gcc-digital-health-regulation

By July 25th, 2026compliant-growth19 min read

Digital Health Regulation and Compliance in the GCC

The Gulf Cooperation Council (GCC) states have made digital health a strategic priority, yet each member country operates its own regulatory framework. This guide cuts through the complexity, giving you a country-by-country breakdown of the rules that matter for telemedicine, health apps, EHRs, data protection, AI, and cross-border care. Whether you are a health-tech startup planning regional expansion or an established healthcare provider deploying digital services, understanding these regulations is essential to avoid penalties, licence revocation, and reputational damage.

Digital Health Regulations by Country

No single digital health law applies across the GCC. Each state has developed its own regime, and the differences are significant. Below is a comparative overview of the key regulatory bodies and instruments that govern digital health in each jurisdiction.

CountryRegulatory BodyKey InstrumentScope
Saudi ArabiaSFDA, CCHI, NHCHealth Informatics and Digital Health Law (draft)Telemedicine, apps, EHR, AI
UAEDHA, DOH, MOHAPDubai Health Strategy 2026, Federal Law No. 2/2019Telemedicine, apps, data protection
QatarMoPH, NPHIDigital Health Strategy 2021–2026EHR, telemedicine, apps
KuwaitMoH KuwaiteHealth Strategy 2020–2025EHR, telemedicine
OmanMoH OmanDigital Health Strategy 2023–2028EHR, apps, telehealth
BahrainNHRA, MoH BahrainHealth Information Law (Decree No. 21/2019)Data protection, EHR, telemedicine

Saudi Arabia leads with the most prescriptive regime under the SFDA and CCHI, while the UAE offers a more federated model where Dubai Health Authority (DHA) rules differ from Abu Dhabi’s DOH standards. This creates a complex compliance landscape for providers operating in multiple emirates. Qatar and Oman have centralised models under their respective Ministries of Health, while Bahrain’s NHRA takes a cross-sector approach that integrates health data protection with broader data privacy law. Kuwait remains the least developed in terms of formal digital health regulation, though a comprehensive eHealth law is expected within the next two years.

Healthcare providers and technology vendors should note that regulatory frameworks in the GCC are evolving rapidly. The Saudi Health Informatics and Digital Health Law, expected to be enacted in 2025, will consolidate requirements across multiple agencies and introduce mandatory certification for all digital health products. Similarly, the UAE’s planned federal digital health law aims to harmonise the currently fragmented emirate-level rules.

Telemedicine Licensing

Telemedicine is regulated differently across the GCC, and operating across borders adds further complexity. Every country requires a local licence to practise telemedicine within its territory, and the application processes, fees, and ongoing obligations vary considerably.

CountryTelemedicine Licence RequiredPlatform ApprovalCross-Border PermittedTypical Processing Time
Saudi ArabiaYes – CCHI licenceYes – SFDA registrationNo3–6 months
UAE (Dubai)Yes – DHA telemedicine licenceYes – DHA app registrationWith MOU2–4 months
UAE (Abu Dhabi)Yes – DOH telehealth licenceYes – DOH platform approvalNot permitted2–4 months
QatarYes – MoPH licenceConditionalNot permitted1–3 months
KuwaitYes – MoH approvalUnder developmentNot permitted3–6 months
OmanYes – MoH telehealth licenceYesNot permitted2–4 months
BahrainYes – NHRA licenceYesCase by case1–2 months

Key takeaway: you cannot serve patients in a GCC country without a local telemedicine licence in that country. The licensing process typically requires proof of the practitioner’s qualifications (attested by the relevant embassies), a valid local practice licence, evidence of malpractice insurance, and a technology platform that meets local security and data protection standards. Cross-border telemedicine remains heavily restricted; only Bahrain and Dubai offer limited exceptions, usually requiring a bilateral memorandum of understanding (MOU).

The DHA in Dubai has been the most progressive, introducing a fast-track licensing pathway for telemedicine platforms that have already been approved by recognised international regulators such as the UK’s CQC or the US’s NCQA. This pathway reduces the processing time from four months to as little as six weeks. Saudi Arabia’s CCHI, by contrast, requires all telemedicine practitioners to hold a full in-person practice licence as a prerequisite, effectively preventing pure-play telemedicine operations without a physical clinic presence.

Health Apps Regulation

Health and wellness apps fall under varying degrees of scrutiny across the GCC. The regulatory trigger is typically whether the app makes clinical claims, offers diagnostic or treatment functions, or processes personal health data. The classification systems used by different regulators determine the level of scrutiny required.

CountryApp Classification SystemRegistration RequiredClinical Evidence Needed
Saudi Arabia3-tier (wellness, informational, clinical)Yes – all tiersTier 3 only
UAE (Dubai)3-tier (low, medium, high risk)Yes – medium and highHigh risk only
Qatar2-tier (health information, clinical service)Yes – both tiersClinical service tier
BahrainData protection triggerYes – if processing health dataNot required
KuwaitNo formal classificationNot yet mandatoryN/A
OmanNo formal classificationNot yet mandatoryN/A

In Saudi Arabia, all health apps must register with the SFDA regardless of classification. Even a wellness app that tracks step count must register if it markets itself as a health product. Apps that provide diagnostic or treatment functions require a CCHI telemedicine licence in addition to SFDA registration. The SFDA has published a detailed guidance document on the evidence requirements for each tier, including cybersecurity testing, data protection impact assessments, and clinical validation protocols.

In Dubai, the DHA operates a digital health app registration programme that classifies apps by risk level. Low-risk apps (health education, appointment booking) require notification only. Medium-risk apps (symptom checkers, medication reminders) require a full registration with technical documentation. High-risk apps (diagnostic tools, remote monitoring of vital signs) require clinical evidence and may trigger a telemedicine licence requirement. The DHA publishes a register of approved health apps, and only registered apps may be marketed to Dubai residents.

Regardless of country, any app processing the health data of GCC residents should assume it is regulated and plan for registration. Bahrain’s NHRA applies data protection rules under Decree No. 21/2019 to all health-related apps, even those that do not offer clinical services. The law defines health data broadly to include any data about a person’s physical or mental health, including wellness and fitness data. This means a meditation app or a nutrition tracker that collects health-related information from Bahraini residents must comply with the same data protection rules as a clinical telemedicine platform.

EHR Requirements

Electronic Health Record (EHR) adoption is mandated or strongly encouraged across the GCC. The requirements vary but share common themes around interoperability, certification, and data localisation. The strategic goal across all six states is to create a connected health ecosystem where patient records can be shared securely between providers, improving care quality and reducing duplication.

CountryEHR MandateInteroperability StandardCertification BodyNational EHR Platform
Saudi ArabiaMandatory for all public and private providersFHIR R4, CDANHC / SFDASeha (public), NHC Health Exchange
UAEMandatory (Dubai) / phased (Abu Dhabi)FHIR, ICD-10, SNOMED CTDHA / DOHNabidh (Dubai), Malaffi (Abu Dhabi)
QatarMandatory for public sector, phased for privateFHIR, CDANPHIQatar EHR (Q-EHR)
KuwaitPhased mandate (public sector complete, private ongoing)FHIR (planned)MoHKuwait Health Information Exchange
OmanPhased mandate (public sector complete)FHIR (planned)MoHOman Health Information Exchange (Shifaa)
BahrainMandatory for all licensed facilitiesFHIR, DICOMNHRABahrain Health Information Exchange (IKE)

All GCC states are converging on FHIR R4 as the interoperability standard, though legacy systems using CDA remain in use during transitional periods. Data localisation is a firm requirement everywhere – patient health records must be stored within the country. Cloud-based EHR solutions must demonstrate that data never leaves the national borders, even for backup or disaster recovery purposes. Saudi Arabia’s NHC requires that EHR systems undergo a formal certification process before they can be deployed, including testing for interoperability, security, and compliance with national coding standards (ICD-10 and SNOMED CT).

In the UAE, the landscape is more complex because of the absence of a single federal EHR mandate. Dubai requires mandatory EHR adoption under the DHA’s Nabidh programme, which connects all healthcare facilities in the emirate. Abu Dhabi operates Malaffi, which serves a similar function but uses different technical specifications. Healthcare providers operating across multiple emirates must ensure their EHR systems are compatible with both platforms, which has driven adoption of FHIR as a common denominator. The UAE Ministry of Health and Prevention (MOHAP) is developing a federal health information exchange that will eventually connect the emirate-level platforms, but this initiative is still in its early stages.

Medical Device Registration for Digital Health

Digital health products that meet the definition of a medical device must be registered with the relevant national authority before they can be marketed or used in clinical settings. This applies to software as a medical device (SaMD), diagnostic algorithms, remote monitoring systems, and certain clinical decision support tools.

  • Saudi Arabia – The SFDA regulates SaMD under the Medical Devices Interim Regulation. Products are classified using the IMDRF framework (Class A through D). A Class C or D SaMD requires a full conformity assessment, including a review of clinical evidence and quality management system certification (ISO 13485). Processing time is 6–12 months.
  • UAE – The Ministry of Health and Prevention (MOHAP) regulates medical devices, including SaMD, under Cabinet Resolution No. 57/2020. Registration is required for all classes. The UAE accepts international approvals (FDA, CE, TGA) as a basis for expedited registration.
  • Qatar – The MoPH Medical Devices Division requires registration of all SaMD products. Products with a valid CE mark or FDA clearance benefit from a streamlined registration process.
  • Bahrain – The NHRA requires medical device registration for any digital health product that meets the international definition of a medical device. The process mirrors the EU MDR classification system.
  • Kuwait and Oman – Medical device registration frameworks exist but SaMD-specific guidance is still developing. Products with international approvals are generally accepted while local guidelines are formalised.

A common mistake is assuming that because a product is a mobile app, it does not qualify as a medical device. If the app performs a medical function – calculating drug dosages, interpreting diagnostic images, or making treatment recommendations – it is almost certainly a medical device in the eyes of GCC regulators and must be registered accordingly.

Data Protection in Healthcare

Personal health data is classified as sensitive data across the GCC, attracting the highest levels of protection. The data protection landscape has changed dramatically with the enactment of comprehensive privacy laws in Saudi Arabia (PDPL, 2022), the UAE (Federal PDPL, 2021), and Bahrain (PDPL, 2019). Qatar and Oman are expected to enact similar laws within the next two years.

The key requirements that apply to all healthcare data processing across the GCC are:

  • Consent – Explicit, informed consent is required before collecting or processing health data in all GCC states. Consent must be specific to the purpose, freely given, and revocable at any time. Pre-ticked checkboxes and blanket consent clauses are not compliant.
  • Data localisation – Health data must remain within the country of origin. Cross-border transfer is either prohibited or subject to strict conditions, including adequacy decisions, standard contractual clauses, and explicit patient consent. Saudi Arabia’s PDPL permits transfers only for specific purposes such as treatment continuity or public health emergencies.
  • Breach notification – Mandatory reporting of health data breaches is required in Saudi Arabia (to NCA within 72 hours), UAE (to the relevant authority within 72 hours), Qatar (to MoPH), and Bahrain (to iGA within 72 hours). Failure to notify attracts significant penalties.
  • Data Protection Officer (DPO) – Saudi Arabia and the UAE require a DPO for healthcare entities processing significant volumes of patient data. The DPO must be registered with the national data protection authority and must report directly to senior management.
  • Processing records – Maintain a register of all health data processing activities, including lawful basis, data categories, retention periods, and technical security measures. This register must be available for inspection by the regulator on demand.
  • Data protection impact assessment (DPIA) – A DPIA is required before implementing any new health data processing activity that presents high risk to individuals, including the deployment of AI-based diagnostic tools, population health analytics platforms, and health data sharing arrangements with third parties.
  • The data protection requirements in the GCC are closely aligned with the GDPR in principle but differ in key details, particularly around data localisation. Organisations that have achieved GDPR compliance should not assume automatic compliance with GCC health data protection laws. A gap analysis is essential before launching any digital health service in the region.

    AI in Healthcare Regulation

    The use of artificial intelligence in healthcare is an emerging regulatory area. Saudi Arabia and the UAE are the most advanced, while other GCC states are developing their approach. The regulation of AI in healthcare spans medical device regulation (when AI is used as a diagnostic or treatment tool), data protection (when AI processes personal health data), and professional practice standards (when AI supports clinical decision-making).

    • Saudi Arabia – The SFDA has issued comprehensive guidance on AI as a medical device (AIaMD). Developers must demonstrate clinical safety, bias testing across demographic groups, robustness against adversarial inputs, and human oversight mechanisms. The Saudi Data and AI Authority (SDAIA) provides overarching AI governance through the AI Ethics Framework, which applies to all AI deployments in the healthcare sector. The framework requires transparency (patients must be informed when AI is used in their care), fairness (algorithms must be tested for bias across age, gender, and nationality groups), and accountability (a named clinician must take responsibility for AI-assisted decisions).
    • UAE – The DHA’s AI in Healthcare framework requires validation of AI algorithms against real-world clinical data from the local population. The UAE AI Ethics Guidelines apply to all health AI deployments. Dubai has established an AI Ethics Board that reviews high-risk healthcare AI applications before deployment. The DHA also requires ongoing monitoring of AI algorithm performance, with mandatory reporting of any adverse events or performance degradation.
    • Qatar – MoPH is developing AI guidelines for clinical decision support systems. Human-in-the-loop is mandatory for all AI systems that influence clinical decisions. The guidelines are expected to be finalised in 2025 and will align with WHO guidance on AI in healthcare.
    • Bahrain – NHRA requires pre-market approval for any AI tool used in clinical decision-making. The approval process includes a review of the training data, algorithm validation methodology, and clinical safety evidence. Post-market surveillance is required, with periodic reporting to NHRA.

    Common themes across all GCC states include explainability (the AI must justify its outputs in terms that clinicians can understand and challenge), validation against local population data (algorithms trained on Western populations may not perform accurately on GCC populations), and mandatory human oversight for any autonomous decision-making. There is also a growing emphasis on algorithmic fairness, with regulators increasingly concerned about bias in AI systems used for clinical decision-making, particularly where decisions affect access to healthcare services.

    Cross-Border Telemedicine

    Cross-border telemedicine – where a practitioner in one GCC country treats a patient in another, or where a practitioner outside the GCC treats a patient in the region – remains the most challenging area of digital health regulation. The general rule across all six states is that the practitioner must be licensed in the patient’s country, not their own. This creates significant barriers to regional telemedicine networks.

    • Saudi Arabia – No cross-border telemedicine. Doctors must hold a CCHI licence and be physically or legally established in the Kingdom. Foreign practitioners cannot treat Saudi patients remotely unless they are working through a licensed Saudi entity.
    • UAE – Limited cross-border provisions exist under DHA rules, provided the foreign provider has an MOU with DHA and the patient is physically in Dubai. Abu Dhabi’s DOH does not permit cross-border telemedicine. Dubai’s approach is the most liberal in the GCC but still requires a formal agreement between the foreign provider and DHA.
    • Bahrain – NHRA may grant exemptions on a case-by-case basis for specialist consultations where the required expertise is not available locally. The exemption is time-limited and must be renewed annually.
    • Qatar, Kuwait, Oman – No cross-border telemedicine provisions currently exist. Practitioners must hold a full local licence.

    However, GCC-wide initiatives such as the Gulf Health Council are working toward mutual recognition of telemedicine licences. The council has established a technical committee on digital health that is developing a framework for cross-border telemedicine within the GCC. This framework is expected to include common licensing standards, a shared register of approved telemedicine practitioners, and protocols for cross-border data sharing. Implementation is likely within the next three to five years, but in the meantime, providers must comply with each country’s individual requirements.

    Enforcement Trends and Regulatory Outlook

    Enforcement of digital health regulations across the GCC has intensified significantly since 2023. Regulators are moving from guidance-based to enforcement-based approaches, with notable actions including:

    • The SFDA issued fines totalling over SAR 12 million to unregistered health app operators in 2024, with several apps ordered to cease operations immediately.
    • DHA conducted a sweep of health apps available on UAE app stores in 2024, issuing 47 enforcement notices and blocking 12 apps that were operating without registration.
    • Bahrain’s NHRA suspended two telemedicine licences for non-compliance with data localisation requirements, sending a strong signal about the seriousness of health data protection rules.

    The regulatory outlook points toward greater harmonisation within the GCC, stricter enforcement of existing rules, and new requirements for AI governance and cybersecurity. Providers and vendors should invest in compliance capabilities now, rather than waiting for enforcement actions to force compliance.

    Frequently Asked Questions

    Do I need a separate licence for each GCC country?

    Yes. There is no GCC-wide digital health licence. You must obtain a licence from the competent authority in each country where you operate or serve patients. This means separate applications, separate fees, and separate ongoing compliance obligations for each jurisdiction.

    Can I store patient health data outside the GCC?

    No. All GCC states require health data to be stored locally. Cross-border transfer is either prohibited or subject to stringent conditions, including explicit patient consent and adequacy assessments. Cloud providers offering services to GCC healthcare entities must have data centres within the country or demonstrate that data never leaves the national border.

    What happens if my health app is not registered?

    Penalties range from fines and suspension to criminal liability in the case of a data breach. In Saudi Arabia, unregistered health apps face fines of up to SAR 1 million and the SFDA may refer the matter to the Public Prosecution for criminal proceedings. In Dubai, DHA may block the app from app stores, issue fines of up to AED 100,000, and refer the matter for prosecution under the UAE Medical Liability Law.

    Do AI clinical decision support tools require regulatory approval?

    Yes, in Saudi Arabia and the UAE. These tools are regulated as medical devices or classified under specific AI frameworks. Expect to provide clinical validation data, bias testing results, and evidence of human oversight mechanisms. In Saudi Arabia, the SFDA classifies AI clinical decision support tools as SaMD and requires a full conformity assessment. In Dubai, the DHA AI Ethics Board reviews high-risk AI healthcare applications before deployment.

    Is telemedicine permanent or a COVID-era measure?

    Telemedicine is now permanently regulated across the GCC. The temporary flexibilities introduced during the pandemic have been replaced by standing regulatory frameworks in every member state. The regulations are more comprehensive than the pandemic-era rules and include requirements for platform security, practitioner qualifications, and patient consent that did not exist during the emergency period.

    What is the penalty for a health data breach in the GCC?

    Penalties vary significantly by country. Saudi Arabia’s PDPL imposes fines up to SAR 5 million for serious health data breaches, plus potential imprisonment for individuals. The UAE’s PDPL fines can reach AED 5 million for processing sensitive data without a lawful basis. Qatar and Bahrain also impose significant financial penalties and potential imprisonment for violations involving sensitive health data. In all cases, the regulator may also impose a temporary or permanent ban on data processing activities.

    Get Expert Guidance on GCC Digital Health Compliance

    Navigating nine distinct regulatory regimes is complex and the cost of getting it wrong is high. Our team of digital health compliance specialists can help you map requirements, prepare licence applications, conduct gap analyses, and build compliance programmes that satisfy regulators across the GCC. We have assisted health-tech providers, hospital groups, and pharmaceutical companies with digital health regulatory compliance in all six GCC states.