Introduction: ADHICS Compliance UAE — Why It Matters
ADHICS compliance UAE has become a major cybersecurity priority for healthcare organizations operating in Abu Dhabi. The Abu Dhabi Department of Health (DoH) published the revised Abu Dhabi Healthcare Information and Cyber Security Standard, ADHICS V2, in May 2024, with the standard becoming effective in August 2024.
The standard applies to entities including healthcare facilities, payers, healthcare technology companies and service providers that generate, access, store, use, process or transmit health information in Abu Dhabi.
For healthcare organizations, the issue goes beyond protecting electronic medical records. ADHICS establishes requirements designed to strengthen information security governance, risk management, privacy, access controls, incident management and the secure use of healthcare technology.
What Is ADHICS and Who Must Follow It?
ADHICS stands for Abu Dhabi Healthcare Information and Cyber Security Standard. It is issued by the Department of Health – Abu Dhabi and forms part of the emirate’s broader AAMEN healthcare information security programme.
The DoH states that AAMEN is designed to help healthcare facilities comply with information security and data privacy standards while protecting the confidentiality, accuracy and availability of sensitive healthcare information. The DoH also identifies ADHICS V2 as the current version of the standard.
The scope of ADHICS V2 includes:
- Healthcare facilities and providers
- Payers and healthcare-related organizations
- Healthcare technology providers
- Healthcare service providers
- Entities that generate, access, store, process or transmit health information
This broad scope means cybersecurity responsibilities can extend beyond a hospital’s internal IT department to technology and service providers handling healthcare information on its behalf.
ADHICS Compliance UAE: Key Requirements
The central objective of ADHICS compliance UAE is to protect the confidentiality, integrity and availability of health information while managing information-security risks.
Organizations should establish appropriate controls covering areas such as:
- Cybersecurity governance and accountability
- Information-security risk management
- Access control and user privileges
- Data privacy and protection
- Secure communications and operations
- Asset and technology management
- Third-party and service-provider security
- Information-security incident management
- Business continuity and resilience
- Secure healthcare technology and information exchange
ADHICS V2 also replaced several earlier DoH security initiatives, including the previous ADHICS standard, the Internet of Medical Things security standard and the Patient Healthcare Data Privacy Standard.
Healthcare Data Security UAE and Data Retention
Healthcare data protection in Abu Dhabi also involves requirements for where information is stored and how long it is retained.
The DoH’s Data Storage and Retention Standard states that healthcare-sector data must comply with applicable data-sovereignty requirements. It further states that the minimum retention period for health data is 25 years under UAE Federal Law No. 2 of 2019.
This makes data lifecycle management an important part of medical data compliance UAE. Healthcare organizations should know what information they hold, where it is stored, who can access it, how it is protected and when it can legally be disposed of.
Organizations should also distinguish Abu Dhabi-specific requirements from Dubai healthcare requirements. The term “patient data protection Dubai” may be used in broader UAE searches, but ADHICS specifically concerns healthcare entities regulated by Abu Dhabi’s Department of Health.
Why ADHICS Requirements Matter for Healthcare Organizations
Healthcare systems hold highly sensitive information, including clinical records, diagnostic information, identification details and other information that could cause serious harm if improperly accessed or altered.
Weak security can create risks such as:
- Unauthorized access to patient records
- Theft or misuse of sensitive information
- Disruption of clinical systems
- Compromise of connected medical technology
- Loss of patient and public trust
- Regulatory and operational consequences
The DoH’s AAMEN programme specifically focuses on strengthening cybersecurity across Abu Dhabi’s healthcare sector and includes capabilities for cyber incident management, vulnerability assessment and threat intelligence.
ADHICS Compliance and Audits
Compliance is not simply a one-time documentation exercise. Organizations need evidence that security controls are implemented, monitored and maintained.
The DoH’s governance documentation states that regulated entities may be subject to periodic audits and technical assessments. It also calls for regular internal audits and assessments to verify the effectiveness of implemented controls and identify risks related to non-compliance.
Healthcare organizations should therefore maintain clear evidence covering policies, procedures, risk assessments, access reviews, security testing, incident response activities, staff awareness and third-party security controls.
For organizations reviewing other regulatory developments, the Laws & Government section provides additional cybersecurity and compliance coverage.
UAE Healthcare Compliance and Data Protection Laws
ADHICS operates alongside broader UAE laws and healthcare regulations. Organizations should avoid treating one framework as a replacement for all other legal obligations.
The UAE Personal Data Protection Law establishes requirements concerning the security, confidentiality and lawful processing of personal data. It also includes provisions relating to personal-data breaches and cross-border transfers. Importantly, the federal law states that personal health data covered by legislation regulating its protection and processing is outside its general scope, meaning healthcare organizations must consider the specific legislation and sector rules that apply to their operations.
The UAE’s official data-protection guidance provides additional information on the federal privacy framework.
How Healthcare Organizations Can Improve ADHICS Readiness
Organizations preparing for ADHICS compliance UAE should take a structured approach:
- Identify applicable requirements: Determine which ADHICS controls and healthcare regulations apply to the organization.
- Map healthcare information: Document where patient and health information is collected, processed, transmitted and stored.
- Review access controls: Apply least-privilege access and regularly review user permissions.
- Assess third parties: Evaluate vendors, cloud providers and technology partners that handle healthcare information.
- Test security controls: Conduct appropriate vulnerability assessments, security testing and technical reviews.
- Prepare incident procedures: Establish clear processes for detecting, investigating, containing and reporting cybersecurity incidents.
- Maintain compliance evidence: Keep policies, assessment results, audit records and remediation evidence organized and current.
- Perform continuous reviews: Reassess the security programme as technologies, threats and regulatory requirements change.
Organizations can also use CyberNexora’s Learn & Protect resources to follow broader cybersecurity best practices.
Key Takeaways
- ADHICS V2 was published by Abu Dhabi DoH in May 2024 and became effective in August 2024.
- The standard applies to a broad range of entities handling health information in Abu Dhabi.
- ADHICS compliance UAE covers governance, risk management, data protection, access control, incident management and other security areas.
- Abu Dhabi’s healthcare data-retention standard specifies a minimum 25-year retention period for health data.
- DoH conducts or requires audits and assessments as part of its regulatory oversight.
Conclusion: ADHICS Compliance UAE and What Happens Next
ADHICS compliance UAE should be treated as an ongoing cybersecurity programme rather than a checklist completed once. Healthcare organizations need to demonstrate that security controls are operating effectively and that sensitive information remains protected throughout its lifecycle.
As Abu Dhabi continues expanding digital healthcare, health information exchanges and technology-enabled services, organizations should regularly review their security controls, third-party risks, data-storage practices and audit readiness. The DoH’s official ADHICS and AAMEN resources should remain the primary reference for current requirements and implementation guidance.
Frequently Asked Questions(FAQs)
ADHICS is the Abu Dhabi Healthcare Information and Cyber Security standard governing how healthcare entities protect patient data and systems.
Health data must be stored within the UAE and retained for 25 years under healthcare regulations.
Hospitals, clinics, diagnostic centers, and health-tech platforms handling patient data in the UAE.
Healthcare breaches involve multiple overlapping laws and can reach the highest penalty tiers, up to AED 20 million for serious violations.
Through security assessments mapped to ADHICS and PDPL. Providers including CyberNexora offer a free initial gap check.
