ADHICS compliance doesn’t end when you pass the assessment. The real work is keeping those controls working afterwards.
For a healthcare organization in Abu Dhabi, that means knowing what’s happening across your users, systems, endpoints, networks and clinical environment, and being able to show what happened when something goes wrong.
Some ADHICS requirements are about policies and governance. Others need someone actively monitoring, maintaining and testing them. Something which a dedicated managed security team can take care of.
This guide breaks down the ADHICS requirements, what they look like in day-to-day operations, what auditors expect to see, and where MDR can help.
TL; DR
- Know the scope: ADHICS applies to healthcare organizations handling health information in Abu Dhabi.
- Cover the fundamentals: Governance, access control, asset management, network security, cryptography and third-party security are all part of the framework.
- Keep controls operational: Logging, monitoring, vulnerability management, backups and incident response require ongoing attention
- Monitor continuously: Healthcare teams need visibility across users, endpoints, networks, applications and relevant medical devices.
- Get the right support: MDR can support continuous monitoring, while DC Technologies helps keep ADHICS controls operational.
What is ADHICS and Who Needs to Comply?
ADHICS, or the Abu Dhabi Healthcare Information and Cyber Security Standard, is a Department of Health (DoH) standard for healthcare entities in Abu Dhabi that generate, access, store, use, process or transmit health information.
Its scope also extends to the systems, applications, medical devices, infrastructure and third-party systems used within the Abu Dhabi healthcare ecosystem.
The standard does not apply every control equally to every organization. DoH uses Basic, Transitional and Advanced control categories, with the required level depending on the type of healthcare entity and, for hospitals, bed capacity.
So before looking at individual controls, the first step is understanding which ADHICS requirements actually apply to your organization.
What Are The Main ADHICS Security Requirements?
ADHICS covers 11 domains, ranging from governance and HR security to access control, operations, communications, incident management and continuity. The DoH FAQ confirms that the standard contains 692 controls across 11 domains, with the applicable controls depending on the entity’s category.
For most healthcare organizations, the requirements fall into a few practical areas:
The important bit is that these controls are connected. A current asset inventory, for example, affects vulnerability management. Supplier access affects access control. Network security affects how clinical systems and connected devices are monitored.
That’s where ADHICS moves from having a control on paper to actually operating it every day.
Which ADHICS Requirements Need to Be Managed Every Day?
This is where ADHICS moves beyond policies and documentation. Three areas in particular need ongoing attention: access control, operations management, and incident management.
Access control
Having an access policy is only the starting point. Healthcare organizations need to make sure users have the right access for their role, privileged access is controlled, and access is reviewed as roles change.
The practical question is what happens between those reviews. A compromised account can still have perfectly valid credentials. Monitoring authentication activity can help flag unusual logins, repeated failures, privilege changes or other behavior that deserves investigation.
Operations management
This is the broadest operational area. ADHICS covers activities such as malware protection, backup and archival, vulnerability management, and monitoring and logging.
For an IT or security team, that means more than configuring a tool and moving on. Someone needs to know whether critical systems are generating the right logs, whether security alerts are being investigated, whether vulnerabilities are being tracked, and whether backups can actually support recovery.
This is also where MDR or a managed SOC can have a practical role: taking the continuous monitoring and investigation workload off an already stretched internal team, where that service matches the organization’s requirements.
Incident management
ADHICS expects organizations to have processes for detecting, analyzing, containing, eradicating and recovering from security incidents, with defined responsibilities and tested procedures.
That matters in healthcare because an incident can affect the availability of systems used to deliver care, not just expose information.
So the question isn’t simply “Do we have an incident response plan?” It’s “When an alert comes in, who sees it, investigates it, decides whether it is an incident, and starts the response?”
That is the point where continuous security operations become part of keeping an ADHICS control working.
What Should an ADHICS-Covered Healthcare Organization Monitor Every Day?
ADHICS requires operational security controls at every DoH-regulated facility. But how much is required depends on the facility size.
Basic controls apply to every DoH-regulated healthcare entity, regardless of bed count.
Hospitals with 1–20 beds and medical centers also carry transitional controls, while hospitals with 21 or more beds, along with insurance providers, are held to the full advanced tier – the most comprehensive set of requirements in the standard.
So while the monitoring expectations below apply broadly, the depth of what’s mandated scales up sharply once a hospital crosses that 21-bed threshold.
The implementation guidance also covers monitoring of information systems, applications, cloud environments, medical devices and equipment.
In practice, teams need visibility into:
- Security events and logs
- Endpoint and malware activity
- Vulnerabilities and remediation
- User and privileged-account activity
- Network and clinical-system activity
- Security incidents requiring investigation or escalation
Where does MDR fit?
This is where an internal IT team can quickly run into a capacity problem. Collecting the logs is one task. Watching them, investigating alerts and deciding what needs escalation is another.
MDR or a managed SOC can provide that operational layer by continuously monitoring relevant security telemetry, triaging alerts, investigating suspicious activity and escalating incidents according to the organization’s defined process.
It does not replace the organization’s ADHICS governance or accountability. It provides the operational capability for the controls that need to be monitored continuously.
What Should be in Place Before an ADHICS Assessment?
If you are preparing for ADHICS compliance, the key question is whether the required controls are implemented, operating effectively, and consistently maintained.
Use this as a quick check:
For organizations that do not have the internal capacity to monitor security events continuously, MDR or managed security services can provide that operational layer.
The organization still owns its ADHICS responsibilities, but the day-to-day monitoring and investigation work can be supported externally.
Conclusion
ADHICS compliance is ultimately about keeping security controls working as healthcare operations change.
For organizations managing this internally, MDR can support the operational side without taking ownership of the compliance program.
At DC Technologies, we help healthcare organizations build and maintain the security capabilities needed to keep those controls working in practice, not just documented on paper.
FAQs
Is ADHICS mandatory for private hospitals in Abu Dhabi?
What happens if a healthcare organization does not comply with ADHICS?
How do I prepare my organization for an ADHICS assessment?
How often does ADHICS compliance need to be reviewed?
ADHICS requires ongoing compliance monitoring rather than a one-time review. Organizations should periodically assess their controls and update their compliance status as required by the Department of Health.
Can ADHICS compliance be outsourced to a managed security provider?
Specific security activities can be supported by an external provider, but the healthcare organization remains accountable for its ADHICS compliance and security responsibilities.
How can MDR help with ADHICS compliance?
MDR can support the continuous monitoring, alert investigation and incident response activities that sit within ADHICS. DC Technologies provides MDR support to help healthcare organizations maintain this operational layer.