Hmm, but they said SSL is already enabled if you visit the site with https. Shouldn't redirecting http > https be completely risk free then or am I missing something?
You could do this quite subtly as a way to influence people by making certain figures appear more sinister.
These warnings tend to get tougher over time, so what's grey now may be red next year.
Surely the GP wouldn't have asked the question they did if their https site was already broken...