When the Department of Health – Abu Dhabi confirms an assessment date, the timeline stops being yours. Most entities discover at that point how much of their ADHICS programme exists on paper and how little of it exists in daily operations.
Ninety days is enough to prove what you already have. It is not enough to build what you do not. Knowing which position you are in before you spend the first month decides whether you finish with a clean assessment or a corrective action plan.
This is a practical 90-day approach for CISOs and Information Security Managers facing a DoH-driven ADHICS assessment including the parts of the standard that ninety days cannot close.
Start with applicability, not with controls
ADHICS V2 does not apply uniformly. The standard categorises entities so that obligations scale with risk and size:
- Basic — the minimum set every entity must meet
- Transitional — moderate-risk entities such as smaller hospitals and diagnostic centres
- Advanced — larger hospitals, payers, and entities such as Malaffi
- Service Provider — requirements for external technology vendors
Controls are further split into Always Applicable and Risk-Based. Always Applicable controls are not negotiable, and omitting one is a non-conformity whatever your risk assessment says. Risk-Based controls can be excluded only with documented justification and formal risk acceptance.
Settle your category and your Always Applicable set in the first few days. Teams that skip this spend the opening month assessing themselves against requirements that do not apply or missing ones that do.
Confirm too that you are working from ADHICS V2, effective August 2024, which superseded the 2019 standard and the 2020 IoMT and Patient Healthcare Data Privacy standards. Mappings built against the earlier version prepare you for an assessment that no longer exists.
The failure mode is drift, not weak technology
Entities that struggle in an ADHICS assessment are rarely technically immature. Their controls exist and their policies are well written often by a capable external consultant or an internal specialist who knew exactly what the standard required.
The gap opens after the documents are signed. The framework goes into a repository, the project closes, and the teams expected to execute it never absorb what it says. Six months later the policy mandates a quarterly access review nobody performs and a change process the infrastructure team has quietly worked around.
That is operational drift, and it is where most findings originate. It bites harder under ADHICS because the assessment does not stop at the Information Security Manager’s desk assessors interview the people who operate the controls: system administrators, nursing staff, HR, help-desk agents. A policy your operations team cannot describe is not a control. It is documentation.
So awareness work is not a box to tick in week ten. It is remediation, and it belongs alongside the technical work.
Start the evidence clock on day one
The most common structural mistake is treating evidence collection as a phase that begins once remediation ends. Several ADHICS evidence items are time-series rather than point-in-time, and cannot be produced retroactively:
- Security awareness training records
- Periodic user access reviews
- Backup restoration test results
- Business continuity and incident response exercise reports
- Incident logs and closure records
- Risk register review history
- Vulnerability and penetration testing cycles, with evidence of remediation
Begin on day 61 and you hand the assessor thirty days of history against a control expecting a full cycle. Start on day one, alongside the gap assessment, and treat the later phase as consolidation rather than collection.
What 90 days cannot fix
Two ADHICS requirements are structural rather than procedural. No preparation sprint resolves them.
Data residency. PHI and PII must not be stored, processed, or transferred outside the UAE without an explicit exemption issued by the DoH. If a core clinical, HR, or analytics platform is hosted offshore, this is an architecture and contracting problem measured in quarters, not weeks.
Access residency. Access to systems holding sensitive health data is restricted to individuals physically present in the UAE, or those holding a valid DoH professional licence.This regularly affects offshore managed services, remote vendor support, and follow-the-sun SOC arrangements delivery models that are otherwise entirely sound.
If either applies to you, do not obscure it. The defensible position is a documented one: a formal exemption request to the DoH where the case supports it, a risk accepted at executive level with a named owner, and a remediation plan carrying real dates and real budget. Assessors respond very differently to a gap that is known, owned, and planned than to one they uncover themselves.
The 90-day plan
Days 1–30: Establish the true position
Run a gap assessment against your applicable ADHICS V2 control set — not a generic security checklist, and not the previous version. The output should be a prioritised remediation plan with owners and dates, not a percentage score.
Build a cross-functional readiness team spanning information security, IT operations, compliance, risk, clinical operations, HR, and executive leadership. Compliance is not an IT project, and the assessment makes that obvious quickly. Assign each requirement to a named individual rather than a department.
Then check documentation for currency, approval, version control, and accessibility — unapproved or outdated documents generate findings even where the control itself works.
Days 31–60: Remediate, and close the awareness gap
Validate that technical controls are operating rather than merely configured: multi-factor authentication, endpoint protection, network segmentation, encryption, backup security, vulnerability and patch management. The distance between documented and operational is where most technical findings sit.
Two items are inexpensive to fix and frequently missed:
Asset classification. ADHICS prescribes a specific classification scheme rather than allowing entities to apply their own. Entities that carried across an existing corporate scheme fail this routinely, and relabelling is largely administrative.
Third-party security. Given healthcare’s dependence on external clinical systems, cloud platforms, and connected medical technology, confirm you hold a current vendor inventory, documented assessments, and security obligations written into contracts rather than assumed.
Alongside this, run awareness work aimed at the teams who execute controls not the annual all-staff module. Walk the access review owner through the procedure. Confirm the help desk knows the incident classification thresholds. It is the fastest way to close drift before an interview exposes it.
Days 61–75: Consolidate evidence
Bring everything collected since day one into a single structured repository, mapped control by control. Scattered evidence slows the assessment and suggests a programme reconstructed for the occasion rather than one that runs.
Check consistency as you go. Where a policy states one frequency and the records show another, resolve it now by correcting practice or amending the policy through proper approval. Assessors find these contradictions quickly, and each one invites a wider sample.
Days 76–85: Internal audit
Run an internal audit that mirrors the DoH approach, interviews included. Document review tells you whether your paperwork is complete; only interviews tell you whether your controls are real.
Speak to the people who operate controls rather than those who wrote the policies, and ask them to describe what they do rather than whether they comply. The gaps that surface here are the ones that would otherwise surface in front of the assessor.
Days 86–90: Final readiness review
Complete a management review covering outstanding risks, open remediation items, evidence completeness, policy approvals, and stakeholder responsibilities. Confirm every named control owner knows they are one and can speak to their area without preparation. Avoid significant system changes in the final week unless the risk of not making them is demonstrably higher.
| Phase | Primary focus | ADHICS areas most exercised |
| Days 1–30 | Applicability and gap assessment | Governance, risk management, asset management |
| Days 31–60 | Remediation and awareness | Access control, communications and operations, data privacy and protection, cloud and third-party security |
| Days 61–75 | Evidence consolidation | All domains — evidence mapped control by control |
| Days 76–85 | Internal audit and interviews | Human resource security, incident management, continuity management |
| Days 86–90 | Management review | Governance and oversight |
If you already hold ISO 27001
An operating ISMS is a real head start: risk, asset and access management, supplier security, incident management, and continuity map across reasonably well. What it does not cover is what is specific to Abu Dhabi healthcare data and access residency, the prescribed classification scheme, and obligations arising from Malaffi connectivity. Budget your ninety days for the delta, not the whole.
Closing thought
Ninety days is a reasonable window in which to prove a functioning security programme and an unreasonable one in which to build one. If your gap assessment says you are in the second position, say so early internally, and where necessary to the DoH rather than arriving with a full set of documents and an operations team that has never read them.
The question worth asking before the assessment is not whether your policies meet ADHICS. It is whether the person performing the control tomorrow morning could describe it without opening the document.
Achieving ADHICS compliance depends less on the quality of your documentation than on whether your operations match it. ValueMentor supports healthcare entities across gap assessment, remediation, evidence readiness, and internal audit including the awareness work that stops a programme drifting after the documents are signed. Talk to our team if you have an assessment date and want an honest read on where you stand.
FAQs
It is mandated by the Department of Health – Abu Dhabi, underpins participation in the Healthcare Information Exchange (Malaffi), and aligns with UAE federal legislation on ICT in healthcare and data privacy.
When should an organisation start preparing for an ADHICS audit?
Compliance should be continuous. Ninety days is realistic for proving and consolidating an existing programme, but not for building one from scratch — particularly where evidence must span a full cycle.
How do I know which ADHICS requirements apply to us?
Applicability is driven by entity type and size, with separate expectations for service providers. Establish your category before scoping, as it determines which controls are Always Applicable and which are Risk-Based.
What are the key phases of ADHICS audit preparation?
Gap assessment, remediation and awareness, evidence consolidation, internal audit, and management review — with evidence collection running from day one rather than starting midway.
Does ISO 27001 certification cover ADHICS requirements?
No. It gives a substantial head start on management system controls but leaves a delta covering data and access residency, the prescribed classification scheme, and healthcare-specific obligations.
Can we store patient data with a cloud provider outside the UAE?
Not without an explicit exemption from the DoH. Offshore hosting of PHI or PII is a structural issue that cannot be resolved inside a short preparation window.
What role does risk management play in ADHICS compliance?
It determines which Risk-Based controls apply and justifies any exclusion. Exclusions require documented rationale and formal risk acceptance, not silence.
Is technical security alone enough to pass an ADHICS audit?
No. Governance, documentation, and operational awareness are assessed alongside technical controls, and assessors interview the staff who operate them.
What happens if an organisation is not fully prepared?
Expect findings, corrective action requirements, and possible re-assessment. A gap that is documented, owned, and scheduled is treated very differently from one the assessor discovers.
How often should healthcare organisations review their ADHICS compliance?
Continuously, supported by periodic internal audits and an independent audit programme. Reviewing only before an assessment is what lets operational drift accumulate.


