Hands typing on a laptop running automated scripts, the kind of bot that sends fake appointment requests to a medical practice booking form
Most fake appointment requests are not typed by a person at all. They come from automated scripts that hit thousands of forms a day. Photo: Pexels.

A dermatology office messaged us one morning, half annoyed and half worried. Their online booking had run smoothly for years, then over a single weekend it started spitting out fake requests. Names like "asdfgh," phone numbers that were all nines, message boxes full of links. The office manager had spent an hour calling numbers that went nowhere, sure she was missing real patients somewhere in the pile. She wanted to know if they had been hacked.

They had not. Nothing was broken. What happened is the same thing happening to practices all over the country right now, and it has a simple explanation. Let us walk through what a fake appointment request actually is, why your form suddenly became a target, what it really costs you, and the free and low cost ways to make it stop.

What a fake appointment request actually is

A fake appointment request is your booking or contact form getting filled out by something that is not a patient. Most of the time it is a bot, a small automated program that roams the web looking for open forms and submits them by the thousand. Sometimes it is a low paid worker running a script for a spam operation. Either way, the goal is never to see a doctor. It is to drop a link, test a stolen credit card, harvest your auto reply, or just flood you because your form was easy to find.

The tells are usually obvious once you know them. The name is random letters or a famous person. The phone is missing, fake, or the same number over and over. The message field, if you have one, is stuffed with links or a wall of text in another language. And the timing gives it away: real patients trickle in through the day, while bots tend to arrive in bursts at 3am.

Why bots love a medical booking form

Here is the part that surprises most owners. The web is not mostly people anymore. According to Imperva's 2026 Bad Bot Report, automated traffic passed 53% of all web activity in 2025, up from 51% the year before, meaning machines now outnumber humans online. A big share of that automation is bad bots doing exactly this kind of work: scanning for forms, testing logins, scraping data and submitting junk.

Lead forms get hit especially hard. Across industries, analyses of web forms regularly find that somewhere between 30% and 40% of public form submissions are fake or bot generated. Your patient booking form is not special to a bot. It is just another open door on the internet, and open doors get knocked on constantly, whether you run a bakery or a busy orthopedic group.

53% More than half of all web traffic in 2025 was automated, not human, per Imperva's 2026 Bad Bot Report. An unprotected form sitting on the open web is a target by default, not by accident.

Three reasons it starts happening to you

Fake requests rarely appear for no reason. When a practice goes from clean to flooded, it is almost always one of these:

It costs more than a wasted hour

The obvious cost is your front desk's time. Every fake request is a name someone has to read, a number someone has to dial, a decision someone has to make about whether it is real. Multiply that across a week and it is real payroll spent chasing ghosts. Worse, in a pile of junk, a genuine new patient can get deleted by mistake, and that one is worth far more than the annoyance of the other ten.

The bigger hidden cost is your data. If fake submissions count as conversions in your ad account, Google's automated bidding learns to go find more people like the ones who converted, which means more bots. Your cost per lead looks great on paper while your real bookings stay flat. That gap between "leads" and "actual patients" is one of the most misleading numbers in healthcare marketing, and we broke it down in what a good cost per lead really looks like. When the number is polluted with junk, you cannot trust your own reports, and you cannot tell where your patients actually come from.

Real patient or bot? A quick gut check

Before your front desk spends twenty minutes on a suspicious request, look for three things. First, does the phone number have a real area code and the right number of digits? Bots often leave it blank or fill it with repeats. Second, does the name match the email, or is it random letters next to a string of numbers at gmail? Third, when did it arrive? A cluster of requests at 2am, seconds apart, is almost never a family deciding to book at the same moment. If two of the three feel off, treat it as spam and move on.

How to stop it, mostly for free

The good news: you do not need to take down your form or make patients jump through hoops. The fixes that work are invisible to real people and brutal on bots.

If most of your leads come through social platforms, the same rules apply there. We covered the tradeoffs of on platform forms in whether your practice should use Facebook lead forms, because the easier a form is to submit, the more junk it tends to attract unless you protect it.

Our honest take

We think fake appointment requests are one of the most under discussed leaks in a practice's front office. Owners obsess over ad spend and reviews, then let a broken form burn staff hours behind the scenes and corrupt the numbers they use to make every other decision. It is not a glamorous problem, but cleaning it up is one of the highest return things you can do, because it makes every report you read afterward actually true.

The other honest point: a flood of junk is not a reason to make booking harder for real patients. We have seen practices react by adding long CAPTCHAs, extra required fields and clunky steps, and all that does is scare off the nervous first timer who was finally ready to book. The goal is not friction. The goal is smart, invisible filtering that stops bots without ever touching the human on the other side.

Where EtherealMinds fits

When we build websites that convert for practices, bot protection is baked in from the start: silent CAPTCHA, honeypots, real time phone and email validation, and forms that stay effortless for real patients. Every request then flows into a full patient acquisition system that confirms genuine bookings, filters the junk before it reaches your team, and keeps your conversion tracking clean so your ad dollars chase humans, not scripts. You get fewer fake requests, a calmer front desk, and numbers you can finally trust.

So if your inbox has been filling up with names like "asdfgh," you are not being hacked and your marketing is not broken. You are just running an open form in a web that is now more machine than human. Close the door on the bots, keep it wide open for patients, and get your Monday mornings back.

Tired of junk requests clogging your front desk?

Book a free strategy call. We will look at your booking form together, show you where the fake requests are getting in, and set up the invisible protection that stops bots without making real patients work harder. No jargon, no pressure.

Book a free strategy call →