Department of Health – Abu Dhabi (DoH) · United Arab Emirates (Abu Dhabi)

Abu Dhabi Healthcare Information and Cyber Security Standard, Version 2 compliance software

DoH's mandatory security standard for every licensed healthcare entity in Abu Dhabi — 11 domains and 131 controls in the standard's own words, graded Basic, Transitional and Advanced so a clinic and a hospital each see exactly the tier they are held to.

At a glance
  • RegulatorDepartment of Health – Abu Dhabi
  • InstrumentADHICS v2 (DOH/SD/ICSO/ADHICS/V2/2024) — effective August 2024
  • Structure11 domains, 45 control families, 131 controls
  • GradingBasic 58 · Transitional 40 · Advanced 33 · Service Provider flag
ADHICS v2Available
Overview

What ADHICS v2 requires

Who it applies to

  • Hospitals, day-surgery centres and clinics licensed by DoH Abu Dhabi
  • Pharmacies, laboratories, diagnostic and rehabilitation centres
  • Health insurers and third-party administrators
  • Healthcare Technology and Service Providers (EMR, HIS, PACS, telehealth, managed services)

The Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS) is issued by the Department of Health – Abu Dhabi under Federal Law No. 2 of 2019 and the Emirate's health data policy. Version 2 (DOH/SD/ICSO/ADHICS/V2/2024) took effect in August 2024 and binds every DoH-licensed hospital, clinic, pharmacy, laboratory, insurer and third-party administrator, as well as the Healthcare Technology and Service Providers that supply them. Compliance is audited by DoH and is a condition of licensing and of connection to Malaffi, the Abu Dhabi health information exchange.

Section B carries eleven control domains — Human Resources Security, Asset Management, Physical and Environmental Security, Access Control, Communications and Operations Management, Data Privacy and Protection, Cloud Security, Third Party Security, Information Systems Acquisition, Development and Maintenance, Information Security Incident Management and Information Systems Continuity Management — with 131 controls. Appendix 2 grades every control Basic (58), Transitional (40) or Advanced (33) and flags the ones that also bind Service Providers. Small entities are held to Basic and Transitional; large entities to all three.

GRCLens generates the catalogue from DoH's published PDF, so the domain names, control titles and sub-control text are the standard's own, and the Basic/Transitional/Advanced grade and Service Provider flag are carried on every control. An entity selects its size once and the questionnaire, dashboard and report scope themselves to the tier DoH will audit.

In the platform

How GRCLens supports ADHICS v2

ADHICS v2 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

The tier you are held to

Choose small entity, large entity or service provider and the assessment scopes itself: Basic and Transitional for a clinic, all three tiers for a hospital, the Service Provider rows for a vendor. Nothing is deleted when the choice changes.

Localisation as a finding

The five controls that carry Article 13 of the ICT Health Law — in-country hosting, UAE-domain email, no offshore development or support — are tracked as one indicator, because a miss there is a legal prohibition, not a maturity gap.

DoH's reporting clocks

Incident notification to the Abu Dhabi Health SOC, the 72-hour Data Breach Form and the 30-working-day evidence deadline are pinned to the controls that carry them and surface as a readiness indicator before anything happens.

Arabic and English

Every control, family and domain carries Arabic written to the standard's structure, so the CISO and the DoH auditor read the same enumerated sub-controls.

Questions

ADHICS v2 frequently asked questions

How is ADHICS different from the ICT Health Law?

Federal Law No. 2 of 2019 is the legal duty — confidentiality, localisation, retention, Central System access. ADHICS is DoH's technical standard for how an Abu Dhabi entity implements it, with 131 specific controls. GRCLens carries both as separate frameworks; a facility is assessed against each.

We are a small clinic. Do the Advanced controls apply?

No. DoH holds small entities to the Basic and Transitional tiers. Select 'small healthcare entity' and the 33 Advanced controls leave scope; select 'large' and they return, with their answers intact.

We supply software to hospitals. Which controls are ours?

Appendix 2 flags the controls that also bind Healthcare Technology and Service Providers. Select 'service provider' and the catalogue narrows to those rows.

Talk to us about ADHICS v2

Security Solution Consultants provides ADHICS and healthcare security advisory alongside the platform, so you can combine tooling with hands-on expertise.