We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / UAE compliance

UAE compliance

ADHICS v2 for a Clinic: Three Tiers, a 24-Hour Clock and What the DoH Auditor Asks

ADHICS v2 compliance for an Abu Dhabi clinic: which tier applies, what the 24-hour breach notice means, and what the DoH auditor asks at renewal.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programs2 September 2026 · 6 min read

The renewal notice mentions a standard nobody has heard of

The operations manager of a 12-chair dental centre in Khalifa City opens the DoH licence-renewal pack on a Sunday morning. Most of it is familiar: staff licences, the sterilisation log, the radiation safety certificate. One line is new. It asks for evidence of compliance with ADHICS, with a reference number and a section list.

She calls the IT company that installed the network in 2021 and looks after the practice-management server. The account manager has not heard of it. He offers a "security scan" for AED 1,500.

She calls the practice-management software vendor. They say the software is "fully compliant" and send a two-page brochure. It does not mention the DoH.

By Tuesday she has learned three things. The standard applies to the centre, not to the vendor. It has tiers, and she does not know which one the centre is in. And there is a clause about telling the DoH within 24 hours if patient data is exposed, which nobody in the building would recognise as their job at 6 p.m. on a Thursday.

The renewal is due in seven weeks. The chief dentist asks her one question: "Is this a form, or is this a project?"

It is a project. A manageable one, if she starts this week.

ADHICS, in plain words

ADHICS is the Abu Dhabi Healthcare Information and Cyber Security Standard. Version 2.0 is the current one. It is the DoH's rulebook for how any organisation that creates, stores or processes health information in the emirate protects that information.

Health information: anything about a patient's care, from the X-ray to the appointment note to the insurance claim.

Tier: the level of controls you must evidence. Basic, Transitional and Advanced, assigned by the DoH according to the type and size of your facility.

Control domain: a group of related requirements, such as access control, asset management, third-party security or incident management. There are eleven.

Evidence: the document, screenshot or log that proves a control is in place. The auditor does not take your word for it; the auditor takes the evidence.

The 24-hour notification: if health information is exposed, the DoH must know within a day. That is not a suggestion in an appendix; it is a clause with a clock.

None of this asks a clinic to become a technology company. It asks the clinic to know where patient data lives, who can reach it, and what happens on the day something goes wrong. A good practice already does the first two for medicines. This is the same discipline, applied to data.

The numbers that matter

ADHICS v2.0 took effect in August 2024 with three tiers, Basic, Transitional and Advanced, eleven control domains, and a 24-hour breach notification window, according to the Department of Health Abu Dhabi's 2024 standard. The window is the part most small facilities have not planned for.

The standard applies to every entity that creates, stores or processes health information in the emirate, with no size exemption, under DoH ADHICS v2.0. A two-dentist clinic and a 300-bed hospital are both inside the scope; the tier is what differs.

Compliance is checked at licensing, at renewal and at periodic audit, per the DoH's 2024 guidance. That is why the line appeared in the renewal pack, and why it will appear again.

What to do this week

  1. Confirm your tier. Ask the DoH, or your licensing consultant, which classification your facility carries, and get it in writing before you build anything. (CIS 3 Data Protection)
  2. Draw the patient-data map: the practice-management system, imaging workstations, the lab portal, the insurance claims tool, the WhatsApp group reception uses for recalls. If it touches a patient record, it goes on the list, and so does the vendor behind it, with their ADHICS or ISO 27001 position noted in writing. (CIS 3 Data Protection)
  3. Clean up access. Every staff member gets their own login, shared front-desk passwords go, leavers are removed the same day, and the chief dentist is not using the admin account for daily work. (CIS 6 Access Control Management)
  4. Write the 24-hour page: who decides an event is a reportable exposure, who calls the DoH, who calls the software vendor, and where the phone numbers live. Rehearse it once with the front desk. (CIS 17 Incident Response Management)
  5. Train the staff on the two things that cause most exposures: a convincing email and a shared password. Keep the attendance list; it is evidence. (CIS 14 Security Awareness and Skills Training)

Where AccuSights fits

Our assessment maps your clinic against ADHICS v2.0, your tier and the DoH's own evidence expectations, and hands you a ranked list rather than a findings dump. The read-only compliance agent then keeps the picture current: read-only insight into where the gaps are, so you can prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where. Customised, scored security awareness and phishing training for your staff is part of the engagement, without add-on charges per module.

Questions people ask

Which ADHICS tier applies to a small clinic? The DoH assigns the tier by the type and size of the facility, not by how much IT you have. A single-specialty clinic or dental centre usually sits in the Basic tier, while multi-site groups and hospitals move into Transitional or Advanced. Confirm your classification with the DoH rather than assuming, because the tier decides how many of the controls you must evidence.

Is ISO 27001 enough for ADHICS? It helps, and it is not the same thing. ISO 27001 gives you the management system and most of the technical controls ADHICS expects, so a certified clinic has a head start. ADHICS adds health-specific requirements, the 24-hour DoH notification and the tier structure, and the DoH audits against ADHICS, not against your ISO certificate. Map one to the other once and keep both current.

How long does ADHICS implementation take? For a Basic-tier clinic that already has decent IT, expect three to six months from first gap assessment to an evidence file the DoH can review. Most of that time goes to policy writing, access clean-up and staff training rather than buying equipment. Larger facilities in the Advanced tier should plan for a year.

A patient trusts you with an X-ray the way they trust you with a needle. Handle the record with the same care, and the renewal pack becomes paperwork instead of a scare.

Questions people ask

Which ADHICS tier applies to a small clinic?

The DoH assigns the tier by the type and size of the facility, not by how much IT you have. A single-specialty clinic or dental centre usually sits in the Basic tier, while multi-site groups and hospitals move into Transitional or Advanced. Confirm your classification with the DoH rather than assuming, because the tier decides how many of the controls you must evidence.

Is ISO 27001 enough for ADHICS?

It helps, and it is not the same thing. ISO 27001 gives you the management system and most of the technical controls ADHICS expects, so a certified clinic has a head start. ADHICS adds health-specific requirements, the 24-hour DoH notification and the tier structure, and the DoH audits against ADHICS, not against your ISO certificate. Map one to the other once and keep both current.

How long does ADHICS implementation take?

For a Basic-tier clinic that already has decent IT, expect three to six months from first gap assessment to an evidence file the DoH can review. Most of that time goes to policy writing, access clean-up and staff training rather than buying equipment. Larger facilities in the Advanced tier should plan for a year.

Controls this post maps to

CIS 3 Data ProtectionCIS 6 Access Control ManagementCIS 17 Incident Response Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.