Skip to content
TechEdge

Compliance · US and UAE

Compliance designed in from week one.

Rules differ by market, so we plan for yours in discovery: HIPAA for the US, PDPL and ADHICS for the UAE. Here is what that means in the software we build.

United States

HIPAA

For products that create, store or move protected health information (PHI) in the US.

HIPAA Privacy and Security Rules
Administrative, physical and technical safeguards mapped in discovery and built into the product.
BAAs with every vendor
Business associate agreements in place with each vendor that touches PHI, from hosting to messaging.
Encryption at rest and in transit
PHI is encrypted in the database, in backups and on every connection.
Audit logging
Every read and change of patient data is logged with who, what and when.
Role-based access
Each user sees only what their role requires, with access reviewed over time.
Breach response plan
A documented plan for detecting, containing and reporting incidents.

United Arab Emirates

PDPL, health data law and ADHICS

For products that handle personal and health data in the UAE, including Dubai and Abu Dhabi.

PDPL
The UAE Personal Data Protection Law governs how personal data is collected, used and protected.
UAE health data law
Federal Law No. 2 of 2019, including in-country storage of health data.
ADHICS in Abu Dhabi
Abu Dhabi Healthcare Information and Cyber Security Standard controls built into the product.
DHA requirements and Nabidh in Dubai
Dubai Health Authority rules and integration with the Nabidh health information exchange.
Malaffi in Abu Dhabi
Integration with Malaffi, the Abu Dhabi health information exchange.
Arabic language support
Arabic and English from day one, including right-to-left layouts.

In our process

How compliance shows up in our process.

Compliance is not a final audit. It is a gate every release passes: a security scan with patient data checks, then your sign-off in UAT, before anything reaches production.

  1. 01

    Code

    Feature branches, small commits

  2. 02

    Peer review

    Second engineer on every change

  3. 03

    Automated tests

    Unit, integration and API

  4. 04

    Compliance gate

    Security scan

    Dependencies, secrets, patient data checks

  5. 05

    Staging

    Production-like, no real patient data

  6. 06

    Compliance gate

    Your UAT

    You test and sign off

  7. 07

    Production

    Zero-downtime release

This page describes how we build software. It is not legal advice. We work alongside your compliance advisor.

Free MVP audit

Find out what your MVP really needs in 15 minutes.

You leave with a scope, a timeline and a compliance checklist for your market.

TechEdge.
  • Top Rated on Upwork
  • 100% Job Success
  • 7+ years building healthcare software
  • TechEdge (PK) and MedStack LLC (US)