Blog / UAE compliance
UAE compliance
NABIDH Compliance for a Dubai Clinic: Access, Consent and the Audit Trail You Have to Prove
NABIDH compliance for a Dubai clinic: what the DHA expects on access control, patient consent and audit trails, and why connecting your EMR is only the start.
Connected to the exchange, leaking at the front desk
The clinic manager of a physiotherapy practice in Jumeirah is proud of the integration. The EMR vendor connected the clinic to NABIDH in the spring, the certificate is framed in the corridor, and every session note flows to the exchange the way the DHA wants. The physiotherapists like it. A new patient from Deira arrived last week and her MRI report was already there.
On a Thursday afternoon the manager walks past reception and sees the receptionist attach a discharge summary to an email. The "from" address ends in gmail.com. The receptionist explains: the clinic mailbox has a 25 MB limit, the scans are large, and the patient's insurer wants the report "today."
The manager asks how long this has been going on. Since the mailbox filled up in February. She asks how many reports. The receptionist scrolls. A hundred and forty, give or take, sent to insurers, referring doctors and patients, from an account whose password is the receptionist's daughter's name and birth year.
The NABIDH connection works as designed. The audit trail on the exchange is complete. The audit trail for the 140 reports that left through Gmail does not exist, because Gmail was never on the list of places the clinic thought patient data lived.
NABIDH, in plain words
NABIDH is the Dubai Health Authority's health information exchange: the platform every DHA-licensed facility connects to so that a patient's record follows the patient between clinics and hospitals. It is a good thing for care. It also changes what the regulator expects of you.
Health information exchange: a shared record system across facilities; your clinic contributes and reads.
HL7 FHIR R4: the technical language the exchange speaks; your EMR vendor handles it, but the obligation to share in real time is yours.
Consent status: the patient's choice about who may see their record on the exchange, recorded per patient and enforced by the platform.
Audit trail: a complete log of who viewed or changed a record, when, and from where; it must exist for every record, not just the ones on the exchange.
Access control: each person sees only what their role requires, under their own login.
The point that catches most clinics is scope. Connecting the EMR satisfies the sharing rule. The rules on access, consent and audit apply to every place a patient record travels, including the scanner, the WhatsApp recall group and the receptionist's personal email.
The numbers that matter
All DHA-licensed facilities must connect to NABIDH and share clinical data in real time through HL7 FHIR R4, under the Dubai Health Authority's NABIDH policies in force in 2026. Connection is not optional and it is not a one-time event; the flow must keep running.
Every record needs a complete audit trail of access and modification, with visibility controlled by the patient's consent status, per the DHA's NABIDH policies as they stand in 2026. A trail with gaps is a finding, and a report sent from Gmail is a gap.
Phishing incidents in the UAE rose 32% in the first quarter of 2026, according to the UAE Cyber Security Council's 2026 figures. Clinic mailboxes are a favourite target because a stolen login gives the attacker both patient data and a trusted address to send from.
What to do this week
- List every place a patient record can travel: the EMR, imaging, the lab portal, insurance submissions, the recall messaging tool, and every email account used to send reports. Personal accounts go on the list so they can come off it. (CIS 3 Data Protection)
- Close the personal-email route today. Give reception a clinic account with enough storage, or a secure file-transfer link, and tell the insurers the new address. (CIS 3 Data Protection)
- Give every staff member their own login for the EMR and the clinic mailbox, remove shared front-desk credentials, and set role-based access so reception cannot open clinical notes it does not need. (CIS 6 Access Control Management)
- Turn on audit logging in the EMR and the email platform, extend retention to at least a year, and assign one person to review the access report monthly. (CIS 8 Audit Log Management)
- Train the team on consent status: how to check it, what emergency access means, and why "the insurer needs it today" is not a reason to email a record. Keep the attendance sheet as evidence. (CIS 14 Security Awareness and Skills Training)
Where AccuSights fits
Our assessment maps your clinic against DHA's NABIDH and information security expectations, with the gaps ranked so the front desk and the IT partner know what to fix first. The read-only compliance agent then keeps that picture current: read-only insight into where patient data travels and where the controls are missing, so you can prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where. Like a falcon over the creek, it looks at everything and singles out the one thing that matters.
Questions people ask
Is NABIDH mandatory for small clinics? Yes. Every DHA-licensed facility is expected to connect and share clinical data through the platform, and the size of the clinic does not change that. What differs is how you connect: a single-doctor clinic usually goes through its EMR vendor's certified interface, while larger groups may integrate directly. Either way, the obligations on access, consent and audit trail sit with the licensed facility, not the vendor.
What happens if a patient withdraws consent in NABIDH? Their record becomes invisible to other facilities on the exchange, subject to the emergency-access rules the DHA defines. Your own clinic can still see the records it created. The practical point is that consent status is part of the record, so your staff must know how to check it, respect it, and never work around it by emailing a report to another clinic.
Does NABIDH connection cover HISS requirements? No. NABIDH is the data-sharing obligation; HISS, the DHA's information security standards for licensed facilities, covers how you protect your own systems, users and data. A clinic can be fully connected and still fail HISS on shared passwords, unpatched machines and reports sent from personal email. Treat them as two lists that overlap on access control and audit logging.
The certificate in the corridor says the exchange trusts you. The audit trail is how you keep earning it, one record at a time.
Questions people ask
Is NABIDH mandatory for small clinics?
Yes. Every DHA-licensed facility is expected to connect and share clinical data through the platform, and the size of the clinic does not change that. What differs is how you connect: a single-doctor clinic usually goes through its EMR vendor's certified interface, while larger groups may integrate directly. Either way, the obligations on access, consent and audit trail sit with the licensed facility, not the vendor.
What happens if a patient withdraws consent in NABIDH?
Their record becomes invisible to other facilities on the exchange, subject to the emergency-access rules the DHA defines. Your own clinic can still see the records it created. The practical point is that consent status is part of the record, so your staff must know how to check it, respect it, and never work around it by emailing a report to another clinic.
Does NABIDH connection cover HISS requirements?
No. NABIDH is the data-sharing obligation; HISS, the DHA's information security standards for licensed facilities, covers how you protect your own systems, users and data. A clinic can be fully connected and still fail HISS on shared passwords, unpatched machines and reports sent from personal email. Treat them as two lists that overlap on access control and audit logging.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
ADHICS v2 for a Clinic: Three Tiers, a 24-Hour Clock and What the DoH Auditor Asks
ADHICS v2 compliance for an Abu Dhabi clinic: which tier applies, what the 24-hour breach notice means, and what the DoH auditor asks at renewal.
UAE complianceCBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks
CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.
UAE complianceDIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
