Security & Governance

How RebateRight protects your data and ensures compliance with Australian healthcare regulations
View as Markdown
Zero Data Persistence

Patient data is never stored. Every request is processed in real time and immediately discarded.

Australian Data Sovereignty

Your data never leaves Australia. Requests are processed within Microsoft Azure’s Australia East region.

Your Key, Hashed

Your API key is held only as a one-way hash, which cannot be reversed to recover the key.


Zero Data Persistence Architecture

Real-time processing only: Patient data flows through our system without ever being stored. Each request is processed immediately and discarded, ensuring no sensitive information remains in our infrastructure.

Stateless serverless design: Every request is handled independently, with no session carried from one request to the next. Patient data is not retained once the response is returned.


Australian Data Sovereignty & Compliance

Complete geographic containment: Your data never crosses Australian borders. Requests are processed within Microsoft Azure’s Australia East region, from ingestion to response.

Government-grade security: Microsoft Azure has completed an IRAP (Information Security Registered Assessors Program) assessment for Australian government data processing, supporting workloads up to and including the PROTECTED classification level in Australian regions.

Enterprise compliance framework: Azure provides compliance with ISO 27001, SOC 2, HIPAA, GDPR, and numerous other global security standards.

For more information on Microsoft Azure’s compliance certifications, see Microsoft Azure Compliance.


Your Keys, Your Control

Your API key is never stored in a readable form: we hold a one-way hash of it, which is enough to recognise your key on a request but cannot be reversed to recover the key itself. If you lose your key we issue a new one rather than retrieving the old one, because retrieving it is not something we are able to do.


Enterprise-Grade Infrastructure

Azure reliability: RebateRight runs on Microsoft Azure infrastructure that scales with demand rather than fixed capacity, so a busy period needs no provisioning on your side or ours. Response times and recovery are covered on the Reliability page.

Security by design: Every component follows security best practices including:

  • TLS 1.2/1.3 encrypted transit
  • Minimal attack surface
  • Secure development lifecycle with vulnerability scanning
  • Continuous monitoring for threats

Government-standard integration: Communications with Services Australia, including Medicare, use PRODA (Provider Digital Access), Services Australia’s secure authentication mechanism.


Usage Data We Store

To keep billing accurate and provide you with usage insights, RebateRight stores a minimal set of operational metadata about requests.

This metadata never includes patient information: no names, Medicare card numbers, dates of birth or Individual Healthcare Identifiers. It is retained for billing and for the usage reports you see in the application.

Metadata stored includes details such as:

  • When the request was made, and which endpoint was called
  • Which MBS item numbers were requested
  • The outcome of the operation (for example, eligible or not eligible)

We do not use government-related identifiers as our own identifier for you or for any patient. Your account is keyed to a subscriber code we issue. How we handle identifiers is set out in full in our Privacy Policy.