Health Information System Approval
DHA needs EMR conformance and NABIDH links; DOH needs approval and Malaffi.
The DHA governs Dubai and the DOH governs Abu Dhabi, each with distinct standards, registries and HIEs a system must meet to operate across the Emirates.
DHA needs EMR conformance and NABIDH links; DOH needs approval and Malaffi.
DHA Smart Health and the DOH Telehealth Policy both govern apps and AI.
DHA and DOH registries must verify clinician licences and prescribers.
Dubai claims run through DHA Shafafiya; Abu Dhabi runs its own via DOH.
Federal Decree-Law No. 45 applies UAE-wide; DHA and DOH add local rules.
MOHAP sets national standards and regulates the Northern Emirates.
Regulatory mapping to live operation, DHA and DOH.
DHA and DOH have distinct requirements — meeting both pays off.
Book a Free ConsultationEach DHA and DOH standard maps to a design and approval commitment made before a system can deploy across the UAE's dual-regulator market.
EMR and clinical systems must meet DHA and DOH recognition standards.
Frameworks for telemedicine, digital therapeutics, and AI-enabled tools.
Verify clinician licensure against the practicing Emirate's registry.
Compliant electronic claims submission through each Emirate's system.
Federal data protection law plus Emirate-specific health data standards.
Federal MOHAP standards plus Northern Emirates coverage requirements.
Most vendors do not fail UAE approval on features. They fail on assumptions carried in from another market: that one approval covers the country, that a generic FHIR build satisfies a national implementation guide, or that the Emirate a patient is treated in does not change the rules. These are the six that cost the most time.
DHA and DOH are independent authorities with separate standards, separate health information exchanges and separate claims platforms. A system cleared in Dubai has no standing in Abu Dhabi. Budget approval effort per Emirate, not per country, and sequence them rather than assuming reuse.
Both run on HL7 FHIR R4, but each publishes its own implementation guide with local profiles, code systems and identifier rules. A working FHIR server validates against base FHIR and still fails conformance. Build against the published IG from day one — retrofitting profiles after a failed assessment is the single most common source of schedule slip.
Emirates ID is the primary patient identifier for residents and citizens, with passport handling for visitors. Systems that key records on an internal MRN and treat the national ID as a secondary field produce records that are rejected or attached to the wrong patient. Identity reconciliation belongs in the data model, not in a mapping layer bolted on later.
Dubai routes through Shafafiya; Abu Dhabi through the DOH claims pathway. A single hardcoded submission endpoint works until the first cross-Emirate encounter, then fails silently against the wrong payer rules. Routing has to be driven by the facility and the payer, evaluated per claim.
A clinician licensed by DHA is not thereby licensed by DOH. Prescription authority, order signing and telehealth eligibility all depend on verification against the registry of the Emirate where care is delivered — which means the registry check is a runtime call, not an onboarding checkbox.
Federal Decree-Law No. 45 of 2021 applies UAE-wide, and DHA and DOH add health-specific localization, access control and audit logging. Where patient data physically lives, and which cloud region serves it, is an architecture decision that is expensive to reverse once a system is in assessment.
The UAE does not have one healthcare regulator. Dubai, Abu Dhabi and the Northern Emirates each answer to a different authority with its own standards, its own health information exchange and its own claims platform. A system approved in one Emirate is not approved in the others.
| DHA — Dubai | DOH — Abu Dhabi | MOHAP — Federal | |
|---|---|---|---|
| Full name | Dubai Health Authority | Department of Health Abu Dhabi | Ministry of Health and Prevention |
| Jurisdiction | Emirate of Dubai | Emirate of Abu Dhabi (incl. Al Ain, Al Dhafra) | Northern Emirates — Sharjah, Ajman, UAQ, RAK, Fujairah |
| Health information exchange | NABIDH | Malaffi | Riayati (national record) |
| Claims platform | Shafafiya / eClaimLink | DOH claims (Riayati-aligned) | Riayati claims |
| Professional registry | DHA Sheryan | DOH professional licensing | MOHAP licensing |
| System approval | DHA EMR standards + NABIDH conformance | DOH clinical IS standards + Malaffi onboarding | MOHAP health facility IT requirements |
| Telehealth framework | DHA Smart Health / telehealth standards | DOH Telehealth Policy | MOHAP telehealth licensing |
| Data protection | DHA health data standards | DOH health data standards | Federal Decree-Law No. 45 of 2021 (applies UAE-wide) |
| Separate approval needed? | Yes | Yes — a NABIDH-approved system still needs DOH sign-off | Yes, for Northern Emirates deployment |
Federal Decree-Law No. 45 of 2021 applies across all three jurisdictions; DHA and DOH layer additional health-specific localization, access control and audit requirements on top of it. A vendor selling nationally is building against all three regimes, not one.
FHIR, HIE connectors and UAE-resident cloud for DHA and DOH.
We build dual-regulator compliance — EMR approval, NABIDH and Malaffi connectivity, registry verification and claims — into the architecture and carry it through to production in both Emirates.
Book a UAE Consult
100 Fastest Growth Companies
Global Spring Winner
Top App Development Company
AWS Partner Network
Google Cloud Partner
Highly Rated on Trustpilot
Verified Agency
Top App Development Company
ASSOCHAM Member
Yes. DHA and DOH are independent authorities, not branches of one regulator, so a system approved in Dubai has no standing in Abu Dhabi. Each maintains its own standards, its own health information exchange — NABIDH for Dubai, Malaffi for Abu Dhabi — and its own claims pathway. Plan approval per Emirate and sequence them; the second is usually faster than the first because the conformance work is reusable even when the approval is not.
MOHAP is the federal Ministry of Health and Prevention and regulates the Northern Emirates — Sharjah, Ajman, Umm Al Quwain, Ras Al Khaimah and Fujairah — where DHA and DOH have no jurisdiction. It also operates Riayati, the national unified medical record. A vendor selling nationally is therefore building against three regimes, not one, and should decide early whether Northern Emirates coverage is in scope or a later phase.
Federal Decree-Law No. 45 of 2021 is the baseline and applies UAE-wide. On top of it, DHA and DOH each add health-specific requirements covering data localization, role-based access control and audit logging. The practical consequence is architectural: where patient data physically resides and which cloud region serves it has to be settled before build, because reversing it once a system is in assessment is expensive.
Plan it in phases rather than as a single number. Registration and documentation is largely administrative. The build and conformance mapping is the longest phase and scales with how far your data model sits from the published implementation guide and how many local code sets need mapping. Assessment itself then depends partly on a review queue outside your control. For a vendor with a working product and a contained scope, a few months per Emirate is realistic; a multi-facility group with legacy systems should plan for longer. The biggest variable is how many assessment cycles you need, which is why we validate continuously during the build.
Almost always a compliance layer rather than a rebuild, and that is the more common engagement. We read your existing data model, map local codes to the required standards, reconcile patient identity to Emirates ID, and emit conformant FHIR to NABIDH or Malaffi alongside the system your clinicians already use. This also avoids depending on your EMR vendor to extend their product, which matters when the vendor is unwilling or the version is old.
Cost tracks the integration surface rather than a per-facility price. The drivers are how far your current data model is from the published FHIR implementation guides, how many Emirates are in scope, how many downstream systems connect, and whether you need support after approval. We scope in two steps: a paid discovery producing an integration inventory and conformance plan, then a fixed or phased build against that plan. We do not publish a headline price because a number given before seeing your system would be a guess, and the discovery output is useful to you even if you build elsewhere.
If the facility is DHA-licensed, NABIDH connectivity is mandatory; if DOH-licensed, Malaffi connectivity is mandatory. The rollouts are phased by facility type, and new licence applicants are expected to demonstrate connectivity capability as part of licensing. In practice this means the integration determines whether the facility can operate, not just whether it is compliant.
Yes. Licensure is Emirate-scoped: a clinician licensed by DHA is not thereby licensed by DOH. Prescription authority, order signing and telehealth eligibility all depend on verification against the registry of the Emirate where care is actually delivered. That makes the registry check a runtime call in the clinical workflow rather than a one-time onboarding step.
Yes, as a defined scope rather than an informal understanding. NABIDH, Malaffi and the claims platforms are live systems: implementation guides are versioned, payer behaviour changes and code systems get revised, so a connection that passed assessment can begin failing quietly. Post-approval scope covers submission and rejection monitoring by category, alerting when error rates shift, handling implementation guide revisions as published, and named response expectations.