Blog / UAE compliance

UAE compliance

The NABIDH Connection Audit: What a Dubai Clinic Is Asked, in the Order It Is Asked

The NABIDH connection audit for a Dubai clinic, in the order the DHA asks: facility identity, EMR interface, consent, access control, audit trail and evidence.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programs24 September 2026 · 6 min read

The questionnaire came to the clinic, not to the vendor

The clinic director of a three-chair paediatric dental practice in Al Barsha signed the EMR contract in April partly because of one sentence in the proposal: full NABIDH integration handled end to end. She took it at face value. The vendor was competent, the interface went live in June, and records started flowing to the exchange without drama.

In September a questionnaire arrives. It is addressed to the facility. Section 1 asks for the DHA licence and the named information security officer for the practice. Section 3 asks for a list of every user account with its role and the date of the last access review. Section 5 asks how consent status is checked before a record is shared, and by whom. Section 7 asks for audit log samples.

She forwards it to the vendor. The vendor replies, politely, that they can supply the interface certificate and the transaction logs on their side, and that the rest sits with the clinic.

The clinic has four staff sharing one reception login called "frontdesk". The last access review is not a thing that has ever happened. Nobody has been named as information security officer. The interface is fine. Everything the interface connects to is the problem, and there are eleven working days.

NABIDH, in plain words

NABIDH is the Dubai Health Authority's health information exchange. Every DHA-licensed facility connects so that a patient's record travels with the patient. The connection is technical. The obligations are not, and they sit with the licensed facility.

The audit asks in a predictable order, and the order tells you what the regulator cares about.

Facility identity comes first: licence, scope of services, and a named person accountable for information security. A clinic with no name in that box has answered nothing yet.

The EMR interface comes second: is the certified integration live, and is data flowing in real time rather than in batches when somebody remembers.

Consent comes third: the patient's recorded choice about who may view their record on the exchange, and the emergency-access rules the DHA defines around it.

Access control comes fourth: named accounts, roles that match what a person needs, and a record of the last review.

Audit trail comes fifth: a complete log of who viewed or changed each record, when, and from where, retained long enough to answer a question months later.

Evidence comes last, and it is the section that decides how the rest are read. The strongest answers are dated documents, not descriptions.

The numbers that matter

Healthcare recorded 1,438 confirmed breaches in the Verizon 2026 Data Breach Investigations Report, more than almost any other sector in the study. Clinics of three chairs are inside that count, because attackers pick by data value and defensive gaps rather than by headcount.

The human element was involved in 62 percent of breaches in the same Verizon 2026 report. That figure is the argument for named accounts and role-based access in one line: when four people share a login, every mistake is anonymous and every log entry is useless.

The Center for Internet Security's Community Defense Model v2.0 found that Implementation Group 1, a set of 56 safeguards, defends against 77 percent of attack techniques and 86 percent of insider and privilege-misuse techniques. Access control and audit logging are in that group, and they happen to be sections 4 and 5 of the questionnaire.

What to do this week

  1. Name the person. One line, in writing, with the DHA licence number: who is accountable for information security at this facility. Section 1 of every audit starts there and the answer takes ten minutes. (CIS 3 Data Protection)
  2. Kill every shared login this week. Each dentist, nurse, hygienist and receptionist gets a named account in the EMR and in the clinic mailbox, with a second factor on both. Delete "frontdesk" rather than renaming it. (CIS 6 Access Control Management)
  3. Set roles so reception can book, bill and register without opening clinical notes, then run an access review and record the date and the reviewer. Put the next review in the calendar for three months out. (CIS 5 Account Management)
  4. Turn on audit logging in the EMR and the mail platform, extend retention to at least twelve months, and export one week of samples now so section 7 has an answer that exists. (CIS 8 Audit Log Management)
  5. Map every route patient data can take out of the clinic: the exchange, insurance portals, the imaging system, the lab, referral letters, the messaging group the team uses for photographs, and any personal email account. Close the ones that should not exist and write down the ones that should. Read the NABIDH requirements alongside the map so the two match. (CIS 3 Data Protection)
  6. Train the team on consent status in a ten-minute session: how to check it, what emergency access means, and why a referring doctor asking for a record today is not a reason to work around it. Keep the attendance sheet, dated. (CIS 6 Access Control Management)

Where AccuSights fits

Our assessment walks your clinic through the same order the audit uses, from facility identity to evidence, and hands back a ranked list your practice manager and IT partner can work from. The read-only compliance agent then keeps that picture current: where patient data travels, which accounts exist, which controls are missing, so you can prioritise and keep an eye on it between reviews. We have no access to your systems and we do not remediate. You or your IT partner fix; we show you where. We work with clinics across Dubai.

Questions people ask

Our EMR vendor says they handle NABIDH. Is that enough? The vendor handles the interface. The licensed facility answers for everything the interface touches: who has an account, what each role can see, whether consent status is respected at the front desk, and whether the audit trail is complete. Ask your vendor in writing which questions they will answer on your behalf and which ones they will not. The gap between those two lists is your work.

What evidence should we have ready before the audit? A current user list with roles, the date of the last access review, audit log samples showing who opened which record and when, your consent handling procedure, your data flow map including every place a report can leave the clinic, and your incident procedure with a named person. Assemble it as a folder, not as a promise, because reconstructing it under a deadline is where small clinics lose weeks.

What usually fails first in a connection audit? Shared accounts. One reception login used by four people breaks access control and audit trail at the same time, because no log entry can be attributed to a person. The second most common finding is a route patient data takes that nobody wrote down, usually a personal email account or a messaging group used for reports and images.

The interface proves the clinic can share a record. The rest of the questionnaire asks whether the clinic deserved to hold it in the first place.

Questions people ask

Our EMR vendor says they handle NABIDH. Is that enough?

The vendor handles the interface. The licensed facility answers for everything the interface touches: who has an account, what each role can see, whether consent status is respected at the front desk, and whether the audit trail is complete. Ask your vendor in writing which questions they will answer on your behalf and which ones they will not. The gap between those two lists is your work.

What evidence should we have ready before the audit?

A current user list with roles, the date of the last access review, audit log samples showing who opened which record and when, your consent handling procedure, your data flow map including every place a report can leave the clinic, and your incident procedure with a named person. Assemble it as a folder, not as a promise, because reconstructing it under a deadline is where small clinics lose weeks.

What usually fails first in a connection audit?

Shared accounts. One reception login used by four people breaks access control and audit trail at the same time, because no log entry can be attributed to a person. The second most common finding is a route patient data takes that nobody wrote down, usually a personal email account or a messaging group used for reports and images.

Controls this post maps to

CIS 6 Access Control ManagementCIS 8 Audit Log ManagementCIS 3 Data Protection

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.