We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / UAE compliance

UAE compliance

NABIDH Compliance for a Dubai Clinic: Access, Consent and the Audit Trail You Have to Prove

NABIDH compliance for a Dubai clinic: what the DHA expects on access control, patient consent and audit trails, and why connecting your EMR is only the start.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programs2 September 2026 · 6 min read

Connected to the exchange, leaking at the front desk

The clinic manager of a physiotherapy practice in Jumeirah is proud of the integration. The EMR vendor connected the clinic to NABIDH in the spring, the certificate is framed in the corridor, and every session note flows to the exchange the way the DHA wants. The physiotherapists like it. A new patient from Deira arrived last week and her MRI report was already there.

On a Thursday afternoon the manager walks past reception and sees the receptionist attach a discharge summary to an email. The "from" address ends in gmail.com. The receptionist explains: the clinic mailbox has a 25 MB limit, the scans are large, and the patient's insurer wants the report "today."

The manager asks how long this has been going on. Since the mailbox filled up in February. She asks how many reports. The receptionist scrolls. A hundred and forty, give or take, sent to insurers, referring doctors and patients, from an account whose password is the receptionist's daughter's name and birth year.

The NABIDH connection works as designed. The audit trail on the exchange is complete. The audit trail for the 140 reports that left through Gmail does not exist, because Gmail was never on the list of places the clinic thought patient data lived.

NABIDH, in plain words

NABIDH is the Dubai Health Authority's health information exchange: the platform every DHA-licensed facility connects to so that a patient's record follows the patient between clinics and hospitals. It is a good thing for care. It also changes what the regulator expects of you.

Health information exchange: a shared record system across facilities; your clinic contributes and reads.

HL7 FHIR R4: the technical language the exchange speaks; your EMR vendor handles it, but the obligation to share in real time is yours.

Consent status: the patient's choice about who may see their record on the exchange, recorded per patient and enforced by the platform.

Audit trail: a complete log of who viewed or changed a record, when, and from where; it must exist for every record, not just the ones on the exchange.

Access control: each person sees only what their role requires, under their own login.

The point that catches most clinics is scope. Connecting the EMR satisfies the sharing rule. The rules on access, consent and audit apply to every place a patient record travels, including the scanner, the WhatsApp recall group and the receptionist's personal email.

The numbers that matter

All DHA-licensed facilities must connect to NABIDH and share clinical data in real time through HL7 FHIR R4, under the Dubai Health Authority's NABIDH policies in force in 2026. Connection is not optional and it is not a one-time event; the flow must keep running.

Every record needs a complete audit trail of access and modification, with visibility controlled by the patient's consent status, per the DHA's NABIDH policies as they stand in 2026. A trail with gaps is a finding, and a report sent from Gmail is a gap.

Phishing incidents in the UAE rose 32% in the first quarter of 2026, according to the UAE Cyber Security Council's 2026 figures. Clinic mailboxes are a favourite target because a stolen login gives the attacker both patient data and a trusted address to send from.

What to do this week

  1. List every place a patient record can travel: the EMR, imaging, the lab portal, insurance submissions, the recall messaging tool, and every email account used to send reports. Personal accounts go on the list so they can come off it. (CIS 3 Data Protection)
  2. Close the personal-email route today. Give reception a clinic account with enough storage, or a secure file-transfer link, and tell the insurers the new address. (CIS 3 Data Protection)
  3. Give every staff member their own login for the EMR and the clinic mailbox, remove shared front-desk credentials, and set role-based access so reception cannot open clinical notes it does not need. (CIS 6 Access Control Management)
  4. Turn on audit logging in the EMR and the email platform, extend retention to at least a year, and assign one person to review the access report monthly. (CIS 8 Audit Log Management)
  5. Train the team on consent status: how to check it, what emergency access means, and why "the insurer needs it today" is not a reason to email a record. Keep the attendance sheet as evidence. (CIS 14 Security Awareness and Skills Training)

Where AccuSights fits

Our assessment maps your clinic against DHA's NABIDH and information security expectations, with the gaps ranked so the front desk and the IT partner know what to fix first. The read-only compliance agent then keeps that picture current: read-only insight into where patient data travels and where the controls are missing, so you can prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where. Like a falcon over the creek, it looks at everything and singles out the one thing that matters.

Questions people ask

Is NABIDH mandatory for small clinics? Yes. Every DHA-licensed facility is expected to connect and share clinical data through the platform, and the size of the clinic does not change that. What differs is how you connect: a single-doctor clinic usually goes through its EMR vendor's certified interface, while larger groups may integrate directly. Either way, the obligations on access, consent and audit trail sit with the licensed facility, not the vendor.

What happens if a patient withdraws consent in NABIDH? Their record becomes invisible to other facilities on the exchange, subject to the emergency-access rules the DHA defines. Your own clinic can still see the records it created. The practical point is that consent status is part of the record, so your staff must know how to check it, respect it, and never work around it by emailing a report to another clinic.

Does NABIDH connection cover HISS requirements? No. NABIDH is the data-sharing obligation; HISS, the DHA's information security standards for licensed facilities, covers how you protect your own systems, users and data. A clinic can be fully connected and still fail HISS on shared passwords, unpatched machines and reports sent from personal email. Treat them as two lists that overlap on access control and audit logging.

The certificate in the corridor says the exchange trusts you. The audit trail is how you keep earning it, one record at a time.

Questions people ask

Is NABIDH mandatory for small clinics?

Yes. Every DHA-licensed facility is expected to connect and share clinical data through the platform, and the size of the clinic does not change that. What differs is how you connect: a single-doctor clinic usually goes through its EMR vendor's certified interface, while larger groups may integrate directly. Either way, the obligations on access, consent and audit trail sit with the licensed facility, not the vendor.

What happens if a patient withdraws consent in NABIDH?

Their record becomes invisible to other facilities on the exchange, subject to the emergency-access rules the DHA defines. Your own clinic can still see the records it created. The practical point is that consent status is part of the record, so your staff must know how to check it, respect it, and never work around it by emailing a report to another clinic.

Does NABIDH connection cover HISS requirements?

No. NABIDH is the data-sharing obligation; HISS, the DHA's information security standards for licensed facilities, covers how you protect your own systems, users and data. A clinic can be fully connected and still fail HISS on shared passwords, unpatched machines and reports sent from personal email. Treat them as two lists that overlap on access control and audit logging.

Controls this post maps to

CIS 8 Audit Log ManagementCIS 6 Access Control ManagementCIS 3 Data Protection

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.