ADHICS Compliance in Abu Dhabi

ADHICS is the mandatory information and cyber security standard for healthcare in Abu Dhabi. Here is what it expects, who it applies to, and how security testing delivers the audit evidence.

Comprehensive security assessment by Rootsec

What is ADHICS?

ADHICS — the Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health — is mandatory for healthcare providers, insurers and their service partners operating in Abu Dhabi. It defines controls across governance, human resources, asset management, access control and — crucially — technical security, and it expects those controls to be demonstrated, not just documented. ADHICS compliance is checked through audits, and evidence of security testing is one of the strongest artefacts you can put on the table.

Who must comply with ADHICS?

Hospitals & clinicsEvery licensed healthcare facility in the emirate, from hospital groups to single-specialty clinics.
Insurers & TPAsPayers and claims administrators handling member health data.
Healthcare IT & suppliersEMR vendors, labs, telehealth platforms and any service provider touching health information.

What the ADHICS standard expects on security testing

The standard requires organisations to identify technical vulnerabilities and to verify that controls actually work. In practice that means periodic vulnerability assessment and penetration testing (VAPT) of the systems that process health information — patient portals, EMR integrations, internal networks — plus remediation and retesting. Reports should map findings to the ADHICS control set, so your auditor can trace evidence directly.

The practical route to ADHICS compliance evidence:

  • Scope the systems that store or process health information
  • Run a VAPT with reporting mapped to ADHICS controls
  • Remediate, then retest — the retest report is your audit evidence
  • Repeat annually and after major system changes

The full standard is published by the Department of Health Abu Dhabi. For how ADHICS sits next to the other UAE frameworks, see our UAE cybersecurity compliance guide.

Related guides and services

Frequently asked questions

Quick answers on the Abu Dhabi healthcare standard.
What does ADHICS stand for?

ADHICS stands for the Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health Abu Dhabi.

Is ADHICS compliance mandatory?

Yes — for licensed healthcare providers, insurers and their service partners operating in Abu Dhabi.

Does ADHICS require penetration testing?

The standard requires organisations to identify technical vulnerabilities and verify controls, which in practice means periodic VAPT with remediation and retesting.

How often should ADHICS security testing happen?

At least annually, and after significant changes to systems that process health information.

Next step

Need ADHICS audit evidence?

Book a free 30-minute strategy call. You get clarity on scope, approach and a fixed price — no obligations.