UAE Healthcare Website Compliance: DHA, DOH & HAAD Guide (2026)
A healthcare website in the UAE operates under layered regulatory requirements depending on emirate, facility type, and services offered. Getting this wrong exposes your facility to regulatory action from DHA, DOH, or MOHAP and more seriously, erodes patient trust. This guide covers the specific compliance requirements your website must meet.

Requirements by regulatory authority
DHA Dubai Health Authority
Dubai
- Display DHA facility licence number on the website
- List all DHA-registered practitioners with their licence numbers
- No medical advice that could be interpreted as a consultation without DHA telehealth approval
- Patient testimonials must not make clinical claims not endorsed by DHA
- NABIDH data integration required for facilities sharing patient records
DOH Department of Health, Abu Dhabi
Abu Dhabi
- Display DOH facility licence number prominently
- Healthcare professional profiles must include DOH licence number and specialty
- Telemedicine services require specific DOH telehealth facility approval
- Patient rights must be displayed (available from DOH)
- Arabic language content required for all mandatory disclosures
MOHAP Ministry of Health & Prevention
Other Emirates
- MOHAP facility registration number must be displayed
- Practitioner MOHAP licence numbers listed on profile pages
- Pharmaceutical advertising requires MOHAP pre-approval
- Medical device claims on website must comply with MOHAP medical device guidance
Patient data and privacy requirements
DIFC Data Protection Law (2020)
Healthcare facilities operating in or serving DIFC must comply with the DIFC Data Protection Law one of the most comprehensive data protection frameworks in the region. This means having a clear Privacy Policy, appointing a Data Protection Officer if processing health data at scale, patient consent mechanisms, and data subject rights (access, rectification, erasure) accessible via the website.
NABIDH integration (Dubai)
NABIDH (National Backbone for Integrated Dubai Health) is DHA's health information exchange. Healthcare providers in Dubai who share patient records are required to connect to NABIDH. Your website's patient portal or booking system should be designed with NABIDH compatibility in mind particularly the data fields captured at booking that feed into a patient's health record.
Patient consent for digital communications
Collecting a patient's email address or mobile number for appointment reminders, health newsletters, or marketing requires explicit consent under UAE data regulations. Website contact forms and booking systems must include a clear opt-in checkbox (not pre-ticked) for marketing communications, separate from operational appointment-related messages.
Telemedicine website compliance
Telemedicine in the UAE is separately regulated. In Dubai, telemedicine facilities require a specific DHA Telehealth Facility Licence. In Abu Dhabi, DOH has issued a Telehealth Policy that sets requirements for platform security, practitioner identification, and patient consent. Your website must not advertise telemedicine services or allow online consultations without the appropriate licence.
The key website requirements for licensed telemedicine platforms include: clearly identified practitioner credentials visible before consultation, a patient consent acknowledgement before any clinical interaction, technical security standards for video consultation platforms (encryption at rest and in transit), and clearly displayed practitioner DHA/DOH licence numbers accessible from the consultation interface.
Common compliance questions
What is the difference between DHA, DOH, and HAAD?
DHA (Dubai Health Authority) regulates healthcare facilities and practitioners operating in the Emirate of Dubai, covering everything from hospital licensing to individual practitioner registration and telehealth approval. DOH (Department of Health) performs the equivalent regulatory role in Abu Dhabi and has formally subsumed HAAD (Health Authority – Abu Dhabi), its predecessor body, so older HAAD licence numbers should now be updated to DOH registration. Facilities in the remaining emirates Sharjah, Ajman, Fujairah, Ras Al Khaimah, and Umm Al Quwain fall under the federal Ministry of Health and Prevention (MOHAP), which runs its own separate licensing and registration numbering system. Each regulator has slightly different requirements for what must be displayed on a website and how practitioner credentials are presented, so a multi-emirate healthcare group needs its website built to reflect the correct regulator credentials and licence numbers for each individual facility, not a single blanket disclosure covering every location.
Is online medical advice allowed on UAE healthcare websites?
General health information articles explaining conditions, treatments, or wellness topics are permitted on UAE healthcare websites without restriction. However, anything that amounts to specific medical advice, diagnosis, or a treatment recommendation for an individual reader must only be delivered by a licensed practitioner, typically once the relationship moves into an actual consultation rather than website content. Telemedicine consultations are separately regulated by DHA in Dubai and DOH in Abu Dhabi under dedicated telehealth frameworks, which require the facility and the individual practitioner to hold specific telehealth licensing before offering remote consultations through your website or app. In practice, a blog post about 'symptoms of seasonal allergies' is fine, but a chatbot or contact form that attempts to diagnose a visitor's specific symptoms crosses into regulated territory. Every piece of clinical content published on your website blog article, FAQ, or service description should be reviewed and formally approved by a licensed medical professional before publishing, with appropriate disclaimers attached.
What patient data laws apply to UAE healthcare websites?
Healthcare facilities operating within DIFC are subject to the DIFC Data Protection Law 2020, one of the most comprehensive data protection frameworks in the region, requiring a published privacy policy, defined data subject rights, and in many cases a designated Data Protection Officer. Facilities in mainland Dubai and Abu Dhabi must comply with DHA and DOH patient confidentiality regulations respectively, which govern how patient records are stored, accessed, and shared, including requirements around data residency within the UAE. In Dubai specifically, NABIDH (the National Backbone for Integrated Dubai Health) requires patient data from facilities sharing electronic health records to be stored and made accessible in a standardised format compatible with DHA's health information exchange. Beyond these healthcare-specific frameworks, general UAE data protection law also applies to how your website collects and processes personal data through contact forms, booking systems, or newsletter sign-ups, so your privacy policy needs to address both sets of obligations together.
Related reading
Build a compliant UAE healthcare website
TheWebBrew builds DHA and DOH-compliant healthcare websites for UAE clinics, hospitals, and telehealth platforms with proper licence display, patient consent flows, and NABIDH-aware booking systems.
Discuss Your Healthcare Website