Looms is designed from the ground up to meet the compliance, privacy, and security requirements of regulated healthcare environments — including DHA, NABIDH, SOC 2 Type II, HIPAA, and GDPR.
From Dubai's national health exchange to global data protection standards — here is how Looms addresses each framework.
Looms is designed to operate in alignment with the Dubai Health Authority's regulatory framework for digital health platforms, supporting healthcare providers operating under DHA jurisdiction.
NABIDH (National Backbone for Integrated Dubai Health) is DHA's Health Information Exchange (HIE) platform. Looms structures its health data to align with NABIDH interoperability standards.
Looms runs on cloud infrastructure that holds SOC 2 Type II certification — independently audited to verify that security, availability, and confidentiality controls are operating continuously.
Looms is designed around the administrative, physical, and technical safeguards required by HIPAA — protecting the confidentiality, integrity, and availability of Protected Health Information (PHI).
Looms applies GDPR principles to all personal data — giving individuals meaningful control over their health information and providing the tools to exercise their data rights.
Compliance isn't a checkbox — it's the architecture. Here are the controls that protect patient data on Looms every day.
Every user, staff member, and administrator has precisely scoped permissions. Patients see only their own data; clinic staff see only their clinic.
Every data access, document issuance, and settings change is logged with a timestamp and actor identity — fully searchable by administrators.
Every issued medical document carries a unique cryptographic signature allowing anyone to verify its authenticity and detect tampering.
Opaque, cryptographically random session tokens with 30-day TTL. Password reset revokes all active sessions simultaneously.
Patients explicitly approve each data-sharing connection with a clinic. Connections can be reviewed and revoked at any time.
Automated uptime checks, error rate monitoring, and anomaly detection run 24/7 with escalation to the on-call engineering team.
Defined playbooks for security events covering detection, containment, notification, and post-incident review within documented timescales.
Medical centers must be reviewed and approved before they can issue verifiable clinical documents — preventing unauthorized certificate generation.
Looms operates with UAE-based data hosting options to meet DHA and NABIDH data residency requirements. Our infrastructure partners maintain data centre presence in the UAE to ensure patient health information stays within the required jurisdiction.
For enterprise deployments requiring specific residency guarantees, contact our compliance team to discuss dedicated hosting arrangements.
We take security vulnerabilities seriously. If you discover a potential security issue in the Looms platform, please report it directly to our security team at security@looms.app. We commit to acknowledging your report within 48 hours and working with you to resolve confirmed issues promptly.
We can provide BAAs, DPAs, security questionnaires, penetration test summaries, and infrastructure audit reports to support your procurement and regulatory process.