ADHICS is the Abu Dhabi Healthcare Information and Cyber Security standard, issued by the Department of Health in Abu Dhabi. It sets information security expectations for healthcare entities operating in the emirate. If you run a clinic, diagnostic centre or hospital in Abu Dhabi, it is relevant to how you run your IT.
Verify your own position
This is an orientation guide written from an IT perspective, not a compliance opinion. Confirm your specific obligations, applicable version and timelines directly with the Department of Health or a qualified compliance advisor.
Why healthcare is treated differently
Patient data is among the most sensitive categories any business holds and among the most attractive to attackers, because it cannot be reissued the way a card number can. Healthcare is also a sector where system unavailability has consequences well beyond inconvenience. Standards in this space reflect both facts.
Where clinic IT usually falls short
Working with smaller healthcare providers, the same gaps recur. None of them are exotic, and most are fixable without significant expenditure.
- Shared logins to the clinical system, so nobody can attribute an action to a person
- No access review, meaning staff who left months ago still appear in the system
- Backups that report success but have never been restored from
- Patient data copied onto personal devices or personal cloud accounts for convenience
- Unsupported operating systems on machines attached to diagnostic equipment
- No logging of who accessed which patient record, which is a core expectation in this sector
- Wi-Fi where guest and clinical traffic share one network
What to fix first
- 1Eliminate shared accounts, so every action is attributable to a named individual
- 2Enforce multi-factor authentication on email and any remote access to clinical systems
- 3Verify that backups actually restore, and document the test
- 4Separate guest Wi-Fi from clinical systems at the network level
- 5Establish an access review, with a record showing it happened
- 6Document your asset inventory, since almost every control depends on knowing what you have
The evidence problem
Healthcare providers frequently have better controls than their documentation suggests, and it is the documentation that gets assessed. Being able to demonstrate that access reviews took place, that backups were tested and that staff received training is a different task from doing those things, and it needs building into normal operations rather than assembled retrospectively.
Practical constraints in a small clinic
| Constraint | Common shortcut | Better approach |
|---|---|---|
| Clinicians share a workstation | One shared login | Individual logins with fast switching |
| Urgent access needed | Give everyone full access | Role-based access with a documented break-glass |
| Old diagnostic equipment | Leave it on the main network | Segment it, since the vendor may not support patching |
| No dedicated IT person | Nothing gets reviewed | Scheduled reviews with an external provider |
Where an IT provider fits
An IT provider handles the technical half: access control, logging, segmentation, backup verification, endpoint management and evidence collection. It does not certify you and it does not replace compliance advice specific to your licence and your practice. Be cautious of anyone blurring that line.
Running a clinic in Abu Dhabi?
We handle the technical side of healthcare information security, from access control and segmentation through to the evidence trail assessors ask for.
Frequently asked questions
What is ADHICS?
It is the Abu Dhabi Healthcare Information and Cyber Security standard, issued by the Department of Health in Abu Dhabi, setting information security expectations for healthcare entities in the emirate. Confirm the current version and how it applies to your licence directly with the Department of Health.
What is the most common gap in clinic IT?
Shared logins to the clinical system. They make it impossible to attribute an action to an individual, which undermines access logging entirely. Replacing them with individual accounts and fast user switching is usually the highest-value first step.
Do we need to log who views patient records?
Access logging is a core expectation in healthcare information security, and most clinical systems support it even when it is not enabled. Check whether yours is configured and whether the logs are retained long enough to be useful.
Can our IT provider make us compliant?
An IT provider can implement and evidence the technical controls, which is a substantial part of the work. Compliance itself involves policy, process and clinical governance beyond IT, and formal assessment comes from the relevant authority rather than from a supplier.
What about old diagnostic equipment we cannot patch?
Segment it onto its own network so it cannot reach the internet or the clinical system directly, and document the compensating controls. Vendors frequently do not support patching on medical devices, so isolation is the practical answer rather than an excuse.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for IT Compliance Consulting Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.