Abu Dhabi Healthcare Information and Cyber Security Standard

ADHICS v2 Compliance Software for Abu Dhabi Healthcare

Waaqi's configurable control library maps ADHICS v2 requirements directly to ISO 27001, NIST CSF, and HIPAA equivalents, so healthcare entities in Abu Dhabi implement controls once and satisfy all four frameworks simultaneously.

Framework at a glancePre-loaded
Standard version
v2
Framework mappings
4
Compliance tiers
3
DoH-ready evidence
Ready

Control library, gap assessment, risk register, and audit packs ship ready on day one.

01Context

Why ADHICS Matters

Every healthcare entity licensed by the Department of Health Abu Dhabi must comply with the ADHICS standard, and certification is a mandatory checkpoint for healthcare license renewal. Entities that fall out of compliance risk delays or complications renewing their DoH license. Compliance is verified through independent audits conducted by TASNEEF, the DoH-appointed certification body, with evidence and self-assessments submitted through the AAMEN platform, DoH's official reporting portal.

Version 2 expanded the scope significantly, adding controls that overlap heavily with ISO 27001, NIST CSF, and HIPAA, plus new requirements around connected medical devices (IoMT), covering everything from infusion pumps to imaging systems, reflecting how deeply networked modern healthcare infrastructure has become. Healthcare CISOs managing compliance manually face a compounding problem: duplicating work already covered by existing certifications, tracking a growing device fleet, and still risking gaps at renewal.

ADHICS v2 organizes healthcare entities into three tiers: Basic, Transitional, and Advanced. Your tier is determined by the scale of your operations, the sensitivity of the patient data you handle, and the criticality of your healthcare services. The Basic tier covers smaller clinics and pharmacies with foundational security controls. The Transitional tier applies to medium-sized facilities that must bridge core controls with more structured governance. The Advanced tier targets large hospitals, health information exchanges, and any provider managing highly sensitive health data or extensive IoMT deployments, requiring the full control set plus independent audits, continuous monitoring, and board-level reporting.

Waaqi's cross-framework mapping is the answer. Implement a control once, and Waaqi shows you exactly which ADHICS v2, ISO 27001, NIST CSF, and HIPAA requirements it satisfies, with evidence reused across all four, and organized in a format ready for TASNEEF audit and AAMEN submission.

02Inside Waaqi

How Waaqi Supports ADHICS

01

Gap Assessment

ADHICS-aligned control scoring with prioritized recommendations and automated policy generation tailored to healthcare environments.

02

Cross-Framework Control Mapping

ADHICS controls are mapped directly to ISO 27001, NIST CSF, and HIPAA equivalents, so a single implementation satisfies all four, reducing duplicate assessment cycles and eliminating redundant policy work.

03

Statement of Applicability

Auto-generated, ADHICS-mapped, and defensible in a DoH assessment, showing which controls apply, how they're implemented, and where exceptions are justified.

04

Risk and Controls

A risk register populated only through deliberate action, critical for healthcare entities where risk records must withstand scrutiny from both the DoH and external auditors.

05

Third-Party Risk Management

Healthcare entities depend on outsourced IT and clinical vendors. Waaqi's TPRM module governs the full vendor lifecycle with tier-based risk registers and evidence tracking built for health-data exposure.

06

Data Residency

Regional Cloud (UAE) or on-premises deployment ensures patient data and compliance records stay within UAE jurisdiction, aligned with ADHICS data sovereignty requirements.

03Efficiency

Multi-Framework Efficiency

Healthcare entities in the UAE typically carry ADHICS, ISO 27001, and HIPAA obligations simultaneously, plus UAE PDPL for patient privacy. Waaqi lets you assess once and generate compliance evidence for all four frameworks from the same control set, cutting audit preparation time significantly.

DoH assessments follow a recurring renewal cycle. Most entities complete a self-assessment and submit evidence annually, with Advanced tier organizations reviewed more frequently. A first-time ADHICS v2 implementation typically takes 3 to 6 months depending on starting maturity, while smaller Basic tier facilities often reach readiness in 8 to 12 weeks. Waaqi's pre-loaded ADHICS workspace, automated evidence workflows, and control mapping can reduce that timeline by up to 50 percent, so your team spends less time on administration and more time on patient care.

Go deeper on the mapping: ADHICS v2 Control Mapping: A Practical Guide and ADHICS vs ISO 27001: What Healthcare CISOs Need to Know.

05FAQ

Questions we get asked

Every healthcare entity licensed by the Department of Health Abu Dhabi, including hospitals, clinics, labs, pharmacies, and health insurance providers operating in the emirate.

ADHICS v2 uses three tiers: Basic for smaller clinics and pharmacies, Transitional for medium-sized facilities needing structured governance, and Advanced for large hospitals and sensitive health-data environments. Each tier scales the number of required controls and the depth of evidence and auditing expected.

DoH assessments follow a recurring renewal cycle. Most healthcare entities complete a self-assessment and submit evidence annually, while Advanced tier organizations are reviewed more frequently. Continuous control monitoring between formal reviews keeps the program current.

ADHICS is modeled on international standards including ISO 27001 and NIST CSF, with healthcare-specific additions. Waaqi's control mapping engine automatically shows which ISO 27001 implementations satisfy ADHICS requirements and where ADHICS adds healthcare-specific obligations beyond ISO 27001.

No. ADHICS is the mandatory standard for Abu Dhabi healthcare entities. HIPAA applies if you handle US patient data. Waaqi maps both frameworks so you can maintain dual compliance from a single control implementation.

A first-time ADHICS v2 implementation typically takes 3 to 6 months depending on starting maturity, while smaller Basic tier facilities often reach readiness in 8 to 12 weeks. Waaqi's pre-loaded ADHICS workspace, automated evidence workflows, and control mapping can reduce that timeline by up to 50 percent.

See your ADHICS control mapping in a live walkthrough

Book a session with our team and we will show the cross-framework mapping engine, gap assessment, and DoH evidence pack running on your scenario.

Request a demo