How it worksFor practicesSecurity & trustPricingResourcesAbout Help Centre Contact
← All resources
Article

Medilee is ISO/IEC 27001 certified. Here is what that actually means for your data.

M
The Medilee team
6 minute read
ISO/IEC 27001:2022 certifiedSOC 2 Type 1 attested

Medilee has passed its ISO/IEC 27001:2022 certification, and has completed a SOC 2 Type 1 examination. Both were independently audited. Our SOC 2 Type 2 examination is in progress.

Every referral file that passes through Medilee is somebody's medical history. Not a customer record with an email address attached, but imaging, diagnoses, psychiatric history, injuries and the parts of a life that ended up in a claim. Under the Privacy Act 1988 (Cth) that is health information, which sits in the most protected category the Act defines. It is the kind of material that should make a specialist ask a hard question before uploading anything: what exactly happens to this once it leaves my desk?

We have now put an independent answer behind that question. Medilee has been certified to ISO/IEC 27001:2022, the international standard for information security management, alongside the SOC 2 Type 1 attestation we already held. We think it is worth explaining what that does and does not prove, because "certified" is a word that gets used loosely in software marketing and the detail is the part that matters.

Why this matters more in medico-legal than almost anywhere else

Health is not an average sector for data breaches. It is the worst one. In the Office of the Australian Information Commissioner's notifiable data breaches statistics, health service providers have consistently been the single largest reporting sector, and the OAIC reported that 2025 set an all-time high for notifications overall, with health accounting for roughly a fifth of them. If you handle medico-legal files, you are working in the most-targeted part of the Australian economy.

The second thing worth knowing is that using a vendor does not move the obligation off you. Australian Privacy Principle 11 requires an entity holding personal information to take reasonable steps to protect it from misuse, interference, loss and unauthorised access, and the OAIC's guidance is explicit that what counts as reasonable scales with the sensitivity and volume of the information. Health information at volume sits at the demanding end of that scale. Choosing a supplier is one of the steps you are expected to have taken reasonably, which in practice means you need something better than a vendor's own assurance that they take security seriously.

That is the gap a certification fills. Not marketing copy about our commitment to your privacy, but a third party who has no incentive to flatter us going through the evidence.

What ISO 27001 actually certifies

The most common misunderstanding is that ISO 27001 is a checklist of security features. It is not. It certifies a management system: the way an organisation identifies its information security risks, decides what to do about each one, assigns someone accountable, and reviews whether any of it is working.

The 2022 revision of the standard sets out a reference list of 93 controls in Annex A, grouped into four themes: organisational, people, physical and technological. Those cover the things you would expect, including access control, cryptography, supplier relationships, logging and monitoring, secure development and incident response. Crucially, an organisation does not simply tick all 93. It runs a risk assessment and produces a Statement of Applicability recording which controls apply, how they are implemented, and a justification for anything excluded. The auditor then tests that document against reality.

This is why the management-system framing matters. A feature list tells you what a product had on the day the page was written. A certified ISMS tells you there is a defined process for noticing when something changes, and a named person answerable for it.

A certificate is not a promise that nothing will ever go wrong. It is independent evidence that there is a system for making it less likely, and for catching it quickly when it does.

It is an ongoing commitment, not a one-off exam

Certification is awarded after a two-stage audit. Stage 1 reviews the ISMS documentation and readiness. Stage 2 is the substantive assessment of whether the controls are genuinely implemented and effective. A certificate then runs on a three-year cycle with annual surveillance audits in between, and recertification at the end of it.

The practical consequence is the part specialists should care about. We cannot pass once, put a logo in the footer and let things slide, because an external auditor returns every year and the certificate can be withdrawn. The standard obliges us to keep the risk assessment current, keep evidence of the controls operating, and demonstrate improvement over time.

ISO 27001 and SOC 2 answer different questions

We hold both, and they are genuinely not duplicates. They are different instruments produced by different processes.

We will be direct about where we sit: we have a SOC 2 Type 1 attestation, and the Type 2 examination is in progress rather than complete. We would rather say that plainly than let a badge imply more than it should. The ISO 27001 certification is the reason we think the overall picture is now a strong one, because the annual surveillance cycle it commits us to covers the same ground continuously.

What certification does not mean

Honesty about the limits is part of the point, so here is what we are not claiming.

What sits behind the certificate

The controls the standard governs are the ones we describe on our security and trust page, and they have not changed because of the audit. They are simply now independently verified. Data is hosted onshore, in Australia for Australian customers. It is encrypted with AES-256 at rest and TLS 1.3 in transit. Access is role-based and least-privilege, with multi-factor authentication. Everything is logged, with document access history and user activity tracking, and we run regular security testing. For practices, enterprise controls including SSO via SAML and OIDC and IP allowlisting are available.

If you are completing a vendor security questionnaire, or your practice manager or insurer is asking for evidence, the certificates and reports are available through our Trust Centre, and our privacy policy sets out how information is handled, where it is stored and what we do and do not do with it. If something you need is not there, ask us and we will send it.

The point of all of this

Medilee's design principle is that you form the opinion and we handle everything around it. Handling everything around it includes being trustworthy with the material you hand over. A specialist should not have to take a software vendor's word about how a 500-page referral bundle full of somebody's medical history is stored, who can reach it and what happens if something goes wrong. Now you do not have to take ours.

Bring the security questions.

Twenty minutes on a representative referral file matched to your work, and we will walk through hosting, access, retention and audit logging with you rather than around you.

Keep reading
Article
Keeping clinical judgement defensible when AI is in the workflow
Article
Why fixed-fee schemes make capacity the only way to grow
For practices
Clear the report backlog across your whole practice