UAE Health Data Platforms: NABIDH, Malaffi, and Riayati
The UAE isn't one regulatory market. A Dubai clinic deals with NABIDH, an Abu Dhabi clinic with Malaffi, and one in Sharjah or Ajman with Riayati. Clinics opening a second-emirate branch usually find this out too late.
Contrary to what many providers assume, there is no single health information exchange in the UAE. There are three principal systems under different regulators, and your facility's location determines which one applies to you.
| Platform | Regulator | Geographic scope |
|---|---|---|
| NABIDH | Dubai Health Authority (DHA) | Health facilities in the Emirate of Dubai |
| Malaffi | Department of Health – Abu Dhabi (DoH) | Health facilities in the Emirate of Abu Dhabi |
| Riayati | Ministry of Health and Prevention (MoHAP) | Federal facilities and the Northern Emirates |
The most expensive mistake
A successful Dubai clinic opens a branch in Sharjah, then discovers its system connects to NABIDH only and the new location needs a different path. Plan for expansion up front: ask your vendor about all three emirates before signing, not after signing the branch lease.
Why these platforms exist
The shared goal is a unified health record: a clinician at any facility can see the patient's relevant history instead of reconstructing it from scratch every visit. The clinical benefit is direct — fewer duplicate tests, fewer drug interactions, faster decisions in emergencies.
For a clinic, this means your system is no longer a closed box. The data you enter becomes part of a wider record, which raises the bar on standardised coding and entry quality.
What it means for your clinic system
- Standardised coding: free text is no longer enough. Diagnoses need ICD-10, and procedures, medications, and labs need standard coding so the data is intelligible outside your system.
- A reliable patient identifier: linking records accurately to the Emirates ID — errors in this field produce duplicate or unmatched records.
- Structured exchange: the ability to send and receive data to the regulator's required standards, rather than manual exports.
- Entry completeness: fields that could previously be left blank become required — a behavioural change for staff more than a technical one.
- Audit logging: tracking who accessed which data and when, both locally and across the exchange.
Health data localisation
One of the most important things to verify when choosing a cloud system in the UAE is where data is stored. UAE legislation on the use of information technology in healthcare places restrictions on storing or transferring health data outside the country, with specific exceptions requiring approvals.
The question to ask any vendor before signing: where is my data stored geographically, and can you confirm that in writing? "In the cloud" is not an answer. See also the data protection checklist in our PDPL compliance guide — most of the practical controls are shared across markets.
Three questions for the vendor
1) Which country hosts the primary database? 2) Where are the backups? 3) Can any of your staff outside the country access patient data, and under what controls? Together, the three reveal the real picture.
Health insurance: a separate track
Health information exchanges are commonly confused with insurance claims platforms — they are different tracks under different systems. Health insurance is mandatory in Dubai and Abu Dhabi, and each has its own infrastructure for exchanging claims data.
In practice: your clinic system needs to handle both tracks — the health record on one side, the claims cycle on the other. Ask your vendor about both explicitly; some systems support one and leave the other as manual work.
A readiness plan for the clinic
1. Define your regulatory scope
Where is your facility today, and where do you plan to expand within two years? That determines which platforms your system must support.
2. Audit your data readiness
Clean duplicate records and correct ID numbers. Dirty data fails matching on the first exchange attempt.
3. Adopt standard coding
Move diagnoses from free text to ICD-10 inside the system, and start training on it before it becomes mandatory in your workflow.
4. Verify data location
Get written confirmation from your vendor on where data and backups reside.
5. Train staff on completeness
Missing fields are the most common cause of exchange failure — a behavioural problem, not a technical one.
What to ask your software vendor
- Which UAE platforms do you actually support today — not on the roadmap?
- How many UAE facilities are connected through your system right now?
- Where is data stored, and will you confirm that in the contract in writing?
- Does the system support the required standard coding inside the clinician's screen, or as a bolt-on?
- How do you handle a clinic with branches in more than one emirate?
- What support do you provide in local time zone and in Arabic?
Built for the region, not translated for it
3yadtk is designed for Gulf clinic workflows — a native Arabic interface, Hijri calendar, embedded ICD-10 coding, and branch-scoped permissions for multi-location practices.
Explore the platform