Agents 17 August 2026 9 min read

AI receptionists for UAE clinics: what DHA and DoH rules allow

An AI receptionist can book appointments, send reminders and handle intake for a UAE clinic — but health data changes the rules. Here is what DHA, DoH and the PDPL allow, and where the hard boundaries are.

Reception is the busiest and most interrupted role in any clinic, and most of what it handles is not clinical — it is scheduling. Booking, rescheduling, reminders, “what do I need to bring”, “do you take my insurance”. That is exactly the kind of high-volume, rules-based work an AI receptionist does well.

But a clinic is not a restaurant. The moment health data is involved, the rules change — and in the UAE they change in two directions at once. This piece explains what is allowed, what is not, and why the sequence matters.

It is informational, not legal or clinical advice.

What an AI receptionist can genuinely do for a clinic

The safe, high-value work sits firmly on the administrative side:

  • Book, reschedule and cancel appointments against your practice-management system, respecting each clinician’s availability and appointment types.
  • Send reminders and confirmations at the intervals that actually reduce no-shows, with one-tap reschedule — and automatically offer the freed slot to the next patient.
  • Collect structured pre-visit intake — the administrative and history information you need before the appointment, written straight into the record so nothing is re-keyed.
  • Answer strictly administrative questions — opening hours, location, parking, what to bring, insurance accepted, preparation instructions you have already published.

All of it in English and Arabic, around the clock, without a patient hitting voicemail at 8pm.

Done well, this does not replace your reception team — it removes the calls they should not be taking, so they can give more time to the patient in front of them.

The two layers of rules

Here is what makes healthcare different. A patient-facing agent in the UAE sits under two regimes simultaneously:

A data-protection regime — determined by where your clinic is registered:

  • Onshore (mainland) clinics fall under the federal PDPL (full compliance by 1 January 2027), and Ministry of Health and Prevention (MOHAP) requirements where they apply.
  • A DIFC or ADGM entity falls under that free zone’s regime instead.

A health regulator — determined by the emirate:

  • DHA (Dubai Health Authority) for clinics in Dubai.
  • DoH (Department of Health – Abu Dhabi, formerly HAAD) for Abu Dhabi.

Both apply. You comply with your data-protection regime and your health regulator’s rules on patient data. This is not a reason to avoid an AI receptionist — plenty of clinics run them compliantly — but it is the reason the design has to start from the rules rather than from the technology.

The hard boundaries

Some things an AI receptionist must never do, and we build these as enforced guardrails outside the model, not as polite suggestions in a prompt:

  • No clinical advice, ever. The agent does not triage, diagnose, interpret symptoms or advise on medication. Any clinical question is an immediate, unconditional handover to a person.
  • Emergencies bypass everything. If a caller’s language suggests urgency, the agent instructs them to contact emergency services immediately and hands over. This path is tested harder than any other.
  • Data governance is agreed first. Before any build, we settle what data the agent may see, where it is processed, how long it is retained and who can access it — aligned to your regime and regulator.
  • Consent and disclosure. Patients are told at the start of the call that they are speaking to an automated system and how their information will be used.

These are not limitations that make the product weaker. They are what makes it deployable in a clinic at all.

Why we start with governance, not the build

With most businesses we can move quickly to building. With a clinic we deliberately do not, and it is worth understanding why.

The combination of a data-protection regime and a health regulator genuinely constrains what can be built and where data can flow. If we discovered a blocking constraint in week six — a data-residency requirement, a retention rule, an integration that cannot be made compliant — that is an expensive and demoralising place to find it. Establishing the rules in the first fortnight is faster overall, and it means everything built afterwards is built on solid ground.

So a clinic engagement runs governance first, then the reminder and confirmation flows (lowest clinical risk, fastest effect on utilisation), then booking, then intake — each step proven on live traffic before the next.

What it changes in practice

Clinics that get this right see the same pattern: no more lost after-hours calls, a measurable drop in no-shows once rescheduling is made frictionless, reception freed from the phone, and patients served in their own language. The utilisation you recover from filling cancelled slots alone often pays for the system.


If you run a clinic in the UAE and want to know what is possible within your regulator’s rules, start with the governance-first approach or read how we work with clinics and healthcare providers. A 30-minute call is free, and we will tell you plainly what can and cannot be done for your setup.

Written by the Altus delivery team. We publish what we learn on real engagements, including the findings that do not flatter us.

Want this applied to your operation?

The readiness call is thirty minutes and free. Bring your numbers and we will work through them with you.