Protect the information.
Limit the data an agent receives. Restrict access to the people and services that need it, for an agreed purpose and an appropriate period.
Privacy & security
Patient trust belongs at the center of healthcare technology. Explore our approach to protecting patient information and putting AI agents to work within Bahrain’s data-protection framework.
Follow the dataOur principles
Start with the patient, define the work, and build a clear boundary around what people and agents can do.
Limit the data an agent receives. Restrict access to the people and services that need it, for an agreed purpose and an appropriate period.
Assess risk before enabling a workflow. Review the model, tools, recipients and failure modes, then verify that the safeguards work.
Give reviewers the evidence and context to make a decision. Make access, approvals and changes understandable to the team responsible for the record.
From information to action
Explore three administrative workflows. Each starts with a permitted purpose and ends with an outcome the responsible team can review.
Task-specific permissions. Approved tools and recipients. No general access to the patient record.
A routine status check should not receive a complete clinical record. Some payer channels still require patient identifiers; minimize what is sent to each recipient.
Before enabling it, review the provider, hosting and support locations, data retention, training terms, subprocessors, and any lawful cross-border transfer route. Hosting the application in Bahrain alone does not settle these questions.
Grounded in Bahrain
Bahrain’s Personal Data Protection Law and implementing orders govern how identifiable patient information is used. Applying those rules to AI requires a review of the actual task, people, data and recipients.
Sources reviewed 16 September 2026This is a practical reading of the sources, with proposed design choices shown separately. The Arabic legislation and current regulator requirements should be checked for each deployment.
Patient health information is sensitive personal data. Define the purpose, the general lawful basis, and the additional sensitive-data condition. Article 5(5) includes necessary healthcare-services management by qualifying professionals or people legally bound to confidentiality; its application to an outsourced AI workflow must be established. A vendor contract alone does not settle that question. Where relying on consent, meet the law’s written, explicit, informed and specific consent requirements.
PDPL · Law 30/2018Order 45/2022 · Sensitive dataIdentify who determines the purpose and means of each activity. The hospital will normally be the controller for its RCM records; a service acting on its instructions may be a processor. Article 8 requires appropriate processor safeguards and a written agreement. Define permitted use, confidentiality, recipients and deletion. Check processing notification and prior-authorization triggers separately; authorization is required for specified activities, not simply every use of AI.
PDPL · Law 30/2018Order 44/2022 · ProceduresAssess AI inference, backups, support access, telemetry and onward transfers. Order 42 permits transfers to listed adequate jurisdictions without transfer authorization. Other destinations require an applicable statutory exception or authorization route. An adequate destination does not remove the remaining purpose, confidentiality and security obligations. Agree the actual locations and recipients before enabling any external processing.
Order 42/2022 · TransfersProvide understandable notices and a route for access, correction and other applicable rights. Order 80/2025 added structured, machine-readable data access and controller-to-controller transfer where necessary and technically possible. Consent withdrawal and erasure requests must be assessed alongside lawful medical-record retention. Route requests about hospital records through the responsible hospital; do not promise automatic deletion of every record.
Order 48/2022 · Individual rightsOrder 80/2025 · Gazette p. 12Article 22 addresses specified evaluations of a person based solely on automated processing and provides a route to request another method, subject to its conditions. Our proposed workflow uses agents for administrative assistance, with human review of consequential or uncertain actions. An approval button is a safeguard; the underlying processing and disclosure must still be lawful.
PDPL · Law 30/2018Assess the workflow against Order 43’s data-protection impact assessment triggers, including large-scale sensitive-data processing. Bahrain’s Ministry of Justice identified health among the high-risk private sectors required to appoint a data-protection guardian in 2025. Involve the organization’s guardian and responsible clinical, legal and security teams in deployment decisions, vendor review and change control.
Order 43/2022 · SafeguardsMinistry announcement · April 2025The Private Health Facilities Law requires confidentiality, controlled access and traceable record changes. Set retention by record type and applicable sector duties. Under Order 43, notify the Authority within 72 hours of discovering a breach unless it would not affect individuals’ rights; record the assessment and explain delay. Patient notification follows the Order’s risk-based provisions, including where the Authority requires it.
NHRA · Private Health Facilities LawOrder 43/2022 · SafeguardsProposed deployment controls
These are the technical and operational safeguards to implement and validate for a live deployment.
Encrypt stored data and connections. Separate patient identity from task context where practical. Apply record-specific retention, legal holds, controlled exports and verified disposal to primary data and backups.
Separate hospital workspaces. Use scoped service accounts and role-based permissions. Give a status-checking tool read access only; allow submission tools to use approved destinations and payloads.
Review code and dependencies, manage secrets outside prompts, and test permission boundaries. Evaluate agent outputs and prompt-injection resistance using synthetic or appropriately approved data.
Review hosting locations, physical-security evidence, provider contracts and subprocessors. Test restoration and continuity. Require approved data-use terms that prevent model training or unrelated reuse of patient information.
Record who authorized a task, what evidence was used, which tool acted and the outcome. Keep unnecessary clinical content out of logs. Alert on unexpected access, destinations and repeated failed actions.
Train the people handling patient information. Exercise the incident runbook, review access regularly, and test safeguards before rollout and after material changes. Resolve findings with accountable owners.
Before the first live record
Agree the use case, lawful basis, patient information requirements, controller and processor roles, and any notification or authorization.
Map the data flow, complete the required risk assessment, and confirm hosting, recipient locations, contracts and transfer arrangements.
Test access boundaries, agent permissions, human review, audit records and restoration with synthetic data before enabling live records.
Confirm the accountable owners, retention schedule, patient-rights process and breach runbook; approve a defined initial scope and monitor it.
Start with the right conversation
Bring your clinical, privacy and technology teams into the conversation. We can work through the data requirements and safeguards together.
Request a demoFor privacy enquiries, contact husainaltaraif@gmail.com. Please keep patient records out of general enquiry emails. The demo form prepares an email draft; you choose whether to send it.