Blog / UAE compliance
UAE compliance
ADHICS v2 for an Abu Dhabi Clinic: Triage the Control List, Then Start With Six Things
ADHICS v2 for an Abu Dhabi clinic: how to triage a long control list, the six things a small facility does first, and what evidence the DoH expects.
The consultant leaves a control list on the reception desk
The quality and patient safety officer of a two-site family medicine and physiotherapy clinic, one in Al Reem Island and one in Mussafah, is handed a printed control list by a consultant on a Sunday morning. It runs to dozens of pages. She flicks to the middle and reads a line about cryptographic key management, then another about media disposal.
She asks the sensible question. Which of these do we do first?
The consultant says all of them, and quotes for a project.
She is a clinician by training, so she recognises what she has been handed. It is a list of every possible condition, with no triage. In a clinic you do not treat in the order the textbook prints; you treat by severity, by what threatens the patient in the next hour, then by what threatens them next month. A control list works the same way, and nothing in ADHICS says you must implement it alphabetically.
The clinic has twenty-two staff, one practice management system, an imaging workstation, a laboratory portal, an insurance claims tool and a WhatsApp group reception uses for appointment recalls. The renewal is in the spring.
By Thursday she has a one-page plan with six items on it. That plan is worth more than the consultant's quotation, and it costs a morning.
ADHICS, in plain words
ADHICS is the Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health. Version 2.0 is current. It applies to organisations that create, store or process health information in the emirate, with the depth of what you implement set by the tier the DoH assigns to your facility.
Health information: anything about a patient's care. The radiograph, the appointment note, the insurance claim, the recall message on WhatsApp.
Control: a required practice, such as giving every user their own account or keeping a recoverable copy of clinical data. Grouped into domains covering areas like access, assets, third parties and incidents.
Tier: the classification the DoH assigns, which decides how much of the standard you must evidence. Ask for it in writing. Do not infer it from your bed count.
Evidence: the dated artefact that shows a control is real. A reviewer does not accept a description; a reviewer accepts an export, a screenshot, a signed policy, a training sheet.
The falcon on the glove is not looking at more of the desert than you are. It is looking at one thing in it, clearly, while everything else stays background. That is exactly the discipline a long control list asks for: sight and focus, one item singled out from the noise, then the next.
The numbers that matter
ADHICS v2.0 was issued by the Department of Health Abu Dhabi in 2024 with a tiered control structure, so the same standard asks different depths of a single-specialty clinic and a hospital group, per the DoH's 2024 standard. Your tier is the first fact to establish, because it sets the size of everything that follows.
Healthcare recorded 1,438 confirmed breaches in the Verizon 2026 Data Breach Investigations Report. The pattern in that data is ordinary rather than exotic: exposed credentials, unpatched systems and third parties, which is precisely what the early ADHICS controls address.
Implementation Group 1 of the CIS Controls, 56 safeguards in total, defends against 77% of attack techniques overall and 78% of ransomware techniques according to the CIS Community Defense Model v2.0. That is the arithmetic behind triage: a small, correct first tranche does most of the protective work, and it maps cleanly onto the ADHICS domains a small clinic starts with.
What to do this week
- Get your classification in writing from the DoH or your licensing consultant, and file the email. Everything you plan afterwards is sized by that answer, and an assumption here is expensive to correct in month four. (CIS 3 Data Protection)
- Draw the health information map on one page: the practice management system, the imaging workstation, the laboratory portal, the claims tool, the recall group, the reception PC where somebody keeps a spreadsheet of no-shows. If a patient can be identified from it, it goes on the map. (CIS 3 Data Protection)
- Give every person their own login. Remove the front desk shared password, remove leavers the day they leave, and stop the medical director from using an administrator account for daily clinical work. Export the user list afterwards, because that export is your evidence. (CIS 6 Access Control Management)
- Switch on multi-factor authentication for email and for any remote access to the clinic's systems, and choose a method that takes a clinician seconds rather than a minute. A second factor that slows a consultation will be worked around by Thursday. (CIS 6 Access Control Management)
- Take one backup copy offline or into an account your daily administrator cannot delete, then restore the practice management database into a test space and time it. Write the date and the number of minutes on a sheet and sign it. Nobody knows their restore time until they measure it. (CIS 11 Data Recovery)
- List every vendor that touches patient data, with a named contact, what they hold, and the clause in their contract that tells you when something goes wrong at their end. Send a short addendum to the ones with no clause. (CIS 15 Service Provider Management)
Where AccuSights fits
Our assessment maps your clinic against ADHICS v2.0 at your tier, alongside the other rules a UAE health facility carries, and returns a ranked plan rather than a findings dump. The read-only compliance agent then keeps the picture current, giving you continuous insight into where the gaps are and visibility across your cloud and infrastructure, so you can prioritise and keep an eye on what matters. We have no access to your systems and we do not remediate. You or your IT partner fix, and we show you exactly where. Read more about how we work with clinics in Abu Dhabi and what ADHICS asks for.
Questions people ask
Where should a small clinic start with ADHICS v2? With the two documents that everything else depends on: your confirmed classification from the DoH, and a written map of where health information lives, including the systems nobody thinks of as clinical. Almost every control in the standard asks a question about a system or a person, and you cannot answer for systems you have not listed. Clinics that start with policy writing instead of the map end up rewriting the policies.
Do we need to buy security products to satisfy ADHICS? Far less than vendors suggest. The early controls are about knowing what you have, deciding who may reach it, keeping a copy you can restore, and being able to show that these things are true. Most small facilities already own the licences for named accounts, multi-factor authentication and encrypted backup inside the software they pay for, and the work is configuration and evidence rather than procurement.
How do we prove a control to the DoH? With something dated that a third person can read: an exported user list, a screenshot of a setting, a signed policy with a review date, an attendance sheet from training, a restore test log with the time it took. The pattern that holds up is one folder per control domain, each item dated and owned by a named person, updated when the system changes rather than the week before a review.
You already triage patients by severity every morning. Give the control list the same courtesy, and the standard becomes a schedule instead of a wall.
Questions people ask
Where should a small clinic start with ADHICS v2?
With the two documents that everything else depends on: your confirmed classification from the DoH, and a written map of where health information lives, including the systems nobody thinks of as clinical. Almost every control in the standard asks a question about a system or a person, and you cannot answer for systems you have not listed. Clinics that start with policy writing instead of the map end up rewriting the policies.
Do we need to buy security products to satisfy ADHICS?
Far less than vendors suggest. The early controls are about knowing what you have, deciding who may reach it, keeping a copy you can restore, and being able to show that these things are true. Most small facilities already own the licences for named accounts, multi-factor authentication and encrypted backup inside the software they pay for, and the work is configuration and evidence rather than procurement.
How do we prove a control to the DoH?
With something dated that a third person can read: an exported user list, a screenshot of a setting, a signed policy with a review date, an attendance sheet from training, a restore test log with the time it took. The pattern that holds up is one folder per control domain, each item dated and owned by a named person, updated when the system changes rather than the week before a review.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
The NABIDH Connection Audit: What a Dubai Clinic Is Asked, in the Order It Is Asked
The NABIDH connection audit for a Dubai clinic, in the order the DHA asks: facility identity, EMR interface, consent, access control, audit trail and evidence.
UAE complianceADHICS v2 for a Clinic: Three Tiers, a 24-Hour Clock and What the DoH Auditor Asks
ADHICS v2 compliance for an Abu Dhabi clinic: which tier applies, what the 24-hour breach notice means, and what the DoH auditor asks at renewal.
UAE complianceNABIDH Compliance for a Dubai Clinic: Access, Consent and the Audit Trail You Have to Prove
NABIDH compliance for a Dubai clinic: what the DHA expects on access control, patient consent and audit trails, and why connecting your EMR is only the start.
