ADHICS Compliance Platform

ADHICS compliance, on autopilot

Operationalize the Abu Dhabi Healthcare Information and Cyber Security Standard with pre-loaded controls, evidence, and DoH-ready audit reporting.

Compliance postureLive
Control coverage
94%
Open risks
7
Evidence items
1,284
Audit findings
2
Implemented94%
In progress58%
Evidence freshness82%
  • ADHICS control coverage by domain and tier
  • Open clinical, IT, and vendor risks
  • Incident timelines with DoH notification status
01The problem

The ADHICS challenge

ADHICS demands healthcare-grade cybersecurity across governance, access, medical devices, and incident response, on top of UAE PDPL and clinical operations pressures.

  • Hundreds of controls across ADHICS domains and tiers
  • Medical device and clinical system security
  • DoH attestations and audits on tight cycles
  • Patient data protection alongside UAE PDPL
  • Vendor and connected provider risk
  • Incident reporting to DoH within prescribed timelines
02The approach

Healthcare cyber, structured for ADHICS

Waaqi pre-loads every ADHICS control and runs them as a living program with clear ownership, evidence, and audit trails.

01

ADHICS-native library

All ADHICS domains, controls, and tiering pre-mapped and ready to operate.

02

Healthcare-aware

Coverage for medical devices, clinical systems, payer integrations, and connected providers.

03

DoH-ready reports

Generate attestation packages and incident reports for the Department of Health on demand.

03Capabilities

What you get inside Waaqi

Every module works from one control library, one evidence store, and one risk register.

Full ADHICS Library

All ADHICS control domains and sub-controls pre-loaded with guidance and tiering.

Risk Management

Healthcare-tailored risk register linked to ADHICS controls and clinical impact.

Internal Audit

Plan and run ADHICS internal audits with findings, CAPA, and management reviews.

Policy Automation

Auto-generate ADHICS policies and procedures aligned to your scope and tier.

Continuous Monitoring

Detect control drift in clinical and corporate systems before it impacts an audit.

Third-Party Risk

Assess connected providers, MedTech vendors, and processors with audit trails.

Incident Reporting

Workflow for DoH incident reporting with timelines, evidence, and lessons learned.

Multi-Framework Mapping

Reuse ADHICS controls for ISO 27001, HIPAA, NIST CSF, and UAE PDPL.

04Workflow

From control definition to audit-ready evidence

Each step is owned, dated, and traceable, so nothing depends on a spreadsheet or a single person.

  1. Step 1

    Set scope & tier

    Define entity scope, ADHICS tier, and applicable controls.

  2. Step 2

    Assign owners

    Route controls to clinical, IT, and security owners with SLAs.

  3. Step 3

    Collect evidence

    Connectors and tasks gather technical and procedural evidence.

  4. Step 4

    Report to DoH

    Generate attestation packages and incident notifications on demand.

05Audit readiness

DoH audits, without disruption

Hand the Department of Health a complete, structured ADHICS package with evidence and trails for every control.

  • Read-only auditor workspace scoped to ADHICS
  • Per-domain evidence packages and policies
  • Internal audit and management review records
  • Incident register with timelines and remediation
  • Vendor risk and connected provider assurance
06For leadership

Board level answers without a fire drill

Boards, CISOs, and risk committees get the same numbers the compliance team works from.

Patient safety first

Strong cybersecurity reduces clinical disruption and patient harm risk.

Lower audit overhead

Continuous evidence collection cuts audit prep time and external advisor cost.

DoH and DoH+ confidence

Demonstrate maturity to regulators, payers, and partner providers.

07FAQ

Questions we get asked

What is ADHICS?

ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, is the mandatory cybersecurity and information security standard issued by the Department of Health Abu Dhabi (DoH). It defines the controls all licensed healthcare entities in the Emirate of Abu Dhabi must implement to protect patient data and healthcare information systems.

Who must comply with ADHICS?

Every healthcare entity licensed by the Department of Health Abu Dhabi falls within ADHICS scope. That includes public and private hospitals, day-surgery centers, clinics, diagnostic labs, pharmacies, insurance payers, telehealth providers, and IT service providers supporting healthcare operations.

What is the difference between ADHICS v1 and ADHICS v2?

ADHICS v2 is the current version of the standard. It expands the control catalog, introduces tighter requirements around medical device security, cloud, third-party risk, and incident reporting, and aligns more closely with ISO 27001, NIST CSF, and the UAE Information Assurance Standards. Waaqi ships with the latest ADHICS v2 control library.

What ADHICS tier applies to my organization?

ADHICS classifies entities into tiers based on size, patient volume, and the criticality of services. Larger and more critical providers must implement the full Basic and Transitional controls plus Advanced controls. Waaqi auto-scopes the applicable tier and surfaces only the controls relevant to your entity.

How often does the DoH audit ADHICS compliance?

DoH expects continuous compliance and conducts attestations and on-site audits on a recurring cycle, with additional reviews triggered by incidents, license renewals, or sectoral campaigns. Waaqi keeps evidence current so an audit never starts from scratch.

How does ADHICS relate to UAE PDPL and HIPAA?

ADHICS focuses on cyber and information security; UAE PDPL governs personal data protection; and HIPAA is often referenced by international partners. Waaqi maps one control library across all three, so the same evidence satisfies ADHICS, UAE PDPL, and HIPAA gap assessments.

Does ADHICS cover medical devices and connected providers?

Yes. ADHICS includes specific controls for medical device security, network segmentation, vendor risk, and connected provider assurance. Waaqi tracks medical device inventories, firmware, and vendor attestations alongside corporate IT controls.

How does Waaqi help with ADHICS compliance?

Waaqi pre-loads the full ADHICS v2 control library, assigns owners, runs evidence collection on a schedule, manages internal audits and CAPA, and produces DoH-ready attestation packages and incident reports, turning ADHICS into a continuous program rather than an annual project.

ADHICS compliance: what Abu Dhabi healthcare entities must do

ADHICS, the Abu Dhabi Healthcare Information and Cyber Security Standard, is the binding cybersecurity standard for every healthcare entity licensed by the Department of Health Abu Dhabi (DoH). It applies to hospitals, clinics, diagnostic labs, payers, telehealth providers, and the IT and MedTech vendors that support them. Compliance is not optional: it conditions licensing, renewals, and the ability to operate in the Emirate.

The standard covers governance, risk management, asset management, human resources security, physical security, communications, access control, system acquisition and development, incident management, business continuity, and compliance assurance. Each domain contains controls grouped into Basic, Transitional, and Advanced tiers, and entities are scoped to a tier based on size, criticality, and the sensitivity of the data they process.

ADHICS v2 also introduced sharper requirements around medical device security, cloud adoption, third-party risk, and incident reporting timelines, areas where most healthcare providers struggle without a dedicated GRC platform.

Running ADHICS as a continuous program with Waaqi

Most ADHICS programs fail not because the standard is unclear, but because spreadsheets cannot keep up. Controls drift, ownership is ambiguous, evidence ages out, and every DoH audit becomes a fire drill. Waaqi replaces that model with a continuous ADHICS operating system.

The full ADHICS v2 control library ships pre-loaded with guidance, tiering, and suggested evidence. Waaqi auto-scopes the applicable controls based on your entity classification, routes each one to a clinical, IT, or security owner with an SLA, and collects evidence through connectors and recurring tasks. Internal audits, CAPA, management reviews, and risk treatment plans are first-class objects, not attachments to an email thread.

When an incident occurs, Waaqi opens a workflow aligned with DoH reporting expectations, timelines, severity scoring, evidence capture, regulator notification templates, and post-incident lessons learned, so reporting deadlines are met without scrambling.

One control library for ADHICS, ISO 27001, HIPAA, and UAE PDPL

Abu Dhabi healthcare providers rarely face only ADHICS. International accreditations (JCI, ISO 27001), insurance partners (often HIPAA-aligned), and the UAE PDPL all demand evidence of the same underlying controls. Waaqi maps ADHICS to ISO 27001 Annex A, NIST CSF, HIPAA Security and Privacy Rules, and UAE PDPL, so a single implementation satisfies multiple frameworks.

This unified control model cuts duplicate work, eliminates conflicting evidence, and lets compliance leaders demonstrate maturity across regulators, accreditors, payers, and connected providers, without expanding the team.

DoH audit readiness and incident reporting

DoH audits move fast. Waaqi's auditor workspace gives the regulator a read-only, ADHICS-scoped view of policies, controls, evidence, internal audit history, risk treatment, and incident records. Every control links to current evidence and historical trail, so the question "show me how you implement control X" is answered in seconds.

For incidents, Waaqi maintains a unified register with DoH notification status, internal RCA, CAPA, and trend analytics across the organization, closing the loop between detection, response, and ADHICS reporting obligations.

Operationalize ADHICS

See how Waaqi makes ADHICS compliance continuous and DoH-ready.