Basic
The absolute minimum essentials of information security, applicable to every entity in scope.

Regulation · Abu Dhabi healthcare
The Abu Dhabi Healthcare Information and Cyber Security Standard binds every entity that generates, accesses, stores, uses, processes or transmits health information in Abu Dhabi. Version 2 was published in May 2024 and took effect in August 2024.
Healthcare facilities, payers, and healthcare technology and service providers alike. Size does not exempt anyone: small clinics are in scope. What changes with size is which categories of control you must meet.
The absolute minimum essentials of information security, applicable to every entity in scope.
High-priority controls that strengthen the security posture. Required of hospitals with 1 to 20 beds and diagnostic centres, on top of Basic.
Required of hospitals with 21 beds or more, the Malaffi health information exchange, payers, insurers and third-party administrators, on top of Basic and Transitional.
A dedicated category for external entities providing healthcare technology and services.
Every category shares one deadline: within six months of official programme induction or of the standard’s release, whichever comes first. Entities keep a roadmap and report compliance status to the Department of Health.
The standard requires an annual audit programme to verify compliance, and an independent audit after any significant change. The Department of Health’s own guidance makes compliance a prerequisite for onboarding to Malaffi, and ties it to audit and licence registration and renewal.
Health data must also stay in the UAE under Federal Law 2/2019, which shapes how any assessment is delivered.
An ADHICS readiness assessment: we confirm which categories apply to you, assess each applicable control against evidence, produce a prioritised gap list and a roadmap you can share with the Department of Health, and brief your governance committee. The work is designed so that patient data never leaves your environment.
See our healthcare information security service for scope and approach.
We never assess work we have advised on, and we never sell the fix for anything we assess. Where a framework requires a licensed or accredited assessor, we say so and tell you who can sign it.
Yes. Version 2 applies to healthcare technology and service providers that handle Abu Dhabi health information, through a dedicated Service Provider control category.
The standard requires an annual audit programme, and an independent audit whenever there is a significant change to the operating environment.
Hospitals with 1 to 20 beds and diagnostic centres must meet the Basic and Transitional controls. Hospitals with 21 beds or more, payers and the Malaffi exchange must also meet the Advanced controls.
Checked 30 September 2026. Nothing on this page is legal advice; the standard as published by the Department of Health is the authority.
Tell us your facility type, bed count and where you are in the Department of Health programme.