Compliance & Regulation

UAE health data law for clinics: the ICT Health Law, data localization and consent

What Federal Law No. 2 of 2019 means for a clinic's software, hosting, retention and consent, how it relates to the UAE's general data protection law, and the questions to ask every vendor.

Short answer: the main UAE law on health data is Federal Law No. 2 of 2019 on the use of information and communications technology in health fields. It applies across the UAE, including free zones. It restricts storing or processing UAE health data outside the country, requires confidentiality, and sets a minimum retention period of 25 years from the patient's last procedure. Your clinic software's security should be built for it.

Clinic owners do not need to become lawyers, but they do need to ask the right questions of their software and cloud vendors. This guide summarizes the parts of the law that most affect clinic IT, and it points out where you should get legal advice.

This article is general guidance, not legal advice. Regulators update their standards, circulars and deadlines often, so always confirm the current requirement with the relevant authority or a qualified advisor before you act on it.

The ICT Health Law in brief

Federal Law No. 2 of 2019 came into force in 2019. It applies to entities across the UAE, including free zones, that provide healthcare, health insurance, health IT or related services. Its executive regulation was issued by Cabinet Resolution No. 32 of 2020, and later ministerial resolutions added clarifications and exceptions. The law sits alongside emirate-level rules from the DHA, DOH and MOHAP, which have their own data and security policies.

The four provisions that matter most for clinic IT

TopicWhat the law says (in general terms)What it means for your software
Data localizationHealth data relating to health services provided in the UAE may not be stored, processed, generated or transferred outside the UAE, except in cases set by decision of the health authority and the ministry.Know where your EMR, backups and any AI or analytics services are hosted. 'The cloud' is not an answer.
ConfidentialityHealth data must be kept confidential and used only for permitted purposes, with disclosure allowed only in defined cases.Role-based access, so staff see only what their job needs.
Integrity and securityHealth data must be accurate and reliable, and protected against unauthorized access, change or deletion.Audit logs of views and edits; no silent deletions.
RetentionHealth data must be kept for as long as needed, and not less than 25 years from the date of the last procedure.Your system must keep records, including migrated ones, retrievable for decades.

The localization rule has the biggest practical impact. It affects cloud hosting abroad, overseas support teams with remote access, offshore transcription, and any third-party AI service that receives patient data. Exceptions exist, but they are specific. If a vendor's model depends on sending data outside the UAE, ask them which exception they rely on and get legal advice.

Fig. 01 · Checklist

What the law asks

  • Data stored in the UAE
  • Confidential, role-based access
  • Audit logs, no silent deletions
  • Records kept 25+ years
The four provisions translate into hosting, access, audit and retention questions for your vendor.

Where does the UAE PDPL fit?

The UAE's general data protection law, Federal Decree-Law No. 45 of 2021 (the PDPL), treats health data as sensitive. However, the PDPL itself excludes health personal data that is governed by its own legislation. In practice, the ICT Health Law is the primary law for patient data in clinical systems, while the PDPL may still matter for other personal data a clinic handles, such as marketing lists, job applicants or website forms. Free zones such as DIFC and ADGM have their own data protection regimes. How these laws interact for your specific activities is exactly the kind of question to put to a lawyer.

  • Treatment consent is clinical and procedural. Keep signed consent forms in the patient record, with date, version and signer.
  • Health information exchange participation (NABIDH, Malaffi, Riayati) follows each authority's consent and opt-out rules. Front-desk staff should know them.
  • Marketing and reminders are different from care. Record separate consent for marketing messages, respect opt-outs and keep a history of what was agreed and when.
  • Sharing with third parties (insurers, labs, referral partners) should be limited to what the purpose needs and logged.

Marketing consent is where clinics most often slip. A patient who agreed to appointment reminders has not necessarily agreed to promotional campaigns. A healthcare CRM with a consent ledger, opt-out handling and contact caps makes the difference visible to staff.

Emirate-level rules sit on top

The federal law is the baseline. Each health authority adds its own layer. Abu Dhabi's DOH has ADHICS, its healthcare information and cyber security standard. Dubai's DHA and MOHAP have their own data, exchange and security policies, which also govern how you connect to NABIDH and Riayati. Our UAE compliance overview and the emirate-by-emirate map show which apply where.

Fig. 02 · Layers

How the rules stack

  1. Your clinic systemsHosting, access, audit logs and retention
  2. Health authority rulesDHA, DOH (ADHICS) and MOHAP policies
  3. Federal ICT Health LawFederal Law No. 2 of 2019, the baseline
The federal law sets the baseline, and your health authority's rules sit on top of it.

Questions to ask every software vendor

  1. Where exactly are production data, backups and disaster-recovery copies stored?
  2. Does any service (support, analytics, transcription, AI) access or receive patient data from outside the UAE or the GCC?
  3. If you use AI, which models, hosted where? Is our data used to train them?
  4. How is access controlled by role, and can we see an audit log of who viewed or changed a record?
  5. Can records be deleted outright, or are deletions soft and logged?
  6. How will records stay retrievable for at least 25 years, including through a future migration?
  7. What happens to our data if we leave?

The AI question is new and important. Many AI scribes and chat tools send audio or text to a third-party model provider abroad. Our article on self-hosted AI in healthcare explains why that matters under a localization rule.

How Helix approaches it

Helix runs with full GCC data residency. Its Verto AI models are hosted in Helix's own cloud, never sent to third-party AI APIs, and never trained on customer data. Access is controlled by around 700 role-based permissions, every action is written to an audit log, and deletions are soft, so nothing is silently erased. Consent forms are signed electronically into the record, and the CRM keeps a consent ledger for marketing. Helix is HIPAA, SOC 2 and GDPR compliant. Whether a given setup meets your obligations under UAE law is still a question for your own legal review, and we are happy to answer your lawyer's questions in detail. For the international frameworks, see HIPAA, GDPR and GCC clinics.

Can a UAE clinic store patient data in a cloud outside the UAE?

Federal Law No. 2 of 2019 restricts storing or processing UAE health data outside the country, except in cases permitted by decision of the health authorities. Get legal advice before relying on an exception.

How long must UAE clinics keep medical records?

The law sets a minimum of 25 years from the date of the patient's last procedure, or longer if needed.

Does the UAE PDPL apply to patient records?

The PDPL excludes health personal data that has its own governing legislation, so the ICT Health Law is the main law for clinical data. The PDPL can still matter for other personal data. Confirm with a lawyer.

Does the ICT Health Law apply in free zones?

Yes. It applies across the UAE, including free zones, to entities providing health-related services.