You are here:

How to Prepare for an ADHICS Audit in 90 Days?

3D countdown display showing 90 days for ADHICS audit preparation and DoH Abu Dhabi compliance.

When the Department of Health – Abu Dhabi confirms an assessment date, the timeline stops being yours. Most entities discover at that point how much of their ADHICS programme exists on paper and how little of it exists in daily operations.

Ninety days is enough to prove what you already have. It is not enough to build what you do not. Knowing which position you are in before you spend the first month decides whether you finish with a clean assessment or a corrective action plan.

This is a practical 90-day approach for CISOs and Information Security Managers facing a DoH-driven ADHICS assessment including the parts of the standard that ninety days cannot close.

Start with applicability, not with controls

ADHICS V2 does not apply uniformly. The standard categorises entities so that obligations scale with risk and size:

  • Basic — the minimum set every entity must meet
  • Transitional — moderate-risk entities such as smaller hospitals and diagnostic centres
  • Advanced — larger hospitals, payers, and entities such as Malaffi
  • Service Provider — requirements for external technology vendors

Controls are further split into Always Applicable and Risk-Based. Always Applicable controls are not negotiable, and omitting one is a non-conformity whatever your risk assessment says. Risk-Based controls can be excluded only with documented justification and formal risk acceptance.

Settle your category and your Always Applicable set in the first few days. Teams that skip this spend the opening month assessing themselves against requirements that do not apply or missing ones that do.

Confirm too that you are working from ADHICS V2, effective August 2024, which superseded the 2019 standard and the 2020 IoMT and Patient Healthcare Data Privacy standards. Mappings built against the earlier version prepare you for an assessment that no longer exists.

The failure mode is drift, not weak technology

Entities that struggle in an ADHICS assessment are rarely technically immature. Their controls exist and their policies are well written often by a capable external consultant or an internal specialist who knew exactly what the standard required.

The gap opens after the documents are signed. The framework goes into a repository, the project closes, and the teams expected to execute it never absorb what it says. Six months later the policy mandates a quarterly access review nobody performs and a change process the infrastructure team has quietly worked around.

That is operational drift, and it is where most findings originate. It bites harder under ADHICS because the assessment does not stop at the Information Security Manager’s desk assessors interview the people who operate the controls: system administrators, nursing staff, HR, help-desk agents. A policy your operations team cannot describe is not a control. It is documentation.

So awareness work is not a box to tick in week ten. It is remediation, and it belongs alongside the technical work.

Start the evidence clock on day one

The most common structural mistake is treating evidence collection as a phase that begins once remediation ends. Several ADHICS evidence items are time-series rather than point-in-time, and cannot be produced retroactively:

  • Security awareness training records
  • Periodic user access reviews
  • Backup restoration test results
  • Business continuity and incident response exercise reports
  • Incident logs and closure records
  • Risk register review history
  • Vulnerability and penetration testing cycles, with evidence of remediation

Begin on day 61 and you hand the assessor thirty days of history against a control expecting a full cycle. Start on day one, alongside the gap assessment, and treat the later phase as consolidation rather than collection.

What 90 days cannot fix

Two ADHICS requirements are structural rather than procedural. No preparation sprint resolves them.

Data residency. PHI and PII must not be stored, processed, or transferred outside the UAE without an explicit exemption issued by the DoH. If a core clinical, HR, or analytics platform is hosted offshore, this is an architecture and contracting problem measured in quarters, not weeks.

Access residency. Access to systems holding sensitive health data is restricted to individuals physically present in the UAE, or those holding a valid DoH professional licence.This regularly affects offshore managed services, remote vendor support, and follow-the-sun SOC arrangements delivery models that are otherwise entirely sound.

If either applies to you, do not obscure it. The defensible position is a documented one: a formal exemption request to the DoH where the case supports it, a risk accepted at executive level with a named owner, and a remediation plan carrying real dates and real budget. Assessors respond very differently to a gap that is known, owned, and planned than to one they uncover themselves.

The 90-day plan

Days 1–30: Establish the true position

Run a gap assessment against your applicable ADHICS V2 control set — not a generic security checklist, and not the previous version. The output should be a prioritised remediation plan with owners and dates, not a percentage score.

Build a cross-functional readiness team spanning information security, IT operations, compliance, risk, clinical operations, HR, and executive leadership. Compliance is not an IT project, and the assessment makes that obvious quickly. Assign each requirement to a named individual rather than a department.

Then check documentation for currency, approval, version control, and accessibility — unapproved or outdated documents generate findings even where the control itself works.

Days 31–60: Remediate, and close the awareness gap

Validate that technical controls are operating rather than merely configured: multi-factor authentication, endpoint protection, network segmentation, encryption, backup security, vulnerability and patch management. The distance between documented and operational is where most technical findings sit.

Two items are inexpensive to fix and frequently missed:

Asset classification. ADHICS prescribes a specific classification scheme rather than allowing entities to apply their own.  Entities that carried across an existing corporate scheme fail this routinely, and relabelling is largely administrative.

Third-party security. Given healthcare’s dependence on external clinical systems, cloud platforms, and connected medical technology, confirm you hold a current vendor inventory, documented assessments, and security obligations written into contracts rather than assumed.

Alongside this, run awareness work aimed at the teams who execute controls not the annual all-staff module. Walk the access review owner through the procedure. Confirm the help desk knows the incident classification thresholds. It is the fastest way to close drift before an interview exposes it.

Days 61–75: Consolidate evidence

Bring everything collected since day one into a single structured repository, mapped control by control. Scattered evidence slows the assessment and suggests a programme reconstructed for the occasion rather than one that runs.

Check consistency as you go. Where a policy states one frequency and the records show another, resolve it now  by correcting practice or amending the policy through proper approval. Assessors find these contradictions quickly, and each one invites a wider sample.

Days 76–85: Internal audit

Run an internal audit that mirrors the DoH approach, interviews included. Document review tells you whether your paperwork is complete; only interviews tell you whether your controls are real.

Speak to the people who operate controls rather than those who wrote the policies, and ask them to describe what they do rather than whether they comply. The gaps that surface here are the ones that would otherwise surface in front of the assessor.

Days 86–90: Final readiness review

Complete a management review covering outstanding risks, open remediation items, evidence completeness, policy approvals, and stakeholder responsibilities. Confirm every named control owner knows they are one and can speak to their area without preparation. Avoid significant system changes in the final week unless the risk of not making them is demonstrably higher.

PhasePrimary focusADHICS areas most exercised
Days 1–30Applicability and gap assessmentGovernance, risk management, asset management
Days 31–60Remediation and awarenessAccess control, communications and operations, data privacy and protection, cloud and third-party security
Days 61–75Evidence consolidationAll domains — evidence mapped control by control
Days 76–85Internal audit and interviewsHuman resource security, incident management, continuity management
Days 86–90Management reviewGovernance and oversight

If you already hold ISO 27001

An operating ISMS is a real head start: risk, asset and access management, supplier security, incident management, and continuity map across reasonably well. What it does not cover is what is specific to Abu Dhabi healthcare data and access residency, the prescribed classification scheme, and obligations arising from Malaffi connectivity. Budget your ninety days for the delta, not the whole.

Closing thought

Ninety days is a reasonable window in which to prove a functioning security programme and an unreasonable one in which to build one. If your gap assessment says you are in the second position, say so early internally, and where necessary to the DoH rather than arriving with a full set of documents and an operations team that has never read them.

The question worth asking before the assessment is not whether your policies meet ADHICS. It is whether the person performing the control tomorrow morning could describe it without opening the document.

Achieving ADHICS compliance depends less on the quality of your documentation than on whether your operations match it. ValueMentor supports healthcare entities across gap assessment, remediation, evidence readiness, and internal audit including the awareness work that stops a programme drifting after the documents are signed. Talk to our team if you have an assessment date and want an honest read on where you stand.

FAQs

Why is ADHICS compliance important for healthcare organisations?

It is mandated by the Department of Health – Abu Dhabi, underpins participation in the Healthcare Information Exchange (Malaffi), and aligns with UAE federal legislation on ICT in healthcare and data privacy.


When should an organisation start preparing for an ADHICS audit?

Compliance should be continuous. Ninety days is realistic for proving and consolidating an existing programme, but not for building one from scratch — particularly where evidence must span a full cycle.


How do I know which ADHICS requirements apply to us?

Applicability is driven by entity type and size, with separate expectations for service providers. Establish your category before scoping, as it determines which controls are Always Applicable and which are Risk-Based.


What are the key phases of ADHICS audit preparation?

Gap assessment, remediation and awareness, evidence consolidation, internal audit, and management review — with evidence collection running from day one rather than starting midway.


Does ISO 27001 certification cover ADHICS requirements?

No. It gives a substantial head start on management system controls but leaves a delta covering data and access residency, the prescribed classification scheme, and healthcare-specific obligations.


Can we store patient data with a cloud provider outside the UAE?

Not without an explicit exemption from the DoH. Offshore hosting of PHI or PII is a structural issue that cannot be resolved inside a short preparation window.


What role does risk management play in ADHICS compliance?

It determines which Risk-Based controls apply and justifies any exclusion. Exclusions require documented rationale and formal risk acceptance, not silence.


Is technical security alone enough to pass an ADHICS audit?

No. Governance, documentation, and operational awareness are assessed alongside technical controls, and assessors interview the staff who operate them.


What happens if an organisation is not fully prepared?

Expect findings, corrective action requirements, and possible re-assessment. A gap that is documented, owned, and scheduled is treated very differently from one the assessor discovers.


How often should healthcare organisations review their ADHICS compliance?

Continuously, supported by periodic internal audits and an independent audit programme. Reviewing only before an assessment is what lets operational drift accumulate.

Author

Ronald Mathew

Ronald Mathew is a cybersecurity governance and risk professional specializing in security strategy, program management, and security operations oversight. His work focuses on building sustainable security capabilities, strengthening organizational resilience, and enabling informed decision‑making at the leadership level. Ronald reviews and validates security content through a strategic and risk‑based lens shaped by enterprise‑scale experience.

Table of Contents

Protect Your Business from Cyber Threats Today!

Safeguard your business with tailored cybersecurity solutions. Contact us now for a free consultation and ensure a secure digital future!

Ready to Secure Your Future?

We partner with ambitious leaders who shape the future, not just react to it. Let’s achieve extraordinary outcomes together.

I want to talk to your experts in:

Related Blogs

A red stethoscope resting on a silver laptop keyboard, symbolizing the intersection of healthcare, digital security, and IT compliance auditing in Abu Dhabi.
Small healthcare startup evaluating HITRUST certification costs through a digital healthcare compliance dashboard