locked up properly, so the odds are good that yours is one of them and this post belongs to the clinic down the road.

Everything else I check says the same thing. Chiropractors score 75 out of 100 overall, near the top of everything I graded.

You don’t have to take my word for any of it, since setting the explorer to chiropractors and leaving the city menu on all gives you every rate I’ve quoted with the count of sites behind it.

So your clinic can be in good order nearly everywhere and still hand a stranger her first impression of you in red text.

Nobody will ever thank you for the lock. She only notices it missing.

Thirty seconds, and then you’ll know

Open a private browser window. Type your web address with http and no s in front of it, then hit enter and watch what the browser does with it.

Three things can happen.

  1. It jumps straight over to the secure version and shows you a lock, in which case you’re done and you can go back to seeing patients.

  2. It loads and sits there on the unlocked address, so your certificate may well be fine while the redirect isn’t, and everyone arriving from an old link is stranded outside.

  3. You get a full page warning in red, and I’d stop reading and call whoever hosts your site today.

Number two turns up far more often than anyone in your trade would guess, and I find it’s the one that never gets caught, because the site looks flawless from the inside.

If you want the longer version of locking a site down properly, I wrote one here.

Do it tonight, before you shut the laptop. Thirty seconds, one address, no s on the front of it.

You don’t have to tell me what happened. Just don’t let the next patient with a locked-up neck be the one who finds out on your behalf.