ADHICS compliance: what Abu Dhabi healthcare entities must do
ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, is the binding cybersecurity standard for every healthcare entity licensed by the Department of Health Abu Dhabi (DoH). It applies to hospitals, clinics, diagnostic labs, payers, telehealth providers, and the IT and MedTech vendors that support them. Compliance is not optional: it conditions licensing, renewals, and the ability to operate in the Emirate.
The standard covers governance, risk management, asset management, human resources security, physical security, communications, access control, system acquisition and development, incident management, business continuity, and compliance assurance. Each domain contains controls grouped into Basic, Transitional, and Advanced tiers, and entities are scoped to a tier based on size, criticality, and the sensitivity of the data they process.
ADHICS v2 also introduced sharper requirements around medical device security, cloud adoption, third-party risk, and incident reporting timelines, areas where most healthcare providers struggle without a dedicated GRC platform.
Running ADHICS as a continuous program with Waaqi
Most ADHICS programs fail not because the standard is unclear, but because spreadsheets cannot keep up. Controls drift, ownership is ambiguous, evidence ages out, and every DoH audit becomes a fire drill. Waaqi replaces that model with a continuous ADHICS operating system.
The full ADHICS v2 control library ships pre-loaded with guidance, tiering, and suggested evidence. Waaqi auto-scopes the applicable controls based on your entity classification, routes each one to a clinical, IT, or security owner with an SLA, and collects evidence through connectors and recurring tasks. Internal audits, CAPA, management reviews, and risk treatment plans are first-class objects, not attachments to an email thread.
When an incident occurs, Waaqi opens a workflow aligned with DoH reporting expectations, timelines, severity scoring, evidence capture, regulator notification templates, and post-incident lessons learned, so reporting deadlines are met without scrambling.
One control library for ADHICS, ISO 27001, HIPAA, and UAE PDPL
Abu Dhabi healthcare providers rarely face only ADHICS. International accreditations (JCI, ISO 27001), insurance partners (often HIPAA-aligned), and the UAE PDPL all demand evidence of the same underlying controls. Waaqi maps ADHICS to ISO 27001 Annex A, NIST CSF, HIPAA Security and Privacy Rules, and UAE PDPL, so a single implementation satisfies multiple frameworks.
This unified control model cuts duplicate work, eliminates conflicting evidence, and lets compliance leaders demonstrate maturity across regulators, accreditors, payers, and connected providers, without expanding the team.
DoH audit readiness and incident reporting
DoH audits move fast. Waaqi's auditor workspace gives the regulator a read-only, ADHICS-scoped view of policies, controls, evidence, internal audit history, risk treatment, and incident records. Every control links to current evidence and historical trail, so the question "show me how you implement control X" is answered in seconds.
For incidents, Waaqi maintains a unified register with DoH notification status, internal RCA, CAPA, and trend analytics across the organization, closing the loop between detection, response, and ADHICS reporting obligations.
