Governance. Risk. Compliance. Cybersecurity.
checklist

ADHICS V2 Implementation Checklist

A control-by-control checklist for the Abu Dhabi Healthcare Information & Cyber Security Standard V2 โ€” the mandatory baseline for every DoH-licensed entity.

23 June 2026ADHICSUAEHealthcare

Why ADHICS V2 matters

The Abu Dhabi Department of Health requires every licensed healthcare provider, payer and digital-health platform to maintain compliance with ADHICS. Version 2 raised the bar around governance, third-party risk and incident reporting, with self-attestation due annually.

How this checklist is structured

ADHICS V2 organises controls into three tiers โ€” Basic, Transitional and Advanced. Most providers must reach Transitional; large hospital groups and digital-health platforms typically aim for Advanced.

Track each control as: In place, Compensating, Gap, Not applicable (with justification).

Section 1 โ€” Governance and accountability

  • ISGC charter signed by the CEO
  • CISO appointment with quarterly board reporting
  • Annual ADHICS self-attestation submitted to DoH
  • Information classification scheme aligned to ADHICS taxonomy

Section 2 โ€” Asset and risk management

  • Asset inventory tagged with ADHICS classification
  • Risk register reviewed quarterly
  • Risk treatment plan tied to budget approvals

Section 3 โ€” Access and identity

  • Joiner-Mover-Leaver workflow with HR integration
  • Role-based access control for clinical systems
  • Privileged access management with session recording
  • MFA on every remote and admin entry point

Section 4 โ€” Clinical data protection

  • ePHI encryption at rest and in transit
  • Patient-portal authentication aligned to UAE PDPL
  • Data-sharing agreements with insurers and labs

Section 5 โ€” Operations

  • Change management with clinical-safety review
  • Backup and recovery tested every 90 days
  • 24x7 monitoring for clinical critical systems
  • Vulnerability scanning monthly with SLA tracking

Section 6 โ€” Incident and continuity

  • Incident response plan including DoH notification within prescribed timelines
  • Annual cyber tabletop exercise
  • Business continuity plan covering ePHI availability

Section 7 โ€” Third parties

  • Vendor inventory with ADHICS-aligned security clauses
  • Annual review of every critical vendor
  • Off-boarding procedure for data return or destruction

Next step

MAST is on the DoH consultant panel. Request an ADHICS readiness review.

Related resources