DHA Compliance
Overview
RepHigh is built around Dubai Health Authority (DHA) regulations, UAE Federal Decree-Law No. 45 of 2021 (PDPL), and the NABIDH Data Privacy Framework. This page sets out how we support each requirement — and, where a requirement sits with your clinic rather than with us, says so plainly.
DHA Health Data Quality Policy
Effective November 1, 2023, DHA mandates strict standards for health data accuracy, completeness, security, and retention. RepHigh complies by:
- Retaining patient communication logs for 25 years per DHA mandate
- Maintaining consent records for the full retention period
- Encrypting data at rest and in transit
- Isolating every clinic’s data at the database level
- Storing no medical diagnoses, prescriptions, test results, or insurance data
On data residency: RepHigh is operated from India and patient data is currently hosted outside the UAE. Clinics are the Data Controller and should confirm this is acceptable for their practice before uploading records. Full detail is in our Privacy Policy.
NABIDH Framework
RepHigh's data handling (encryption, UAE residency, access controls, and retention) is designed to be NABIDH-compatible. RepHigh does not connect to NABIDH directly; clinics maintain their own NABIDH registration. We require proof of active NABIDH registration (where applicable) before onboarding.
Patient Data Protection
What We Process
- Patient first name, WhatsApp number, appointment details
- Message delivery status and engagement data
- Last visit date for reactivation workflows
What We Never Process
- Medical diagnoses, conditions, or clinical notes
- Prescription details or medication information
- Test results or health metrics
- Financial or insurance information
- Biometric data
Consent Requirements
Clinics using RepHigh must obtain explicit, documented patient consent before adding any patient to a workflow. Required consent elements include:
- Clear identification of the clinic as data controller
- Identification of RepHigh as data processor
- Specific description of communication types
- WhatsApp as the communication channel
- Right to withdraw consent at any time
- Active opt-in checkbox (unchecked by default)
- Separate consent for utility vs. marketing messages
WhatsApp Business API Compliance
All message templates are pre-approved by Meta, contain only logistics information, do not contain medical advice, include opt-out instructions, and are sent only to patients who have provided explicit consent.
Data Breach Protocol
- Investigation and containment within 24 hours
- Initial notification to affected clinics within 24 hours
- Full notification within 72 hours
- UAE Data Office and DHA notified as required by law
- Clinics provided with all information needed for patient notification
Security Infrastructure
- Encryption at rest and TLS in transit
- Role-based access control (RBAC)
- Row-level security — no clinic can read another clinic’s data
- Application-layer encryption of stored third-party credentials
- An audit log of every message sent, with the consent record behind it
- A named data protection contact: support@rephigh.com
Important Limitation
RepHigh is a communication and workflow platform. We do not provide medical advice, clinical services, or telehealth. All clinical decisions remain with DHA-licensed healthcare professionals.
Contact
Data Protection Contact
RepHigh, Gurugram, Haryana, India
Email: support@rephigh.com
For urgent data breach notifications: support@rephigh.com (24/7 monitored)
