Why Companies in Saudi Arabia and Bahrain Can No Longer Delay Document Digitization

April 2, 2026

PDPL Enforcement Has Arrived: Building a Defensible Records Retention and Destruction Program

July 21, 2026

Patient Records in the NPHIES Era: A Governance Roadmap for Saudi Healthcare Providers

July 15, 2026

Saudi Arabia’s health sector is completing one of the most ambitious digital transitions anywhere in the world. The National Platform for Health and Insurance Exchange Services (NPHIES), introduced by the Council of Health Insurance and the National Health Information Center, now connects providers, insurers, and third-party administrators through a single, standards-based exchange, and works toward a unified digital health record for everyone in the Kingdom. The Seha Virtual Hospital supports more than 240 hospitals, and the Sehhaty application has passed 31 million users, according to figures reported through the Health Sector Transformation Program.

For hospital leadership, this is more than an IT milestone. It changes what a “patient record” is, who is accountable for it, and what happens when it is managed badly. And it exposes a problem that most healthcare organizations in the Kingdom still carry: decades of paper files, mixed-format archives, and departmental record-keeping habits that were designed for a different era.

The regulatory picture has hardened

Three developments define the current environment for health records in Saudi Arabia.

First, NPHIES participation is not optional. Providers and insurers exchange claims and clinical information through the platform using standardized formats, and the Council of Health Insurance regulates thousands of provider organizations within that ecosystem. A hospital whose historical records exist only on paper, or in unindexed scanned images, cannot feed accurate longitudinal information into digital workflows — and inaccurate or incomplete records ripple into claim rejections, delayed authorizations, and clinical risk.

Second, the Personal Data Protection Law (PDPL) treats health data as sensitive personal data. The PDPL has been in force since 14 September 2023, and the compliance grace period ended on 14 September 2024. The law requires a lawful basis for processing, limits retention to what a defined purpose requires, and obliges organizations to apply technical and organizational safeguards proportionate to risk. Breaches that may harm data subjects must be reported to the regulator, SDAIA, within 72 hours. Penalties can reach SAR 5 million per violation, and unlawful disclosure of sensitive data can carry criminal consequences. SDAIA’s enforcement committees issued 48 violation decisions in their first full enforcement cycle — a clear signal that documentation and evidence now matter more than intentions.

Third, cybersecurity expectations have risen. The National Cybersecurity Authority’s updated Essential Cybersecurity Controls (ECC-2:2024) sharpened requirements around third-party arrangements, cloud services, and operational resilience. Healthcare sits squarely within the Kingdom’s critical sectors, and even providers not directly mandated to comply increasingly find ECC-aligned controls appearing in insurer, partner, and government due-diligence questionnaires.

Together, these developments mean a hospital’s records function is now a regulated, auditable capability — not a storage room.

Where healthcare records programs typically break down

In our experience across the Saudi market, the weak points are consistent:

Legacy paper archives with no reliable index. Files exist, but locating a specific episode of care takes hours or days. Retrieval delays affect continuity of care, medico-legal responses, and insurance disputes.

Uncontrolled duplication. The same patient information lives in departmental copies, physician files, and central archives, making it impossible to say with confidence what the organization actually holds — a direct problem under the PDPL’s data-minimization principle.

No defensible retention and destruction practice. Records are kept indefinitely “to be safe.” Under the PDPL, retaining personal data without a continuing purpose is itself a compliance risk, while destroying records without documented authorization and chain of custody creates legal exposure in the other direction.

Digitization projects that stall. Scanning is the easy part. Projects fail on document preparation, indexing quality, metadata standards, and integration with hospital information systems — which is why many organizations end up with terabytes of unsearchable images.

A practical roadmap

A credible patient-records governance program in the Kingdom typically moves through five stages.

1. Inventory and classify. Establish what records exist, where, in what condition, and under which department’s ownership. Classify by record type, sensitivity, and operational value. This inventory becomes the foundation for both PDPL records-of-processing documentation and digitization planning.

2. Set retention rules before scanning anything. Define retention periods per record category based on applicable health-sector requirements, medico-legal considerations, and the PDPL’s purpose-limitation principle, with sign-off from legal and clinical leadership. Digitizing records you should be destroying wastes budget; destroying records you must keep creates liability.

3. Digitize with indexing discipline. Prioritize active and semi-active patient files whose absence from digital workflows creates daily friction. Insist on defined image-quality standards, double-verified indexing against patient identifiers, and structured metadata that your HIS and downstream systems can consume.

4. Move inactive records to secure, compliant offsite storage. Records that must be kept but are rarely accessed do not belong in expensive clinical real estate. Purpose-built records centres with fire suppression, environmental controls, access logging, and audited retrieval provide better protection at lower cost — and produce the evidence trail regulators and accreditors expect.

5. Destroy defensibly. When retention periods expire, destruction should follow documented authorization, secure handling, and certified destruction with chain-of-custody records. A certificate of destruction is not paperwork; it is the artifact that answers an auditor’s or regulator’s question years later.

Governance is the differentiator

Technology and logistics matter, but the organizations that navigate this transition well share something else: clear accountability. A named owner for records governance, a policy approved at executive level, a processor agreement with every external partner that handles patient data, and periodic audits that test whether practice matches policy. Under the PDPL, controllers remain accountable for the personal data their vendors process — which means choosing partners who can demonstrate their own controls, certifications, and Saudi-market regulatory fluency is part of your compliance posture, not separate from it.

The Kingdom’s health transformation is creating a system where information moves as fast as patients do. Providers who treat their records archive as a governed asset will find NPHIES integration, accreditation cycles, and PDPL obligations far easier to satisfy — and will spend less doing it.

Put your records program on solid ground

Tejoury has supported Saudi healthcare organizations, government entities, and enterprises with records management, digitization, secure storage, and certified destruction since 2007, operating purpose-built records centres across the Kingdom. If your organization is preparing patient archives for the digital health era, our team can assess your current state and map a compliant, practical path forward.

Request a healthcare records assessment — schedule a call with Tejoury today.

This article provides general information, not legal advice. Organizations should consult qualified counsel on their specific regulatory obligations.

Related

Schedule a call with us!








    Thank you for considering Tejoury Patient Records in the NPHIES Era: A Governance Roadmap for Saudi Healthcare Providers. We are excited about the possibility of working with you and addressing your requirements. Our team is prepared to reach out to you at your preferred time for a meaningful conversation about how we can assist you.

    Schedule a call with us!








      Thank you for considering Tejoury. We are excited about the possibility of working with you and addressing your requirements. Our team is prepared to reach out to you at your preferred time for a meaningful conversation about how we can assist you.