Skip to content
sehaXG

Privacy & security

Better revenue work.
Responsible by design.

Patient trust belongs at the center of healthcare technology. Explore our approach to protecting patient information and putting AI agents to work within Bahrain’s data-protection framework.

Follow the data
Limited access Clear purpose Human oversight
Patient trust

Our principles

Earn trust at every step.

Start with the patient, define the work, and build a clear boundary around what people and agents can do.

Protect the information.

Limit the data an agent receives. Restrict access to the people and services that need it, for an agreed purpose and an appropriate period.

Question the assumptions.

Assess risk before enabling a workflow. Review the model, tools, recipients and failure modes, then verify that the safeguards work.

Keep people accountable.

Give reviewers the evidence and context to make a decision. Make access, approvals and changes understandable to the team responsible for the record.

From information to action

A smaller data footprint.
A clearer chain of responsibility.

Explore three administrative workflows. Each starts with a permitted purpose and ends with an outcome the responsible team can review.

Proposed authorized processing boundaryIllustrative · No patient data
01 / LIMIT THE INPUT

Only what the task needs.

  • Claim reference
  • Payer & permitted identifiers
  • Authorized task
02 / CONSTRAIN THE AGENT

Read the permitted payer channel

Task-specific permissions. Approved tools and recipients. No general access to the patient record.

03 / REVIEW & RECORD

Escalate a mismatch or unexpected request

Status + source + time checked
Why this matters

A routine status check should not receive a complete clinical record. Some payer channels still require patient identifiers; minimize what is sent to each recipient.

An external AI service is a separate data decision.

Before enabling it, review the provider, hosting and support locations, data retention, training terms, subprocessors, and any lawful cross-border transfer route. Hosting the application in Bahrain alone does not settle these questions.

Review before access

Grounded in Bahrain

The framework behind the workflow.

Bahrain’s Personal Data Protection Law and implementing orders govern how identifiable patient information is used. Applying those rules to AI requires a review of the actual task, people, data and recipients.

Sources reviewed 16 September 2026

This is a practical reading of the sources, with proposed design choices shown separately. The Arabic legislation and current regulator requirements should be checked for each deployment.

01 / LEGAL FOUNDATION

Start with a lawful, specific purpose.

Patient health information is sensitive personal data. Define the purpose, the general lawful basis, and the additional sensitive-data condition. Article 5(5) includes necessary healthcare-services management by qualifying professionals or people legally bound to confidentiality; its application to an outsourced AI workflow must be established. A vendor contract alone does not settle that question. Where relying on consent, meet the law’s written, explicit, informed and specific consent requirements.

PDPL · Law 30/2018Order 45/2022 · Sensitive data
02 / LEGAL FOUNDATION

Make responsibility explicit.

Identify who determines the purpose and means of each activity. The hospital will normally be the controller for its RCM records; a service acting on its instructions may be a processor. Article 8 requires appropriate processor safeguards and a written agreement. Define permitted use, confidentiality, recipients and deletion. Check processing notification and prior-authorization triggers separately; authorization is required for specified activities, not simply every use of AI.

PDPL · Law 30/2018Order 44/2022 · Procedures
03 / LEGAL FOUNDATION

Review every route out of the environment.

Assess AI inference, backups, support access, telemetry and onward transfers. Order 42 permits transfers to listed adequate jurisdictions without transfer authorization. Other destinations require an applicable statutory exception or authorization route. An adequate destination does not remove the remaining purpose, confidentiality and security obligations. Agree the actual locations and recipients before enabling any external processing.

Order 42/2022 · Transfers
04 / LEGAL FOUNDATION

Preserve the patient’s ability to act.

Provide understandable notices and a route for access, correction and other applicable rights. Order 80/2025 added structured, machine-readable data access and controller-to-controller transfer where necessary and technically possible. Consent withdrawal and erasure requests must be assessed alongside lawful medical-record retention. Route requests about hospital records through the responsible hospital; do not promise automatic deletion of every record.

Order 48/2022 · Individual rightsOrder 80/2025 · Gazette p. 12
05 / LEGAL FOUNDATION

Keep consequential judgment with people.

Article 22 addresses specified evaluations of a person based solely on automated processing and provides a route to request another method, subject to its conditions. Our proposed workflow uses agents for administrative assistance, with human review of consequential or uncertain actions. An approval button is a safeguard; the underlying processing and disclosure must still be lawful.

PDPL · Law 30/2018
06 / LEGAL FOUNDATION

Build governance around the technology.

Assess the workflow against Order 43’s data-protection impact assessment triggers, including large-scale sensitive-data processing. Bahrain’s Ministry of Justice identified health among the high-risk private sectors required to appoint a data-protection guardian in 2025. Involve the organization’s guardian and responsible clinical, legal and security teams in deployment decisions, vendor review and change control.

Order 43/2022 · SafeguardsMinistry announcement · April 2025
07 / LEGAL FOUNDATION

Plan for records and incidents from the start.

The Private Health Facilities Law requires confidentiality, controlled access and traceable record changes. Set retention by record type and applicable sector duties. Under Order 43, notify the Authority within 72 hours of discovering a breach unless it would not affect individuals’ rights; record the assessment and explain delay. Patient notification follows the Order’s risk-based provisions, including where the Authority requires it.

NHRA · Private Health Facilities LawOrder 43/2022 · Safeguards

Proposed deployment controls

Protection is an ongoing practice.

These are the technical and operational safeguards to implement and validate for a live deployment.

Data throughout its lifecycle

Encrypt stored data and connections. Separate patient identity from task context where practical. Apply record-specific retention, legal holds, controlled exports and verified disposal to primary data and backups.

Access for a defined purpose

Separate hospital workspaces. Use scoped service accounts and role-based permissions. Give a status-checking tool read access only; allow submission tools to use approved destinations and payloads.

Development with safeguards

Review code and dependencies, manage secrets outside prompts, and test permission boundaries. Evaluate agent outputs and prompt-injection resistance using synthetic or appropriately approved data.

Infrastructure you can account for

Review hosting locations, physical-security evidence, provider contracts and subprocessors. Test restoration and continuity. Require approved data-use terms that prevent model training or unrelated reuse of patient information.

Monitoring that explains the action

Record who authorized a task, what evidence was used, which tool acted and the outcome. Keep unnecessary clinical content out of logs. Alert on unexpected access, destinations and repeated failed actions.

People prepared to respond

Train the people handling patient information. Exercise the incident runbook, review access regularly, and test safeguards before rollout and after material changes. Resolve findings with accountable owners.

Before the first live record

A shared readiness review.

  1. 01

    Agree the use case, lawful basis, patient information requirements, controller and processor roles, and any notification or authorization.

  2. 02

    Map the data flow, complete the required risk assessment, and confirm hosting, recipient locations, contracts and transfer arrangements.

  3. 03

    Test access boundaries, agent permissions, human review, audit records and restoration with synthetic data before enabling live records.

  4. 04

    Confirm the accountable owners, retention schedule, patient-rights process and breach runbook; approve a defined initial scope and monitor it.

Start with the right conversation

Let’s design a responsible
workflow for your organization.

Bring your clinical, privacy and technology teams into the conversation. We can work through the data requirements and safeguards together.

Request a demoFor privacy enquiries, contact husainaltaraif@gmail.com. Please keep patient records out of general enquiry emails. The demo form prepares an email draft; you choose whether to send it.