The ADHICS (Abu Dhabi Healthcare Information and Cyber Security) Standard is the mandatory healthcare information security framework for all healthcare facilities and their technology partners operating in Abu Dhabi. Issued by the Department of Health (DOH) Abu Dhabi and enforced through the facility licensing process, ADHICS sets out specific requirements for how patient health information must be protected, how cyber security risks must be managed, and how incidents must be reported. With healthcare cyber security incidents rising globally, healthcare is one of the most targeted sectors for ransomware and data theft, ADHICS compliance is not just a regulatory checkbox; it is essential risk management for Abu Dhabi healthcare providers. This guide explains the ADHICS standard, its 19 control domains, implementation roadmap, and how Abu Dhabi healthcare organisations can achieve and maintain compliance.
ADHICS, Background and Scope
ADHICS was introduced as Abu Dhabi's healthcare sector modernised its IT infrastructure, electronic medical records (EMR), connected diagnostic systems, laboratory information systems, and digital patient pathways all create cyber security risks that paper-based systems did not face. The DOH mandated ADHICS to establish a consistent baseline of information security across the Abu Dhabi healthcare ecosystem, protecting patient privacy and ensuring the continuity and integrity of clinical care.
ADHICS applies to:
All DOH-licensed healthcare providers, hospitals, clinics, specialist centres, diagnostic and imaging centres, pharmacies, dental practices, home health agencies, and long-term care facilities
Healthcare IT system vendors and managed service providers that access, process, or store patient health information on behalf of Abu Dhabi healthcare facilities
Any third party with physical or electronic access to patient health information (PHI) within the Abu Dhabi healthcare ecosystem
ADHICS is aligned with international best practices (ISO/IEC 27001, NIST Cybersecurity Framework, HIPAA) while being tailored to the specific regulatory and operational context of Abu Dhabi healthcare. Compliance is assessed as part of DOH facility licensing inspections, periodic regulatory audits, and as a condition of healthcare IT vendor procurement in the Abu Dhabi government and private healthcare sector.
ADHICS 19 Control Domains
ADHICS organises information security requirements into 19 control domains. Each domain contains specific requirements, sub-controls, and implementation guidance. Key domains include:
Domain 1, Information Security Governance: Board-level accountability; designated Information Security Officer (ISO); Information Security Committee; formal IS policies approved by senior management; annual IS programme review
Domain 2, Risk Management: Annual information security risk assessment using a documented methodology; risk treatment plan addressing identified risks; risk register maintenance; risk acceptance process for residual risks
Domain 3, Human Resources Security: Background checks for staff with access to patient information; security awareness training at induction and annually; acceptable use agreements; leaver access revocation procedures (within 24 hours)
Domain 4, Asset Management: Complete hardware and software inventory; classification of information assets by sensitivity; media disposal procedures (certified destruction for media containing patient data)
Domain 5, Access Control: Role-based access control (RBAC) aligned to clinical roles; multi-factor authentication (MFA) for EMR and all systems processing sensitive patient data; privileged access management (PAM) for IT admin accounts; quarterly access reviews
Domain 6, Cryptography: Encryption standards for data at rest (AES-256 or equivalent) and in transit (TLS 1.2+); key management procedures; prohibition on weak encryption protocols
Domain 7, Physical Security: Data centre and server room physical access controls; CCTV coverage; clear desk and clear screen policy; visitor management procedures
Domain 9, Communications Security: Network segmentation separating clinical systems from general corporate networks; firewall management with documented rulesets; secure remote access (VPN/Zero Trust); email security (anti-phishing, DLP)
Domain 10, Third Party Management: Information security assessment of all vendors with patient data access; contractual ADHICS security requirements (Data Processing Agreements); periodic vendor re-assessment; vendor incident notification requirements
Domain 11, Incident Management: Formal cyber security incident response plan; DOH incident notification within 4 hours for major incidents; post-incident review and lessons-learned process; staff incident reporting procedures
Domain 12, Business Continuity: Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) for healthcare information systems; documented Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO); regular BCP/DRP testing
Domains 13–19: Cover healthcare-specific requirements including patient identity management, clinical application security, mobile device management, audit logging, software development security for bespoke clinical applications, and healthcare data exchange security
Vendor and Third-Party Obligations
Healthcare IT vendors operating in Abu Dhabi must understand that ADHICS Domain 10 places direct obligations on healthcare facility clients to manage vendor security, which in practice creates procurement requirements that vendors must satisfy:
Security assessment questionnaire: Vendors should expect to complete detailed security questionnaires covering their own information security controls before contract award
Data Processing Agreement (DPA): Contracts must include a DPA specifying how the vendor processes, protects, and disposes of patient data
Penetration testing evidence: Vendors are typically asked to provide annual penetration test reports for systems processing Abu Dhabi healthcare data
SOC 2 Type II certification: Increasingly, Abu Dhabi healthcare facilities require cloud and SaaS vendors to hold SOC 2 Type II certification as evidence of vendor control environment maturity alongside ADHICS Domain 10 assessments. See the full SOC reporting guide for details on obtaining SOC 2 certification in the UAE.
Incident notification SLA: Vendor contracts must include requirements to notify the healthcare facility within agreed timeframes (typically 24–72 hours) of any security incident affecting patient data
ADHICS Implementation Roadmap
Gap Assessment: Conduct a formal ADHICS gap assessment against all 19 domains, identifying current controls vs. ADHICS requirements, scoring compliance maturity, and prioritising gaps by risk level and DOH inspection timeline
Governance Setup: Appoint a qualified Information Security Officer (ISO); establish an Information Security Committee with clinical and operational representation; obtain board-level approval of the IS policy framework
Risk Assessment: Conduct the annual information security risk assessment using a documented methodology; identify and prioritise key risks to patient data and clinical systems; document the risk register and treatment plan
Technical Controls: Implement priority technical controls based on gap assessment, MFA, access control review and RBAC implementation, encryption validation, vulnerability scanning, audit logging to SIEM
Policy and Procedure Library: Develop the full ADHICS policy and procedure library (typically 30–50 documents for a mid-size facility): IS policy, acceptable use policy, access control procedure, incident response plan, BCP, DRP, vendor management procedure, etc.
Staff Training: Deliver security awareness training to all staff with access to patient information; maintain training records; test awareness with phishing simulations
Penetration Testing: Commission an independent penetration test of healthcare IT systems from a qualified tester; remediate critical and high findings before DOH inspection
Internal ADHICS Audit: Conduct internal compliance audit against all 19 domains; close remaining gaps; prepare evidence packs for DOH inspection
Professional Insight, ADHICS and ISO 27001: Many Abu Dhabi healthcare organisations use ISO 27001 certification as a framework for their overall Information Security Management System (ISMS) and then map ADHICS-specific requirements on top. ISO 27001 certification from an accredited certification body provides independent evidence of information security management maturity and significantly streamlines ADHICS compliance work, the two frameworks have approximately 70% control overlap. Healthcare organisations considering both should pursue them in parallel rather than sequentially to maximise efficiency. ISO 27001 certification also supports vendor procurement: healthcare IT vendors that hold ISO 27001 certification have a credible, independently verified security baseline that accelerates DOH-licensed facility due diligence processes under ADHICS Domain 10.
ADHICS and UAE Federal PDPL
The UAE Federal Personal Data Protection Law (PDPL, Federal Decree-Law No. 45 of 2021, effective September 2021) applies to all personal data, including health data, processed in the UAE. ADHICS and the PDPL operate as complementary but distinct frameworks:
PDPL obligations: Lawful basis for processing patient data; patient consent requirements; data subject rights (access, correction, deletion); privacy notices; data transfer restrictions for sending patient data outside the UAE; breach notification to the UAE Data Office
ADHICS obligations: Healthcare-specific technical and governance controls for protecting patient health information, the "how" of security implementation, versus the PDPL's "what" rights and obligations framework
Dual compliance: Healthcare facilities in Abu Dhabi must satisfy both. A single data breach can trigger mandatory notification to both the DOH (under ADHICS incident reporting) and the UAE Data Office (under PDPL breach notification) simultaneously, with different notification timelines and content requirements
Penalties for Non-Compliance
ADHICS non-compliance carries direct and indirect consequences for Abu Dhabi healthcare organisations:
DOH Regulatory Sanctions: Warnings; fines; suspension of specific services; in serious or repeat cases, revocation of the healthcare facility licence
Patient Notification Obligations: Healthcare facilities must notify affected patients following a data breach, both a regulatory and reputational cost
PDPL Penalties: The UAE Data Office can impose fines of up to AED 20 million under the PDPL for serious data protection violations
Reputational Damage: Healthcare data breaches in the UAE receive media attention; patient trust, once damaged, is difficult to recover
Civil Liability: Patients whose data is compromised may have civil law claims against the facility under UAE law
Procurement Exclusion: Healthcare facilities with ADHICS compliance findings may be excluded from Abu Dhabi Health Services Company (SEHA) network participation and mandatory health insurance reimbursement programmes pending remediation
Common Mistakes to Avoid
Treating ADHICS as a one-time project rather than an ongoing programme: Many healthcare facilities achieve ADHICS compliance for a DOH inspection and then allow controls to drift. ADHICS is a continuous programme, controls that pass inspection in 2024 can deteriorate through staff turnover, system changes, and vendor changes. Annual risk assessments, quarterly access reviews, and continuous vulnerability management are not optional.
Appointing an ISO without appropriate authority: ADHICS requires the ISO to be empowered to enforce information security policies. ISO roles assigned to junior IT staff without board backing, budget authority, or the ability to override clinical convenience decisions are ineffective. The ISO must have direct access to senior management and a clear escalation path.
Neglecting vendor ADHICS compliance: Domain 10 vendor obligations are commonly under-implemented. Healthcare facilities that allow vendor access to patient data without executing Data Processing Agreements, completing vendor security assessments, or including ADHICS requirements in contracts are in non-compliance, and exposed to vendor-side incidents that trigger DOH notification obligations.
Delaying penetration testing until just before DOH inspection: Penetration tests regularly uncover critical vulnerabilities requiring remediation that takes weeks or months. Scheduling a penetration test 4 weeks before a DOH inspection provides insufficient time to remediate findings, results in inspection failures and emergency remediation programmes. Schedule tests 6 months before any inspection deadline.
Ignoring the PDPL layer: ADHICS-compliant security controls do not automatically satisfy PDPL obligations around data subject rights, consent, and lawful basis for processing. Privacy notices, patient consent workflows, and data subject request handling procedures must be implemented alongside technical ADHICS controls. A breach that triggers only ADHICS reporting may also require PDPL notification, healthcare legal and compliance teams must review both frameworks jointly.
Business Scenarios
Scenario 1 : New Specialist Clinic Achieving ADHICS Compliance Before DOH Licensing
A new specialist orthopaedic clinic planned to open in Abu Dhabi with a DOH facility licence application submitted 9 months before the target opening date. The clinic's management team had no previous experience with ADHICS. An external consultant was engaged immediately to conduct an ADHICS gap assessment, identifying that governance (no ISO appointed, no IS committee, no policies) and technical controls (EMR not yet procured, network design not finalised) were both starting from zero. The implementation roadmap was scoped at 7 months to allow a 2-month buffer before the DOH licensing inspection. Key actions: ISO appointed (a qualified healthcare IT security professional, part-time initially); IS policies developed from a healthcare-specific template library; EMR vendor selected with an explicit ADHICS Domain 10 assessment as part of the procurement decision; network segmented at setup (clinical network isolated from admin network); MFA configured for all clinical user EMR access from day one; penetration test conducted at month 5; two critical findings remediated before the DOH inspection at month 7. Result: ADHICS compliance achieved before licence issuance; clinic opened without any information security conditions attached to the licence.
Scenario 2 : Healthcare IT Vendor Achieving ADHICS Domain 10 Compliance for UAE Market Entry
A UK-based EMR software provider seeking to enter the Abu Dhabi private hospital market found that every prospective hospital client's procurement process included an ADHICS Domain 10 security assessment questionnaire as a prerequisite to product evaluation. The vendor's UK ISO 27001 certification covered their development environment but not their UAE-hosted cloud environment (which would hold Abu Dhabi patient data). The vendor engaged a UAE-based implementation partner to: extend ISO 27001 scope to include the UAE cloud environment; complete a UAE-specific penetration test of the EMR platform; execute ADHICS-compliant Data Processing Agreements; and prepare an ADHICS Domain 10 evidence pack (penetration test report, ISO 27001 certificate, security questionnaire responses, incident response procedure). With the evidence pack complete, the vendor passed three prospective clients' Domain 10 assessments within the following quarter and signed its first UAE hospital contract. The structured approach to ADHICS vendor compliance transformed a procurement blocker into a competitive advantage, the vendor's documentation was more complete than UAE-headquartered competitors who had not formally mapped their controls to ADHICS.
Frequently Asked Questions
What is the ADHICS standard and who must comply?
ADHICS (Abu Dhabi Healthcare Information and Cyber Security Standard) is a mandatory regulatory requirement issued by the Department of Health (DOH) Abu Dhabi for all healthcare facilities licensed in Abu Dhabi. It applies to: all DOH-licensed healthcare providers (hospitals, clinics, diagnostic centres, pharmacies, home health agencies); healthcare IT vendors and service providers that access or process patient data on behalf of Abu Dhabi healthcare facilities; and any third party with access to patient health information within the Abu Dhabi healthcare ecosystem. ADHICS compliance is assessed as part of DOH facility licensing inspections and ongoing regulatory supervision. The standard covers 19 control domains from governance and risk management through to third party management, incident response, and business continuity.
What are the main requirements of the ADHICS standard?
ADHICS is structured around 19 domains covering information security governance, risk management, and technical controls. Key requirements include: Information Security Management System (ISMS) with designated ISO; Healthcare Information Classification; Access Controls including MFA for sensitive systems; Encryption of patient data at rest and in transit; Audit Logging; Incident Response with DOH notification within 4 hours for major incidents; Business Continuity with tested BCP and DRP; Third-party Management with vendor security assessments; and Vulnerability Management including regular penetration testing. Each domain contains specific sub-controls with implementation guidance tailored to the Abu Dhabi healthcare context.
Does ADHICS apply to healthcare IT vendors and technology providers?
Yes, ADHICS Domain 10 (Third Party Management) requires DOH-licensed healthcare facilities to assess the information security posture of all vendors with access to patient health information; include ADHICS-specific security requirements in vendor contracts (Data Processing Agreements); periodically re-assess vendor compliance; and ensure vendors notify the healthcare facility promptly of any security incidents affecting patient data. Healthcare IT vendors (EMR providers, diagnostic software companies, cloud infrastructure providers, managed IT service providers) operating in Abu Dhabi should therefore proactively prepare their own ADHICS compliance documentation, it is becoming a prerequisite for contract award and renewal. A SOC 2 Type II report is also increasingly requested by UAE healthcare operators as evidence of vendor control environments alongside ADHICS Domain 10 assessments.
How long does ADHICS compliance implementation take?
Timeline depends on the starting point and facility size. For a newly licensed clinic starting from scratch: allow 6–12 months for full ADHICS implementation (governance setup, technical controls, documentation, training, and penetration testing). For an established hospital with some existing information security controls: 3–6 months for gap closure and documentation if gaps are moderate. Common bottlenecks: finding and appointing a qualified ISO; procurement and implementation of technical security tools (MFA, PAM, logging solutions); and penetration test scheduling and findings remediation. Healthcare facilities should begin ADHICS implementation well before their DOH licence renewal inspection, engaging an external ADHICS consultant can significantly accelerate implementation through gap assessment, documentation templates, and implementation guidance from prior projects.
What is the relationship between ADHICS and the UAE Federal PDPL?
The UAE Federal Personal Data Protection Law (PDPL, Federal Decree-Law No. 45 of 2021) applies to all personal data, including health data, processed in the UAE. ADHICS is a sector-specific standard issued by DOH Abu Dhabi covering healthcare information security. Healthcare facilities in Abu Dhabi must comply with both: the federal PDPL (data subject rights, consent, lawful basis for processing, breach notification to the UAE Data Office) and ADHICS (healthcare-specific technical and governance controls). A single cyber security incident can trigger liabilities under both frameworks simultaneously, with different notification timelines and content requirements for the DOH (ADHICS: 4 hours for major incidents) and the UAE Data Office (PDPL: 72 hours). Healthcare legal and compliance teams must review both frameworks jointly rather than treating them as separate streams.
Conclusion and Next Steps
ADHICS compliance is a non-negotiable requirement for Abu Dhabi healthcare providers, and increasingly, a de facto requirement for healthcare IT vendors seeking to serve the Abu Dhabi market. The cost of non-compliance, regulatory sanctions, licence risk, PDPL fines, breach notification costs, and reputational damage, far exceeds the cost of a properly resourced ADHICS implementation programme. If you are a DOH-licensed healthcare facility or a healthcare IT vendor serving Abu Dhabi clients, the following priorities will position you for sustainable ADHICS compliance:
Conduct a formal ADHICS gap assessment against all 19 domains, do not attempt to build a compliance programme without first understanding your current control baseline and priority gaps relative to your DOH inspection timeline.
Appoint a qualified ISO with appropriate authority and direct access to senior management, information security governance without an empowered ISO consistently fails at the implementation stage.
Schedule your annual penetration test 6 months before any DOH inspection deadline, critical findings take time to remediate, and last-minute test scheduling is the most common cause of avoidable inspection failures.
If you are a healthcare IT vendor, proactively prepare an ADHICS Domain 10 evidence pack, security questionnaire responses, penetration test report, Data Processing Agreement template, incident notification SLA, before your first Abu Dhabi procurement process, not during it.
Consider pursuing ISO 27001 certification in parallel with ADHICS implementation, the 70% control overlap makes dual pursuit significantly more cost-effective than sequential implementation, and ISO 27001 certification provides ongoing independent validation of your ISMS maturity beyond the DOH inspection cycle.