ADHICS V2.0 Compliance
Healthcare Intelligence Platform
Abu Dhabi • ADPHCSystem Governance & Compliance
ADHICS V2.0, Federal Data Protection, Sovereign Cloud Infrastructure & Operational Compliance
Overall ADHICS Compliance
6-month trend
Compliance Trend
ADHICS, Federal Laws, and Data Sovereignty
Domain Compliance Scores
ADHICS domain performance
Security Incident Trends
6-month incident severity breakdown
Abu Dhabi Healthcare Information and Cyber Security Standard V2.0
The operational mandate for all healthcare facilities, insurers, and professionals licensed by DoH
ADHICS V2.0 Overview
Operational mandate via AAMEN program for license renewal
The Six Strategic Pillars of ADHICS V2.0
Beyond checklist compliance toward holistic security culture
- Mandates formation of Information Security Steering Committees
- Requires appointment of qualified CISO at executive level
- Ensures security is discussed at board meetings regularly
- Links compliance to commercial viability via license renewal
- CISO certification (e.g., CCSP for cloud security)
- Quarterly steering committee meetings
- Executive sign-off on security policies
- Direct reporting line to CEO/Board
- Requires robust Disaster Recovery (DR) plans
- Incident Response mechanisms must be tested quarterly
- Facilities must demonstrate rapid service restoration
- RTO/RPO metrics must be defined and achieved
- DR plan tested quarterly with documented results
- RTO (Recovery Time Objective) < 4 hours for critical systems
- RPO (Recovery Point Objective) < 15 minutes for patient data
- Direct reporting line to DoH cybersecurity center
Basic Controls
Smaller entities (clinics, small practices)
Transitional Controls
Mid-sized entities scaling operations
Advanced Controls
Large hospitals and critical infrastructure
Control Family CM4: Cloud Computing
Data residency and CSP requirements
Health information related to services provided within the UAE MUST NOT be stored, developed, or transferred outside the country. This is a HARD operational constraint with no exemptions without specific DoH approval.
- • ISO 27001 (Information Security)
- • ISO 27017 (Cloud Security)
- • ISO 27018 (Privacy in Cloud)
- • Contract must guarantee UAE jurisdiction
- • No foreign "follow-the-sun" support access
AAMEN Certification Process
Mandatory audit for license renewal
Fully Compliant - All controls implemented and verified
Partially Compliant - Managing residual risks with mitigations