Discover your OT Blind spots today! Get your free Executive Readiness Heatmap.

Contact Us
Close
Chat
Get In Touch

Get Immediate Help

Get in Touch!

Tell us what you need and we’ll connect you with the right specialist within 10 minutes.

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

We appreciate your interest in our cybersecurity services! Our team will review your submission and reach out to you soon to discuss next steps.

UK: +44 (0)20 3336 7200
UAE: +971 454 01252
KSA: +966 1351 81844

4.9 Microminder Cybersecurity

310 reviews on

Trusted by 2600+ Enterprises & Governments

Trusted by 2600+ Enterprises & Governments

Contact the Microminder Team

Need a quote or have a question? Fill out the form below, and our team will respond to you as soon as we can.

What are you looking for today?

Managed security Services

Managed security Services

Cyber Risk Management

Cyber Risk Management

Compliance & Consulting Services

Compliance & Consulting Services

Cyber Technology Solutions

Cyber Technology Solutions

Selected Services:

Request for

  • Yes, I agree with the storage and handling of my data by this website, to receive periodic emails from microminder cybersecurity related to products and services and can unsubscribe at any time. By proceeding, you consent to allow microminder cybersecurity to store and process the personal information submitted above to provide you the content requested. I accept microminder's Privacy Policy.*

  • This site is protected by reCAPTCHA.

Thank You

Thank you

In the meantime, please help our team scope your requirement better and to get the right expert on the call by completing the below section. It should take 30 seconds!

30 seconds!

Untick the solutions you don’t need

  • Untick All
  • Untick All
  • Untick All
  • Untick All
Thank You

What happens next?

Thanks for considering us for your cybersecurity needs! Our team will review your submission and contact you shortly to discuss how we can assist you.

01

Our cyber technology team team will contact you after analysing your requirements

02

We sign NDAs for complete confidentiality during engagements if required

03

Post a scoping call, a detailed proposal is shared which consists of scope of work, costs, timelines and methodology

04

Once signed off and pre-requisites provided, the assembled team can commence the delivery within 48 hours

05

Post delivery, A management presentation is offered to discuss project findings and remediation advice

Home  Resources  Blogs  ADHICS Compliance in the UAE: Requirements, Controls and Audit Process

ADHICS Compliance in the UAE: Requirements, Controls and Audit Process

 
Sanjiv Cherian

Sanjiv Cherian, Chief Commercial Officer
Sep 15, 2026

  • LinkedIn

ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, is the mandatory cybersecurity framework issued by the Department of Health – Abu Dhabi for any entity that generates, accesses, stores, uses, processes, or transmits health information in the Emirate. Version 2 took effect in August 2024, organises 692 controls across 11 domains into four control categories applied by entity type, and mandates both annual independent audits and annual penetration testing directly in the published requirements. This guide explains who falls in scope, how the framework is structured, and what the audit process actually involves.

Key Takeaways

Before working through ADHICS in detail, these points shape everything else.

  • ADHICS applies to healthcare facilities, payers, and healthcare technology and service providers in Abu Dhabi, with obligations that flow down to vendors handling health information on their behalf.
  • Controls apply through four categories: Basic, Transitional, Advanced, and Service Provider, determined by entity type and, for hospitals, bed capacity.
  • The standard mandates annual independent audits and annual vulnerability assessment and penetration testing, both stated directly in the published requirements, not left as implied good practice.
  • Version 2, effective August 2024, consolidated three separate 2019 and 2020 DoH standards into one framework spanning 692 controls across 11 domains.
  • ISO 27001 and ADHICS overlap meaningfully in control areas, though ADHICS carries healthcare-specific requirements ISO 27001 does not address.


Understanding this structure first makes the detailed requirements below far easier to apply to your own entity.

Understanding the Abu Dhabi Healthcare Information and Cyber Security Standard

The Department of Health – Abu Dhabi, the Emirate's health sector regulator, issues ADHICS to secure health information across the entities that create, hold, and exchange it. The standard exists because healthcare data carries a combination of sensitivity and operational criticality that generic IT security frameworks do not fully address: a breach threatens not just confidentiality but, in the case of connected medical devices and clinical systems, patient safety directly.

ADHICS Version 2 carries the official reference DOH/SD/ICSO/ADHICS/V2/2024, published in May 2024 and taking effect in August. It applies to any entity in Abu Dhabi generating, accessing, storing, using, processing, or transmitting health information, a scope that reaches well beyond hospitals to cover payers, diagnostic and dialysis centres, and the technology vendors and service providers supporting them. Our overview of cyber security companies in Abu Dhabi covers the broader provider landscape entities can draw on when building an ADHICS compliance programme.

The standard is reviewed on a three-year cycle, with the next scheduled revision due in May 2027. Entities are expected to treat compliance as an ongoing operational discipline rather than a one-time project, a point the standard itself reinforces by requiring continuous risk monitoring and periodic compliance reporting to the DoH throughout the certification cycle. Our GRC overview covers how a governance, risk, and compliance function typically supports this kind of ongoing regulatory obligation.

Who Must Comply With ADHICS

ADHICS applies broadly across the Abu Dhabi health sector, and the specific controls an entity must implement depend on its classification rather than a single uniform requirement.

Entity typeIn  scopeApplicable control categoryPractical implication
Hospitals, 1–20 bedsYesTransitional (Basic and Transitional controls apply)Smaller hospitals carry a lighter control set than larger facilities
Hospitals, 21+ bedsYesAdvanced (Basic, Transitional, and Advanced controls apply)Larger hospitals implement the full control set
Diagnostic, dialysis, fertilisation (IVF), and rehabilitation centresYesTransitionalSpecialist centres sit at the same tier as smaller hospitals
Health Information Exchange (Malaffi), insurers, and Third-Party AdministratorsYesAdvancedThese entities implement the full control set regardless of size
Healthcare technology and service providers (medical device or technology providers, EMR providers, web and mobile applications)YesService ProviderExternal vendors carry their own dedicated control category

Entities determine their own classification against these criteria, and where a specific control demand genuinely does not apply to an entity's operations, the standard allows the entity to submit a documented business justification to the DoH rather than implementing it regardless. This is less a loophole than an acknowledgement that a small diagnostic centre and a large hospital operate under materially different risk profiles, even when both fall under the same standard. Our IT security audit guide covers how this kind of scoping decision typically shapes a broader compliance audit beyond ADHICS specifically.

How the ADHICS Control Framework Is Organised

Every entity, regardless of category, operates under a defined governance structure before any technical control comes into play. The standard requires an Information Security Governance Committee chaired by a senior management resource, a Health Information Infrastructure Protection Workgroup that coordinates implementation, and a designated Chief Information Security Officer or equivalent who reports progress to both. This governance layer is not optional scaffolding; it is where the standard places accountability for the technical controls that follow.

According to the Department of Health's own published guidance, ADHICS comprises 692 controls across 11 domains, split into 162 primary controls and 530 secondary controls, distributed as 328 controls at Basic level, 218 at Transitional, and 146 at Advanced. This figure comes from DoH's official ADHICS FAQ document, and its entity classification thresholds match the current V2 standard text exactly, which strongly suggests the domain and control count still hold under V2.

  • Human Resources Security — recruitment, onboarding, awareness training, and exit procedures for staff and contractors.
  • Asset Management — inventory, classification, and handling of information assets including medical devices.
  • Physical and Environmental Security — protection of facilities, secure areas, and equipment.
  • Access Control — user access management, password policy, network and system-level access restrictions.
  • Communications and Operations Management — change management, backup, malware protection, logging, patch management, and technical security testing.


These five domains are confirmed directly against the published standard text, in the order the standard itself presents them. This article confirms five of the standard's eleven domains directly; the remaining six are not stated here, since a guessed name is worse than an honest gap. Completing this section properly requires direct access to the full standard document, not the web version that kept truncating during this research pass.

Within the confirmed domains, the standard is genuinely specific rather than aspirational. Password policy, for example, mandates a minimum of twelve characters with complexity requirements, account lockout after five failed attempts, and a history check preventing reuse of the three most recent passwords. Access revocation on termination is required within 24 hours. These specifics matter because they illustrate what "compliance" actually means in practice: not a general commitment to security, but adherence to stated technical thresholds an auditor can check directly.

What Changed in ADHICS V2

Version 2 is not a minor revision. It formally supersedes three separate documents the DoH previously published: the original ADHICS Standard V0.9 of 2019, the Internet of Medical Things Security Standard V0.9 of 2020, and the Standard on Patient Healthcare Data Privacy V0.9 of 2020. Consolidating these three into a single framework is the most structurally significant change in V2, since entities previously navigating three separate documents now work from one.

Beyond consolidation, V2 aligns the standard with the Abu Dhabi Healthcare Information and Cybersecurity Strategy published in 2021, reflecting several years of accumulated regulatory intent rather than an isolated update.

Two ADHICS-specialist consultancies publish directly conflicting breach notification windows for V2: one states 24 hours, the other 72. Neither traces to a quoted clause from the standard itself. This article does not state a notification window as fact anywhere, since neither figure could be confirmed against the primary source.

The ADHICS Audit and Submission Process

Compliance under ADHICS follows a defined path rather than a single point-in-time assessment. Scoping and classification come first, establishing which control category applies to the entity. A gap assessment against the applicable controls follows, identifying where current practice falls short. From there, the entity conducts risk assessments, implements controls, and develops supporting policies and documentation, followed by internal audit and management review before any external submission.

The standard itself mandates that entities develop an annual audit programme and undergo independent audits at least once a year, or following any significant change to the entity's environment. These audits can be conducted by internal or external resources, provided they maintain functional independence to avoid conflicts of interest. The entity shares outcomes with its governance committee and, as part of periodic compliance reporting, submits them to the DoH.

Health entities most commonly stall on evidence and documentation rather than the technical controls themselves. Implementing a password policy is straightforward; maintaining a year's worth of access review records, training completion logs, and change management documentation that an auditor can verify is where compliance programmes lose momentum. Building evidence collection into day-to-day operations from the outset, rather than assembling it retroactively before an audit, is the difference between a smooth submission and a difficult one. Our vulnerability assessment service covers one of the technical inputs this evidence base typically draws on.

ADHICS and ISO 27001: Where They Overlap

Health entities that already hold or are pursuing ISO 27001 certification carry real advantages into an ADHICS programme. Both frameworks share substantial ground in access control, risk management, asset management, and incident handling, since both are built on internationally recognised information security principles applied to an organisational control environment.

ADHICS diverges from ISO 27001 specifically where healthcare operations introduce risk ISO 27001 was never designed to address: connected medical device security, the Malaffi health information exchange integration, restrictions on where health information may be stored or transferred, and DoH-specific reporting obligations. ISO 27001 certification does not substitute for ADHICS compliance; the overlap reduces the incremental work required, but a certification issued against a different standard does not satisfy a separate regulatory requirement. Our ISO 27001 certification guide covers that certification path in detail for entities weighing whether to pursue both.

Technical Testing Obligations Under ADHICS

ADHICS does not leave vulnerability assessment and penetration testing as an implied good practice. The standard states directly that entities shall establish yearly schedules and conduct vulnerability assessment and penetration testing covering the entity's systems, network, and infrastructure, internet-facing web and mobile applications, and connected medical devices. This requirement sits at the Advanced and Service Provider control tiers, meaning larger hospitals, the health information exchange, insurers, TPAs, and healthcare technology vendors all carry this obligation directly rather than as an optional enhancement.

Findings from this testing must be tracked through to remediation, with defined timelines and follow-up progress reviews, and the standard explicitly calls for revalidation assessment to confirm mitigation measures actually worked rather than simply being reported as complete. Our enterprise penetration testing guide covers scope, cost, and provider selection for organisations planning this annual testing cycle. The standard also restricts where health information may reside: under Federal Law No. 2 of 2019 on the use of ICT in healthcare, health information related to services provided within the country may not be stored, developed, or transferred outside the UAE. Our data security solutions page covers the technical controls that typically support this kind of residency requirement.

Maintaining Compliance After Your First Submission

Compliance under ADHICS is an ongoing obligation, not a one-time certificate. Beyond the annual audit and annual testing cycle already covered, entities are expected to maintain several ongoing practices.

  • Periodic risk assessment, revisiting the entity's risk register as its environment and threat landscape change.
  • Control review, confirming implemented controls remain adequate and effective rather than assuming initial implementation is permanent.
  • Incident reporting, maintaining the escalation and DoH notification processes the standard requires.
  • Staff awareness training, delivered on the schedule the standard specifies for general and role-based audiences.
  • Supplier assurance, extending ADHICS-equivalent expectations to third parties handling health information.
  • Evidence refresh, keeping documentation and audit trails current rather than static from the initial submission.


The operational cost of this ongoing maintenance is real and should be budgeted as a permanent line item rather than treated as a project expense that ends once initial compliance is achieved. Entities weighing whether to build this capability internally or bring in support can review NESA compliance and DESC compliance for how comparable UAE regulatory obligations are typically resourced. This article provides general guidance based on the currently published ADHICS Version 2 standard and does not constitute legal advice; the published standard itself, available directly from the Department of Health, remains the authoritative source for any specific compliance decision.

Don’t Let Cyber Attacks Ruin Your Business

  • Certified Security Experts: Our CREST and ISO27001 accredited experts have a proven track record of implementing modern security solutions
  • 41 years of experience: We have served 2600+ customers across 20 countries to secure 7M+ users
  • One Stop Security Shop: You name the service, we’ve got it — a comprehensive suite of security solutions designed to keep your organization safe

FAQs

What does ADHICS stand for?

Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health – Abu Dhabi.

Is ADHICS mandatory in Abu Dhabi?

Yes, for healthcare facilities, payers, and healthcare technology and service providers in scope of the standard.

Who issues the ADHICS standard?

The Department of Health – Abu Dhabi, through its Information & Cyber Security Office.

How long does ADHICS compliance take?

All four control categories carry the same six-month compliance timeline from official programme induction or the standard's release date, whichever comes first.

What is the difference between ADHICS and ISO 27001?

ISO 27001 is a general standard. ADHICS adds healthcare-specific requirements. See our ISO 27001 guide.

Does ADHICS require penetration testing?

Yes. The standard mandates annual VAPT covering systems, web and mobile applications, and connected medical devices.

What is ADHICS V2?

The current version, effective August 2024, consolidates three earlier DoH standards into one framework of 692 controls across 11 domains.

Do health IT vendors need to comply with ADHICS?

Yes, under the Service Provider control category, covering medical device, EMR, and application vendors.
Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health – Abu Dhabi.
Yes, for healthcare facilities, payers, and healthcare technology and service providers in scope of the standard.
The Department of Health – Abu Dhabi, through its Information & Cyber Security Office.
All four control categories carry the same six-month compliance timeline from official programme induction or the standard's release date, whichever comes first.
ISO 27001 is a general standard. ADHICS adds healthcare-specific requirements. See our ISO 27001 guide.
Yes. The standard mandates annual VAPT covering systems, web and mobile applications, and connected medical devices.
The current version, effective August 2024, consolidates three earlier DoH standards into one framework of 692 controls across 11 domains.
Yes, under the Service Provider control category, covering medical device, EMR, and application vendors.