Digital Health Regulation and Compliance in the GCC
The Gulf Cooperation Council (GCC) states have made digital health a strategic priority, yet each member country operates its own regulatory framework. This guide cuts through the complexity, giving you a country-by-country breakdown of the rules that matter for telemedicine, health apps, EHRs, data protection, AI, and cross-border care. Whether you are a health-tech startup planning regional expansion or an established healthcare provider deploying digital services, understanding these regulations is essential to avoid penalties, licence revocation, and reputational damage.
Digital Health Regulations by Country
No single digital health law applies across the GCC. Each state has developed its own regime, and the differences are significant. Below is a comparative overview of the key regulatory bodies and instruments that govern digital health in each jurisdiction.
| Country | Regulatory Body | Key Instrument | Scope |
|---|---|---|---|
| Saudi Arabia | SFDA, CCHI, NHC | Health Informatics and Digital Health Law (draft) | Telemedicine, apps, EHR, AI |
| UAE | DHA, DOH, MOHAP | Dubai Health Strategy 2026, Federal Law No. 2/2019 | Telemedicine, apps, data protection |
| Qatar | MoPH, NPHI | Digital Health Strategy 2021–2026 | EHR, telemedicine, apps |
| Kuwait | MoH Kuwait | eHealth Strategy 2020–2025 | EHR, telemedicine |
| Oman | MoH Oman | Digital Health Strategy 2023–2028 | EHR, apps, telehealth |
| Bahrain | NHRA, MoH Bahrain | Health Information Law (Decree No. 21/2019) | Data protection, EHR, telemedicine |
Saudi Arabia leads with the most prescriptive regime under the SFDA and CCHI, while the UAE offers a more federated model where Dubai Health Authority (DHA) rules differ from Abu Dhabi’s DOH standards. This creates a complex compliance landscape for providers operating in multiple emirates. Qatar and Oman have centralised models under their respective Ministries of Health, while Bahrain’s NHRA takes a cross-sector approach that integrates health data protection with broader data privacy law. Kuwait remains the least developed in terms of formal digital health regulation, though a comprehensive eHealth law is expected within the next two years.
Healthcare providers and technology vendors should note that regulatory frameworks in the GCC are evolving rapidly. The Saudi Health Informatics and Digital Health Law, expected to be enacted in 2025, will consolidate requirements across multiple agencies and introduce mandatory certification for all digital health products. Similarly, the UAE’s planned federal digital health law aims to harmonise the currently fragmented emirate-level rules.
Telemedicine Licensing
Telemedicine is regulated differently across the GCC, and operating across borders adds further complexity. Every country requires a local licence to practise telemedicine within its territory, and the application processes, fees, and ongoing obligations vary considerably.
| Country | Telemedicine Licence Required | Platform Approval | Cross-Border Permitted | Typical Processing Time |
|---|---|---|---|---|
| Saudi Arabia | Yes – CCHI licence | Yes – SFDA registration | No | 3–6 months |
| UAE (Dubai) | Yes – DHA telemedicine licence | Yes – DHA app registration | With MOU | 2–4 months |
| UAE (Abu Dhabi) | Yes – DOH telehealth licence | Yes – DOH platform approval | Not permitted | 2–4 months |
| Qatar | Yes – MoPH licence | Conditional | Not permitted | 1–3 months |
| Kuwait | Yes – MoH approval | Under development | Not permitted | 3–6 months |
| Oman | Yes – MoH telehealth licence | Yes | Not permitted | 2–4 months |
| Bahrain | Yes – NHRA licence | Yes | Case by case | 1–2 months |
Key takeaway: you cannot serve patients in a GCC country without a local telemedicine licence in that country. The licensing process typically requires proof of the practitioner’s qualifications (attested by the relevant embassies), a valid local practice licence, evidence of malpractice insurance, and a technology platform that meets local security and data protection standards. Cross-border telemedicine remains heavily restricted; only Bahrain and Dubai offer limited exceptions, usually requiring a bilateral memorandum of understanding (MOU).
The DHA in Dubai has been the most progressive, introducing a fast-track licensing pathway for telemedicine platforms that have already been approved by recognised international regulators such as the UK’s CQC or the US’s NCQA. This pathway reduces the processing time from four months to as little as six weeks. Saudi Arabia’s CCHI, by contrast, requires all telemedicine practitioners to hold a full in-person practice licence as a prerequisite, effectively preventing pure-play telemedicine operations without a physical clinic presence.
Health Apps Regulation
Health and wellness apps fall under varying degrees of scrutiny across the GCC. The regulatory trigger is typically whether the app makes clinical claims, offers diagnostic or treatment functions, or processes personal health data. The classification systems used by different regulators determine the level of scrutiny required.
| Country | App Classification System | Registration Required | Clinical Evidence Needed |
|---|---|---|---|
| Saudi Arabia | 3-tier (wellness, informational, clinical) | Yes – all tiers | Tier 3 only |
| UAE (Dubai) | 3-tier (low, medium, high risk) | Yes – medium and high | High risk only |
| Qatar | 2-tier (health information, clinical service) | Yes – both tiers | Clinical service tier |
| Bahrain | Data protection trigger | Yes – if processing health data | Not required |
| Kuwait | No formal classification | Not yet mandatory | N/A |
| Oman | No formal classification | Not yet mandatory | N/A |
In Saudi Arabia, all health apps must register with the SFDA regardless of classification. Even a wellness app that tracks step count must register if it markets itself as a health product. Apps that provide diagnostic or treatment functions require a CCHI telemedicine licence in addition to SFDA registration. The SFDA has published a detailed guidance document on the evidence requirements for each tier, including cybersecurity testing, data protection impact assessments, and clinical validation protocols.
In Dubai, the DHA operates a digital health app registration programme that classifies apps by risk level. Low-risk apps (health education, appointment booking) require notification only. Medium-risk apps (symptom checkers, medication reminders) require a full registration with technical documentation. High-risk apps (diagnostic tools, remote monitoring of vital signs) require clinical evidence and may trigger a telemedicine licence requirement. The DHA publishes a register of approved health apps, and only registered apps may be marketed to Dubai residents.
Regardless of country, any app processing the health data of GCC residents should assume it is regulated and plan for registration. Bahrain’s NHRA applies data protection rules under Decree No. 21/2019 to all health-related apps, even those that do not offer clinical services. The law defines health data broadly to include any data about a person’s physical or mental health, including wellness and fitness data. This means a meditation app or a nutrition tracker that collects health-related information from Bahraini residents must comply with the same data protection rules as a clinical telemedicine platform.
EHR Requirements
Electronic Health Record (EHR) adoption is mandated or strongly encouraged across the GCC. The requirements vary but share common themes around interoperability, certification, and data localisation. The strategic goal across all six states is to create a connected health ecosystem where patient records can be shared securely between providers, improving care quality and reducing duplication.
| Country | EHR Mandate | Interoperability Standard | Certification Body | National EHR Platform |
|---|---|---|---|---|
| Saudi Arabia | Mandatory for all public and private providers | FHIR R4, CDA | NHC / SFDA | Seha (public), NHC Health Exchange |
| UAE | Mandatory (Dubai) / phased (Abu Dhabi) | FHIR, ICD-10, SNOMED CT | DHA / DOH | Nabidh (Dubai), Malaffi (Abu Dhabi) |
| Qatar | Mandatory for public sector, phased for private | FHIR, CDA | NPHI | Qatar EHR (Q-EHR) |
| Kuwait | Phased mandate (public sector complete, private ongoing) | FHIR (planned) | MoH | Kuwait Health Information Exchange |
| Oman | Phased mandate (public sector complete) | FHIR (planned) | MoH | Oman Health Information Exchange (Shifaa) |
| Bahrain | Mandatory for all licensed facilities | FHIR, DICOM | NHRA | Bahrain Health Information Exchange (IKE) |
All GCC states are converging on FHIR R4 as the interoperability standard, though legacy systems using CDA remain in use during transitional periods. Data localisation is a firm requirement everywhere – patient health records must be stored within the country. Cloud-based EHR solutions must demonstrate that data never leaves the national borders, even for backup or disaster recovery purposes. Saudi Arabia’s NHC requires that EHR systems undergo a formal certification process before they can be deployed, including testing for interoperability, security, and compliance with national coding standards (ICD-10 and SNOMED CT).
In the UAE, the landscape is more complex because of the absence of a single federal EHR mandate. Dubai requires mandatory EHR adoption under the DHA’s Nabidh programme, which connects all healthcare facilities in the emirate. Abu Dhabi operates Malaffi, which serves a similar function but uses different technical specifications. Healthcare providers operating across multiple emirates must ensure their EHR systems are compatible with both platforms, which has driven adoption of FHIR as a common denominator. The UAE Ministry of Health and Prevention (MOHAP) is developing a federal health information exchange that will eventually connect the emirate-level platforms, but this initiative is still in its early stages.
Medical Device Registration for Digital Health
Digital health products that meet the definition of a medical device must be registered with the relevant national authority before they can be marketed or used in clinical settings. This applies to software as a medical device (SaMD), diagnostic algorithms, remote monitoring systems, and certain clinical decision support tools.
- Saudi Arabia – The SFDA regulates SaMD under the Medical Devices Interim Regulation. Products are classified using the IMDRF framework (Class A through D). A Class C or D SaMD requires a full conformity assessment, including a review of clinical evidence and quality management system certification (ISO 13485). Processing time is 6–12 months.
- UAE – The Ministry of Health and Prevention (MOHAP) regulates medical devices, including SaMD, under Cabinet Resolution No. 57/2020. Registration is required for all classes. The UAE accepts international approvals (FDA, CE, TGA) as a basis for expedited registration.
- Qatar – The MoPH Medical Devices Division requires registration of all SaMD products. Products with a valid CE mark or FDA clearance benefit from a streamlined registration process.
- Bahrain – The NHRA requires medical device registration for any digital health product that meets the international definition of a medical device. The process mirrors the EU MDR classification system.
- Kuwait and Oman – Medical device registration frameworks exist but SaMD-specific guidance is still developing. Products with international approvals are generally accepted while local guidelines are formalised.
A common mistake is assuming that because a product is a mobile app, it does not qualify as a medical device. If the app performs a medical function – calculating drug dosages, interpreting diagnostic images, or making treatment recommendations – it is almost certainly a medical device in the eyes of GCC regulators and must be registered accordingly.
Data Protection in Healthcare
Personal health data is classified as sensitive data across the GCC, attracting the highest levels of protection. The data protection landscape has changed dramatically with the enactment of comprehensive privacy laws in Saudi Arabia (PDPL, 2022), the UAE (Federal PDPL, 2021), and Bahrain (PDPL, 2019). Qatar and Oman are expected to enact similar laws within the next two years.
The key requirements that apply to all healthcare data processing across the GCC are:
The data protection requirements in the GCC are closely aligned with the GDPR in principle but differ in key details, particularly around data localisation. Organisations that have achieved GDPR compliance should not assume automatic compliance with GCC health data protection laws. A gap analysis is essential before launching any digital health service in the region.
AI in Healthcare Regulation
The use of artificial intelligence in healthcare is an emerging regulatory area. Saudi Arabia and the UAE are the most advanced, while other GCC states are developing their approach. The regulation of AI in healthcare spans medical device regulation (when AI is used as a diagnostic or treatment tool), data protection (when AI processes personal health data), and professional practice standards (when AI supports clinical decision-making).
- Saudi Arabia – The SFDA has issued comprehensive guidance on AI as a medical device (AIaMD). Developers must demonstrate clinical safety, bias testing across demographic groups, robustness against adversarial inputs, and human oversight mechanisms. The Saudi Data and AI Authority (SDAIA) provides overarching AI governance through the AI Ethics Framework, which applies to all AI deployments in the healthcare sector. The framework requires transparency (patients must be informed when AI is used in their care), fairness (algorithms must be tested for bias across age, gender, and nationality groups), and accountability (a named clinician must take responsibility for AI-assisted decisions).
- UAE – The DHA’s AI in Healthcare framework requires validation of AI algorithms against real-world clinical data from the local population. The UAE AI Ethics Guidelines apply to all health AI deployments. Dubai has established an AI Ethics Board that reviews high-risk healthcare AI applications before deployment. The DHA also requires ongoing monitoring of AI algorithm performance, with mandatory reporting of any adverse events or performance degradation.
- Qatar – MoPH is developing AI guidelines for clinical decision support systems. Human-in-the-loop is mandatory for all AI systems that influence clinical decisions. The guidelines are expected to be finalised in 2025 and will align with WHO guidance on AI in healthcare.
- Bahrain – NHRA requires pre-market approval for any AI tool used in clinical decision-making. The approval process includes a review of the training data, algorithm validation methodology, and clinical safety evidence. Post-market surveillance is required, with periodic reporting to NHRA.
Common themes across all GCC states include explainability (the AI must justify its outputs in terms that clinicians can understand and challenge), validation against local population data (algorithms trained on Western populations may not perform accurately on GCC populations), and mandatory human oversight for any autonomous decision-making. There is also a growing emphasis on algorithmic fairness, with regulators increasingly concerned about bias in AI systems used for clinical decision-making, particularly where decisions affect access to healthcare services.
Cross-Border Telemedicine
Cross-border telemedicine – where a practitioner in one GCC country treats a patient in another, or where a practitioner outside the GCC treats a patient in the region – remains the most challenging area of digital health regulation. The general rule across all six states is that the practitioner must be licensed in the patient’s country, not their own. This creates significant barriers to regional telemedicine networks.
- Saudi Arabia – No cross-border telemedicine. Doctors must hold a CCHI licence and be physically or legally established in the Kingdom. Foreign practitioners cannot treat Saudi patients remotely unless they are working through a licensed Saudi entity.
- UAE – Limited cross-border provisions exist under DHA rules, provided the foreign provider has an MOU with DHA and the patient is physically in Dubai. Abu Dhabi’s DOH does not permit cross-border telemedicine. Dubai’s approach is the most liberal in the GCC but still requires a formal agreement between the foreign provider and DHA.
- Bahrain – NHRA may grant exemptions on a case-by-case basis for specialist consultations where the required expertise is not available locally. The exemption is time-limited and must be renewed annually.
- Qatar, Kuwait, Oman – No cross-border telemedicine provisions currently exist. Practitioners must hold a full local licence.
However, GCC-wide initiatives such as the Gulf Health Council are working toward mutual recognition of telemedicine licences. The council has established a technical committee on digital health that is developing a framework for cross-border telemedicine within the GCC. This framework is expected to include common licensing standards, a shared register of approved telemedicine practitioners, and protocols for cross-border data sharing. Implementation is likely within the next three to five years, but in the meantime, providers must comply with each country’s individual requirements.
Enforcement Trends and Regulatory Outlook
Enforcement of digital health regulations across the GCC has intensified significantly since 2023. Regulators are moving from guidance-based to enforcement-based approaches, with notable actions including:
- The SFDA issued fines totalling over SAR 12 million to unregistered health app operators in 2024, with several apps ordered to cease operations immediately.
- DHA conducted a sweep of health apps available on UAE app stores in 2024, issuing 47 enforcement notices and blocking 12 apps that were operating without registration.
- Bahrain’s NHRA suspended two telemedicine licences for non-compliance with data localisation requirements, sending a strong signal about the seriousness of health data protection rules.
The regulatory outlook points toward greater harmonisation within the GCC, stricter enforcement of existing rules, and new requirements for AI governance and cybersecurity. Providers and vendors should invest in compliance capabilities now, rather than waiting for enforcement actions to force compliance.
Frequently Asked Questions
Do I need a separate licence for each GCC country?
Yes. There is no GCC-wide digital health licence. You must obtain a licence from the competent authority in each country where you operate or serve patients. This means separate applications, separate fees, and separate ongoing compliance obligations for each jurisdiction.
Can I store patient health data outside the GCC?
No. All GCC states require health data to be stored locally. Cross-border transfer is either prohibited or subject to stringent conditions, including explicit patient consent and adequacy assessments. Cloud providers offering services to GCC healthcare entities must have data centres within the country or demonstrate that data never leaves the national border.
What happens if my health app is not registered?
Penalties range from fines and suspension to criminal liability in the case of a data breach. In Saudi Arabia, unregistered health apps face fines of up to SAR 1 million and the SFDA may refer the matter to the Public Prosecution for criminal proceedings. In Dubai, DHA may block the app from app stores, issue fines of up to AED 100,000, and refer the matter for prosecution under the UAE Medical Liability Law.
Do AI clinical decision support tools require regulatory approval?
Yes, in Saudi Arabia and the UAE. These tools are regulated as medical devices or classified under specific AI frameworks. Expect to provide clinical validation data, bias testing results, and evidence of human oversight mechanisms. In Saudi Arabia, the SFDA classifies AI clinical decision support tools as SaMD and requires a full conformity assessment. In Dubai, the DHA AI Ethics Board reviews high-risk AI healthcare applications before deployment.
Is telemedicine permanent or a COVID-era measure?
Telemedicine is now permanently regulated across the GCC. The temporary flexibilities introduced during the pandemic have been replaced by standing regulatory frameworks in every member state. The regulations are more comprehensive than the pandemic-era rules and include requirements for platform security, practitioner qualifications, and patient consent that did not exist during the emergency period.
What is the penalty for a health data breach in the GCC?
Penalties vary significantly by country. Saudi Arabia’s PDPL imposes fines up to SAR 5 million for serious health data breaches, plus potential imprisonment for individuals. The UAE’s PDPL fines can reach AED 5 million for processing sensitive data without a lawful basis. Qatar and Bahrain also impose significant financial penalties and potential imprisonment for violations involving sensitive health data. In all cases, the regulator may also impose a temporary or permanent ban on data processing activities.
Get Expert Guidance on GCC Digital Health Compliance
Navigating nine distinct regulatory regimes is complex and the cost of getting it wrong is high. Our team of digital health compliance specialists can help you map requirements, prepare licence applications, conduct gap analyses, and build compliance programmes that satisfy regulators across the GCC. We have assisted health-tech providers, hospital groups, and pharmaceutical companies with digital health regulatory compliance in all six GCC states.