Skip to content
ADHICS

ADHICS — Healthcare information security, Abu Dhabi

The Department of Health – Abu Dhabi information and cyber security standard for healthcare entities operating in the emirate.

Accreditation scheme available

ADHICS is an EIAC accreditation scheme. It is also the standard where being an Abu Dhabi body matters most: the entities being certified, the regulator and the certification body are in one jurisdiction.

What the standard actually requires

ADHICS — the Abu Dhabi Healthcare Information and Cyber Security Standard — is issued by the Department of Health – Abu Dhabi. Unlike the ISO standards on this site, it is not an international standard adopted voluntarily: it is a regulatory requirement for healthcare entities operating in the emirate, and the Department is the authority behind it.

It sets out control requirements across domains covering governance, human resources security, asset management, physical and environmental security, access control, operations, communications, acquisition and development, incident management, continuity, and compliance — organised so that an entity can be assessed against them consistently.

Two things distinguish it in practice:

  • It is sector-specific. The controls assume a healthcare context: patient data, clinical systems, medical devices attached to networks, and the particular consequences of a system being unavailable when someone needs care.
  • It is tiered. Requirements are applied according to the type and size of the entity, so what applies to a large hospital group is not what applies to a single clinic.

Do you actually need it?

If you are a healthcare entity licensed by the Department of Health – Abu Dhabi, this is not really a question of whether certification is commercially worthwhile. Compliance is expected of you as a condition of operating, and independent certification is how you evidence it.

If you are a supplier to Abu Dhabi healthcare entities — a health IT vendor, a laboratory, a managed service provider handling clinical data — ADHICS is increasingly what your customers are required to ask you about, whether or not it applies to you directly.

Organisations already certified to ISO/IEC 27001 usually find much of the groundwork is done: the management system, the risk assessment and a good deal of the control set overlap. The work is in the healthcare-specific requirements, not in starting again.

What a UMA certificate against ADHICS does and does not assert

It asserts that we assessed your information security arrangements against the ADHICS requirements applicable to your entity type, for the scope stated on the certificate, and that on the evidence we saw they conform.

It does not assert that your clinical practice is safe, that your care meets any standard, that you hold a valid Department of Health licence, or that you comply with every other obligation the Department places on you. Certification against ADHICS is about information and cyber security. It is not a health regulator’s approval, and it is not a substitute for one.

How audit time is worked out for this standard

Audit duration follows the Department of Health – Abu Dhabi’s own requirements for ADHICS assessment, not the IAF audit-time tables written for ISO management system standards.

The inputs are the entity’s classification under the standard, the number of people within the scope, the number and type of facilities, and the clinical systems in use. Where you hold ISO/IEC 27001 certification for an overlapping scope, that is taken into account. We show you the calculation with the quotation.

Why an Abu Dhabi body

ADHICS is the one standard on this site where where we are registered makes a practical difference. The standard is issued by a regulator in this emirate, the entities being certified operate here, and the requirements are read in the context of how healthcare is regulated here. UMA is registered and operates from Abu Dhabi.

The cycle

Assessment, then a certification decision taken by someone who had no part in the assessment. Certification runs for three years, with surveillance in each of the two intervening years — the first due within twelve months of the decision — and full reassessment before the three years are up.