What Is ADHICS v2.0?

ADHICS - the Abu Dhabi Health Information and Cyber Security standard - is the mandatory cybersecurity framework for every healthcare entity licensed by the Abu Dhabi Department of Health. Version 2.0, introduced in 2024, represents a significant tightening of requirements across all control domains.

692
Total ADHICS v2.0 controls across all domains

What Changed in Version 2.0

The most operationally significant changes fall into four areas:

Breach Containment Window

The required response window for high-risk incidents dropped from 72 hours to 4 hours. This is not a minor adjustment. It requires a fundamentally different operational posture - continuous monitoring, a documented incident response plan and a team capable of acting immediately at any hour.

Zero Trust Architecture

ADHICS v2.0 makes Zero Trust mandatory for all healthcare entities. This means no implicit trust for any device, user or system - even those inside the network perimeter. Every access request must be verified.

Annual Vendor Assessments

All EMR vendors, billing platforms and third-party technology partners must be assessed annually for security and compliance posture. If your vendor cannot pass assessment, you carry the risk.

Malaffi Connectivity

Non-compliant entities face exclusion from Malaffi, Abu Dhabi's health information exchange. Exclusion from Malaffi effectively disconnects a hospital from the broader care ecosystem.

The Three-Tier Compliance Structure

ADHICS v2.0 applies different control sets depending on organisation size:

Basic tier covers small clinics and specialist centres with limited complexity. Transitional tier covers medium-sized facilities. Advanced tier covers hospitals and large health systems.

Understanding which tier applies to your organisation is the essential first step before any implementation work.

4 hours
Maximum breach containment window under ADHICS v2.0 - down from 72

What to Do Before Your Next Audit

The TASNEEF audit cycle is not predictable. Organisations that treat compliance as an annual event find themselves exposed when an audit arrives between preparation cycles.

The practical steps are: complete a gap assessment against all applicable control domains, prioritise remediation by risk level, implement the highest-risk controls first, document everything as you go, and establish continuous monitoring so your posture is known at all times.

How SEHANEXIS Can Help

We conduct full ADHICS v2.0 gap assessments covering all applicable control domains. The output is a detailed gap report with a prioritised remediation roadmap and a realistic timeline to compliance.

Every platform and system we build for UAE clients is designed to ADHICS requirements from the start, which means no retrofit required at audit time.