Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

HIPAA Compliance Kuwait | Healthcare Data Privacy

HIPAA compliance in Kuwait covering healthcare data privacy, CITRA requirements, medical confidentiality, assessment, cost, telemedicine and readiness.

  1. Home
  2. Knowledge Centre
  3. HIPAA Compliance Kuwait | Healthcare Data Privacy

HIPAA Compliance in Kuwait – Healthcare Data Protection, Privacy & Assessment

HIPAA Compliance in Kuwait – Healthcare Data Protection, Privacy & Assessment
HIPAA compliance in Kuwait for hospitals, clinics, telemedicine, health-tech and healthcare IT organizations, with a focus on Kuwait privacy, CITRA and medical confidentiality.

HIPAA Compliance in Kuwait – Healthcare Data Protection, Privacy & Assessment

http://www.scscertification.com/contactus.php

Healthcare organizations in Kuwait are handling more information electronically than ever before. Hospitals, clinics, laboratories, pharmacies, telemedicine providers, healthcare software companies and health-tech businesses may collect, store, process or exchange sensitive patient information through digital systems.

For organizations working with U.S. healthcare customers, HIPAA can become an additional business and compliance requirement. However, HIPAA is not the only consideration for a Kuwait organization.

Kuwait has its own privacy, electronic-transactions and healthcare confidentiality requirements. CITRA's current Data Privacy Protection Regulation was issued under Resolution No. 26/2024, which replaced the earlier regulation issued under Resolution No. 42/2021.

Kuwait Law No. 20 of 2014 concerning Electronic Transactions also contains privacy and data-protection provisions. Article 32 specifically addresses personal information relating to health status and restricts unlawful access, disclosure or publication.

Kuwait Law No. 70 of 2020 concerning the practice of the medical profession and supporting professions contains additional requirements concerning patient confidentiality, medical records, privacy and remote healthcare.

This makes the Kuwait market different from simply applying a generic HIPAA checklist.

For a Kuwait organization, the better approach is to understand when HIPAA applies, what Kuwait requirements apply, how healthcare information is protected and what evidence international customers may expect.

What HIPAA Compliance Means for a Kuwait Organization

HIPAA is a U.S. federal healthcare privacy and security framework. It does not automatically apply to every healthcare organization outside the United States.

A Kuwait organization may encounter HIPAA requirements when it provides services to a U.S. healthcare organization or operates in a relationship where HIPAA requirements apply.

Examples can include:

  • Healthcare software providers
  • Cloud and hosting providers
  • Healthcare IT companies
  • Telemedicine platforms
  • Healthcare BPO providers
  • Data-processing companies
  • Health-tech businesses
  • Other service providers handling protected health information

The first step is therefore to establish whether HIPAA actually applies to the organization and what role it performs.

Is HIPAA Certification Required in Kuwait?

The term "HIPAA certification" is widely used in the market, but HIPAA should not be treated as an ISO management-system standard with one universal certification issued by the U.S. Department of Health and Human Services.

Organizations may instead require services such as:

  • HIPAA compliance assessment
  • HIPAA readiness assessment
  • HIPAA gap assessment
  • HIPAA risk assessment
  • HIPAA compliance review
  • Customer-specific HIPAA assessment
  • Independent assessment
  • Compliance evidence preparation

The appropriate service depends on the organization's business relationship, systems, information and customer requirements.

This distinction is particularly important for Kuwait companies searching for "HIPAA certification Kuwait."

Why HIPAA and Kuwait Privacy Should Be Considered Together

A Kuwait healthcare organization may have two different sets of obligations to consider.

The first is the organization's Kuwait legal and regulatory environment.

The second is any international or contractual requirement, including HIPAA where applicable.

These requirements are not interchangeable.

A Kuwait organization may therefore need to consider:

  • CITRA privacy requirements
  • Healthcare confidentiality
  • Electronic information requirements
  • Patient-record obligations
  • HIPAA requirements where applicable
  • Customer contracts
  • Supplier requirements
  • Information-security controls

The objective should be a practical compliance structure rather than separate disconnected programmes.

Kuwait CITRA Data Privacy Protection Regulation

CITRA issued Resolution No. 26/2024 adopting a Data Privacy Protection Regulation. The decision states that the previous Data Privacy Protection Regulation issued under Resolution No. 42/2021 and its amendments was cancelled.

For Kuwait organizations processing personal information, this makes the current CITRA framework an important part of privacy planning.

Healthcare organizations should consider how personal information is:

  • Collected
  • Used
  • Processed
  • Stored
  • Accessed
  • Transferred
  • Protected
  • Retained
  • Deleted

The organization should also identify who is responsible for information processing and how privacy responsibilities are communicated.

Kuwait Law No. 20 of 2014 and Healthcare Information

Kuwait Law No. 20 of 2014 concerning Electronic Transactions includes a chapter addressing privacy and data protection.

Article 32 states that specified entities and their employees must not unlawfully access, disclose or publish personal data or information held in electronic processing systems, including information relating to health status. It also addresses the purpose of collecting such information.

For healthcare organizations, this is particularly relevant because medical information increasingly exists in electronic systems.

An assessment should therefore look beyond the existence of a privacy policy and examine how patient information is actually handled.

Medical Confidentiality Under Kuwait Law No. 70 of 2020

Kuwait Law No. 70 of 2020 contains specific requirements concerning patient confidentiality.

Article 13 prohibits healthcare professionals from disclosing patient secrets except in circumstances permitted by law. The provision also extends the confidentiality obligation to people working in relevant healthcare establishments or other entities who become aware of the information.

The law also addresses patient records.

Article 28 requires healthcare establishments to maintain patient files containing information relating to the patient's health condition, examinations, diagnoses, treatment and other relevant information.

This creates a strong Kuwait-specific connection between healthcare operations, medical confidentiality and information protection.

HIPAA and Telemedicine in Kuwait

Kuwait's Law No. 70 of 2020 expressly provides for medical and healthcare services to be delivered remotely and allows the use of artificial intelligence, advanced technologies, communications and digital and electronic media subject to requirements and controls established by the Ministry.

For telemedicine organizations, privacy and security therefore become practical operational issues.

A review may consider:

  • Patient identification
  • User authentication
  • Secure communication
  • Electronic medical records
  • Access permissions
  • Video consultation platforms
  • Data transmission
  • Cloud services
  • Mobile applications
  • Third-party technology
  • Incident response
  • Patient confidentiality

Where HIPAA applies, the relevant U.S. requirements should be mapped separately.

HIPAA Requirements for Kuwait Hospitals

Hospitals can have complex information environments.

Systems may include:

  • Electronic medical records
  • Laboratory systems
  • Radiology systems
  • Pharmacy systems
  • Patient portals
  • Insurance systems
  • Billing platforms
  • Medical devices
  • Telemedicine platforms
  • Cloud applications

A Kuwait hospital should first map where patient information moves.

The assessment can then examine access, confidentiality, security, supplier relationships, incident management and evidence.

Where a U.S. healthcare customer requires HIPAA assurance, applicable HIPAA requirements should be assessed in addition to Kuwait obligations.

HIPAA Requirements for Kuwait Clinics and Medical Centres

Clinics may operate smaller technology environments, but they still process sensitive information.

A clinic may maintain:

  • Patient records
  • Appointment information
  • Prescriptions
  • Diagnostic reports
  • Billing information
  • Insurance information
  • Electronic communications

The assessment should be proportionate to the clinic's actual environment.

The key question is not whether the organization is large or small.

It is whether the organization has identified and controlled the risks associated with the information it handles.

HIPAA and Kuwait Medical Laboratories

Laboratories process information across several stages:

Patient registration → sample collection → laboratory testing → results → physician → patient record.

Each stage can introduce privacy and security considerations.

Laboratories should understand:

  • Who can access results
  • How results are transmitted
  • How systems are protected
  • How external laboratories are controlled
  • How information is retained
  • How information is securely disposed of

Where an international healthcare relationship creates HIPAA requirements, the applicable HIPAA controls should be included in the assessment scope.

HIPAA and Kuwait Pharmacies

Pharmacies may process prescriptions, patient information, medication information and insurance-related information.

The organization should determine what information it handles, who can access it and whether external systems or international customers introduce additional requirements.

HIPAA applicability should be determined from the actual business relationship rather than assumed simply because the organization operates in healthcare.

HIPAA for Kuwait Health-Tech Companies

Kuwait's health-tech sector may include:

  • Digital-health applications
  • Patient portals
  • Healthcare SaaS
  • Telemedicine platforms
  • Medical applications
  • Healthcare analytics
  • AI-enabled healthcare solutions
  • Electronic-record platforms

A health-tech company should understand its role in the information lifecycle.

Questions include:

  • Who owns or controls the information?
  • What information is processed?
  • Where is it stored?
  • Who can access it?
  • Which suppliers have access?
  • How are incidents handled?
  • What happens when a contract ends?

These questions are useful whether the organization is preparing for a HIPAA assessment or a broader healthcare privacy review.

HIPAA for Kuwait Healthcare SaaS Providers

A healthcare SaaS provider may handle information through:

  • Web applications
  • Databases
  • APIs
  • Cloud platforms
  • Backups
  • Administrative interfaces
  • Customer-support systems

The provider should map these systems and identify privileged access.

Where the customer is a HIPAA-regulated organization and the relationship falls within HIPAA requirements, the provider should assess the applicable obligations.

HIPAA for Kuwait Cloud and IT Providers

Cloud, hosting and IT-support companies may not be healthcare organizations themselves, but they can still encounter healthcare privacy requirements through their customers.

A Kuwait technology provider should consider:

  • Administrator access
  • Authentication
  • Encryption
  • Logging
  • Backup
  • Disaster recovery
  • Remote access
  • Supplier access
  • Data retention
  • Data deletion
  • Incident management

The exact HIPAA obligations depend on the service and relationship.

Kuwait Healthcare Data Mapping

Data mapping is one of the most useful starting points for a healthcare privacy assessment.

Map:

  1. Where information is collected
  2. Where it is entered
  3. Where it is stored
  4. Who can access it
  5. Where it is transmitted
  6. Which suppliers receive it
  7. Where backups are maintained
  8. How long it is retained
  9. How it is deleted

This helps the organization identify gaps that may not be visible from policies alone.

HIPAA Readiness Assessment in Kuwait

A Kuwait HIPAA readiness assessment can follow a practical sequence.

Step 1: Understand the Business

Identify services, customers, systems and healthcare information.

Step 2: Establish HIPAA Applicability

Determine whether the organization has an applicable HIPAA relationship.

Step 3: Define the Scope

Identify facilities, applications, people, suppliers and information included in the assessment.

Step 4: Review Kuwait Requirements

Consider applicable privacy, electronic-information and healthcare confidentiality requirements.

Step 5: Assess Existing Controls

Review policies, procedures, technology and actual implementation.

Step 6: Identify Gaps

Document areas where controls or evidence need improvement.

Step 7: Prioritize Actions

Address significant risks first.

Step 8: Prepare Evidence

Collect documentation and records supporting implementation.

Step 9: Complete the Assessment

Conduct the agreed review against the applicable requirements.

HIPAA Gap Assessment for Kuwait Organizations

A gap assessment answers a practical question:

Where are we now, and what needs to change?

Typical areas may include:

  • Privacy governance
  • Access control
  • Authentication
  • User management
  • Risk assessment
  • Incident response
  • Backup
  • Business continuity
  • Employee awareness
  • Supplier management
  • Physical security
  • Technical safeguards
  • Documentation

The output should be useful to management rather than simply a list of generic requirements.

HIPAA Evidence for Kuwait Healthcare Organizations

Evidence may include:

  • Policies
  • Procedures
  • Risk assessments
  • User-access reviews
  • Training records
  • Incident records
  • Supplier assessments
  • Backup records
  • System inventories
  • Data-flow diagrams
  • Access-control evidence
  • Corrective-action records

Evidence should reflect actual implementation.

A policy alone does not demonstrate that the process is operating effectively.

HIPAA and CITRA Privacy: What Is the Difference?

HIPAA and CITRA privacy requirements have different legal origins and purposes.

HIPAA is a U.S. healthcare framework.

CITRA's Data Privacy Protection Regulation is part of Kuwait's local privacy regulatory environment.

A Kuwait organization should not assume that meeting one automatically satisfies the other.

Instead, requirements can be mapped together where common controls exist.

HIPAA and Kuwait Medical Confidentiality

Healthcare confidentiality is another important layer.

Law No. 70 of 2020 contains patient confidentiality provisions and identifies limited circumstances in which disclosure may be permitted.

This means that healthcare organizations should consider confidentiality not only as an IT issue but also as part of clinical and administrative practice.

HIPAA and ISO 27001 in Kuwait

ISO 27001 and HIPAA have different purposes.

ISO 27001 provides an information-security management-system framework.

HIPAA contains requirements applicable to covered healthcare entities and certain business relationships.

ISO 27001 can provide useful controls for HIPAA readiness, but ISO 27001 certification should not automatically be represented as proof of HIPAA compliance.

HIPAA and ISO 7101 in Kuwait

ISO 7101 focuses on healthcare organization management systems.

HIPAA focuses on specific U.S. healthcare privacy and security requirements.

A Kuwait healthcare organization may use both for different objectives.

They should be treated as complementary rather than interchangeable.

HIPAA Compliance Cost in Kuwait

There is no universal HIPAA certification price for Kuwait.

The cost of an assessment depends on factors such as:

  • Organization size
  • Number of locations
  • Number of systems
  • Number of users
  • Information volume
  • Cloud environment
  • Existing controls
  • Documentation
  • Supplier relationships
  • Assessment scope
  • Customer requirements

A small clinic and a multi-site healthcare group should not automatically receive the same assessment scope.

How to Get HIPAA Compliance in Kuwait

A Kuwait organization can begin by preparing:

  • Organization profile
  • Customer requirements
  • Services
  • Healthcare information types
  • Applications
  • IT infrastructure
  • Cloud services
  • Suppliers
  • Existing policies
  • Existing security controls

The next step is to determine HIPAA applicability and define the assessment scope.

How to Prepare Quickly for a HIPAA Assessment in Kuwait

Preparation can be accelerated by:

  • Defining scope early
  • Mapping healthcare information
  • Identifying systems
  • Reviewing user access
  • Preparing policies
  • Assigning control owners
  • Gathering evidence
  • Identifying high-risk gaps
  • Establishing corrective actions

The objective should be efficient preparation without reducing the quality of the assessment.

HIPAA Compliance Across Kuwait

HIPAA-related searches may come from organizations in different parts of Kuwait, including:

  • Kuwait City
  • Hawally
  • Salmiya
  • Farwaniya
  • Ahmadi
  • Jahra
  • Mubarak Al-Kabeer
  • Other commercial and healthcare areas

The applicable HIPAA question is determined by the organization's activities and relationships, not simply its location.

However, local businesses can have different healthcare, technology and customer environments, so the assessment should be tailored accordingly.

Why Choose SCS for HIPAA Compliance Support in Kuwait?

SCS can discuss the organization's actual business situation before defining an assessment approach.

The discussion can cover:

  • Kuwait healthcare activities
  • International customers
  • HIPAA requirements
  • CITRA privacy considerations
  • Patient information
  • Healthcare applications
  • Cloud systems
  • Supplier access
  • Existing security controls
  • Assessment evidence

The objective is to establish what the organization actually needs rather than treating every company as having the same HIPAA requirement.

Start Your HIPAA Assessment in Kuwait

If your Kuwait organization has received a HIPAA requirement from a U.S. healthcare customer, technology partner or international business, the first step is to understand the requirement and define the information and systems involved.

A structured assessment can then identify gaps, prioritize improvements and prepare appropriate evidence.

For Kuwait healthcare organizations, the assessment should also consider the local privacy and healthcare confidentiality environment.

Need HIPAA Compliance Support in Kuwait?

SCS can discuss HIPAA readiness, gap assessment, healthcare information protection and customer compliance requirements for organizations operating in Kuwait.

Contact SCS Certification:

http://www.scscertification.com/contactus.php

UAE

Saudi Arabia

UK

Canada

India

SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE.

SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia

SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ.

SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada.

Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India.

Bangalore: Bangalore, Karnataka, India.

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

It refers to meeting applicable HIPAA requirements when a Kuwait organization handles protected health information within a relationship covered by HIPAA.
No. HIPAA applicability depends on the organization's activities, information and relationships with U.S. healthcare organizations.
It may apply when the company performs activities that fall within an applicable HIPAA relationship.
There is no general Kuwait requirement making every healthcare organization obtain HIPAA certification.
No. HIPAA should not be treated as an ISO management-system standard with one universal certification.
The term is commonly used commercially for HIPAA assessments, readiness reviews, gap assessments or compliance evaluations.
HIPAA does not operate as a universal certification programme issued by HHS.
It is a structured review of applicable HIPAA requirements against the organization's defined systems, processes and controls.
It evaluates whether an organization is prepared to address applicable HIPAA requirements.
It identifies differences between applicable requirements and the organization's current controls.
It examines risks affecting healthcare information and systems within the defined assessment scope.
International healthcare customers may require evidence of HIPAA-related privacy and security controls.
Kuwait Law No. 20 of 2014 includes privacy provisions covering information relating to health status.
Article 32 addresses unlawful access, disclosure or publication of specified personal data, including health-status information.
CITRA issued Resolution No. 26/2024 adopting a Data Privacy Protection Regulation.
Yes. CITRA's Resolution No. 26/2024 states that the earlier regulation under Resolution No. 42/2021 and its amendments was cancelled.
It can be relevant where healthcare organizations process personal information within the scope of the regulation.
CITRA's privacy framework covers public and private sectors within its scope.
Yes. The framework addresses requirements concerning personal-data collection and processing.
Yes. Data protection includes security-related obligations and controls.
Yes. Law No. 70 of 2020 contains specific patient-confidentiality requirements.
It prohibits healthcare professionals from disclosing patient secrets except in circumstances permitted by law.
The law extends confidentiality obligations to people working in relevant healthcare establishments and others who become aware of patient secrets.
Yes. Article 28 requires healthcare establishments to maintain patient files containing relevant health information.
Law No. 70 of 2020 allows patient information and records to be maintained in written or electronic form subject to the law's requirements.
Law No. 70 of 2020 provides for healthcare services to be delivered remotely subject to applicable Ministry requirements and controls.
It can be where the telemedicine provider handles protected health information in an applicable HIPAA relationship.
It can include patient identification, authentication, communication security, records, access controls, platforms, suppliers and incident response.
Yes. It refers to advanced technology, communications, digital and electronic media and related healthcare applications subject to Ministry controls.
It is the set of legal, organizational and technical measures used to protect healthcare and personal information.
It concerns the appropriate collection, use, access, disclosure, storage and protection of patient and medical information.
It involves protecting patient information from unauthorized access, disclosure, loss, misuse or inappropriate processing.
No. HIPAA and Kuwait privacy requirements should be assessed separately.
No. Where HIPAA applies, its applicable requirements must also be considered.
Yes. Common controls can support multiple requirements, although each framework should be mapped separately.
It may need one if its activities or customer relationships create applicable HIPAA requirements.
Not automatically. Applicability depends on its business activities and relationships.
They may when they process protected health information within an applicable HIPAA relationship.
It depends on the services they provide and whether an applicable HIPAA relationship exists.
It can apply where the company provides services involving protected health information within a covered relationship.
It can, depending on the customer's status, the services provided and information processed.
It may where cloud services involve protected health information within an applicable HIPAA relationship.
It can when the services involve protected health information and the applicable HIPAA conditions are met.
They may when processing protected health information for a HIPAA-regulated customer.
It should map where patient information is collected, stored, accessed, transmitted, backed up and deleted.
It helps identify information flows, access points, suppliers and potential control gaps.
Access reviews help ensure that only appropriate personnel can access sensitive information.
Privileged accounts can provide extensive system access and therefore require stronger controls.
Yes. Employees should understand their privacy, security and information-handling responsibilities.
Yes. Organizations should have suitable processes for detecting, managing and responding to information-security incidents.
Yes. Backups support the availability and recovery of critical healthcare information.
It can be important where the availability of healthcare information and systems affects operations.
Useful evidence can include policies, risk assessments, access reviews, training records, incident procedures, supplier assessments and technical records.
A suitable information-security policy can provide a foundation for security governance and control implementation.
Risk assessment is a useful way to identify threats, vulnerabilities and potential impacts affecting healthcare information.
Common risks can include excessive access, weak authentication, poor monitoring, insecure suppliers, inadequate backups and insufficient incident preparedness.
It can because cloud services may involve additional access, supplier, configuration and data-management considerations.
Relevant suppliers should be considered where they access, store, process or transmit healthcare information.
There is no universal cost; it depends on the organization's scope, systems, locations, controls and assessment requirements.
The cost depends on what the organization actually needs, such as a readiness assessment, gap assessment, risk assessment or independent review.
Yes. Larger environments generally require more systems, users, locations and evidence to be reviewed.
It can where different locations have separate systems, processes or access arrangements.
Establish applicability, define scope, review current controls, identify gaps, implement improvements and prepare evidence.
Prepare the scope, systems, policies, data map, evidence and responsible personnel before the assessment starts.
The timeframe depends on scope, organization size, system complexity and evidence availability.
It can help demonstrate preparedness during customer security and privacy due diligence.
It may provide useful evidence when a tender or customer requires HIPAA-related controls.
Yes. Early preparation can identify gaps before commercial due diligence begins.
A structured assessment and supporting evidence can help customers understand an organization's privacy and security controls.
Yes. ISO 27001 can provide an information-security framework containing controls that may support HIPAA readiness.
No. ISO 27001 and HIPAA have different purposes and requirements.
It can provide a privacy-management framework that may complement Kuwait privacy and security activities.
No. It should not be treated as a replacement for applicable HIPAA requirements.
No. ISO 7101 addresses healthcare organization management systems, while HIPAA addresses specific U.S. healthcare privacy and security requirements.
Yes. The two can support different healthcare management and information-protection objectives.
It can be relevant to healthcare, technology and health-tech organizations in Kuwait City when applicable HIPAA circumstances exist.
It may be relevant to healthcare and technology organizations in Hawally depending on their information and customer relationships.
It can be relevant where organizations handle applicable healthcare information or serve international healthcare customers.
Organizations in Farwaniya can seek an assessment based on their business activities, systems and customer requirements.
It can be relevant to healthcare, technology and service organizations where HIPAA requirements apply.
It can be relevant where organizations process healthcare information within an applicable HIPAA relationship.
Applicability depends on business activities and information processing rather than location alone.
It helps an organization understand applicable requirements, identify gaps and prepare evidence for customers or partners.
It provides management with a clearer picture of weaknesses and improvement priorities.
It helps identify risks affecting patient information, systems, users and suppliers.
It can reduce duplicated work by identifying controls that support multiple requirements while keeping each legal framework distinct.
Medical confidentiality creates healthcare-specific obligations that should not be assumed to be fully addressed by a general cybersecurity programme.
CITRA's current privacy framework forms an important part of Kuwait's data-protection environment.
The law contains privacy provisions specifically addressing personal information, including health-status information.
It contains healthcare-specific provisions concerning patient confidentiality, records, privacy and remote healthcare.
CITRA's official Resolution No. 26/2024 page records the issuance of the current Data Privacy Protection Regulation and cancellation of the previous regulation.
Kuwait's Law No. 20 of 2014 concerning Electronic Transactions contains privacy and data-protection provisions including health-status information.
Kuwait Law No. 70 of 2020 contains provisions concerning patient confidentiality and healthcare records.
SCS can discuss HIPAA readiness, gap assessment, healthcare information protection and customer requirements according to the organization's scope.
SCS can discuss the hospital's systems, healthcare information, customer requirements and appropriate assessment scope.
SCS can discuss HIPAA-related requirements and readiness based on the clinic's actual business and information environment.
SCS can discuss the technology, information flows, privacy controls and applicable HIPAA requirements.
SCS can discuss HIPAA-related readiness and assessment requirements for health-tech organizations.
You can contact SCS Certification at http://www.scscertification.com/contactus.php to discuss your Kuwait organization, HIPAA requirement and assessment scope.