Blog / UAE compliance
UAE compliance
ADHICS v2 for a Clinic: Three Tiers, a 24-Hour Clock and What the DoH Auditor Asks
ADHICS v2 compliance for an Abu Dhabi clinic: which tier applies, what the 24-hour breach notice means, and what the DoH auditor asks at renewal.
The renewal notice mentions a standard nobody has heard of
The operations manager of a 12-chair dental centre in Khalifa City opens the DoH licence-renewal pack on a Sunday morning. Most of it is familiar: staff licences, the sterilisation log, the radiation safety certificate. One line is new. It asks for evidence of compliance with ADHICS, with a reference number and a section list.
She calls the IT company that installed the network in 2021 and looks after the practice-management server. The account manager has not heard of it. He offers a "security scan" for AED 1,500.
She calls the practice-management software vendor. They say the software is "fully compliant" and send a two-page brochure. It does not mention the DoH.
By Tuesday she has learned three things. The standard applies to the centre, not to the vendor. It has tiers, and she does not know which one the centre is in. And there is a clause about telling the DoH within 24 hours if patient data is exposed, which nobody in the building would recognise as their job at 6 p.m. on a Thursday.
The renewal is due in seven weeks. The chief dentist asks her one question: "Is this a form, or is this a project?"
It is a project. A manageable one, if she starts this week.
ADHICS, in plain words
ADHICS is the Abu Dhabi Healthcare Information and Cyber Security Standard. Version 2.0 is the current one. It is the DoH's rulebook for how any organisation that creates, stores or processes health information in the emirate protects that information.
Health information: anything about a patient's care, from the X-ray to the appointment note to the insurance claim.
Tier: the level of controls you must evidence. Basic, Transitional and Advanced, assigned by the DoH according to the type and size of your facility.
Control domain: a group of related requirements, such as access control, asset management, third-party security or incident management. There are eleven.
Evidence: the document, screenshot or log that proves a control is in place. The auditor does not take your word for it; the auditor takes the evidence.
The 24-hour notification: if health information is exposed, the DoH must know within a day. That is not a suggestion in an appendix; it is a clause with a clock.
None of this asks a clinic to become a technology company. It asks the clinic to know where patient data lives, who can reach it, and what happens on the day something goes wrong. A good practice already does the first two for medicines. This is the same discipline, applied to data.
The numbers that matter
ADHICS v2.0 took effect in August 2024 with three tiers, Basic, Transitional and Advanced, eleven control domains, and a 24-hour breach notification window, according to the Department of Health Abu Dhabi's 2024 standard. The window is the part most small facilities have not planned for.
The standard applies to every entity that creates, stores or processes health information in the emirate, with no size exemption, under DoH ADHICS v2.0. A two-dentist clinic and a 300-bed hospital are both inside the scope; the tier is what differs.
Compliance is checked at licensing, at renewal and at periodic audit, per the DoH's 2024 guidance. That is why the line appeared in the renewal pack, and why it will appear again.
What to do this week
- Confirm your tier. Ask the DoH, or your licensing consultant, which classification your facility carries, and get it in writing before you build anything. (CIS 3 Data Protection)
- Draw the patient-data map: the practice-management system, imaging workstations, the lab portal, the insurance claims tool, the WhatsApp group reception uses for recalls. If it touches a patient record, it goes on the list, and so does the vendor behind it, with their ADHICS or ISO 27001 position noted in writing. (CIS 3 Data Protection)
- Clean up access. Every staff member gets their own login, shared front-desk passwords go, leavers are removed the same day, and the chief dentist is not using the admin account for daily work. (CIS 6 Access Control Management)
- Write the 24-hour page: who decides an event is a reportable exposure, who calls the DoH, who calls the software vendor, and where the phone numbers live. Rehearse it once with the front desk. (CIS 17 Incident Response Management)
- Train the staff on the two things that cause most exposures: a convincing email and a shared password. Keep the attendance list; it is evidence. (CIS 14 Security Awareness and Skills Training)
Where AccuSights fits
Our assessment maps your clinic against ADHICS v2.0, your tier and the DoH's own evidence expectations, and hands you a ranked list rather than a findings dump. The read-only compliance agent then keeps the picture current: read-only insight into where the gaps are, so you can prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where. Customised, scored security awareness and phishing training for your staff is part of the engagement, without add-on charges per module.
Questions people ask
Which ADHICS tier applies to a small clinic? The DoH assigns the tier by the type and size of the facility, not by how much IT you have. A single-specialty clinic or dental centre usually sits in the Basic tier, while multi-site groups and hospitals move into Transitional or Advanced. Confirm your classification with the DoH rather than assuming, because the tier decides how many of the controls you must evidence.
Is ISO 27001 enough for ADHICS? It helps, and it is not the same thing. ISO 27001 gives you the management system and most of the technical controls ADHICS expects, so a certified clinic has a head start. ADHICS adds health-specific requirements, the 24-hour DoH notification and the tier structure, and the DoH audits against ADHICS, not against your ISO certificate. Map one to the other once and keep both current.
How long does ADHICS implementation take? For a Basic-tier clinic that already has decent IT, expect three to six months from first gap assessment to an evidence file the DoH can review. Most of that time goes to policy writing, access clean-up and staff training rather than buying equipment. Larger facilities in the Advanced tier should plan for a year.
A patient trusts you with an X-ray the way they trust you with a needle. Handle the record with the same care, and the renewal pack becomes paperwork instead of a scare.
Questions people ask
Which ADHICS tier applies to a small clinic?
The DoH assigns the tier by the type and size of the facility, not by how much IT you have. A single-specialty clinic or dental centre usually sits in the Basic tier, while multi-site groups and hospitals move into Transitional or Advanced. Confirm your classification with the DoH rather than assuming, because the tier decides how many of the controls you must evidence.
Is ISO 27001 enough for ADHICS?
It helps, and it is not the same thing. ISO 27001 gives you the management system and most of the technical controls ADHICS expects, so a certified clinic has a head start. ADHICS adds health-specific requirements, the 24-hour DoH notification and the tier structure, and the DoH audits against ADHICS, not against your ISO certificate. Map one to the other once and keep both current.
How long does ADHICS implementation take?
For a Basic-tier clinic that already has decent IT, expect three to six months from first gap assessment to an evidence file the DoH can review. Most of that time goes to policy writing, access clean-up and staff training rather than buying equipment. Larger facilities in the Advanced tier should plan for a year.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
NABIDH Compliance for a Dubai Clinic: Access, Consent and the Audit Trail You Have to Prove
NABIDH compliance for a Dubai clinic: what the DHA expects on access control, patient consent and audit trails, and why connecting your EMR is only the start.
Reputation and business riskLicence, Accreditation and Reputation: The Breach That Ends a Practice Without a Fine
Healthcare data breach consequences rarely arrive as a fine. They arrive as a conditional licence renewal, a delisted insurer network and referrals that stop.
ThreatsRansomware in a Clinic: What Nine Days Without the EHR Really Looks Like
Healthcare ransomware stops refills, referrals and the front desk, not just files. What nine days of EHR downtime looks like, and how a small practice prepares.
