Qualysec
Blog

What Is ADHICS Compliance? Complete Guide, Checklist & Benefits

ADHICS Compliance is required in the UAE to stop healthcare breaches. We help facilities implement security controls, pass DoH audits, and stay compliant.

Published on July 22, 2026
Read Time: 12 min
CONNECT WITH US

In the UAE, cyberattacks on healthcare facilities surged 37% in 2024, with ransomware incidents rising 45% amid the expansion of digital health adoption. DoH specifically requires all licensed clinics, hospitals, and other health centres to adhere to ADHICS Compliance to ensure that patient information remains confidential, correct, and accessible. The ADHICS standard also aligns with the national cybersecurity plans of the UAE, particularly in health IT. More facilities will transition to compliance, which can lower the risk of breaches for those that comply.

Defining ADHICS Compliance

ADHICS asks hospitals and other health centres in Abu Dhabi to adopt 692 security rules in 11 categories so as to ensure the safety of medical information. Since 2019, the Department of Health – Abu Dhabi (DoH) has operated this program and updates according to 2026 threats. Compliance by facilities is Basic, Transitional, or Advanced, depending on size and risk.

Why Get ADHICS Compliance in the UAE 2026?

ADHICS Compliance is being driven by the healthcare cybersecurity compliance framework in the UAE due to a survey of the largest hospitals in 2025. According to DoH data, institutions that comply with the requirements of ADHICS can reduce the time required to respond to security incidents by half and thus become more resilient. This compliance also allows the providers to access services like Malaafi and Shafafiya with ease.

The Federal Law No. 2 of 2019 of the UAE requires ADHICS. Failing to adhere to it by a facility may make it face the loss of its license, as well as millions of AED in fines, by 2026. ADHICS-certified facilities are expected to achieve more patient trust.

Who Needs to Follow ADHICS Compliance?

All hospitals, clinics, health centres, pharmacies, and insurers licensed by the DoH in Abu Dhabi have to do so. Basic and Transitional rules apply to small hospitals with 1120 beds, all Advanced rules apply to large hospitals with 21 or more beds, and to insurers.

A small clinic consisting of a single doctor is required by the minimum basic rules, such as controls to safeguard against significant threats. This compliance covers any third-party vendor that has contracts with Abu Dhabi health data through supplier contracts. Medical device makers and the IT partners will also be covered by the rules in 2026.

Are you prepared to defend your healthcare operations? Request assistance with ADHICS Compliance with the help of the experts – contact Qualysec Technologies!

Struggling with ADHICS Compliance? We Can Help.

Our compliance experts help you achieve and maintain ADHICS certification — from gap assessment to remediation to final audit support.

Book Your Assessment Now

compliance

What Are the 11 Domains of the ADHICS Standard?

What Are the 11 Domains of the ADHICS Standard

1. Health IT Standards and Policies

Three levels govern healthcare institutions: the Information Security Governance Committee (ISGC) manages strategy, Health Information Infrastructure Protection (HIIP) monitors operations, and the Information Security Group (ISG) performs daily tasks. Together, they create over 15 policies covering acceptable use, passwords, and remote access, while annual reviews and board approvals hold everyone accountable.

2. Human Resource Security

Background checks and NDAs are done on new employees of the company. All employees go through compulsory cybersecurity education every year, which addresses phishing and data management. On leaving, an exit interview is conducted. The same protection is enjoyed by the contractors.

3. Asset Management

The organisation puts all assets such as medical devices, servers, patient data, etc. on the list and labels them Public, Internal, Confidential or Secret. Owners are responsible for and monitor the entire life of the asset. The inventories are updated at least once a year. Disposal regulations and labels prevent leakage. This space is used to provide risk-based protection on valuable health IT assets.

4. Access Control

Have multi-factor authentication (MFA) on all logins and role-based access control (RBAC). Limit privileged accounts to privileged users and log privileged users. Breaks and imposes password policies. Check access every quarter. The Department of Health (DoH) audits MFA, while providers connect scalable controls to LDAP.

5.Cryptography

Stored data is encrypted using AES-256, and data transit is secured using TLS 1.3. Adhere to FIPS standards of key management, and the keys remain within the UAE. Demand certificate pinning and safe protocols. This ensures that sensitive health data is not intercepted. The providers switch keys annually and audit their crypto systems.

6. Environmental and Physical Security

Install CCTV, access cards and alarm systems. Use climate control, fire suppression and backup power for servers. Record visitor lists and implement a no-desk policy to reduce the risks. Fence off the off‑site storage. This safeguards against theft and calamities. During licensing, DoH inspectors are involved. Providers do yearly drills.

7. Operations Security

Install antivirus, repair vulnerabilities within 30 days, and test backups after every quarter. Malware scan and record findings in order to identify issues. Split duties to stop fraud. This region makes defence common practice. SIEM tools help the providers monitor activity. ADHICS needs 99% uptime and good operations.

8. Communications Security

Use VPNs to work remotely, secure networks, use firewalls, and store data in UAE-only clouds. Separate health data flows. Encrypt emails and APIs. Look at undesirable data exports. This secures the avenues of transmission. The providers are under TRA rules and ADHICS.

9. System Maintenance, Acquisition, Development

Integrate security in the software life cycle – perform threat modelling, code reviews, and use secure code. Alterations with penetration testing. Shut down old systems safely. This allows new systems to be resistant to attacks. DevSecOps pipelines are utilised by providers to match ADHICS.

10. Supplier Relationships

Vendors of checks are reviewed with a Service Level Agreement (SLA) and annual auditing. Need NDAs and ADHICS requirements. Observes performance everywhere. This provides third-party security. DoH can hold providers responsible for breaches by vendors.

11. Information Security Incident Management

Develop response plans for incidents and submit to the Department of Health Certificate of Registration (CERT) within 24 hrs. Classify, imprison, and eradicate threats. Look back on incidents later to become stronger. Train works with simulated situations. This minimises losses in case of breaches.

How to Get ADHICS Certification?

The first step is to verify gaps with the 692 rules by the health providers. Then they develop a roadmap, establish policies, and conduct internal audits. Following that, a DoH audit occurs. Reports and AAMEN are also audited by DoH on an annual basis.

The steps required to be followed to ADHICS Certification are –

  • Determine what kind of organisation you have and what level of control you require.  
  • Establish an ISGC, HIIP and ISG governance pyramid.  
  • Evaluate risks of assets, including patient records and devices.  
  • Implement some simple policies, such as access control and backups.  
  • Complete the ADHICS audit and provide reports to DoH.
  • Become certified and network with Malaafi.

What does the ADHICS Compliance Checklist Cover?

Governance and Policies

  • Take note of meetings by selecting a HIIP.  
  • Develop policies, including password policies and remote access, of at least 15.

Risk and Asset Management

  • Use Secret assets when dealing with highly sensitive data or Confidential assets when dealing with regular patient records.
  • Conduct a risk assessment on an annual basis.

Technical Controls

  • The technical controls were SOX standard controls concerning the process of technological advancement and its potential benefits.
  • MFA, Data encryption, and antivirus software.  
  • Conduct a list of all medical devices and systems.  

Operations and Incident Response

  • Backups of the test should be performed quarterly, and the incidents reported to DoH CERT.  
  • Educate personnel annually on phishing and other forms of detectable attacks.

Advanced Additions

  • Establish a security operations centre (SOC) and audit the suppliers.  
  • Continue to monitor the issues of frequent vulnerability checks.  
  • Track progress using DoH templates, and achieve total basic compliance in six months.

Need a Real Penetration Testing Report Sample Today?

See exactly how security experts document vulnerabilities, risks, and remediation steps in a professional pentest report.

Download Sample Report

Pentest Report

How Qualysec May Assist You in ADHICS Compliance

Expert Roadmap Development

Qualysec Technologies develops bespoke roadmaps within two weeks. Our experts will ADHICS audit your facility against the 692 controls, identify gaps in the 11 areas, and the steps will be classified as Basic and Advanced. You receive phased plans that will enable you to become certified in a short period of time.

Proven Process-Based Testing Excellence

Now a CREST Accredited Penetration Testing Company, Qualysec implements comprehensive and repeatable tests, which simulate actual attacks. Testers verify all the ADHICS controls and provide evidence-based reports. We rely on automated scans and manual hacking and keep up with the requirements of the ADHICS, like multi-factor authentication and encryption.

Healthcare System Penetration Testing

Qualysec performs network tests, medical equipment tests, and Malaffi integration tests. We detect zero-day errors before the DoH audit and minimise vulnerability to breaches. Reports contain the details of the exploit, what should be fixed, and evidence that is in accordance with DoH rules.

Risk Assessments Adapted to UAE Threats

Qualysec has annual risk testing on assets such as patient records (confidential class). Our data classification, phishing analysis, and risk mitigation plans are the predictions used to 2026.

Full ADHICS Audit Preparation

Qualysec conducts simulated audits that resemble DoH. You provide prepared dashboards containing governance documents, logs, and policy templates. We have an excellent success rate on the first time round and thus ensure easy ADHICS Certification.

Governance and Policy Implementation

Qualysec constructs your ISGC, HIIP, and ISG layers. We maintain over 15 policies including password management, remote access, data backups, and mandatory annual staff training.

Technical Controls Implementation

Qualysec implements antivirus, quarterly backups, and UAE-only cloud services. More complex solutions would be to establish an SOC and supplier NDAs.

Constant Support and Re-Verification

Qualysec provides post-certification checks and annual re-tests. We search for new threats, refer to 2026 requirements, and maintain ADHICS in compliance.

Get smooth ADHICS Compliance now with Qualysec – book your free evaluation today!

Speak Directly With Qualysec’s
Certified Security Experts

Discover vulnerabilities before attackers exploit them

Schedule Free Consultation

Security Expert

Conclusion

ADHICS Compliance will keep the health services of Abu Dhabi out of the increasing insecurity in 2026, providing the necessary security and establishing trust. When the providers adopt the 692 controls, they are more robust, more functional, and remain above regulations. Compliant facilities reduce incidents and prevent fines worth millions. Today, concentrate on compliance to ensure that your operations are secure. Adoption of this ADHICS standard enables UAE health leaders to develop patient confidence and ensure the continuity of services.

Compliance with ADHICS is easy to achieve – contact Qualysec Technologies for experts who can be trusted!

FAQs

1. What is ADHICS compliance?

ADHICS Compliance is a code of conduct that health facilities in Abu Dhabi are supposed to adhere to. They have to implement 692 security controls in 11 areas that the Department of Health (DoH) requires. The rules address issues such as the regulation of data, data access, encryption, and managing events. Depending on the size of their facilities, small clinics will start at the Basic level and then Transition and Advanced levels, i.e., 328 basic controls. The standard protects patient information to ensure it remains secure, confidential, and accessible in 2026.

2. Why is ADHICS compliance important?

The importance of this compliance is that it reduces the possibility that a breach can occur. It safeguards patient information and complies with the UAE federal law provisions, as hacking is increasing. It also fosters trust – patients will give preference to certified providers. ADHICS also provides easy data dissemination on Malaffi and Shafafiya, avoiding the loss of a license and massive fines. Health leaders implement it to have better security.

3. Which organisations must follow ADHICS compliance?

All DoH licensed facilities in Abu Dhabi, including hospitals, clinics, centers, and pharmacies, must follow this compliance, though specific rules vary by facility size. Hospitals having 1 to 20 beds should use Basic plus Transitional controls, and all 21 and above hospitals and insurers should utilise Advanced controls. Small single-doctor clinics adhere to minimum rules. Health data vendors must also comply, typically through supplier clauses. Similarly, medical device manufacturers and ICT partners collaborating with the ADHICS system fall under these rules in 2026.

4. How does ADHICS compliance improve cybersecurity?

ADHICS implements tools such as multi-factor authentication, encryption, and rapid response to incidents that have helped reduce incidents and decrease downtime. Facilities catalogue all the assets, evaluate risk, and educate the staff to combat phishing. The 11 areas provide good business operations, scrutinised suppliers, and no transfer of data to the outside of the UAE. On the Advanced level, there is a security operations centre monitoring and vulnerability scans. The ADHICS audit operation is in line with the 2026 threats of AI and reduces recovery expenses by half. Facilities enhance policy for physical security.

5. Is ADHICS compliance mandatory in Abu Dhabi?

Yes. The DoH requires this compliance to issue licenses, grant access to Malaffi, and conduct audits. Facilities that fail to comply risk heavy fines and license revocation. This healthcare cybersecurity compliance framework is obligatory according to Federal Law No. 2 of 2019 among all licensed providers. The DoH conducts frequent audits and requests corrective plans. In 2026, providers must inspect advanced facilities annually, create roadmaps, and provide evidence.ADHICS Certification opens platforms. A rise in breaches is very dangerous in health facilities that do not pay attention to ADHICS.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.