Healthcare · PDPL and NCA

IT and cyber security for organisations that hold health data.

Managed IT, Microsoft 365 governance and cyber security for hospitals, clinics and health-technology firms, where patient data is sensitive and downtime affects care.
Built for healthcare

Patient data is the highest-stakes data you hold

The Saudi PDPL defines health data and genetic data as sensitive data. A breach is reportable to SDAIA within 72 hours, and penalties can reach SAR 5 million. Clinical systems also need to be available when patients are being treated.
Cre8 IT runs the technical controls you own, keeps clinical and administrative systems reliable, and produces the evidence your compliance lead needs.

What healthcare organisations ask us for

What the regulator expects

How we support your obligations

Health organisations answer to several authorities. These are the technical areas that come up most, and what we do for each.

Sensitive data

The PDPL treats health data as sensitive. We limit who can see it, log who did, and protect it on devices and in transit.

Access and identity

Multi-factor authentication, least-privilege roles, prompt removal of leavers and regular access reviews.

Availability

Backup, recovery and tested downtime procedures for the systems clinicians rely on.

Breach readiness

A written, exercised process that gets the facts to your decision-maker inside the 72-hour window.

Suppliers and cloud

Contract terms, incident notification and data return for medical-system suppliers and cloud services.

ECC where in scope

If your organisation is within the NCA’s ECC scope, we map the technical controls to ECC-2:2024 and keep the evidence.
Summary for orientation, checked against the regulators’ published text on 20 September 2026. Confirm the current wording with the regulator. This is not legal advice.

Where we help on data protection

Data protection

PDPL: what IT does and what legal decides

The PDPL is overseen by SDAIA and has been fully enforceable since 14 September 2024. The Implementing Regulations and your sector regulators may set further requirements for health data, so confirm with your compliance lead which apply to you.
Access control, encryption, logging and retention are IT jobs, and we implement them. What data you hold, your lawful basis and your notices are legal decisions.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against PDPL technical measures and, where in scope, ECC-2:2024, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your due diligence.
We will tell you plainly what we can and cannot evidence, including where each service is delivered from.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for healthcare organisations

Sourced to the regulator’s own text, dated and written by a named specialist.
PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
4 min read · Reviewed 20 September 2026
Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
3 min read · Reviewed 20 September 2026
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026
FAQ

Healthcare questions

Is health data special under the Saudi PDPL?

Yes. The PDPL’s definition of sensitive data includes health data and genetic data, so it carries higher risk and stricter handling.

How fast must a breach involving patient data be reported?

According to DLA Piper’s summary of the PDPL, to SDAIA within 72 hours of becoming aware of it, and to affected individuals without undue delay. Your legal adviser decides whether an event must be notified.

Does ECC apply to a private clinic?

Only if it owns, operates or hosts critical national infrastructure or is an affiliated entity of a government agency. The NCA encourages other organisations to use the controls.

Does using Cre8 IT make us PDPL compliant?

No provider can. We build and evidence the technical measures. Your legal adviser or data protection lead owns the legal decisions.

Talk to a specialist about protecting health data

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.