Healthcare · Updated 2026-09-08
How do I check if my Dubai clinic's software is DHA-compliant?
Short answer
Your clinic software is DHA-compliant only if it meets all of: UAE-hosted patient data, Nabidh Health Information Exchange integration, encrypted patient records with audit trails, explicit consent capture with amendment history, eClaim insurance submission, breach notification procedures, and role-based access with mandatory MFA for clinical staff. Compliance isn't a badge — it's the shape of the whole system.
Most clinics that fail their first DHA audit fail on data residency (patient data hosted on generic AWS us-east-1 rather than AWS Middle East / Azure UAE North) or on Nabidh integration being deferred until 'later'.
The 10-point DHA compliance checklist
Run this against your current vendor. Any 'no' is a compliance risk.
- 1. Is patient data stored on UAE-hosted infrastructure (AWS Middle East, Azure UAE North, or licensed on-prem)?
- 2. Is your system integrated with Nabidh (Dubai) or Riayati (federal)?
- 3. Are diagnoses coded in SNOMED CT and lab tests in LOINC (not free text)?
- 4. Do you generate eClaim XML for insurance submission at point-of-care?
- 5. Are patient consent forms captured with timestamp, IP, and amendment history?
- 6. Are patient-facing communications available in Arabic with medical-grade translation?
- 7. Do clinical users have MFA (multi-factor authentication)?
- 8. Is there a documented breach notification procedure to DHA within 72 hours?
- 9. Are audit logs retained per DHA requirement (typically 7 years)?
- 10. Can patients export their own data on request (patient-rights compliance)?
What DHA actually checks in an audit
Auditors look for evidence, not claims. Prepare these before the audit:
- Data flow diagrams showing where every piece of patient data lives and moves
- Sample encrypted export of a patient record demonstrating audit trail
- Consent capture demo with the amendment history visible
- Nabidh integration logs showing successful submissions
- Breach response playbook with named responsible party
