Healthcare & Life Sciences
Three emirates. Three health regimes. One program.
A clinic group with sites in Abu Dhabi, Dubai and Sharjah answers to ADHICS, to DHA and NABIDH, and to MoHAP with Riayati, and in each case cybersecurity compliance is tied to the licence itself. We run all of it as one program, with your assessments on one calendar and your evidence collected once.
We are the GRC and compliance experts who pull it all together and make security look easy, so you can focus on actual security.
third-party and supply-chain compromise is the leading Middle East healthcare breach vector, which makes your EMR and practice-management vendors part of your risk
Source: IBM Cost of a Data Breach 2025
yearly growth of the UAE digital-health market to a projected $2.65B by 2030, and every new app widens the attack surface
Source: Grand View Research
ADHICS compliance operates as a precondition of facility licensing in Abu Dhabi
Source: Department of Health, Abu Dhabi
Why it feels harder than it should
Several rulebooks, one business.
Healthcare regulation in the Emirates maps to geography. Abu Dhabi’s Department of Health mandates ADHICS and participation in the Malaffi exchange. Dubai’s DHA runs NABIDH with its own standards, including ST-14 for telehealth, in force since November 2025. Sharjah and the Northern Emirates answer to MoHAP and Riayati. The federal health-data law adds localization duties, and Dubai Healthcare City layers free-zone rules on top. Every regime protects patients; every regime asks differently.
What this looks like in practice
A concrete case: a dental group with two Abu Dhabi clinics, one Dubai clinic and a telehealth service. Abu Dhabi requires ADHICS compliance and Malaffi connection as licensing preconditions. Dubai requires NABIDH participation, and the telehealth service brings ST-14 with ISO 27001 expectations. The federal law governs where all of that patient data may live. Four obligations, one patient record, and one AccuSights program covering the lot.
What actually hits healthcare
Verizon confirmed 1,438 healthcare breaches this year, and the pattern that never leaves the top three is the honest mistake: misdelivered records, wrong recipients, exposed files, with no attacker involved at all. In the Middle East the leading healthcare breach vector is your vendors: third-party and supply-chain compromise. The practice-management system shared across a hundred clinics is exactly the door attackers prefer.
third-party and supply-chain compromise leads Middle East healthcare breaches
Source: IBM Cost of a Data Breach 2025
of healthcare breach motives are financial. Patient data is currency
Source: Verizon 2026 DBIR
How they get in
Source: Verizon 2026 DBIR, Healthcare breach entry points
The authorities that reach this sector.
DoH
Department of Health, Abu Dhabi
Licenses Abu Dhabi healthcare and mandates ADHICS, the emirate’s healthcare information and cyber security standard, with Malaffi HIE participation.
DHA
Dubai Health Authority
Licenses Dubai healthcare, runs the NABIDH health information exchange, and sets standards including ST-14 for telehealth and health data.
MoHAP
Ministry of Health and Prevention
Federal health ministry; licenses providers in Sharjah and the Northern Emirates and runs the Riayati health information platform.
DHCC / DHCA
Dubai Healthcare City Authority
Free-zone regulator for providers inside Dubai Healthcare City, with its own licensing and data rules layered on Dubai requirements.
CBUAE
Central Bank of the UAE
Regulates banks, finance companies, exchange houses, payment providers, stored-value facilities, and insurers, with information security and consumer data duties throughout.
Your regulators, sector by sector
Find yourself in the list.
We cover every name on it.
Hospitals and multi-specialty clinics
- Focus
- ADHICS or NABIDH controls, health information exchange onboarding security, ransomware and patient-data protection, connected medical device security, breach notification duties.
- Standards
- ADHICS v2, NABIDH or Riayati; federal health-data law; PDPL.
- Certification
- Yes: ADHICS compliance and exchange security assessment are licensing preconditions.
- Rhythm
- Assessment aligned to licence renewal; breach notification on tight regulator clocks.
Dental and specialist clinics
- Focus
- ADHICS Basic tier, imaging and record protection, exchange connection, phishing and ransomware resilience for small teams.
- Standards
- ADHICS Basic; NABIDH or Riayati connection.
- Certification
- ADHICS self-assessment tied to licensing.
- Rhythm
- Aligned to licence renewal.
Pharmacies, labs and imaging centres
- Focus
- Dispensing and e-prescription security, lab and imaging system protection, data localization for cloud imaging, exchange result delivery.
- Standards
- ADHICS; exchange requirements; ISO 15189 alongside for labs.
- Certification
- ADHICS plus exchange connection.
- Rhythm
- Annual with licensing; accreditation cycles run separately.
Telehealth and digital health
- Focus
- DHA ST-14 in force since November 2025: ISO 27001 expectations, multi-factor authentication, encryption, data localization, consent, application and API security.
- Standards
- ST-14 v4; ADHICS; federal health-data law; ISO 27001.
- Certification
- Telehealth authorization plus ISO 27001 under ST-14.
- Rhythm
- ISO annual surveillance and three-year recertification; authorization renewal.
Health-IT and EMR vendors
- Focus
- Exchange integration certification, secure development, UAE data hosting, third-party risk borne on behalf of every client clinic, tenant isolation.
- Standards
- ADHICS third-party controls; exchange interoperability standards; ISO 27001 buyer-expected.
- Certification
- Exchange certification; losing it makes the product unsellable to licensed providers.
- Rhythm
- Re-certification per exchange authority; ISO annual.
Health-insurance TPAs
- Focus
- ADHICS Advanced tier for large-scale patient data, claims-data localization, provider integrations, fraud and ransomware resilience.
- Standards
- ADHICS Advanced; ISO 27001 expected; PCI where card data.
- Certification
- ADHICS Advanced.
- Rhythm
- Annual, with continuous monitoring expected at the Advanced tier.
These are summary profiles. Behind each one sits a complete obligation map, control set and calendar that AccuSights maintains for clients. Seeing yours is what a demo is for.
One program instead
How we make it one control set.
AccuSights turns ADHICS, NABIDH, Riayati, ST-14 and the federal health-data law into one program: one control set cross-mapped to every regime, evidence collected once, licence-renewal assessments prepared before they are due, and the read-only compliance agent watching your posture continuously across clinics and cloud. Compliance becomes the by-product of running securely, not a season of binders.
Cross-mapped controls
One control, mapped to every regulator on this page that it satisfies.
Evidence collected once
Reused across every emirate, free zone, and framework that applies to you.
Always audit-ready
A read-only compliance agent keeps the picture current. You keep the keys.
Global breach figures: Verizon 2026 Data Breach Investigations Report, the 19th edition, analyzing more than 22,000 confirmed breaches across 145 countries. Regional figures: EMEA section of the same report, and UAE public statistics as cited.
Book a demo
See your obligations as one program.
Thirty minutes with an engineer who works in UAE regulation. You leave knowing which rules apply to you, where the gaps are, and how one control set covers them.