العربية

Regulation · Abu Dhabi healthcare

ADHICS V2: what the Department of Health expects, and how to be ready

The Abu Dhabi Healthcare Information and Cyber Security Standard binds every entity that generates, accesses, stores, uses, processes or transmits health information in Abu Dhabi. Version 2 was published in May 2024 and took effect in August 2024.

Who it applies to

Healthcare facilities, payers, and healthcare technology and service providers alike. Size does not exempt anyone: small clinics are in scope. What changes with size is which categories of control you must meet.

The four control categories

All entities

Basic

Six months

The absolute minimum essentials of information security, applicable to every entity in scope.

Applies toEveryone
Smaller providers

Transitional

Six months

High-priority controls that strengthen the security posture. Required of hospitals with 1 to 20 beds and diagnostic centres, on top of Basic.

Applies toBasic + Transitional
Larger providers and payers

Advanced

Six months

Required of hospitals with 21 beds or more, the Malaffi health information exchange, payers, insurers and third-party administrators, on top of Basic and Transitional.

Applies toBasic + Transitional + Advanced
Suppliers

Service Provider

Six months

A dedicated category for external entities providing healthcare technology and services.

Applies toService Provider controls

Governance the standard expects to see

  • Information Security Governance Committee, headed by senior management: approves policy, oversees budget and reviews compliance reports.
  • Health Information Infrastructure Protection workgroup: coordinates implementation across functions and with the sector-level workgroup.
  • Chief Information Security Officer: leads the workgroup, owns the security architecture and is the single point of contact with the Department of Health.

Timelines, audit and Malaffi

Every category shares one deadline: within six months of official programme induction or of the standard’s release, whichever comes first. Entities keep a roadmap and report compliance status to the Department of Health.

The standard requires an annual audit programme to verify compliance, and an independent audit after any significant change. The Department of Health’s own guidance makes compliance a prerequisite for onboarding to Malaffi, and ties it to audit and licence registration and renewal.

Health data must also stay in the UAE under Federal Law 2/2019, which shapes how any assessment is delivered.

Where organisations usually fall short

  • An asset inventory that misses connected medical devices and third-party systems.
  • Governance on paper only: a committee that exists but has no minutes, reports or decisions to show.
  • Supplier and remote access that is not reviewed or time-limited.
  • Evidence that sits with individuals rather than in a form an auditor can sample.
  • Assessments that require exporting patient data, which the residency rule does not allow.

How we help

An ADHICS readiness assessment: we confirm which categories apply to you, assess each applicable control against evidence, produce a prioritised gap list and a roadmap you can share with the Department of Health, and brief your governance committee. The work is designed so that patient data never leaves your environment.

See our healthcare information security service for scope and approach.

Independence

We never assess work we have advised on, and we never sell the fix for anything we assess. Where a framework requires a licensed or accredited assessor, we say so and tell you who can sign it.

Questions we are asked

Does ADHICS apply to technology suppliers?

Yes. Version 2 applies to healthcare technology and service providers that handle Abu Dhabi health information, through a dedicated Service Provider control category.

How often must we audit ADHICS compliance?

The standard requires an annual audit programme, and an independent audit whenever there is a significant change to the operating environment.

Which controls apply to a 15-bed hospital?

Hospitals with 1 to 20 beds and diagnostic centres must meet the Basic and Transitional controls. Hospitals with 21 beds or more, payers and the Malaffi exchange must also meet the Advanced controls.

Primary sources

Checked 30 September 2026. Nothing on this page is legal advice; the standard as published by the Department of Health is the authority.

Start with a scoping call

Tell us your facility type, bed count and where you are in the Department of Health programme.