Every time you are treated at a licensed clinic or hospital in the UAE, your record is uploaded to a government health information exchange, and no one has to ask your permission first. Dubai’s rulebook says so in one line: consent is not required for uploading health information to NABIDH by healthcare facilities. Your file must then stay inside the country, and it must be kept for at least 25 years after your last procedure.
That surprises most residents, who assume a medical record is something their own clinic holds and nobody else sees. This guide sets out who actually holds your UAE health data, which staff can open it, when a doctor can read it in an emergency without asking, the five situations where it can be shared without your written approval, whether you can opt out, and what the law does to anyone who moves it abroad.
The Three Systems That Hold Your UAE Health Record
The UAE does not run one national medical record. It runs three connected exchanges, split by regulator, and which one holds your file depends on where you were treated rather than where you live. The federal platform is Riayati, run by the Ministry of Health and Prevention; Abu Dhabi has Malaffi; Dubai has NABIDH. The three were formally integrated, so a record created in one emirate can surface in another.
| System | Who runs it | Coverage | Documented patient opt-out |
|---|---|---|---|
| Riayati (National Unified Medical Record) | Ministry of Health and Prevention | Federal, including the northern emirates | No published patient-facing opt-out process |
| Malaffi | Abu Dhabi Health Data Services LLC, a public-private partnership with the Department of Health, Abu Dhabi | Emirate of Abu Dhabi | No opt-out route published on the platform’s own patient or FAQ pages |
| NABIDH | Dubai Health Authority | DHA-licensed facilities in Dubai | Yes, a signed opt-out form sent to the DHA NABIDH team |
Malaffi is operated by Abu Dhabi Health Data Services, an M42 company, and its own description of what it holds is broad: demographics, encounters, allergies, laboratory results, radiology reports and images, medications, immunizations, diagnoses, procedures, clinical documents, vital signs and appointments. That is the whole clinical picture, not a summary.
Does Anyone Need Your Consent Before Your Record Is Uploaded?
No. Dubai’s Standards for Health Information Consent and Access Control (DHA/HISHD/ST-09), issued 2 January 2025 and effective 2 April 2025, states at clause 8.17 that consent is not required for uploading health information to NABIDH by healthcare facilities. Clause 8.18 goes further and requires facilities to build a NABIDH sharing clause into their general consent form. Clause 6.1 adds that consent is not required to record or access your data inside your own clinic’s electronic medical record either.
Consent enters the picture at a different point. It is required for accessing your data through other health information systems (clause 8.2), it must be specific, freely given, informed and unambiguous (8.6), it must be in writing in Arabic or English (8.7), and it expires. Under clause 8.16, consent for accessing a health information system remains valid for one year after your last health encounter unless you revoke it earlier.
Who signs for a child or an unconscious patient
The age of consent for health information is 18 (clause 8.13). For anyone younger, consent comes from a person with parental responsibility or legal guardianship, and that authority has to be verified and documented alongside the consent. Where the patient is incompetent or unable to consent, for example unconscious on arrival, consent is taken from the next of kin, which the standard defines as relatives up to the fourth degree, or from a legal guardian. If you have arranged formal guardianship arrangements for your children in the UAE, that documentation is what a hospital will ask to see.
Who Can Actually Open Your File
Access is role-based rather than open. For a licensed clinician, the role is tied to the code attached to their Sheryan license ID as maintained by the DHA (clause 10.11), so the system knows what a given practitioner is entitled to see. Staff without a Sheryan ID are mapped to a standard role defined by the facility.
The operating principles are “need to know” and “least privilege” (clause 10.5), with users split between update access, meaning they can enter and change data, and lookup access, meaning read-only. Every user must sign a User and Confidentiality Access Agreement before touching the system (clause 10.3), passwords and user IDs may not be shared, and authorization has to be reviewed and revalidated at least annually alongside staff reappointment (clause 10.17). Access is revoked immediately when someone leaves, changes duties, misuses their access, or has their account compromised (clause 13.4).
Records of who was granted, changed or removed access are kept for a minimum of six years (clause 13.3). That is separate from, and much shorter than, the retention period for the clinical record itself.
Break the Glass: When a Doctor Reads Your File Without Asking
Health information systems in Dubai must include a “break the glass” procedure that lets a physician without normal access privileges reach your record in an emergency. Only physicians providing direct care to you may use it (clause 17.1), and it is permitted in two situations: treating an emergency condition to lessen or prevent a serious threat to your life, health or safety, and preventing a serious threat to public health, for example tracing the source of a serious infection.
The safeguards are procedural rather than preventive. The system should throw a warning screen before the data opens (clause 17.3), the clinician must justify the circumstances case by case (17.4), the reason and a detailed audit trail must be documented (17.6), and the access must trigger a notification, be strictly monitored, be logged, and be reviewed regularly for unauthorized use (17.7). Clause 17.8 confirms no consent is needed, but requires the facility to make sure break-the-glass access stops once the emergency is over.
Malaffi runs an equivalent control it calls the Privacy Seal. Only Level 1 users have authority to break the Privacy Seal and reach all patient data including sensitive information, and the platform’s own guidance confirms that action is audited and logged.
The Five Cases Where Your Data Can Be Shared Without Your Approval
The federal rule sits in Article 16 of Federal Law No. 2 of 2019 on the Use of Information and Communications Technology in Health Fields. Anyone circulating patient information must keep it confidential and use it only for health purposes without the patient’s written approval, except in five listed cases:
- Data requested by health insurers or any body funding your care, to review, approve or verify the financial entitlements for services you received
- Scientific and clinical research, provided your identity is not disclosed and research ethics are observed
- Preventive and curative measures relating to public health, or protecting the health and safety of you or anyone in contact with you
- A request from the competent judicial authorities
- A request from the Health Authority for monitoring, inspection and protection of public health
The first of those is the one residents meet most often without noticing. Every pre-authorization your insurer runs, and every claim it audits, is a lawful disclosure of your clinical data that needs no separate signature from you. It is also why an insurer’s file on you can be more detailed than you expect when a rejected health insurance claim goes to appeal.
Article 2 of the same law is worth noting for anyone treated in a free zone: it applies to all uses of information and communication technology in health in the State, including the free zones. A DIFC or ADGM clinic is not outside this regime.
Can You Opt Out of the Health Information Exchange?
In Dubai, yes, with real consequences. Standard Five of the DHA rulebook says every patient should be given the opportunity to object to sharing through a health information system where UAE law and DHA regulations allow, and that if the patient still objects after a discussion of the consequences, they must be given the right to withdraw and opt out.
The NABIDH opt-out runs through a defined process (clause 9.9): the facility gives you a copy of the opt-out consent form together with the DHA address [email protected], you sign the form and send it to the DHA NABIDH team, and the team opts you out.
What opting out does not do
Four limits matter more than the right itself.
- It does not cover everything. The right to object does not apply to sharing inside your clinic’s electronic medical record, to public health portals, or to insurance systems (clause 9.2).
- It is not retroactive. Withdrawal does not affect sharing already carried out under consent, and any entity that received your data through the exchange before you revoked and put it into its own records may keep it (clause 9.4).
- Your data still flows. After you opt out, the exchange continues to receive your health information from the facility, but your identifiers must be anonymized (clause 9.6).
- Emergency access is switched off. Once you have opted out, your information must not be retrieved through break-the-glass access (clause 9.7). That is the practical trade: an emergency physician treating you unconscious will not be able to see your allergies, medications or history.
For Abu Dhabi, no patient opt-out route is published on Malaffi’s own patient or FAQ pages, and we could not verify one from an official source. If you want to object to Abu Dhabi sharing, raise it with the Department of Health, Abu Dhabi and your treating facility directly rather than assuming the Dubai process applies.
Your Medical Record Is Not Allowed to Leave the UAE
Article 13 of Federal Law No. 2 of 2019 is blunt: it is not permissible to store, process, generate or transfer health data and information relating to health services provided inside the State outside the State, except where a resolution is issued by the Health Authority in coordination with the Ministry. The cases where transfer is allowed are set out in Ministerial Decision No. 51 of 2021.
The penalty for breaching Article 13 is a fine of no less than AED 500,000 and no more than AED 700,000 under Article 24. That is one of the heaviest data-related penalties in UAE law and it explains a practical point residents run into: a UAE clinic will often refuse to email your file to an overseas doctor, and a telehealth provider hosting records abroad cannot lawfully serve UAE patients. The same localization logic underpins the rules on what telemedicine is actually allowed to do in the UAE.
How Long Your Record Is Kept
Article 20 sets a floor rather than a ceiling. The retention period must match the need for the data, provided it is not less than 25 years from the date of the last health procedure for the person concerned. There is no patient right in the law to have a record deleted earlier, and no expiry that erases an old diagnosis.
Article 21 requires health authorities and relevant entities to record the Emirates ID number in all health transactions, records and files and to use it to organize and keep them, with exceptions for emergencies. In practice this is why your Emirates ID, rather than your passport or insurance card, is the key that pulls your history together across providers, and why the number appears on almost every clinical document you are given.
Sensitive and VIP Records Are Handled Differently
The DHA standards create two protected tiers above ordinary health information. Sensitive health information must be flagged in the system with a special icon, tagged in red on paper files, and restricted to health professionals by role (clauses 18.4 to 18.6). It can still be reached through break-the-glass by defined roles.
VIP health information goes further. It is classified as “SECRET”, access is limited to professionals actually providing care, and clause 19.9 states that the VIP health record should not be shared with the health information system at all. In other words, the exchange that holds everyone else’s file by default does not hold theirs.
What Happens If Someone Looks at Your Record Improperly
Federal Law No. 2 of 2019 puts the enforcement on institutions rather than on individual snoopers. Under Article 25, a health authority can sanction an establishment that breaches the law with a written notice, a written warning, a fine of not less than AED 1,000 and not more than AED 1,000,000, suspension of its license to use the central system for up to six months, or cancellation of that license.
The establishment can complain against a sanction to a complaints committee formed within the health authority within 15 days of being notified, and the committee must consider it within 30 days, with silence treated as rejection. The committee’s decision is final, but a rejected complainant can appeal to the competent courts within 30 days (Article 26). Article 27 lets the Minister of Justice grant law-enforcement status to designated employees to establish violations.
Article 22 preserves any more severe punishment under another law, which is the hook back into the criminal side. Publishing someone’s private medical information online, for instance, is a privacy offense under the cybercrime law rather than a health-data matter, and the exposure there is described in our guide to what UAE social media law treats as a privacy violation.
Where to raise a concern
Complaints go to the regulator that licensed the facility, which is the DHA in Dubai, the Department of Health in Abu Dhabi, and MOHAP elsewhere, the same split that governs how doctors and nurses are licensed across the UAE. Before you complain, it is worth confirming the clinic and practitioner are licensed at all, because an unlicensed provider is a separate and more serious problem. If your concern is about the quality of care rather than the data, the route is different again and runs through the medical liability complaint process and its 30-day deadline.
What This Means in Practice
Three habits are worth adopting. First, ask each new clinic which exchange it reports to, because that tells you whether a Dubai doctor will see the Abu Dhabi results you had last year. Second, ask for a copy of significant results at the time rather than later, since there is no statutory patient right of access in Federal Law No. 2 of 2019 and each facility applies its own release procedure. Third, treat the general consent form you sign at registration as a real document: under clause 8.18 it is where the NABIDH sharing clause lives, and it is the only point at which you are told, in writing, what happens to your data.
One limitation worth stating plainly. The Dubai rulebook is public and specific; the equivalent Abu Dhabi and federal patient-facing consent documents are not published in the same detail, so the precision of this guide is highest for Dubai and lower for Riayati and Malaffi. Where we could not verify an Abu Dhabi opt-out route, we have said so rather than assumed the Dubai rule carries across.
FAQ
Can my employer see my UAE medical records?
No. Nothing in Federal Law No. 2 of 2019 gives an employer access, and the exceptions in Article 16 cover insurers verifying financial entitlements, researchers using de-identified data, public health measures, judicial authorities and the health regulator. An employer is none of those. What an employer does receive is the pass or fail result of the statutory visa medical screening, which is a separate process from your clinical record.
Can I get a copy of my own medical record in the UAE?
In practice yes, by requesting it from the facility that created it, but Federal Law No. 2 of 2019 does not create an express patient right of access, so the procedure, format and any fee are set by the individual hospital or clinic rather than by federal law. Ask the medical records department in writing, bring your Emirates ID, and expect the release to cover only records that facility holds rather than everything on the exchange.
Does opting out of NABIDH delete my existing records?
No. Opting out stops identifiable sharing going forward. Data already shared under consent stays lawfully in the records of any entity that received it, your information continues to flow to the exchange in anonymized form, and the underlying clinical record at each facility remains subject to the 25-year minimum retention rule in Article 20.
Can a UAE hospital send my file to a doctor overseas?
Only within the cases allowed by Ministerial Decision No. 51 of 2021, because Article 13 otherwise prohibits storing, processing or transferring UAE health data outside the country. The fine for breaching Article 13 runs from AED 500,000 to AED 700,000, which is why many clinics simply hand the file to you rather than transmit it abroad themselves.
Who counts as next of kin if I cannot consent?
Under clause 8.15 of the DHA consent standard, where a patient is incompetent or unable to consent, consent is obtained from the next of kin, defined as relatives up to the fourth degree, or from a person with legal guardianship. The facility has to verify and document that authority alongside the consent, so bringing proof of relationship or guardianship speeds the process considerably.
How long does my consent to share data last?
One year after your last health encounter, unless you revoke it sooner, under clause 8.16. That means a long gap between visits can require fresh consent, while continuous treatment keeps the existing consent alive. Facilities must record consent, refusal, withdrawal and any re-opt-in with dates under clause 8.3.
Is my record safe from other staff at the same hospital?
The controls are role-based and audited rather than absolute. Access must follow need-to-know and least privilege, users log in under their own credentials only, every access is monitored and logged, and authorization is revalidated at least annually. Sensitive and VIP records carry additional flags and restrictions. Failure to adhere to the standard is treated as a violation requiring investigation, with disciplinary action or dismissal under UAE law and DHA legislation.
Do these rules apply to clinics in DIFC and ADGM?
Yes. Article 2 of Federal Law No. 2 of 2019 applies the law to all methods and uses of information and communication technology in the areas of health in the State, expressly including the free zones. The data localization rule in Article 13 and the 25-year retention floor in Article 20 apply to a free zone clinic in the same way.
What is the penalty if a clinic mishandles my health data?
The health authority can impose a written notice, a written warning, a fine between AED 1,000 and AED 1,000,000, suspension of the clinic’s central system license for up to six months, or cancellation of that license, under Article 25. Separately, unlicensed health advertising through the central system carries a fine of AED 100,000 to AED 200,000 under Article 23, and Article 22 preserves any heavier penalty available under another law.
Does a tourist have a record in the system too?
Yes. Dubai’s standard requires facilities to capture mandatory demographic information to support consent management and to categorize the patient as a tourist under the health data quality policy (clause 8.12). Treatment received in Dubai therefore creates a NABIDH record whether or not you hold a residence visa.
Official Sources
- UAE Legislation Portal, Federal Law No. 2 of 2019 on the Use of Information and Communications Technology in Health Fields
- Dubai Health Authority, Standards for Health Information Consent and Access Control, DHA/HISHD/ST-09, effective 2 April 2025
- Dubai Health Authority, Policy for Health Data Protection and Confidentiality
- Dubai Health Authority, NABIDH licensing and regulations
- Malaffi, About Malaffi (Abu Dhabi Health Information Exchange)
- Ministry of Health and Prevention, Federal Law No. 2 of 2019
Information current as of August 2026. Health data rules are set by three separate regulators and are revised regularly. Verify the position with the Dubai Health Authority, the Department of Health, Abu Dhabi, or the Ministry of Health and Prevention, and with your treating facility, before acting. This article is general information and is not legal or medical advice.