ADHICS Is Not Optional — and That Changes How You Should Approach It

Most security standards are something an organisation chooses to adopt. ADHICS is not one of them. The Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health – Abu Dhabi (DoH), is mandatory for healthcare entities operating in the Emirate. If you are a DoH-licensed provider — a hospital, clinic, diagnostic lab, day-care centre, telehealth platform, or a business associate that handles Abu Dhabi healthcare information — ADHICS applies to you, and a regulator is the one setting the timeline.

That single fact should shape your whole approach. You are not building a security programme to impress a customer; you are demonstrating, on the record, that patient information is protected to a standard the regulator can verify. The organisations that struggle are the ones who treat it as a last-minute documentation exercise. The ones who do well treat it as an operational programme with a deadline.

This is a practical walkthrough of how to get there — written from the perspective of running these engagements, not reciting the standard.

What ADHICS Actually Covers

ADHICS is built in two halves, and understanding the split tells you where the real work is.

Governance and management — the structural requirements. Who owns information security in your organisation, how risk is governed, how policies are approved and reviewed, how the programme is sponsored at leadership level. This is the part organisations most often underestimate, because it can't be solved by buying a product. It requires named ownership and leadership sign-off.

Security controls — the operational requirements, organised into control domains that will feel familiar to anyone who knows ISO 27001: human resources security, asset management, physical and environmental security, access control, operations and communications, third-party and supplier risk, information systems acquisition and maintenance, incident management, business continuity, and compliance. Each domain carries a set of controls you must implement and — crucially — be able to evidence.

Control applicability is not one-size-fits-all. ADHICS scales expectations to the type and size of the entity, so a large hospital and a single-branch clinic are not held to an identical control set. Mapping your entity classification correctly at the start is what keeps the programme proportionate. Getting that wrong in either direction — over-scoping or under-scoping — is one of the most expensive early mistakes.

A note on specifics: ADHICS evolves, and the DoH-published version is always the authoritative source for exact control references, classification rules, and submission timelines. Work from the current standard, not from memory or a blog — including this one.

The Compliance Journey — What Good Looks Like

A well-run ADHICS programme moves through clear stages. Rushing or skipping any of them is what creates the audit-week panic.

1. Scope and classify. Confirm which entities, facilities, and information assets are in scope, and establish your entity classification. This decides which controls are mandatory for you. An afternoon spent here saves months later.

2. Gap assessment. Assess your current state against every applicable control. The output is a gap register: each gap rated by severity, with the evidence of current state, the remediation needed, an effort estimate, and the dependencies between gaps (some can't close until others do). This register becomes the spine of the whole programme.

3. Risk-based prioritisation. You will not close everything at once, and you shouldn't try. Sequence the work: quick wins first (asset inventory, access reviews, removable-media policy — usually 8–12 controls that close inside the first month and show momentum), then the dependency-bound items, then the structural governance pieces that take longest.

4. Remediate. The actual operational changes — alongside your team, not in a vacuum. Policies tailored to how you really work, access controls enforced, supplier contracts reviewed, training records established, technical configurations brought into line.

5. Build the evidence trail. This is where most programmes are weakest. A control that "is implemented" but has no evidence is a finding at audit. Every applicable control needs an artefact: a signed policy, an access-review log, a training record, an incident drill report. If you can't answer "where is the evidence for control X?" for every control, you are not ready.

6. Internal review before the regulator. Run your own audit-style review against the standard before anyone official looks. Better to find the gaps yourself.

The Mistakes We See Most Often

  • Treating it as a documentation project. A binder of policies nobody follows fails the moment an auditor asks for evidence the control actually operates. ADHICS tests whether controls work, not whether they're written down.
  • Wrong scope or classification. Over-scoping wastes budget on controls you don't need; under-scoping leaves you exposed at audit. Both are avoidable with careful early mapping.
  • Ignoring business associates. Third parties handling healthcare information are in scope. If your billing provider, cloud host, or outsourced IT isn't covered by your supplier-risk controls, that's a gap.
  • No named owner. "Everyone is responsible for security" means no one is. ADHICS expects clear, named accountability — and auditors ask who owns what.
  • Leaving evidence to the end. Evidence collected retroactively, the week before audit, is thin and obviously rushed. The organisations that pass calmly have been collecting evidence as business-as-usual for months.
  • Starting too late. The deadline doesn't move. A staged 4–8 week readiness assessment and a planned remediation roadmap is calm; a three-week scramble before audit is not.

How Long, and How to Start

A realistic ADHICS readiness assessment — scope, stakeholder interviews, full gap analysis, prioritised remediation roadmap, and a leadership briefing — runs roughly four to eight weeks for an SME healthcare entity, longer for larger facilities. Remediation timelines depend entirely on the size of your gaps, which is exactly why the gap assessment comes first: you cannot plan the work until you can see it.

The single best first step is a gap assessment. It is low-commitment, it gives you a costed, prioritised picture of exactly what compliance will take, and it surfaces the quick wins you can start closing immediately. Everything else flows from that register.

Working With Underwings

We run ADHICS readiness and remediation as a hands-on programme — gap assessment, prioritised roadmap, policy and control implementation alongside your team, and audit-ready evidence — led by a named ISO 27001 Lead Auditor, not handed to a junior. We publish indicative AED pricing, scope every engagement in writing within 48 hours, and we are taking a limited number of founding clients at preferential rates while we build our public track record.

If ADHICS is on your horizon — or already overdue — a free 30-minute scoping call will tell you where you genuinely stand. Book at book.underwings.org, email [email protected], or call +971 50 567 0394.

Manoj Prabhakaran is an ISO 27001 Lead Auditor (CPTS, Azure Security) and leads GRC and healthcare compliance at Underwings Cybersecurity Solutions, Abu Dhabi.