Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, is the mandatory cybersecurity framework issued by the Department of Health – Abu Dhabi for any entity that generates, accesses, stores, uses, processes, or transmits health information in the Emirate. Version 2 took effect in August 2024, organises 692 controls across 11 domains into four control categories applied by entity type, and mandates both annual independent audits and annual penetration testing directly in the published requirements. This guide explains who falls in scope, how the framework is structured, and what the audit process actually involves.
Understanding this structure first makes the detailed requirements below far easier to apply to your own entity.
ADHICS Version 2 carries the official reference DOH/SD/ICSO/ADHICS/V2/2024, published in May 2024 and taking effect in August. It applies to any entity in Abu Dhabi generating, accessing, storing, using, processing, or transmitting health information, a scope that reaches well beyond hospitals to cover payers, diagnostic and dialysis centres, and the technology vendors and service providers supporting them. Our overview of cyber security companies in Abu Dhabi covers the broader provider landscape entities can draw on when building an ADHICS compliance programme.
The standard is reviewed on a three-year cycle, with the next scheduled revision due in May 2027. Entities are expected to treat compliance as an ongoing operational discipline rather than a one-time project, a point the standard itself reinforces by requiring continuous risk monitoring and periodic compliance reporting to the DoH throughout the certification cycle. Our GRC overview covers how a governance, risk, and compliance function typically supports this kind of ongoing regulatory obligation.
| Entity type | In scope | Applicable control category | Practical implication |
| Hospitals, 1–20 beds | Yes | Transitional (Basic and Transitional controls apply) | Smaller hospitals carry a lighter control set than larger facilities |
| Hospitals, 21+ beds | Yes | Advanced (Basic, Transitional, and Advanced controls apply) | Larger hospitals implement the full control set |
| Diagnostic, dialysis, fertilisation (IVF), and rehabilitation centres | Yes | Transitional | Specialist centres sit at the same tier as smaller hospitals |
| Health Information Exchange (Malaffi), insurers, and Third-Party Administrators | Yes | Advanced | These entities implement the full control set regardless of size |
| Healthcare technology and service providers (medical device or technology providers, EMR providers, web and mobile applications) | Yes | Service Provider | External vendors carry their own dedicated control category |
Entities determine their own classification against these criteria, and where a specific control demand genuinely does not apply to an entity's operations, the standard allows the entity to submit a documented business justification to the DoH rather than implementing it regardless. This is less a loophole than an acknowledgement that a small diagnostic centre and a large hospital operate under materially different risk profiles, even when both fall under the same standard. Our IT security audit guide covers how this kind of scoping decision typically shapes a broader compliance audit beyond ADHICS specifically.
According to the Department of Health's own published guidance, ADHICS comprises 692 controls across 11 domains, split into 162 primary controls and 530 secondary controls, distributed as 328 controls at Basic level, 218 at Transitional, and 146 at Advanced. This figure comes from DoH's official ADHICS FAQ document, and its entity classification thresholds match the current V2 standard text exactly, which strongly suggests the domain and control count still hold under V2.
These five domains are confirmed directly against the published standard text, in the order the standard itself presents them. This article confirms five of the standard's eleven domains directly; the remaining six are not stated here, since a guessed name is worse than an honest gap. Completing this section properly requires direct access to the full standard document, not the web version that kept truncating during this research pass.
Within the confirmed domains, the standard is genuinely specific rather than aspirational. Password policy, for example, mandates a minimum of twelve characters with complexity requirements, account lockout after five failed attempts, and a history check preventing reuse of the three most recent passwords. Access revocation on termination is required within 24 hours. These specifics matter because they illustrate what "compliance" actually means in practice: not a general commitment to security, but adherence to stated technical thresholds an auditor can check directly.
Beyond consolidation, V2 aligns the standard with the Abu Dhabi Healthcare Information and Cybersecurity Strategy published in 2021, reflecting several years of accumulated regulatory intent rather than an isolated update.
Two ADHICS-specialist consultancies publish directly conflicting breach notification windows for V2: one states 24 hours, the other 72. Neither traces to a quoted clause from the standard itself. This article does not state a notification window as fact anywhere, since neither figure could be confirmed against the primary source.
The standard itself mandates that entities develop an annual audit programme and undergo independent audits at least once a year, or following any significant change to the entity's environment. These audits can be conducted by internal or external resources, provided they maintain functional independence to avoid conflicts of interest. The entity shares outcomes with its governance committee and, as part of periodic compliance reporting, submits them to the DoH.
Health entities most commonly stall on evidence and documentation rather than the technical controls themselves. Implementing a password policy is straightforward; maintaining a year's worth of access review records, training completion logs, and change management documentation that an auditor can verify is where compliance programmes lose momentum. Building evidence collection into day-to-day operations from the outset, rather than assembling it retroactively before an audit, is the difference between a smooth submission and a difficult one. Our vulnerability assessment service covers one of the technical inputs this evidence base typically draws on.
ADHICS diverges from ISO 27001 specifically where healthcare operations introduce risk ISO 27001 was never designed to address: connected medical device security, the Malaffi health information exchange integration, restrictions on where health information may be stored or transferred, and DoH-specific reporting obligations. ISO 27001 certification does not substitute for ADHICS compliance; the overlap reduces the incremental work required, but a certification issued against a different standard does not satisfy a separate regulatory requirement. Our ISO 27001 certification guide covers that certification path in detail for entities weighing whether to pursue both.
Findings from this testing must be tracked through to remediation, with defined timelines and follow-up progress reviews, and the standard explicitly calls for revalidation assessment to confirm mitigation measures actually worked rather than simply being reported as complete. Our enterprise penetration testing guide covers scope, cost, and provider selection for organisations planning this annual testing cycle. The standard also restricts where health information may reside: under Federal Law No. 2 of 2019 on the use of ICT in healthcare, health information related to services provided within the country may not be stored, developed, or transferred outside the UAE. Our data security solutions page covers the technical controls that typically support this kind of residency requirement.
The operational cost of this ongoing maintenance is real and should be budgeted as a permanent line item rather than treated as a project expense that ends once initial compliance is achieved. Entities weighing whether to build this capability internally or bring in support can review NESA compliance and DESC compliance for how comparable UAE regulatory obligations are typically resourced. This article provides general guidance based on the currently published ADHICS Version 2 standard and does not constitute legal advice; the published standard itself, available directly from the Department of Health, remains the authoritative source for any specific compliance decision.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cyber Compliance | 15/09/2026
Cyber Compliance | 15/09/2026
Cyber Compliance | 21/08/2026
What does ADHICS stand for?
Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health – Abu Dhabi.Is ADHICS mandatory in Abu Dhabi?
Yes, for healthcare facilities, payers, and healthcare technology and service providers in scope of the standard.Who issues the ADHICS standard?
The Department of Health – Abu Dhabi, through its Information & Cyber Security Office.How long does ADHICS compliance take?
All four control categories carry the same six-month compliance timeline from official programme induction or the standard's release date, whichever comes first.What is the difference between ADHICS and ISO 27001?
ISO 27001 is a general standard. ADHICS adds healthcare-specific requirements. See our ISO 27001 guide.Does ADHICS require penetration testing?
Yes. The standard mandates annual VAPT covering systems, web and mobile applications, and connected medical devices.What is ADHICS V2?
The current version, effective August 2024, consolidates three earlier DoH standards into one framework of 692 controls across 11 domains.Do health IT vendors need to comply with ADHICS?
Yes, under the Service Provider control category, covering medical device, EMR, and application vendors.