Blog Category

ADHICS v2 Compliance for Abu Dhabi Healthcare: What Changed & How to Get Ready

What ADHICS v2.0 requires of Abu Dhabi healthcare entities — who must comply, the control domains, your compliance timeline, and how to close the gaps.

Every hospital, clinic, insurer, and health-tech vendor operating in the Emirate of Abu Dhabi now sits inside the scope of a single, mandatory cybersecurity rulebook: the Abu Dhabi Healthcare Information and Cyber Security Standard, version 2.0 — ADHICS v2.0, issued by the Department of Health – Abu Dhabi (DoH). If your organisation stores, processes, or transmits health information in Abu Dhabi, ADHICS applies to you.

The first version of ADHICS was published in February 2019. Version 2.0 is a substantial update that raises the bar on governance, asset management, third-party risk, and incident response. This guide explains what ADHICS v2.0 is, who it covers, and the practical steps to reach and hold compliance.

What ADHICS v2.0 is — and who issues it

ADHICS is the healthcare-sector information security standard for Abu Dhabi, published and enforced by the Department of Health – Abu Dhabi. It is mandatory for regulated healthcare entities — a condition of operating, not a best-practice badge. It also sits alongside the UAE's broader data-protection and sector regulations, so a provider is typically navigating ADHICS together with DoH licensing conditions and national data-protection duties at once. ITSEC's DHA and health-sector regulatory practice maps these overlapping obligations so a single control set can satisfy more than one authority.

Who must comply

ADHICS v2.0 applies across the Abu Dhabi health ecosystem: healthcare providers (hospitals, clinics, labs, pharmacies), payers (insurers and third-party administrators), and the health-tech and service vendors that build, host, or operate systems touching patient data. The common thread is health information — if your systems hold it, you are in scope. Vendors often discover their obligations late, assuming the hospital carries the burden, when in reality the vendor's own controls are assessed as part of the provider's third-party risk posture. ITSEC's healthcare and telemedicine security practice works with exactly these platforms.

The control domains ADHICS measures you against

ADHICS is structured around governance and control requirements familiar to anyone who has worked with ISO/IEC 27001, with healthcare-specific expectations layered on top. A programme has to demonstrate maturity across governance and an information-security management structure; asset and information classification; access control and identity; third-party and supply-chain security; operations, resilience and incident response; and physical and environmental controls. The move from v1 to v2.0 sharpens expectations around third-party risk, resilience, and the evidence you must retain to prove a control actually operates — not just that a policy exists on paper.

Your compliance timeline

A recurring mistake is treating ADHICS as an exercise that starts when an assessment is scheduled. In practice, entities are expected to reach compliance within a defined window from official onboarding or release of the standard. That is less generous than it sounds: a mid-sized hospital has hundreds of systems and dozens of vendors, and discovery alone — building an accurate asset inventory and mapping where health data flows — can consume the first weeks. The organisations that pass cleanly start with an honest gap assessment, prioritise the highest-risk gaps, and run remediation as a managed programme with named owners and deadlines.

How to close the gap

Scope and inventory every system and third party that touches health information, and classify the data. Run a gap assessment against the ADHICS v2.0 control set. Remediate by risk — access control, third-party contracts, logging and backup usually top the list. Then prove the controls with technical testing: governance documents are necessary but not sufficient, and penetration testing and vulnerability assessment turn "we have a policy" into "we tested it, and here is the evidence." Finally, operationalise and monitor — compliance is a state you hold, not a certificate you frame.

Where ADHICS meets your other UAE obligations

Healthcare organisations in the UAE rarely face a single regulator. A group operating across emirates may manage ADHICS in Abu Dhabi, Dubai Health Authority requirements in Dubai, and national data-protection duties across the whole footprint. The efficient path is one control framework mapped to every authority you answer to. ITSEC's dedicated ADHICS v2 compliance practice does this mapping, and where a health-tech business also needs UAE corporate structuring or licensing support, our sister firm SecureVisa Group covers the licensing and regulatory setup side.

Talk to ITSEC about your ADHICS v2 readiness

ADHICS v2.0 is enforceable, healthcare-specific, and unforgiving of paper-only compliance. If you operate in Abu Dhabi's health sector — as a provider, a payer, or a vendor — the safest move is to know exactly where you stand before an assessor tells you. ITSEC runs ADHICS v2.0 gap assessments, remediation programmes, and the penetration testing that proves your controls work. Visit our ADHICS v2 compliance page to book a readiness assessment.

ITSEC UAE cybersecurity coverage map

Ready to Secure Your Digital Assets?

Get a comprehensive security assessment from our expert team. Protecting businesses since 2011.

Consult Cyber Experts
NDA Protected
24hr Response
Global Coverage
×

ITSEC Security Agent

AI-Powered • 24/7 Active

👋 Welcome to ITSEC – UAE's first AI-augmented cybersecurity firm.

I'm your AI Security Agent. How can I assist you with your cybersecurity needs today?
ITSEC AI
Secured by ITSEC AI • ISO 27001 Certified