Trust & Compliance

Built for regulated healthcare

Looms is designed from the ground up to meet the compliance, privacy, and security requirements of regulated healthcare environments — including DHA, NABIDH, SOC 2 Type II, HIPAA, and GDPR.

DHA Ready
NABIDH Aligned
SOC 2 Type II
HIPAA Aligned
GDPR Ready

Compliance frameworks

From Dubai's national health exchange to global data protection standards — here is how Looms addresses each framework.

DHA Ready

Dubai Health Authority (DHA) Alignment

Looms is designed to operate in alignment with the Dubai Health Authority's regulatory framework for digital health platforms, supporting healthcare providers operating under DHA jurisdiction.

  • Role-based access control and least-privilege data access per DHA information governance requirements
  • Comprehensive audit logging of all clinical data access, modifications, and sharing events
  • Patient consent management with granular, revocable permissions for data sharing
  • Secure data residency options to support UAE-based storage requirements
  • Electronic health record structures aligned with DHA-endorsed standards
  • Provider credentialing and verified-issuer controls before any medical document issuance
NABIDH Aligned

NABIDH-Compatible Data Exchange

NABIDH (National Backbone for Integrated Dubai Health) is DHA's Health Information Exchange (HIE) platform. Looms structures its health data to align with NABIDH interoperability standards.

  • Patient health records structured around HL7 FHIR-compatible data models for interoperability
  • Standardised clinical terminology including ICD-10 codes for diagnoses and procedures
  • Secure, tokenised document sharing designed to integrate with NABIDH-connected facilities
  • Patient identity matching and record linkage mechanisms aligned with Emirates ID
  • Encrypted data exchange channels meeting NABIDH security requirements
  • Audit trails for all cross-facility data sharing events
SOC 2 Type II

SOC 2 Type II Certified Infrastructure

Looms runs on cloud infrastructure that holds SOC 2 Type II certification — independently audited to verify that security, availability, and confidentiality controls are operating continuously.

  • Infrastructure hosted on SOC 2 Type II certified cloud providers with annual third-party audits
  • AES-256 encryption for all data at rest; TLS 1.2+ enforced for all data in transit
  • Continuous infrastructure monitoring with automated threat detection and alerting
  • Documented incident response procedures with defined recovery time objectives
  • Logical access controls, multi-factor authentication, and privileged access management
  • Regular vulnerability scanning, penetration testing, and patch management
HIPAA Aligned

HIPAA Privacy & Security Rule Alignment

Looms is designed around the administrative, physical, and technical safeguards required by HIPAA — protecting the confidentiality, integrity, and availability of Protected Health Information (PHI).

  • Business Associate Agreements (BAAs) available for covered entities
  • Minimum necessary standard applied to all PHI access and sharing
  • Workforce security policies, training requirements, and access termination procedures
  • Automatic session timeouts and multi-factor authentication for all accounts
  • PHI stored in encrypted form with documented backup and recovery procedures
GDPR Ready

GDPR & Data Subject Rights

Looms applies GDPR principles to all personal data — giving individuals meaningful control over their health information and providing the tools to exercise their data rights.

  • Data Processing Agreements (DPAs) available for EU-based organizations
  • Explicit, granular consent collected at point of data use with easy withdrawal
  • Right of access, rectification, erasure, and portability for all users
  • Data minimisation — only the data needed for the stated purpose is collected
  • Clear retention schedules with automated deletion workflows where applicable
Platform controls

Security built into every layer

Compliance isn't a checkbox — it's the architecture. Here are the controls that protect patient data on Looms every day.

Role-based access

Every user, staff member, and administrator has precisely scoped permissions. Patients see only their own data; clinic staff see only their clinic.

Full audit trail

Every data access, document issuance, and settings change is logged with a timestamp and actor identity — fully searchable by administrators.

Cryptographic document signing

Every issued medical document carries a unique cryptographic signature allowing anyone to verify its authenticity and detect tampering.

Session & token security

Opaque, cryptographically random session tokens with 30-day TTL. Password reset revokes all active sessions simultaneously.

Consent management

Patients explicitly approve each data-sharing connection with a clinic. Connections can be reviewed and revoked at any time.

Continuous monitoring

Automated uptime checks, error rate monitoring, and anomaly detection run 24/7 with escalation to the on-call engineering team.

Incident response

Defined playbooks for security events covering detection, containment, notification, and post-incident review within documented timescales.

Verified issuer controls

Medical centers must be reviewed and approved before they can issue verifiable clinical documents — preventing unauthorized certificate generation.

UAE Data Residency

Looms operates with UAE-based data hosting options to meet DHA and NABIDH data residency requirements. Our infrastructure partners maintain data centre presence in the UAE to ensure patient health information stays within the required jurisdiction.

For enterprise deployments requiring specific residency guarantees, contact our compliance team to discuss dedicated hosting arrangements.

Security disclosure

Responsible disclosure

We take security vulnerabilities seriously. If you discover a potential security issue in the Looms platform, please report it directly to our security team at security@looms.app. We commit to acknowledging your report within 48 hours and working with you to resolve confirmed issues promptly.

Need compliance documentation?

We can provide BAAs, DPAs, security questionnaires, penetration test summaries, and infrastructure audit reports to support your procurement and regulatory process.