A Dubai clinic can run WhatsApp with opted-in patients for booking, reminders, no-show recovery, directions, billing logistics and general enquiries, and on the instruments we could read that is the reasonably safe side of the line. It cannot legitimately run consultations, send test results, or market from patient records without the patient's consent and further DHA permission. The law that governs this is Federal Law No. 2 of 2019 on the use of ICT in the health fields, not HIPAA. Its Article 13 bars health data from services provided inside the UAE from being stored, processed, generated or transferred outside the country, subject to ten narrow exemptions. WhatsApp messaging works normally in the UAE. Voice and video calling over WhatsApp does not.
This page sets out what the primary instruments actually say, where they are silent, and which four clinic workflows survive all of it. Where a fact is contested, unverified or about to change, it says so rather than rounding it into a claim.
Sources checked 3 September 2026. Meta rates were pulled from Meta's own public pricing API for market AE on that date. The DHA policies cited were fetched from dha.gov.ae. Statute text was read from a mirror of the official English translation because the UAE legislation portal blocks automated retrieval, and cross-checked against a law firm alert. This is not legal advice. A clinic making a compliance decision should have the primary instruments reviewed by UAE counsel.
No UAE law and no DHA policy we could find names WhatsApp as permitted or prohibited for clinic use. What the rules govern is what is inside the message and where the data ends up. That makes appointment logistics a materially different and much safer category than clinical content or marketing.
Federal Law No. 2 of 2019 concerning the use of information and communication technology in the areas of health was issued on 6 February 2019 and entered into effect in May 2019. It is the instrument that governs a Dubai clinic's patient data, and almost every vendor page aimed at UAE clinics skips it in favour of a US framework that does not apply here.
Article 2 sets the scope, and the last clause of it is the one operators miss: "This Law shall apply to all methods and uses of the information and communication technology in the areas of health in State, including the free zones." A free-zone clinic is not outside it.
Article 4 sets three duties on anyone using ICT in health: keep health data confidential and do not circulate it outside permitted cases; protect it from unauthorised damage, amendment, alteration, deletion or addition; and keep it available to authorised persons.
Article 16 is the one that bites on marketing. Whoever circulates patient-related information must keep it confidential and must not use it except for health purposes without written approval from the patient. It carves out five cases: insurers and funders verifying entitlements, anonymised scientific and clinical research, preventive or curative public-health measures, requests from competent judicial authorities, and requests from the Health Authority for monitoring and inspection. Marketing is not a health purpose and it is not on that list.
Article 20 sets retention at not less than 25 years from the date of the last health procedure for the person concerned. That is worth knowing before anyone promises a patient that their conversation history will be wiped on request.
| Article | Conduct | Penalty |
|---|---|---|
| 23 | Publishing a health advertisement through the central system without a licence from the Ministry | AED 100,000 to 200,000 |
| 24 | Violating Article 13, the ban on storing, processing, generating or transferring health data outside the State | AED 500,000 to 700,000 |
| 25 | Disciplinary sanctions by the Health Authority against establishments | Notice, warning, AED 1,000 to 1,000,000, licence suspension up to six months, or cancellation |
| 22 | Savings clause | Penalties do not prejudice any more severe penalty under another law |
The AED 500,000 to AED 700,000 band is attached specifically to Article 13, the cross-border storage and processing ban. It is not a general health-data-breach fine and it is not the penalty for sending a patient a message. Any page that implies "message a patient wrongly and you get fined AED 500,000" is false.
Latham & Watkins also noted in its 2019 alert that the law gives no guidance on when stricter penalties will be applied, and does not state whether fines are issued per individual breach. So it should not be modelled as multiplying per message either. And we found no published enforcement actions, fine totals or case examples under Article 24. The penalty is on the books; how often it is applied is not something anyone can show you.
Sources. Article text read from a mirror of the official English translation of Federal Law No. 2 of 2019, cross-checked line by line against the Latham & Watkins client alert of 19 June 2019. The official portal at uaelegislation.gov.ae returned HTTP 403 to every automated fetch, so the government's own site was not read directly in this pass. Cabinet Resolution No. 32 of 2020, the Executive Regulation of this law, is referenced on the MOHAP legislation portal but the host did not respond, so its contents on storage conditions are not reflected here.
HIPAA is United States federal law. A Dubai clinic treating Dubai patients is not a HIPAA covered entity, and no UAE regulator enforces HIPAA. Any vendor telling a Dubai clinic that it "must be HIPAA compliant" as a matter of law is wrong, and the mistake usually travels with a product that was built for a different market.
The correct stack for a Dubai clinic is Federal Law No. 2 of 2019, plus its Executive Regulation (Cabinet Resolution No. 32 of 2020) and Decision No. 51 of 2021, layered with the emirate health authority's own rules. For Dubai, that means the DHA health information governance policies and standards set out further down this page.
The DHA's own Standards for Telehealth Services, Version 4, issued 26 September 2025 and effective 26 November 2025, require at clause 7.6.7(c) that "All platforms must have HIPAA compliance certification", with 7.6.7(d) requiring ISO 27001 and 7.6.7(e) allowing DHA to demand HITRUST or SOC 2 with HIPAA alignment. So in Dubai, HIPAA arrives not as law but as a DHA procurement standard for telehealth platforms. It is a specification a vendor has to meet, not a statute a clinic has to obey.
That is Meta explicitly declining to warrant fitness for healthcare. There is no HIPAA clause and no Business Associate clause anywhere in those Terms.
There is a further sentence, widely quoted across the industry, said to sit in Meta's Cloud API Terms and to state that Meta is not a Business Associate and that Cloud API is not HIPAA compliant. We could not retrieve that page. It is JavaScript-rendered and returned nothing usable to every method attempted. Multiple secondary sources report the same wording, and none of them reproduced it verbatim with a section number when checked. We are not going to quote a clause we could not read. The Business Terms sentence above we did read, and for a clinic's purposes it is enough.
Read that as what it is: a default prohibition, not a transfer-mechanism regime. There is no UAE health-data equivalent of Standard Contractual Clauses. You are either inside the country or inside a listed exemption. That is a materially stricter architecture than the one most international vendors design for.
Decision No. 51 of 2021, dated 28 April 2021, created the exemptions from Article 13. Each carries conditions, and the conditions are where the exemptions get narrow.
| # | Exemption | Principal conditions |
|---|---|---|
| 1 | Patient treated outside the UAE and the information is needed for that treatment | Written approval, shared only with the concerned entity, encrypted |
| 2 | Medical samples sent to laboratories abroad | Written approval, concerned entity only, encrypted |
| 3 | Scientific research approved by the competent health authority | Anonymised, encrypted, highest safety standards, no other use |
| 4 | Information needed by insurance and claims-management companies | Companies operating in the UAE, anonymised, written consent, not fully transferred, encrypted |
| 5 | Organisations cooperating with UAE federal or emirate government | Written approval, encrypted, anonymised, copy kept inside the UAE |
| 6 | Simple consumer devices recording health signs such as blood pressure, blood sugar and oxygen saturation | None specified in the Decision |
| 7 | Pharmacovigilance | Written approval, concerned entity only, encrypted, copy kept inside the UAE |
| 8 | A transfer an emirate health authority approves | Copy kept inside the UAE, no medical secrets disclosed without written patient consent |
| 9 | Information used to provide remote health services | Physician access for a determined duration only, a specific report or image to the concerned physician, patient's written consent |
| 10 | The person requests transfer of their own health information | Written approval, concerned entity or person only, encrypted, copy kept inside the UAE |
Read exemption 10 carefully before anyone builds a sales pitch on it. It is framed as the patient requesting that their own information be transferred, with a copy retained in the UAE and encryption applied. It is not a general "get consent and host anywhere" clause. And nothing in the ten covers routing patient messages through a foreign messaging platform for the clinic's own operational convenience.
The DHA Health Data Protection and Confidentiality Policy at clause 4.15 states that protected health information should not be transferred to a country or territory outside the UAE except within the category of UAE ICT Health Law exemptions, and adds that DHA approval must be granted as per the DHA Health Information Assets Classification Policy. So a clinic in Dubai needs the federal exemption and the emirate approval, not one or the other.
We are not going to tell you where Meta hosts your conversation content, because we did not verify it from Meta's own documentation in this research pass and we are not prepared to assert it. What we will tell you is the question that has to be answered before anything clinical goes near a message: where does the conversation content sit at rest, where is it processed, what leaves the country, and which of the ten exemptions is being relied on. Get the answer in an email you can keep. This is also precisely why the four workflows further down carry booking logistics rather than clinical content: the workflows that carry no health information do not need an exemption at all.
A naming disagreement we are reporting rather than resolving. Latham & Watkins calls the 28 April 2021 instrument "Ministerial Decision No. 51 of 2021". The DHA Telehealth Standards Version 4 also calls it Ministerial. The DHA Health Data Protection and Confidentiality Policy calls it "Cabinet Decision No. (51) of year 2021". DHA's own hosted copy is a scanned PDF that could not be text-extracted. We use "Decision No. 51 of 2021" and do not assert which.
Four DHA instruments matter to a clinic thinking about patient messaging. All four were fetched from dha.gov.ae.
| Reference | Document | Issued | Effective |
|---|---|---|---|
| DHA/HISHD/PP-13 | Policy for Health Data and Information Sharing | 10/08/2024 | 10/11/2024 |
| DHA/HISHD/PP-11 | Health Data Protection and Confidentiality Policy | 10/08/2022 | 10/10/2022 |
| DHA/HISHD/ST-09 | Standards for Health Information Consent and Access Control | 02/01/2025 | 02/04/2025 |
| DHA/HRS/HPSD/ST-14 | Standards for Telehealth Services, Version 4 | 26/09/2025 | 26/11/2025 |
PP-11 carries a discrepancy inside DHA's own document: the cover page states an effective date of 10/10/2022 and the internal footer states 10 November 2022. We report it rather than resolve it.
PP-13 has a named section for sharing protected health information through email (clause 4.10) and a named section for removable media. It has no named section for instant messaging, and no DHA document we read names WhatsApp in a permission or a prohibition. What applies is the general obligation at clause 4.8.4, which requires that all information transfer or sharing in or out of the organisation is protected by appropriate information sharing protocols, and that receipt and transfer of protected health information occurs within the boundaries of UAE laws and DHA regulations.
The email rules at 4.10 are the closest analogue we have. They allow protected health information to be sent by email only "if it is appropriately encrypted or it contains links to Patient data within technology portal that is already protected by an authentication mechanism", only from official entity-issued accounts, never to personal addresses, with manual encryption and "(Encrypt)" in the subject line for domains outside the secure list. Applying those rules to WhatsApp is an inference we are making, not a citation. We say so because a page that dresses that inference as DHA policy is doing a clinic no favours.
WhatsApp is named exactly once in the DHA material read for this page, and not as a channel permission. The DHA Guidelines for Medical Advertisement Content on Social Media (HRS/HPSD/SMA/1/2019) define social media to include "Facebook, Instagram, Twitter, Reddit, Pinterest, Flicker, WhatsApp, YouTube, Snapchat and LinkedIn". That brings promotional WhatsApp content from a DHA-licensed facility inside that guideline. It says nothing about using WhatsApp as a service channel.
Appendix 1, item (p) of the same guideline makes it prohibited to "Provide a patient or client with an unsolicited appointment time that has not been requested by the patient or client."
That is a direct, sourced prohibition on the "Hi, we have booked you in for Tuesday at 3" pattern that appears in a great many automation demos. A reminder for a slot the patient booked is a different thing, and it is fine.
This is the single most commercially important DHA clause for a clinic weighing a WhatsApp campaign. The Health Data Protection and Confidentiality Policy classifies marketing alongside research, audit and public health as a Secondary Use of protected health information:
and, separately in the same policy, that secondary use of identifiable data and health information "needs consent from Subject Data". So under DHA policy, using identifiable patient records to send marketing requires both the patient's consent and further DHA permission. The same policy at 4.10.5 requires that where processing is done on the entity's behalf, the entity uses only processors providing sufficient guarantees of appropriate technical and organisational measures, and 4.10.6 requires written authorisation before a processor engages a sub-processor. A messaging vendor is a processor.
The DHA Telehealth Standards Version 4 define telehealth broadly enough to reach the front desk. The standard states that telehealth services "include but are not limited to scheduling appointments, assessment, providing medical advice, treatment, therapy, laboratory testing, diagnostics, surgery, monitoring chronic conditions, counselling and prescribing and dispensing of medications", and clause 12.2.1 requires physicians to determine and document suitability for telehealth use including "a. Appointment scheduling."
If a clinic's WhatsApp channel is delivering what DHA classifies as a telehealth service, clause 7.6 puts a specification around the platform behind it: assessed and approved by DHA through health facility licensing prior to implementation (7.6.2), legal representation in Dubai with a relevant trade licence (7.6.3), all communication channels approved by the TDRA (7.6.6), data centres at least Tier 3 certified, servers at a cloud provider certified by the Dubai Electronic Security Centre in the UAE, HIPAA compliance certification and ISO 27001 certification (7.6.7).
What follows from that, and what does not. It does not follow that DHA has banned WhatsApp; DHA has not named it either way. What follows is directional and worth stating: the further a clinic's WhatsApp channel drifts from logistics towards clinical content, the harder it becomes to argue it sits outside clause 7.6, and clause 7.6 is a specification that the WhatsApp Cloud API is not documented as meeting. That is a reason to keep the channel on the logistics side of the line, which is exactly what the workflows below do.
Federal Decree-Law No. 45 of 2021, the UAE Personal Data Protection Law, came into force on 2 January 2022. The official text is published in Arabic only. Most vendor content aimed at UAE clinics treats it as the patient data rule. It is not, and the carve-out that says so is short.
Because Federal Law No. 2 of 2019 is legislation regulating the protection and processing of health data, the widely-taken reading is that patient health data in the UAE is governed by Law 2/2019 and the health authority rules, not by the PDPL. DLA Piper's country guide, last modified 27 January 2025, describes exactly this architecture. Item (g) of the same article also excludes companies and establishments located in free zones that have their own special data protection legislation, which is how DIFC, ADGM and Dubai Healthcare City sit outside it.
The practical effect for a clinic. A page that says "clinics must comply with the PDPL" is a simplification. A page that says "the PDPL is the rule for patient data" is wrong. A clinic still holds PDPL-governed personal data: staff, suppliers, and general enquirers who are not yet patients. Its patient data sits under the stricter health regime.
On the enquirer who is not yet a patient, which is a large share of any clinic's WhatsApp inbox.
Article 26 leaves penalties to a Cabinet decision on the proposal of the Director General of the Bureau. The Decree-Law itself specifies no fines. Article 28 required the Executive Regulations to be issued within six months of promulgation, and Article 29 then gives controllers six months from that issuance to regularise.
DLA Piper recorded the Executive Regulations as unpublished as of 6 January 2025 and the Data Office as not yet established. A 2026 practice guide surfaced in search indicates they were still unpublished in February 2026, but we did not read that source directly and we are not going to date-stamp a "still not issued in September 2026" claim we have not verified. Anyone quoting you a PDPL fine schedule should be asked which instrument it comes from.
Penalties that do exist today, reported via DLA Piper rather than read in the underlying instruments: Cyber Crime Law Article 13, detention and a fine of AED 50,000 to AED 500,000 for unlawfully collecting or processing personal data in violation of applicable legislation; and Penal Code Article 432, a minimum of AED 20,000 and up to one year for a professional disclosing secrets without authority.
This is the synthesis of everything above, with the basis for each row named. Where the sources are silent, the row says so.
| Message | Basis and conditions |
|---|---|
| Confirmation of an appointment the patient booked | Transactional, not marketing. No clinical content. Existing relationship, and the patient gave you the number. Still needs WhatsApp opt-in under the Business Messaging Policy. Keep out any diagnosis, treatment name, or department name that reveals a condition. |
| Reminder, reschedule, cancellation | Same basis. Note that DHA's advertising guideline Appendix 1(p) prohibits pushing an unsolicited appointment time the patient did not request. A reminder for a booked slot is not that. A cold "we have scheduled you" is. |
| "Your results are ready, log in to the portal or call the clinic" | Carries no health information itself. Mirrors the pattern DHA permits for email at PP-13 clause 4.10.1, which allows links to patient data inside a technology portal already protected by an authentication mechanism. |
| Directions, opening hours, parking, document checklist, billing logistics | No protected health information and no marketing of a health product. |
| General public-health awareness content not tied to an individual's record | DHA advertising guideline 6.7.1 permits promoting public health information as part of a public health campaign, and 6.7.2 raising awareness of products and services through public health. Still needs Medical Director approval under 5.2 to 5.4. |
| Message | Basis |
|---|---|
| Test results, diagnoses, scan reports, clinical findings | Health information under Law 2/2019. Meta's own policy says do not send or request health related information where regulations demand heightened handling. DHA requires encryption or an authenticated portal for the analogous email case. |
| A remote consultation, triage or clinical advice conversation | That is telehealth. DHA Telehealth Standards V4 clause 7.6 puts a DHA-approved, TDRA-approved, UAE-hosted, ISO 27001 and HIPAA-certified specification around the platform. Meta's Business Messaging Policy says outright: "Don't use WhatsApp for telemedicine." |
| Treatment names that disclose a condition, for example "your IVF cycle", "your oncology follow-up", "your psychiatric review" | The condition is itself health information. Article 16 restricts using patient information other than for health purposes without written approval, and Article 4 requires confidentiality. Practically: the message preview lands on a lock screen a family member may read. |
| Marketing to a list assembled from clinical records | DHA PP-11 makes marketing a Secondary Use of protected health information requiring the patient's consent and further permission from DHA. PDPL Article 17 gives an unconditional right to object to direct marketing where the PDPL applies. |
| Promotional messages with guaranteed outcomes, superlatives, before and after images without a disclaimer, or testimonials without written consent | DHA advertising guideline 6.3, 6.9 and Appendix 2. |
| Cold outbound to purchased or scraped numbers | Meta requires that the person gave you their number and opted in. Cabinet Resolution No. 56 of 2024 requires an opt-in channel and Do Not Call Register screening for telemarketing, and its definition reaches marketing messages sent through social media applications. |
The WhatsApp Business Messaging Policy prohibits using the Business Services for buying, selling, promoting or facilitating the exchange of certain regulated or restricted goods and services, and that list includes "Drugs, whether prescription, recreational, or otherwise" and "Medical and healthcare products". It adds that "These prohibitions apply irrespective of the global or local licenses, registrations, or other approvals your business may hold." A separate section then carves out "Regulated Verticals" in named countries, but the only allowed-country lists published are for online gambling and gaming, over-the-counter drugs, and alcohol. The UAE appears on none of them, and there is no allowed-country list at all for medical and healthcare products. On the free WhatsApp Business App the position is blunter still: "You are prohibited from messaging about any Regulated Verticals on the WhatsApp Business App."
The honest reading: the prohibition is written around products, and Meta enforces it "as determined in our sole discretion" rather than through any published adjudication. A clinic sending an appointment reminder is not plausibly promoting a medical or healthcare product. A clinic blasting a promotion for an IV drip package or a prescription weight-loss programme plausibly is. Meta has not drawn that line. We are drawing it, and telling you that we are.
Meta requires that before you contact anyone, they have given you their mobile number and you have received opt-in permission confirming they wish to receive subsequent messages from you. But its own developer documentation, last updated 16 June 2026, is explicit that the opt-in "can be general and not specifically for WhatsApp, as long as businesses comply with all local laws". The requirements are that you clearly state a person is opting in to receive communication from the business, that you name the business, and that you comply with applicable law. Accepted methods listed by Meta are SMS, website, an IVR flow by phone, and in person or on paper. For a clinic, that means the intake form is a legitimate opt-in surface if it is written properly.
Everything above narrows the field, and what is left is narrower than most automation pitches but considerably more useful than a clinic front desk running on a personal phone. These four carry no health information, need no Article 13 exemption, and sit on the logistics side of the DHA telehealth line.
Sent as utility templates against a slot the patient booked. No clinical content, no treatment name, no department that discloses a condition. The template carries the time, the branch and what to bring.
A missed slot is a logistics event, not a clinical one. The message says the slot was missed and offers to rebook. It never names the treatment, and it never proposes a time the patient did not ask for, which is what DHA Appendix 1(p) prohibits.
The notification carries no health information. The result stays behind authentication. This mirrors the pattern DHA permits for email at PP-13 clause 4.10.1, which allows a link into a technology portal already protected by an authentication mechanism.
The highest-volume, lowest-risk lane, and the one where an assistant earns its keep. Directions, opening hours, parking, what to bring, insurance networks accepted, billing questions, the price of a consultation where the clinic publishes it. Anything clinical routes to a person.
Templates and the window. Business-initiated conversations must use an approved message template, and Meta reserves the right to review, approve, pause and reject any template at any time. You may reply free-form only within 24 hours of the patient's last message. Outside that window, templates only.
Automation is allowed, escalation is mandatory. Meta's Business Messaging Policy states you may use automation when responding during the 24-hour window, but must also have available prompt, clear and direct escalation paths, and it names them: in-chat human agent transfer, a phone number, an email address, web support on the business website, an in-store visit, or a support form. A clinic assistant that cannot hand over to a person is not compliant, and separately it is not usable.
There is a commercial edge in that last point which most vendors do not mention. Meta's own guidance on driving high-quality conversations notes that "the bot functionality and how quickly questions and other enquiries are resolved" can influence a phone number's quality rating. A good assistant is not only a service improvement. It is a deliverability input.
Meta did not ban AI chatbots on WhatsApp. The clause added to the WhatsApp Business Solution Terms, last modified 6 March 2026, is headed "AI Providers" and bars providers and developers of AI technologies from using the Business Solution to distribute their own assistant "when such technologies are the primary (rather than incidental or ancillary) functionality being made available". That is the general-purpose-assistant distribution case. The same clause then says the opposite explicitly: "you may retain an AI Provider as your Third Party Service Provider."
A clinic running an assistant to serve its own patients is a customer of an AI provider, not an AI provider. Nothing in the clause caps how capable the assistant is, and the vendor framing that "open-ended bots are banned and structured bots are fine" does not appear anywhere in the terms. One data constraint does bite, and it is worth putting in a contract: you may fine-tune on your own conversation data only for a model that is for your exclusive use, so pooling clinic conversation data to train a shared model is prohibited.
The handover list is short, and it should be written into the assistant before the first message goes out rather than discovered later.
Two patterns from our own sales calls, offered as what operators say rather than as a study. The first is that Gulf buyers accept AI on text and reject it on the phone, and they say why, unprompted. The second is that the firms most exposed to reputation risk tend to choose full disclosure as their mitigation without being asked to. One operator put it as "we're not gonna trick, we're not gonna hide it". Telling patients they are talking to an assistant, and how to reach a person, costs nothing, and in our own calls it is the condition operators set for themselves before anyone asks them to.
WhatsApp messaging works normally in the UAE. Voice and video calling over WhatsApp does not. TDRA treats voice and video calls as VoIP, a regulated activity that must be provided by a licensed provider or in collaboration with one, and its published guidance states that licensed providers "are obliged to block the traffic of VoIP applications that are not in compliance". WhatsApp does not appear on TDRA's published list of permitted VoIP applications, in either the general or the telehealth category. UAE press reported in February 2026 that WhatsApp calling remained restricted locally even as WhatsApp Web gained calling globally.
On the WhatsApp Business Calling API specifically: Meta's documentation does not exclude the UAE from business-initiated calling. That is a statement about Meta's own platform availability, not about a carrier-level block that sits downstream of Meta entirely. We found no source, primary or secondary, confirming that such a call connects to a consumer on a UAE mobile network, and none confirming that it fails. We treat it as unresolved, we do not sell a workaround, and we build clinic channels on messaging.
Start with the unit, because most quotes get it wrong. Meta charges on a per-message basis, and has done since 1 July 2025. Conversation-based pricing was deprecated on that date. A proposal priced in "conversations per month" is modelling a billing system that no longer exists.
| Category | USD per message | AED per message | Volume tiers |
|---|---|---|---|
| Marketing | 0.0499 | 0.1832 | None. One flat UAE marketing rate. |
| Utility | 0.0157 | 0.0576 | Tier 1 covers 0 to 100,000 per month |
| Authentication | 0.0157 | 0.0576 | Tier 1 covers 0 to 300,000 per month |
| Service | 0 | 0 | Free today. Chargeable from 1 October 2026. |
Three things follow that are worth holding on to.
Today a clinic answering inbound patient enquiries pays Meta nothing for those replies. Non-template messages are free, service messages have been free for all businesses since 1 November 2024, and utility templates delivered inside an open 24-hour customer service window are free.
Meta has published that from 1 October 2026, service messages become chargeable per message at each market's existing utility or authentication rate with no volume tier discounts, and utility messages inside the 24-hour window become chargeable as well. For a service-led clinic account that is the single largest cost change on the horizon, and it lands within weeks of this page being written.
Documentation conflict, reported because it is load-bearing. Meta's main pricing page still says non-template messages and in-window utility templates are free, and does not mention the change. Meta's dedicated upcoming-changes page does. Both are Meta primary sources and they currently disagree. Re-check both before anyone prices a contract on today's free window. We have deliberately not published a UAE service rate for October, because Meta has not published one. It says service will match the market's utility rate, which implies AED 0.0576, but that is arithmetic rather than a rate card line.
Meta's rate is the floor. Every business solution provider adds something, and there are two distinct models. Twilio publishes $0.005 per message on top of Meta's fees, charged on inbound as well as outbound, which matters because Meta does not charge for inbound at all, so a service-heavy clinic account is not free on Twilio. 360dialog publishes a flat €49 per number per month for its Regular plan and states no markup on Meta fees. Those two are cited because both are the vendor's own published price. The flat 20% markups quoted for various other providers in comparison blogs could not be traced to a primary source, so they are not on this page.
One observation from our own sales calls, offered as an observation. In one meeting nobody in the room knew what Meta's per-message fee actually was, and a figure read aloud went uncorrected by either side. When a rate card has moved twice in twelve months, it is worth checking against Meta's own published card rather than a vendor's slide.
Three blocks. The third is operator practice observed in the market, and it is labelled as operator practice because none of it is Meta policy or UAE law.
A tension worth knowing rather than papering over. The definition in Resolution 56/2024 sweeps in social media marketing messages, but the operative obligations in Articles 4 and 5 are written in call language: record the marketing phone call, identify the company at the beginning of the call, call only between 9:00 am and 6:00 pm. How that maps onto a WhatsApp template message is not specified in the text. A cautious clinic treats the opt-in channel and the timing window as applying. It is not settled that they do. Separately, TDRA's Regulatory Policy on Unsolicited Electronic Communications, Version 1.1 of 13 June 2022, bans marketing texts between 9:00 pm and 7:00 am, but on its face that instrument governs SMS and MMS over a public telecommunications network and binds licensees and their messaging subscribers. We found no TDRA statement extending it to over-the-top apps. Two instruments, two different windows, each correct for itself.
None of the following is a rule. It is what operators in this market tell us they do, and each one carries a risk that is worth naming before it is copied.
Messaging limits start at 250, not 1,000. A newly created business portfolio can initiate conversations with 250 unique WhatsApp users per rolling 24 hours. That rises to 2,000 by completing a scaling path, then 10,000, 100,000 and unlimited through automatic scaling. The 1,000-per-day "Tier 1" figure that appears across vendor content is stale.
Per-user marketing limits apply in the UAE. Meta caps how many marketing template messages an individual receives from any business in a given period, based on that person's recent marketing read rate and how full their inbox is. The UAE is not among the markets excluded from this. Separately, WhatsApp gives users an "Offers and announcements" setting that stops your marketing messages entirely; when it is set, the API accepts the request and does not send, returning a failed status your CRM will not otherwise see.
There is no UAE law and no DHA policy that names WhatsApp as permitted or prohibited for clinic use. What the rules govern is the content of the message and the location of the data, not the app. Appointment logistics with an opted-in patient and no clinical content sit in a materially safer category than clinical conversations, results or marketing from patient records. The governing instrument is Federal Law No. 2 of 2019 on the use of ICT in the health fields, and its Article 13 bars health data from services provided inside the UAE from being stored, processed, generated or transferred outside the country outside ten narrow exemptions.
No. HIPAA is United States federal law and no UAE regulator enforces it. The correct analogue is Federal Law No. 2 of 2019, with its Executive Regulation (Cabinet Resolution No. 32 of 2020) and Decision No. 51 of 2021, layered with the Dubai Health Authority's health information governance policies.
HIPAA does reappear in Dubai in one specific place. The DHA Standards for Telehealth Services Version 4, effective 26 November 2025, require at clause 7.6.7(c) that all telehealth platforms hold HIPAA compliance certification, and at 7.6.7(d) ISO 27001. That is a DHA procurement standard for platforms, not a law a clinic is bound by.
By default, no. Article 13 of Federal Law No. 2 of 2019 prohibits storing, processing, generating or transferring health data related to health services provided inside the UAE outside the country, absent a resolution from the Health Authority in coordination with the Ministry. Decision No. 51 of 2021, dated 28 April 2021, created ten exemptions covering overseas treatment, samples sent to laboratories abroad, approved research, insurance, cooperating organisations, consumer health devices, pharmacovigilance, health authority approval, remote medical services and a patient's own request. Most carry conditions of written approval, encryption and a copy retained inside the UAE. None covers routing patient messages through a foreign platform for operational convenience.
Violating Article 13 carries a penalty under Article 24 of not less than AED 500,000 and not more than AED 700,000. That band attaches specifically to Article 13. It is not a general health data breach fine and it is not the penalty for sending a patient a message. In Dubai, the DHA adds a second gate: its confidentiality policy requires DHA approval on top of the federal exemption.
No DHA document read for this page names WhatsApp in a permission or a prohibition. The DHA Policy for Health Data and Information Sharing (DHA/HISHD/PP-13, effective 10 November 2024) has a named section for email and one for removable media, and none for instant messaging. What applies is the general obligation at clause 4.8.4 that all information transfer occurs within the boundaries of UAE laws and DHA regulations, and the email rules at 4.10 are the closest available analogue.
WhatsApp is named once in DHA material, inside the definition of "social media" in the DHA Guidelines for Medical Advertisement Content on Social Media. That brings promotional WhatsApp content from a DHA-licensed facility inside that guideline. It says nothing about using WhatsApp as a service channel.
Send the notification, not the result. A message saying "your results are ready, please log in to the portal or call the clinic" carries no health information and mirrors the pattern the DHA permits for email at PP-13 clause 4.10.1, which allows links to patient data inside a technology portal that is already protected by an authentication mechanism.
The result itself should not go into the message. WhatsApp's own Business Messaging Policy states: "Don't use WhatsApp for telemedicine or to send or request any health related information, if applicable regulations prohibit distribution of such information to systems that do not meet heightened requirements to handle health related information." Meta's Business Terms of Service separately disclaim any warranty that its Business Services meet the needs of entities with heightened confidentiality requirements such as healthcare.
Not from clinical records without two things. The DHA Health Data Protection and Confidentiality Policy classifies marketing as a Secondary Use of protected health information which "should require further permission/approval from DHA" and which separately "needs consent from Subject Data". Federal Law No. 2 of 2019 Article 16 also bars using patient-related information other than for health purposes without the patient's written approval, and marketing is not among the five carve-outs.
On top of that, Meta requires opt-in before any business-initiated message, and Cabinet Resolution No. 56 of 2024, in force 27 August 2024, defines telemarketing to include marketing messages sent through social media applications and requires prior approval, an opt-in channel and Do Not Call Register screening. Promotional content from a DHA-licensed facility must also satisfy the DHA advertisement guideline, including Medical Director approval and the ban on superlatives and guaranteed outcomes.
WhatsApp messaging works normally in the UAE. Voice and video calling over WhatsApp does not. TDRA treats voice and video calls as VoIP, a regulated activity that must be provided by a licensed provider or in collaboration with one, and states that licensed providers are obliged to block the traffic of VoIP applications that are not in compliance. WhatsApp does not appear on TDRA's published list of permitted VoIP applications, in either the general or the telehealth category. UAE press reported in February 2026 that WhatsApp calling remained restricted locally even as WhatsApp Web gained calling globally.
On the WhatsApp Business Calling API specifically, Meta's documentation does not exclude the UAE from business-initiated calling. That is a statement about Meta's platform availability, not about a carrier-level block downstream of Meta. We found no source confirming that such a call connects on a UAE mobile network, and none confirming that it fails. The honest position is that it is unresolved, and a clinic should build on messaging.
No. The clause added to the WhatsApp Business Solution Terms in October 2025, and present in the version last modified 6 March 2026, is headed "AI Providers". It bars providers and developers of AI technologies from using the WhatsApp Business Solution to distribute their own assistant where that assistant is "the primary (rather than incidental or ancillary) functionality being made available". That is the general-purpose-assistant distribution case. The same clause explicitly permits the opposite: "you may retain an AI Provider as your Third Party Service Provider."
A clinic running an assistant for its own patients is the permitted case. The framing that "open-ended bots are banned and structured bots are allowed" is vendor commentary and does not appear in the terms. Meta's separate and older rule still applies: automation is allowed inside the 24-hour customer service window, but the business must offer prompt, clear and direct escalation paths to a human. There is also a data restriction: you may fine-tune on your own conversation data only for a model that is for your exclusive use.
Meta charges per delivered template message and has done since 1 July 2025, when conversation-based pricing was deprecated. As pulled from Meta's own public pricing API on 3 September 2026 for market AE: marketing is AED 0.1832 or $0.0499 per message with no volume tiers for the UAE; utility and authentication are AED 0.0576 or $0.0157 at tier one; service messages are free today. Meta publishes an AED rate card directly, so those AED figures should not be recalculated from the USD ones.
Two changes matter. Meta raised the UAE marketing rate effective 1 October 2025, which is why $0.0385 still appears on stale vendor pages. And Meta has published that from 1 October 2026 service messages, and utility messages inside the 24-hour window, become chargeable at the market's utility rate. Meta's main pricing page and its upcoming-changes page currently disagree about that, so both should be re-checked before pricing a contract on today's free window. A business solution provider fee sits on top: Twilio publishes $0.005 per message including inbound, 360dialog publishes €49 per number per month with no markup on Meta's fees.
We are going to be as careful about our own claims as we have been about everyone else's.
What we can show you publicly are the two named clients published on learnmind.ai/results, both outside healthcare, because the mechanism is the same one a clinic front desk needs.
Every enquiry answered within seconds, at any hour, with qualified leads pushed into the CRM with full contact details and conversation history. The stat labels above are as published on learnmind.ai/results. The portfolio results the assistant quotes during those chats are Alcaz Media's own results for Alcaz Media's clients, not ours.
Co-founder Fraser Angus, on the reason it mattered: "it's good to have the peace of mind knowing that there's an actual system that's taking care of it." As published on learnmind.ai/results.
We do not publish a clinic client count, a named clinic, or a percentage from a clinic engagement, because we do not have one we can evidence. What we have instead are patterns from our own sales calls, and those are labelled as patterns everywhere they appear on this page.
Fifteen minutes, no deck. Tell us what your reception actually handles on WhatsApp today, and we will tell you which parts can be automated inside the rules on this page, which parts have to stay with a person, and roughly what Meta will charge you for the difference.
This page is a source-gathering summary, not legal advice. Clinics making compliance decisions should have the primary instruments reviewed by UAE counsel. Regulatory positions and Meta rates as checked on 3 September 2026. Abu Dhabi's Department of Health and the Dubai Healthcare City Authority have their own regimes, and a clinic inside DHCC is not straightforwardly under the DHA policies cited here. See also our healthcare page and WhatsApp automation page.