Healthcare · Updated 2026-09-08

How do I check if my Dubai clinic's software is DHA-compliant?

Short answer

Your clinic software is DHA-compliant only if it meets all of: UAE-hosted patient data, Nabidh Health Information Exchange integration, encrypted patient records with audit trails, explicit consent capture with amendment history, eClaim insurance submission, breach notification procedures, and role-based access with mandatory MFA for clinical staff. Compliance isn't a badge — it's the shape of the whole system.

Most clinics that fail their first DHA audit fail on data residency (patient data hosted on generic AWS us-east-1 rather than AWS Middle East / Azure UAE North) or on Nabidh integration being deferred until 'later'.

The 10-point DHA compliance checklist

Run this against your current vendor. Any 'no' is a compliance risk.

  • 1. Is patient data stored on UAE-hosted infrastructure (AWS Middle East, Azure UAE North, or licensed on-prem)?
  • 2. Is your system integrated with Nabidh (Dubai) or Riayati (federal)?
  • 3. Are diagnoses coded in SNOMED CT and lab tests in LOINC (not free text)?
  • 4. Do you generate eClaim XML for insurance submission at point-of-care?
  • 5. Are patient consent forms captured with timestamp, IP, and amendment history?
  • 6. Are patient-facing communications available in Arabic with medical-grade translation?
  • 7. Do clinical users have MFA (multi-factor authentication)?
  • 8. Is there a documented breach notification procedure to DHA within 72 hours?
  • 9. Are audit logs retained per DHA requirement (typically 7 years)?
  • 10. Can patients export their own data on request (patient-rights compliance)?

What DHA actually checks in an audit

Auditors look for evidence, not claims. Prepare these before the audit:

  • Data flow diagrams showing where every piece of patient data lives and moves
  • Sample encrypted export of a patient record demonstrating audit trail
  • Consent capture demo with the amendment history visible
  • Nabidh integration logs showing successful submissions
  • Breach response playbook with named responsible party

Related questions

Have a question we didn't answer? Drop your email and we'll send a specific reply — or jump into WhatsApp for a real-time chat.

We reply within one working day. No spam, no drip sequences — one human on the other end.

Continue reading