FOR DHA-LICENSED CLINICS IN DUBAI

WhatsApp automation for clinics in Dubai

A Dubai clinic can run WhatsApp with opted-in patients for booking, reminders, no-show recovery, directions, billing logistics and general enquiries, and on the instruments we could read that is the reasonably safe side of the line. It cannot legitimately run consultations, send test results, or market from patient records without the patient's consent and further DHA permission. The law that governs this is Federal Law No. 2 of 2019 on the use of ICT in the health fields, not HIPAA. Its Article 13 bars health data from services provided inside the UAE from being stored, processed, generated or transferred outside the country, subject to ten narrow exemptions. WhatsApp messaging works normally in the UAE. Voice and video calling over WhatsApp does not.

This page sets out what the primary instruments actually say, where they are silent, and which four clinic workflows survive all of it. Where a fact is contested, unverified or about to change, it says so rather than rounding it into a claim.

Sources checked 3 September 2026. Meta rates were pulled from Meta's own public pricing API for market AE on that date. The DHA policies cited were fetched from dha.gov.ae. Statute text was read from a mirror of the official English translation because the UAE legislation portal blocks automated retrieval, and cross-checked against a law firm alert. This is not legal advice. A clinic making a compliance decision should have the primary instruments reviewed by UAE counsel.

The short version

Three buckets, and the line between them is content, not the app

No UAE law and no DHA policy we could find names WhatsApp as permitted or prohibited for clinic use. What the rules govern is what is inside the message and where the data ends up. That makes appointment logistics a materially different and much safer category than clinical content or marketing.

Reasonably safe

  • Confirmations and reminders for appointments the patient booked
  • Rescheduling and cancellation
  • "Your results are ready, log in to the portal or call us"
  • Directions, opening hours, parking, documents to bring
  • Billing and payment logistics
  • Answering inbound enquiries inside the 24-hour window, with a human escalation path

Do not send

  • Results, diagnoses, scan reports, clinical findings
  • Remote consultation, triage or clinical advice
  • Treatment names that disclose a condition
  • Marketing to a list built from clinical records without consent and DHA permission
  • An appointment time the patient never requested
  • Cold outbound to bought or scraped numbers

Genuinely unresolved

  • Whether a WhatsApp booking channel counts as a DHA "telehealth service"
  • Whether the 2024 telemarketing timing controls, drafted for calls, bind template messages
  • Whether the WhatsApp Business Calling API connects on a UAE network
  • The status of the PDPL Executive Regulations in 2026
Section one

The law that actually applies is Federal Law No. 2 of 2019

Federal Law No. 2 of 2019 concerning the use of information and communication technology in the areas of health was issued on 6 February 2019 and entered into effect in May 2019. It is the instrument that governs a Dubai clinic's patient data, and almost every vendor page aimed at UAE clinics skips it in favour of a US framework that does not apply here.

Article 2 sets the scope, and the last clause of it is the one operators miss: "This Law shall apply to all methods and uses of the information and communication technology in the areas of health in State, including the free zones." A free-zone clinic is not outside it.

Article 4 sets three duties on anyone using ICT in health: keep health data confidential and do not circulate it outside permitted cases; protect it from unauthorised damage, amendment, alteration, deletion or addition; and keep it available to authorised persons.

Article 16 is the one that bites on marketing. Whoever circulates patient-related information must keep it confidential and must not use it except for health purposes without written approval from the patient. It carves out five cases: insurers and funders verifying entitlements, anonymised scientific and clinical research, preventive or curative public-health measures, requests from competent judicial authorities, and requests from the Health Authority for monitoring and inspection. Marketing is not a health purpose and it is not on that list.

Article 20 sets retention at not less than 25 years from the date of the last health procedure for the person concerned. That is worth knowing before anyone promises a patient that their conversation history will be wiped on request.

The penalties, and what each one is actually attached to

Federal Law No. 2 of 2019, penalty articles. Effective from May 2019.
ArticleConductPenalty
23Publishing a health advertisement through the central system without a licence from the MinistryAED 100,000 to 200,000
24Violating Article 13, the ban on storing, processing, generating or transferring health data outside the StateAED 500,000 to 700,000
25Disciplinary sanctions by the Health Authority against establishmentsNotice, warning, AED 1,000 to 1,000,000, licence suspension up to six months, or cancellation
22Savings clausePenalties do not prejudice any more severe penalty under another law

Say this precisely or do not say it at all

The AED 500,000 to AED 700,000 band is attached specifically to Article 13, the cross-border storage and processing ban. It is not a general health-data-breach fine and it is not the penalty for sending a patient a message. Any page that implies "message a patient wrongly and you get fined AED 500,000" is false.

Latham & Watkins also noted in its 2019 alert that the law gives no guidance on when stricter penalties will be applied, and does not state whether fines are issued per individual breach. So it should not be modelled as multiplying per message either. And we found no published enforcement actions, fine totals or case examples under Article 24. The penalty is on the books; how often it is applied is not something anyone can show you.

Sources. Article text read from a mirror of the official English translation of Federal Law No. 2 of 2019, cross-checked line by line against the Latham & Watkins client alert of 19 June 2019. The official portal at uaelegislation.gov.ae returned HTTP 403 to every automated fetch, so the government's own site was not read directly in this pass. Cabinet Resolution No. 32 of 2020, the Executive Regulation of this law, is referenced on the MOHAP legislation portal but the host did not respond, so its contents on storage conditions are not reflected here.

Section two

Why HIPAA is the wrong frame for a Dubai clinic, and the one place it comes back

HIPAA is United States federal law. A Dubai clinic treating Dubai patients is not a HIPAA covered entity, and no UAE regulator enforces HIPAA. Any vendor telling a Dubai clinic that it "must be HIPAA compliant" as a matter of law is wrong, and the mistake usually travels with a product that was built for a different market.

The correct stack for a Dubai clinic is Federal Law No. 2 of 2019, plus its Executive Regulation (Cabinet Resolution No. 32 of 2020) and Decision No. 51 of 2021, layered with the emirate health authority's own rules. For Dubai, that means the DHA health information governance policies and standards set out further down this page.

The complication that makes HIPAA relevant anyway

The DHA's own Standards for Telehealth Services, Version 4, issued 26 September 2025 and effective 26 November 2025, require at clause 7.6.7(c) that "All platforms must have HIPAA compliance certification", with 7.6.7(d) requiring ISO 27001 and 7.6.7(e) allowing DHA to demand HITRUST or SOC 2 with HIPAA alignment. So in Dubai, HIPAA arrives not as law but as a DHA procurement standard for telehealth platforms. It is a specification a vendor has to meet, not a statute a clinic has to obey.

What Meta itself says about healthcare

"We make no representations or warranties that our Business Services meet the needs of entities regulated by laws and regulations with heightened confidentiality requirements for personal data, such as healthcare, financial, or legal services entities." WhatsApp Business Terms of Service, Section 4, last modified 16 February 2024

That is Meta explicitly declining to warrant fitness for healthcare. There is no HIPAA clause and no Business Associate clause anywhere in those Terms.

There is a further sentence, widely quoted across the industry, said to sit in Meta's Cloud API Terms and to state that Meta is not a Business Associate and that Cloud API is not HIPAA compliant. We could not retrieve that page. It is JavaScript-rendered and returned nothing usable to every method attempted. Multiple secondary sources report the same wording, and none of them reproduced it verbatim with a section number when checked. We are not going to quote a clause we could not read. The Business Terms sentence above we did read, and for a clinic's purposes it is enough.

Section three

May patient data leave the UAE? Article 13, stated precisely

"It is not permissible to store, process, generate or transform the health data and information outside State, which are related to the health services provided inside State, except in the case where a resolution is issued from the Health Authority in coordination with the Ministry." Federal Law No. 2 of 2019, Article 13, English translation

Read that as what it is: a default prohibition, not a transfer-mechanism regime. There is no UAE health-data equivalent of Standard Contractual Clauses. You are either inside the country or inside a listed exemption. That is a materially stricter architecture than the one most international vendors design for.

The ten exemptions, from Decision No. 51 of 2021

Decision No. 51 of 2021, dated 28 April 2021, created the exemptions from Article 13. Each carries conditions, and the conditions are where the exemptions get narrow.

Exemptions from Article 13, per Decision No. 51 of 2021 (28 April 2021), as summarised by Latham & Watkins, 29 August 2021.
#ExemptionPrincipal conditions
1Patient treated outside the UAE and the information is needed for that treatmentWritten approval, shared only with the concerned entity, encrypted
2Medical samples sent to laboratories abroadWritten approval, concerned entity only, encrypted
3Scientific research approved by the competent health authorityAnonymised, encrypted, highest safety standards, no other use
4Information needed by insurance and claims-management companiesCompanies operating in the UAE, anonymised, written consent, not fully transferred, encrypted
5Organisations cooperating with UAE federal or emirate governmentWritten approval, encrypted, anonymised, copy kept inside the UAE
6Simple consumer devices recording health signs such as blood pressure, blood sugar and oxygen saturationNone specified in the Decision
7PharmacovigilanceWritten approval, concerned entity only, encrypted, copy kept inside the UAE
8A transfer an emirate health authority approvesCopy kept inside the UAE, no medical secrets disclosed without written patient consent
9Information used to provide remote health servicesPhysician access for a determined duration only, a specific report or image to the concerned physician, patient's written consent
10The person requests transfer of their own health informationWritten approval, concerned entity or person only, encrypted, copy kept inside the UAE

Read exemption 10 carefully before anyone builds a sales pitch on it. It is framed as the patient requesting that their own information be transferred, with a copy retained in the UAE and encryption applied. It is not a general "get consent and host anywhere" clause. And nothing in the ten covers routing patient messages through a foreign messaging platform for the clinic's own operational convenience.

The DHA adds a second gate

The DHA Health Data Protection and Confidentiality Policy at clause 4.15 states that protected health information should not be transferred to a country or territory outside the UAE except within the category of UAE ICT Health Law exemptions, and adds that DHA approval must be granted as per the DHA Health Information Assets Classification Policy. So a clinic in Dubai needs the federal exemption and the emirate approval, not one or the other.

The question to put to any messaging vendor in writing

We are not going to tell you where Meta hosts your conversation content, because we did not verify it from Meta's own documentation in this research pass and we are not prepared to assert it. What we will tell you is the question that has to be answered before anything clinical goes near a message: where does the conversation content sit at rest, where is it processed, what leaves the country, and which of the ten exemptions is being relied on. Get the answer in an email you can keep. This is also precisely why the four workflows further down carry booking logistics rather than clinical content: the workflows that carry no health information do not need an exemption at all.

A naming disagreement we are reporting rather than resolving. Latham & Watkins calls the 28 April 2021 instrument "Ministerial Decision No. 51 of 2021". The DHA Telehealth Standards Version 4 also calls it Ministerial. The DHA Health Data Protection and Confidentiality Policy calls it "Cabinet Decision No. (51) of year 2021". DHA's own hosted copy is a scanned PDF that could not be text-extracted. We use "Decision No. 51 of 2021" and do not assert which.

Section four

What the DHA says, and the WhatsApp-shaped gap in it

Four DHA instruments matter to a clinic thinking about patient messaging. All four were fetched from dha.gov.ae.

The four DHA instruments that shape clinic messaging, with their own stated dates.
ReferenceDocumentIssuedEffective
DHA/HISHD/PP-13Policy for Health Data and Information Sharing10/08/202410/11/2024
DHA/HISHD/PP-11Health Data Protection and Confidentiality Policy10/08/202210/10/2022
DHA/HISHD/ST-09Standards for Health Information Consent and Access Control02/01/202502/04/2025
DHA/HRS/HPSD/ST-14Standards for Telehealth Services, Version 426/09/202526/11/2025

PP-11 carries a discrepancy inside DHA's own document: the cover page states an effective date of 10/10/2022 and the internal footer states 10 November 2022. We report it rather than resolve it.

The gap, stated plainly

PP-13 has a named section for sharing protected health information through email (clause 4.10) and a named section for removable media. It has no named section for instant messaging, and no DHA document we read names WhatsApp in a permission or a prohibition. What applies is the general obligation at clause 4.8.4, which requires that all information transfer or sharing in or out of the organisation is protected by appropriate information sharing protocols, and that receipt and transfer of protected health information occurs within the boundaries of UAE laws and DHA regulations.

The email rules at 4.10 are the closest analogue we have. They allow protected health information to be sent by email only "if it is appropriately encrypted or it contains links to Patient data within technology portal that is already protected by an authentication mechanism", only from official entity-issued accounts, never to personal addresses, with manual encryption and "(Encrypt)" in the subject line for domains outside the secure list. Applying those rules to WhatsApp is an inference we are making, not a citation. We say so because a page that dresses that inference as DHA policy is doing a clinic no favours.

WhatsApp is named exactly once in the DHA material read for this page, and not as a channel permission. The DHA Guidelines for Medical Advertisement Content on Social Media (HRS/HPSD/SMA/1/2019) define social media to include "Facebook, Instagram, Twitter, Reddit, Pinterest, Flicker, WhatsApp, YouTube, Snapchat and LinkedIn". That brings promotional WhatsApp content from a DHA-licensed facility inside that guideline. It says nothing about using WhatsApp as a service channel.

What the advertising guideline then requires

  • Medical Director approval. Clauses 5.2 to 5.4: content naming the facility must be approved by the Medical Director, who is accountable for all advertised content.
  • Substantiation, and the risks stated. Clause 6.3: all social media advertising must be substantiated, especially as to treatment outcomes, and "should always include the associated risks".
  • No superlatives. Clause 6.9 rules out "unique, one of a kind, the best, exclusive, safest, the only, incomparable, unprecedented, best product, magic, miraculous, assured success, very limited quantity, has no side effects" and similar.
  • Written consent for any patient featured. Clauses 6.8 and 9.1 to 9.2, aligned with the DHA patient consent guidelines.
  • Appendix 2 prohibitions include patient identifiable information, patient testimonials without written consent, treatments that guarantee full recovery, before and after images without a variability disclaimer, and fear-inducing wording.

The clause that lands directly on outbound messaging

Appendix 1, item (p) of the same guideline makes it prohibited to "Provide a patient or client with an unsolicited appointment time that has not been requested by the patient or client."

That is a direct, sourced prohibition on the "Hi, we have booked you in for Tuesday at 3" pattern that appears in a great many automation demos. A reminder for a slot the patient booked is a different thing, and it is fine.

Marketing from patient records is a "Secondary Use"

This is the single most commercially important DHA clause for a clinic weighing a WhatsApp campaign. The Health Data Protection and Confidentiality Policy classifies marketing alongside research, audit and public health as a Secondary Use of protected health information:

"Secondary use (e.g. Research, Public Health, Clinical Audit and Quality Improvement, Safety Initiatives, Facility Accreditation Purposes, Prosecuting or Defending a Legal Claim or Complaint, and marketing) of PHI should require further permission/approval from DHA ([email protected])." DHA/HISHD/PP-11, Health Data Protection and Confidentiality Policy

and, separately in the same policy, that secondary use of identifiable data and health information "needs consent from Subject Data". So under DHA policy, using identifiable patient records to send marketing requires both the patient's consent and further DHA permission. The same policy at 4.10.5 requires that where processing is done on the entity's behalf, the entity uses only processors providing sufficient guarantees of appropriate technical and organisational measures, and 4.10.6 requires written authorisation before a processor engages a sub-processor. A messaging vendor is a processor.

Consent, per ST-09

  • Consent is not required to record and access a patient's protected health information within the EMR for their own direct care (Standard Two, 6.1).
  • For purposes other than individual care, consider first whether identifiable information is needed at all. Where anonymous data is not practicable, "consent is normally required" (Standard Three, 7.1 to 7.2).
  • Consent for accessing the health information system "remains valid for one year after last health Encounter" (8.16). A dormant patient list ages out of consent faster than most clinics assume.

The telehealth question, which is genuinely unresolved

The DHA Telehealth Standards Version 4 define telehealth broadly enough to reach the front desk. The standard states that telehealth services "include but are not limited to scheduling appointments, assessment, providing medical advice, treatment, therapy, laboratory testing, diagnostics, surgery, monitoring chronic conditions, counselling and prescribing and dispensing of medications", and clause 12.2.1 requires physicians to determine and document suitability for telehealth use including "a. Appointment scheduling."

If a clinic's WhatsApp channel is delivering what DHA classifies as a telehealth service, clause 7.6 puts a specification around the platform behind it: assessed and approved by DHA through health facility licensing prior to implementation (7.6.2), legal representation in Dubai with a relevant trade licence (7.6.3), all communication channels approved by the TDRA (7.6.6), data centres at least Tier 3 certified, servers at a cloud provider certified by the Dubai Electronic Security Centre in the UAE, HIPAA compliance certification and ISO 27001 certification (7.6.7).

What follows from that, and what does not. It does not follow that DHA has banned WhatsApp; DHA has not named it either way. What follows is directional and worth stating: the further a clinic's WhatsApp channel drifts from logistics towards clinical content, the harder it becomes to argue it sits outside clause 7.6, and clause 7.6 is a specification that the WhatsApp Cloud API is not documented as meeting. That is a reason to keep the channel on the logistics side of the line, which is exactly what the workflows below do.

Section five

Where the PDPL applies to a clinic, and where it does not

Federal Decree-Law No. 45 of 2021, the UAE Personal Data Protection Law, came into force on 2 January 2022. The official text is published in Arabic only. Most vendor content aimed at UAE clinics treats it as the patient data rule. It is not, and the carve-out that says so is short.

Article 2(2) lists what the PDPL does not apply to. Item (e): "Personal Health Data that has legislation regulating its protection and processing." Federal Decree-Law No. 45 of 2021, English translation

Because Federal Law No. 2 of 2019 is legislation regulating the protection and processing of health data, the widely-taken reading is that patient health data in the UAE is governed by Law 2/2019 and the health authority rules, not by the PDPL. DLA Piper's country guide, last modified 27 January 2025, describes exactly this architecture. Item (g) of the same article also excludes companies and establishments located in free zones that have their own special data protection legislation, which is how DIFC, ADGM and Dubai Healthcare City sit outside it.

The practical effect for a clinic. A page that says "clinics must comply with the PDPL" is a simplification. A page that says "the PDPL is the rule for patient data" is wrong. A clinic still holds PDPL-governed personal data: staff, suppliers, and general enquirers who are not yet patients. Its patient data sits under the stricter health regime.

Where the PDPL does bite on messaging

On the enquirer who is not yet a patient, which is a large share of any clinic's WhatsApp inbox.

  • Article 4 prohibits processing personal data without the owner's consent, with eleven exceptions including processing necessary for preventive medicine, medical diagnosis, health or social care, treatment or health insurance services. None of the eleven is marketing.
  • Article 6 requires that the controller can prove consent, that consent is prepared in a clear, simple, unambiguous and easily accessible manner in writing or electronically, and that it includes the right to withdraw it easily at any time.
  • Article 13 requires the controller, before starting processing, to tell the data subject the purposes, the sectors or establishments the data will be shared with inside and outside the State, and the protection measures for cross-border processing.
  • Article 17 gives an unconditional right to object to processing for direct marketing, including profiling related to direct marketing. There is no legitimate-interest override anywhere in the text.

The PDPL's unfinished state, which is worth knowing before anyone quotes a fine at you

Article 26 leaves penalties to a Cabinet decision on the proposal of the Director General of the Bureau. The Decree-Law itself specifies no fines. Article 28 required the Executive Regulations to be issued within six months of promulgation, and Article 29 then gives controllers six months from that issuance to regularise.

DLA Piper recorded the Executive Regulations as unpublished as of 6 January 2025 and the Data Office as not yet established. A 2026 practice guide surfaced in search indicates they were still unpublished in February 2026, but we did not read that source directly and we are not going to date-stamp a "still not issued in September 2026" claim we have not verified. Anyone quoting you a PDPL fine schedule should be asked which instrument it comes from.

Penalties that do exist today, reported via DLA Piper rather than read in the underlying instruments: Cyber Crime Law Article 13, detention and a fine of AED 50,000 to AED 500,000 for unlawfully collecting or processing personal data in violation of applicable legislation; and Penal Code Article 432, a minimum of AED 20,000 and up to one year for a professional disclosing secrets without authority.

Section six

What belongs in a message, and what does not

This is the synthesis of everything above, with the basis for each row named. Where the sources are silent, the row says so.

Reasonably safe

MessageBasis and conditions
Confirmation of an appointment the patient bookedTransactional, not marketing. No clinical content. Existing relationship, and the patient gave you the number. Still needs WhatsApp opt-in under the Business Messaging Policy. Keep out any diagnosis, treatment name, or department name that reveals a condition.
Reminder, reschedule, cancellationSame basis. Note that DHA's advertising guideline Appendix 1(p) prohibits pushing an unsolicited appointment time the patient did not request. A reminder for a booked slot is not that. A cold "we have scheduled you" is.
"Your results are ready, log in to the portal or call the clinic"Carries no health information itself. Mirrors the pattern DHA permits for email at PP-13 clause 4.10.1, which allows links to patient data inside a technology portal already protected by an authentication mechanism.
Directions, opening hours, parking, document checklist, billing logisticsNo protected health information and no marketing of a health product.
General public-health awareness content not tied to an individual's recordDHA advertising guideline 6.7.1 permits promoting public health information as part of a public health campaign, and 6.7.2 raising awareness of products and services through public health. Still needs Medical Director approval under 5.2 to 5.4.

Do not send

MessageBasis
Test results, diagnoses, scan reports, clinical findingsHealth information under Law 2/2019. Meta's own policy says do not send or request health related information where regulations demand heightened handling. DHA requires encryption or an authenticated portal for the analogous email case.
A remote consultation, triage or clinical advice conversationThat is telehealth. DHA Telehealth Standards V4 clause 7.6 puts a DHA-approved, TDRA-approved, UAE-hosted, ISO 27001 and HIPAA-certified specification around the platform. Meta's Business Messaging Policy says outright: "Don't use WhatsApp for telemedicine."
Treatment names that disclose a condition, for example "your IVF cycle", "your oncology follow-up", "your psychiatric review"The condition is itself health information. Article 16 restricts using patient information other than for health purposes without written approval, and Article 4 requires confidentiality. Practically: the message preview lands on a lock screen a family member may read.
Marketing to a list assembled from clinical recordsDHA PP-11 makes marketing a Secondary Use of protected health information requiring the patient's consent and further permission from DHA. PDPL Article 17 gives an unconditional right to object to direct marketing where the PDPL applies.
Promotional messages with guaranteed outcomes, superlatives, before and after images without a disclaimer, or testimonials without written consentDHA advertising guideline 6.3, 6.9 and Appendix 2.
Cold outbound to purchased or scraped numbersMeta requires that the person gave you their number and opted in. Cabinet Resolution No. 56 of 2024 requires an opt-in channel and Do Not Call Register screening for telemarketing, and its definition reaches marketing messages sent through social media applications.

Grey, and a decision for the clinic rather than for us

  • Promotional offers for cosmetic, dental or wellness services to people who opted in but are not yet patients. No protected health information is involved, so the DHA secondary-use rule does not obviously bite. The content is still a social media advertisement under the DHA guideline, and Meta's prohibited-vertical list includes "Medical and healthcare products", which may or may not be read to cover services.
  • Post-treatment check-in messages. Arguably clinical follow-up, arguably service. The safe version names no treatment.

Meta's own vertical rules, and an honest reading of them

The WhatsApp Business Messaging Policy prohibits using the Business Services for buying, selling, promoting or facilitating the exchange of certain regulated or restricted goods and services, and that list includes "Drugs, whether prescription, recreational, or otherwise" and "Medical and healthcare products". It adds that "These prohibitions apply irrespective of the global or local licenses, registrations, or other approvals your business may hold." A separate section then carves out "Regulated Verticals" in named countries, but the only allowed-country lists published are for online gambling and gaming, over-the-counter drugs, and alcohol. The UAE appears on none of them, and there is no allowed-country list at all for medical and healthcare products. On the free WhatsApp Business App the position is blunter still: "You are prohibited from messaging about any Regulated Verticals on the WhatsApp Business App."

The honest reading: the prohibition is written around products, and Meta enforces it "as determined in our sole discretion" rather than through any published adjudication. A clinic sending an appointment reminder is not plausibly promoting a medical or healthcare product. A clinic blasting a promotion for an IV drip package or a prescription weight-loss programme plausibly is. Meta has not drawn that line. We are drawing it, and telling you that we are.

Opt-in, which Meta is less prescriptive about than most vendors claim

Meta requires that before you contact anyone, they have given you their mobile number and you have received opt-in permission confirming they wish to receive subsequent messages from you. But its own developer documentation, last updated 16 June 2026, is explicit that the opt-in "can be general and not specifically for WhatsApp, as long as businesses comply with all local laws". The requirements are that you clearly state a person is opting in to receive communication from the business, that you name the business, and that you comply with applicable law. Accepted methods listed by Meta are SMS, website, an IVR flow by phone, and in person or on paper. For a clinic, that means the intake form is a legitimate opt-in surface if it is written properly.

Section seven

The four clinic workflows that survive all of this

Everything above narrows the field, and what is left is narrower than most automation pitches but considerably more useful than a clinic front desk running on a personal phone. These four carry no health information, need no Article 13 exemption, and sit on the logistics side of the DHA telehealth line.

1

Appointment confirmation and reminders

Sent as utility templates against a slot the patient booked. No clinical content, no treatment name, no department that discloses a condition. The template carries the time, the branch and what to bring.

Hello Sara. This is a reminder of your appointment at our Jumeirah branch on Tuesday 8 September at 3:00 pm. Please bring your Emirates ID and insurance card. Reply RESCHEDULE if the time no longer works.Utility template, opted-in patient
2

No-show recovery and rescheduling

A missed slot is a logistics event, not a clinical one. The message says the slot was missed and offers to rebook. It never names the treatment, and it never proposes a time the patient did not ask for, which is what DHA Appendix 1(p) prohibits.

Hello Ahmed, we missed you at your appointment yesterday. Would you like to rebook? Reply with a day that suits and we will send you the available times.Rebooking, no treatment named
3

Results notification, never the result

The notification carries no health information. The result stays behind authentication. This mirrors the pattern DHA permits for email at PP-13 clause 4.10.1, which allows a link into a technology portal already protected by an authentication mechanism.

Hello Layla, your results are ready. Please log in to the patient portal to view them, or call us on the clinic number and we will go through them with you.Notification only, result behind login
4

Enquiry answering inside the 24-hour window

The highest-volume, lowest-risk lane, and the one where an assistant earns its keep. Directions, opening hours, parking, what to bring, insurance networks accepted, billing questions, the price of a consultation where the clinic publishes it. Anything clinical routes to a person.

We are open Saturday to Thursday, 9:00 am to 9:00 pm, and closed on Fridays. Parking is free in the basement, level B1. For anything about your treatment, I will pass you to one of the team now.Automated reply, human escalation offered

Two Meta rules that shape all four

Templates and the window. Business-initiated conversations must use an approved message template, and Meta reserves the right to review, approve, pause and reject any template at any time. You may reply free-form only within 24 hours of the patient's last message. Outside that window, templates only.

Automation is allowed, escalation is mandatory. Meta's Business Messaging Policy states you may use automation when responding during the 24-hour window, but must also have available prompt, clear and direct escalation paths, and it names them: in-chat human agent transfer, a phone number, an email address, web support on the business website, an in-store visit, or a support form. A clinic assistant that cannot hand over to a person is not compliant, and separately it is not usable.

There is a commercial edge in that last point which most vendors do not mention. Meta's own guidance on driving high-quality conversations notes that "the bot functionality and how quickly questions and other enquiries are resolved" can influence a phone number's quality rating. A good assistant is not only a service improvement. It is a deliverability input.

On running an AI assistant at all, since the October 2025 change is widely misread

Meta did not ban AI chatbots on WhatsApp. The clause added to the WhatsApp Business Solution Terms, last modified 6 March 2026, is headed "AI Providers" and bars providers and developers of AI technologies from using the Business Solution to distribute their own assistant "when such technologies are the primary (rather than incidental or ancillary) functionality being made available". That is the general-purpose-assistant distribution case. The same clause then says the opposite explicitly: "you may retain an AI Provider as your Third Party Service Provider."

A clinic running an assistant to serve its own patients is a customer of an AI provider, not an AI provider. Nothing in the clause caps how capable the assistant is, and the vendor framing that "open-ended bots are banned and structured bots are fine" does not appear anywhere in the terms. One data constraint does bite, and it is worth putting in a contract: you may fine-tune on your own conversation data only for a model that is for your exclusive use, so pooling clinic conversation data to train a shared model is prohibited.

Section eight

Where a human must take over

The handover list is short, and it should be written into the assistant before the first message goes out rather than discovered later.

  • Anything clinical. Symptoms, triage, dosage, whether to come in, whether something is normal. That is telehealth, and Meta's own policy says not to use WhatsApp for it.
  • Anything that would put a result, diagnosis, scan report or treatment name into a message. Route to the portal or to a call.
  • Complaints, adverse events and safeguarding concerns. No assistant should be the first responder to those, and the record of them belongs in the clinic's own systems.
  • Requests to access, correct or delete a record. Note that Article 20 of Law 2/2019 requires health data to be kept for not less than 25 years from the last health procedure, which sits awkwardly against a casual "delete my data" promise. That is a decision for the clinic and its counsel, not an automation.
  • Identity and payment details. Meta's own policy: "Don't share or ask people to share full length individual payment card numbers, financial account numbers, personal ID card numbers, or other sensitive identifiers."
  • Any patient who asks for a person. Honour it on the first ask. Meta requires the escalation path anyway.

Two patterns from our own sales calls, offered as what operators say rather than as a study. The first is that Gulf buyers accept AI on text and reject it on the phone, and they say why, unprompted. The second is that the firms most exposed to reputation risk tend to choose full disclosure as their mitigation without being asked to. One operator put it as "we're not gonna trick, we're not gonna hide it". Telling patients they are talking to an assistant, and how to reach a person, costs nothing, and in our own calls it is the condition operators set for themselves before anyone asks them to.

One thing WhatsApp cannot do for a UAE clinic: calls

WhatsApp messaging works normally in the UAE. Voice and video calling over WhatsApp does not. TDRA treats voice and video calls as VoIP, a regulated activity that must be provided by a licensed provider or in collaboration with one, and its published guidance states that licensed providers "are obliged to block the traffic of VoIP applications that are not in compliance". WhatsApp does not appear on TDRA's published list of permitted VoIP applications, in either the general or the telehealth category. UAE press reported in February 2026 that WhatsApp calling remained restricted locally even as WhatsApp Web gained calling globally.

On the WhatsApp Business Calling API specifically: Meta's documentation does not exclude the UAE from business-initiated calling. That is a statement about Meta's own platform availability, not about a carrier-level block that sits downstream of Meta entirely. We found no source, primary or secondary, confirming that such a call connects to a consumer on a UAE mobile network, and none confirming that it fails. We treat it as unresolved, we do not sell a workaround, and we build clinic channels on messaging.

Section nine

What WhatsApp actually costs a UAE clinic, and what changes on 1 October 2026

Start with the unit, because most quotes get it wrong. Meta charges on a per-message basis, and has done since 1 July 2025. Conversation-based pricing was deprecated on that date. A proposal priced in "conversations per month" is modelling a billing system that no longer exists.

UAE rates (market AE), pulled from Meta's own public pricing API on 3 September 2026. Meta publishes an AED rate card directly.
CategoryUSD per messageAED per messageVolume tiers
Marketing0.04990.1832None. One flat UAE marketing rate.
Utility0.01570.0576Tier 1 covers 0 to 100,000 per month
Authentication0.01570.0576Tier 1 covers 0 to 300,000 per month
Service00Free today. Chargeable from 1 October 2026.

Three things follow that are worth holding on to.

  • Do not convert from USD. Meta added AED as a billing currency effective 1 April 2026 and publishes a separate AED rate card. Its AED figures are not a live FX conversion of its USD figures, so a converted number will not match the invoice.
  • The stale figure still circulating for the UAE is $0.0385 marketing. Meta raised the UAE marketing message rate effective 1 October 2025. Vendor pages carrying a 2026 "last updated" stamp still publish the old number.
  • Nobody should quote a UAE clinic the authentication-international rate. It applies only where a business sends more than 750,000 messages outside customer service windows in a rolling 30-day period and is based in a different country from the recipient. A UAE business messaging UAE patients pays the standard authentication rate.

The change that matters most to a clinic, on 1 October 2026

Today a clinic answering inbound patient enquiries pays Meta nothing for those replies. Non-template messages are free, service messages have been free for all businesses since 1 November 2024, and utility templates delivered inside an open 24-hour customer service window are free.

Meta has published that from 1 October 2026, service messages become chargeable per message at each market's existing utility or authentication rate with no volume tier discounts, and utility messages inside the 24-hour window become chargeable as well. For a service-led clinic account that is the single largest cost change on the horizon, and it lands within weeks of this page being written.

Documentation conflict, reported because it is load-bearing. Meta's main pricing page still says non-template messages and in-window utility templates are free, and does not mention the change. Meta's dedicated upcoming-changes page does. Both are Meta primary sources and they currently disagree. Re-check both before anyone prices a contract on today's free window. We have deliberately not published a UAE service rate for October, because Meta has not published one. It says service will match the market's utility rate, which implies AED 0.0576, but that is arithmetic rather than a rate card line.

The provider layer on top of Meta

Meta's rate is the floor. Every business solution provider adds something, and there are two distinct models. Twilio publishes $0.005 per message on top of Meta's fees, charged on inbound as well as outbound, which matters because Meta does not charge for inbound at all, so a service-heavy clinic account is not free on Twilio. 360dialog publishes a flat €49 per number per month for its Regular plan and states no markup on Meta fees. Those two are cited because both are the vendor's own published price. The flat 20% markups quoted for various other providers in comparison blogs could not be traced to a primary source, so they are not on this page.

One observation from our own sales calls, offered as an observation. In one meeting nobody in the room knew what Meta's per-message fee actually was, and a figure read aloud went uncorrected by either side. When a rate card has moved twice in twelve months, it is worth checking against Meta's own published card rather than a vendor's slide.

Section ten

The grey zone: what is safe, what carries a named consequence, and what operators actually do

Three blocks. The third is operator practice observed in the market, and it is labelled as operator practice because none of it is Meta policy or UAE law.

Safe

  • Confirmations and reminders for appointments the patient booked, from an opted-in number, with no clinical content.
  • "Your results are ready, log in or call us", with the result behind authentication.
  • Logistics of every kind: directions, hours, parking, documents to bring, insurance networks accepted, billing.
  • Answering inbound enquiries inside the 24-hour window using automation, with a working human escalation path.
  • General public health awareness content that is not tied to an individual's record, approved by the Medical Director.

Triggers a consequence, and here is the consequence

Marketing to a list built from clinical records, without consent and DHA permission
ConsequenceDHA PP-11 makes this a Secondary Use requiring both, and that policy states it applies to all healthcare entities under DHA jurisdiction. Separately, and stated as a general power rather than as a penalty the law attaches to this specific act, Article 25 of Law 2/2019 gives the Health Authority disciplinary sanctions against establishments running from a written notice, to a written warning, to a fine of AED 1,000 to AED 1,000,000, to suspension of the central-system licence for up to six months, to cancellation of that licence. No published enforcement action under these provisions was found.
Storing, processing, generating or transferring health data outside the UAE outside the Decision 51/2021 exemptions
ConsequenceArticle 24: not less than AED 500,000 and not more than AED 700,000. That is the Article 13 penalty specifically, not a general breach fine, and there is no published guidance on when the higher end applies.
Pushing an appointment time the patient never asked for
ConsequenceProhibited outright by DHA's advertisement guideline, Appendix 1 item (p). The guideline states that it applies to all DHA licensed health facilities and healthcare professionals engaged in social media advertising, and the Medical Director is accountable for advertised content under clauses 5.2 to 5.4.
Sending a marketing message under a Utility or Authentication template category to pay the cheaper rate
ConsequenceMeta names "template misclassifications" in its own platform enforcement documentation as a trigger. The published ladder is a warning, then a 1 or 3 day block on sending template messages and adding phone numbers, then a 5, 7 or 30 day block on sending any messages, then an account lock removable only by appeal, then permanent removal from the platform. All policy violations can be appealed within 90 days. Meta's Business Help Centre says reviews typically take 24 hours; its developer documentation says 24 to 48. Both are Meta and they disagree.
Poor-quality outbound that draws blocks, reports, mutes or archives
ConsequenceYour phone number quality rating is Green, Yellow or Red, calculated on the past seven days and weighted by recency. Blocks, reports, mutes and archives all count, not just blocks. When a user blocks you they pick a reason from: No longer needed, Didn't sign up, Spam, Offensive messages, No reason. "Didn't sign up" is a direct read on your opt-in quality. Separately, a template that reaches the lowest quality rating is auto-paused for 3 hours, then 6 hours, then disabled. Note also that the Flagged and Restricted phone number statuses were discontinued on 7 October 2025, so any guide built around them is describing a system that no longer exists.
Cold outbound to bought, scraped or walk-in numbers with no opt-in
ConsequenceMeta requires that the person gave you the number and opted in. Separately, Cabinet Resolution No. 56 of 2024, in force 27 August 2024, defines telemarketing to include "marketing text messages and marketing messages through social media applications", applies to all companies licensed in the State including free zones, and requires prior approval from the competent authority, a dedicated opt-in channel, Do Not Call Register screening and record-keeping. Cabinet Resolution No. 57 of 2024 sets the penalties for breaching it. We read that fine schedule only in a law firm's summary table rather than in the instrument, so no figure from it appears on this page.

A tension worth knowing rather than papering over. The definition in Resolution 56/2024 sweeps in social media marketing messages, but the operative obligations in Articles 4 and 5 are written in call language: record the marketing phone call, identify the company at the beginning of the call, call only between 9:00 am and 6:00 pm. How that maps onto a WhatsApp template message is not specified in the text. A cautious clinic treats the opt-in channel and the timing window as applying. It is not settled that they do. Separately, TDRA's Regulatory Policy on Unsolicited Electronic Communications, Version 1.1 of 13 June 2022, bans marketing texts between 9:00 pm and 7:00 am, but on its face that instrument governs SMS and MMS over a public telecommunications network and binds licensees and their messaging subscribers. We found no TDRA statement extending it to over-the-top apps. Two instruments, two different windows, each correct for itself.

Operator practice, with the specific risk stated

None of the following is a rule. It is what operators in this market tell us they do, and each one carries a risk that is worth naming before it is copied.

Sending in batches of roughly 500, staggered, on a number carrying a high quality rating
Operator practiceOperators do this because Meta's enforcement feels like a black box. Risk: it does not raise your messaging limit, and it does not bypass template pacing, where Meta holds messages after an unspecified threshold to gather early feedback and then drops them if the signal is bad, surfacing as error code 132015. Meta effectively runs this test for you.
Splitting sends across several numbers to spread risk
Operator practiceRisk: messaging limits are calculated and set at the business portfolio level and are shared by every phone number in that portfolio. Splitting buys no additional volume. It only isolates number-level quality. Anyone selling it as a way to send more is wrong.
Number "warm-up" schedules, often presented as a ramp of ten to twenty messages a day rising weekly
Operator practiceRisk: no Meta document prescribes a warm-up ramp. The only Meta-documented ramps are the messaging-limit ladder and template pacing. Treat vendor warm-up tables as folk practice, and do not let one be sold to you as a compliance measure.
Naming the treatment in a reminder so the patient recognises what it is for
Operator practiceRisk: the condition is itself health information. Article 16 restricts using patient information other than for health purposes without written approval, and the notification preview appears on a lock screen a family member may see. The safe version names the branch and the time, not the treatment.
Keeping the whole patient conversation history inside WhatsApp itself
Operator practiceAn operator once described the problem exactly: if you close WhatsApp you cannot find the data, you have to open chat by chat. Risk: Article 20 requires health data to be retained for not less than 25 years from the last health procedure, and Meta's Business Solution Terms restrict what you may do with data obtained through the platform. A messaging app is not a record system. The record belongs in the clinic's own systems.

Two more mechanics that quietly cap a clinic's outbound

Messaging limits start at 250, not 1,000. A newly created business portfolio can initiate conversations with 250 unique WhatsApp users per rolling 24 hours. That rises to 2,000 by completing a scaling path, then 10,000, 100,000 and unlimited through automatic scaling. The 1,000-per-day "Tier 1" figure that appears across vendor content is stale.

Per-user marketing limits apply in the UAE. Meta caps how many marketing template messages an individual receives from any business in a given period, based on that person's recent marketing read rate and how full their inbox is. The UAE is not among the markets excluded from this. Separately, WhatsApp gives users an "Offers and announcements" setting that stops your marketing messages entirely; when it is set, the API accepts the request and does not send, returning a failed status your CRM will not otherwise see.

Questions

Frequently asked questions

Is it legal for a Dubai clinic to use WhatsApp with patients?

There is no UAE law and no DHA policy that names WhatsApp as permitted or prohibited for clinic use. What the rules govern is the content of the message and the location of the data, not the app. Appointment logistics with an opted-in patient and no clinical content sit in a materially safer category than clinical conversations, results or marketing from patient records. The governing instrument is Federal Law No. 2 of 2019 on the use of ICT in the health fields, and its Article 13 bars health data from services provided inside the UAE from being stored, processed, generated or transferred outside the country outside ten narrow exemptions.

Does HIPAA apply to a clinic in Dubai?

No. HIPAA is United States federal law and no UAE regulator enforces it. The correct analogue is Federal Law No. 2 of 2019, with its Executive Regulation (Cabinet Resolution No. 32 of 2020) and Decision No. 51 of 2021, layered with the Dubai Health Authority's health information governance policies.

HIPAA does reappear in Dubai in one specific place. The DHA Standards for Telehealth Services Version 4, effective 26 November 2025, require at clause 7.6.7(c) that all telehealth platforms hold HIPAA compliance certification, and at 7.6.7(d) ISO 27001. That is a DHA procurement standard for platforms, not a law a clinic is bound by.

Can patient data leave the UAE?

By default, no. Article 13 of Federal Law No. 2 of 2019 prohibits storing, processing, generating or transferring health data related to health services provided inside the UAE outside the country, absent a resolution from the Health Authority in coordination with the Ministry. Decision No. 51 of 2021, dated 28 April 2021, created ten exemptions covering overseas treatment, samples sent to laboratories abroad, approved research, insurance, cooperating organisations, consumer health devices, pharmacovigilance, health authority approval, remote medical services and a patient's own request. Most carry conditions of written approval, encryption and a copy retained inside the UAE. None covers routing patient messages through a foreign platform for operational convenience.

Violating Article 13 carries a penalty under Article 24 of not less than AED 500,000 and not more than AED 700,000. That band attaches specifically to Article 13. It is not a general health data breach fine and it is not the penalty for sending a patient a message. In Dubai, the DHA adds a second gate: its confidentiality policy requires DHA approval on top of the federal exemption.

Has the DHA approved WhatsApp for clinics?

No DHA document read for this page names WhatsApp in a permission or a prohibition. The DHA Policy for Health Data and Information Sharing (DHA/HISHD/PP-13, effective 10 November 2024) has a named section for email and one for removable media, and none for instant messaging. What applies is the general obligation at clause 4.8.4 that all information transfer occurs within the boundaries of UAE laws and DHA regulations, and the email rules at 4.10 are the closest available analogue.

WhatsApp is named once in DHA material, inside the definition of "social media" in the DHA Guidelines for Medical Advertisement Content on Social Media. That brings promotional WhatsApp content from a DHA-licensed facility inside that guideline. It says nothing about using WhatsApp as a service channel.

Can a clinic send test results over WhatsApp?

Send the notification, not the result. A message saying "your results are ready, please log in to the portal or call the clinic" carries no health information and mirrors the pattern the DHA permits for email at PP-13 clause 4.10.1, which allows links to patient data inside a technology portal that is already protected by an authentication mechanism.

The result itself should not go into the message. WhatsApp's own Business Messaging Policy states: "Don't use WhatsApp for telemedicine or to send or request any health related information, if applicable regulations prohibit distribution of such information to systems that do not meet heightened requirements to handle health related information." Meta's Business Terms of Service separately disclaim any warranty that its Business Services meet the needs of entities with heightened confidentiality requirements such as healthcare.

Can a clinic send marketing offers to its patient list on WhatsApp?

Not from clinical records without two things. The DHA Health Data Protection and Confidentiality Policy classifies marketing as a Secondary Use of protected health information which "should require further permission/approval from DHA" and which separately "needs consent from Subject Data". Federal Law No. 2 of 2019 Article 16 also bars using patient-related information other than for health purposes without the patient's written approval, and marketing is not among the five carve-outs.

On top of that, Meta requires opt-in before any business-initiated message, and Cabinet Resolution No. 56 of 2024, in force 27 August 2024, defines telemarketing to include marketing messages sent through social media applications and requires prior approval, an opt-in channel and Do Not Call Register screening. Promotional content from a DHA-licensed facility must also satisfy the DHA advertisement guideline, including Medical Director approval and the ban on superlatives and guaranteed outcomes.

Can a clinic call patients over WhatsApp in the UAE?

WhatsApp messaging works normally in the UAE. Voice and video calling over WhatsApp does not. TDRA treats voice and video calls as VoIP, a regulated activity that must be provided by a licensed provider or in collaboration with one, and states that licensed providers are obliged to block the traffic of VoIP applications that are not in compliance. WhatsApp does not appear on TDRA's published list of permitted VoIP applications, in either the general or the telehealth category. UAE press reported in February 2026 that WhatsApp calling remained restricted locally even as WhatsApp Web gained calling globally.

On the WhatsApp Business Calling API specifically, Meta's documentation does not exclude the UAE from business-initiated calling. That is a statement about Meta's platform availability, not about a carrier-level block downstream of Meta. We found no source confirming that such a call connects on a UAE mobile network, and none confirming that it fails. The honest position is that it is unresolved, and a clinic should build on messaging.

Did Meta ban AI chatbots on WhatsApp?

No. The clause added to the WhatsApp Business Solution Terms in October 2025, and present in the version last modified 6 March 2026, is headed "AI Providers". It bars providers and developers of AI technologies from using the WhatsApp Business Solution to distribute their own assistant where that assistant is "the primary (rather than incidental or ancillary) functionality being made available". That is the general-purpose-assistant distribution case. The same clause explicitly permits the opposite: "you may retain an AI Provider as your Third Party Service Provider."

A clinic running an assistant for its own patients is the permitted case. The framing that "open-ended bots are banned and structured bots are allowed" is vendor commentary and does not appear in the terms. Meta's separate and older rule still applies: automation is allowed inside the 24-hour customer service window, but the business must offer prompt, clear and direct escalation paths to a human. There is also a data restriction: you may fine-tune on your own conversation data only for a model that is for your exclusive use.

What does WhatsApp cost a clinic in the UAE?

Meta charges per delivered template message and has done since 1 July 2025, when conversation-based pricing was deprecated. As pulled from Meta's own public pricing API on 3 September 2026 for market AE: marketing is AED 0.1832 or $0.0499 per message with no volume tiers for the UAE; utility and authentication are AED 0.0576 or $0.0157 at tier one; service messages are free today. Meta publishes an AED rate card directly, so those AED figures should not be recalculated from the USD ones.

Two changes matter. Meta raised the UAE marketing rate effective 1 October 2025, which is why $0.0385 still appears on stale vendor pages. And Meta has published that from 1 October 2026 service messages, and utility messages inside the 24-hour window, become chargeable at the market's utility rate. Meta's main pricing page and its upcoming-changes page currently disagree about that, so both should be re-checked before pricing a contract on today's free window. A business solution provider fee sits on top: Twilio publishes $0.005 per message including inbound, 360dialog publishes €49 per number per month with no markup on Meta's fees.

About our work in this sector

What we can and cannot tell you about our clinic clients

We are going to be as careful about our own claims as we have been about everyone else's.

"We also work with clients in the healthcare and aesthetics space. Due to the sensitive nature of these engagements, we are unable to publicly disclose their identities. If you are a healthcare provider and would like to learn more about our work in this sector, get in touch and we can share relevant details privately." Published on learnmind.ai/results

What we can show you publicly are the two named clients published on learnmind.ai/results, both outside healthcare, because the mechanism is the same one a clinic front desk needs.

Alcaz Media, UAE performance marketing agency

Seconds, response time 24/7 100% lead capture rate Zero leads lost 100% uptime success rate

Every enquiry answered within seconds, at any hour, with qualified leads pushed into the CRM with full contact details and conversation history. The stat labels above are as published on learnmind.ai/results. The portfolio results the assistant quotes during those chats are Alcaz Media's own results for Alcaz Media's clients, not ours.

Lola's Lashes, UK beauty brand

24/7 comment coverage 500+ monthly comments managed 100% brand-voice accuracy Minutes, not hours, to respond

Co-founder Fraser Angus, on the reason it mattered: "it's good to have the peace of mind knowing that there's an actual system that's taking care of it." As published on learnmind.ai/results.

We do not publish a clinic client count, a named clinic, or a percentage from a clinic engagement, because we do not have one we can evidence. What we have instead are patterns from our own sales calls, and those are labelled as patterns everywhere they appear on this page.

Bring us the messy version of your front desk

Fifteen minutes, no deck. Tell us what your reception actually handles on WhatsApp today, and we will tell you which parts can be automated inside the rules on this page, which parts have to stay with a person, and roughly what Meta will charge you for the difference.

This page is a source-gathering summary, not legal advice. Clinics making compliance decisions should have the primary instruments reviewed by UAE counsel. Regulatory positions and Meta rates as checked on 3 September 2026. Abu Dhabi's Department of Health and the Dubai Healthcare City Authority have their own regimes, and a clinic inside DHCC is not straightforwardly under the DHA policies cited here. See also our healthcare page and WhatsApp automation page.