ADHICS - the Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health - Abu Dhabi - sets the information-security controls healthcare entities in the emirate must implement, including vulnerability management and security testing of systems handling health information. In practice that means VAPT with findings tracked to closure and reported against the ADHICS controls. CyberFortify maps every engagement to ADHICS and weights the health-data access-control risks that matter most.
// 01 What ADHICS is
The Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health - Abu Dhabi (DoH), is the cyber security standard that healthcare entities in the emirate must comply with. It defines information-security controls covering governance, risk, asset and access management, operations and technical security.
Among those controls are vulnerability management and security testing of systems handling health information - which is where periodic vulnerability assessment and penetration testing fit.
ADHICS is the defining cyber security driver for Abu Dhabi's healthcare sector. For the practitioner view, see our ADHICS penetration testing requirements guide, the healthcare testing playbook, and the Abu Dhabi services overview.
// 02 The testing controls in practice
Security testing
Testing of systems handling health information - vulnerability assessment and penetration testing. Our manual-led testing satisfies the intent.
Health-data access control
The critical risk: one patient's record must not be reachable by another. We weight access-control testing heavily.
Findings tracked to closure
Findings remediated and closed - our retest is included to evidence it.
Reported against ADHICS
Findings and coverage mapped to the ADHICS controls a health-sector assessor checks.
// 03 Who is in scope
ADHICS applies to healthcare entities operating in the Emirate of Abu Dhabi under the Department of Health - Abu Dhabi: hospitals, clinics, insurers and other providers, and their relevant service providers handling health information. Any organisation in the Abu Dhabi healthcare ecosystem that creates, processes or stores health information is expected to implement the standard - making ADHICS the primary cyber security driver for the emirate's healthcare sector. It applies alongside the federal UAE PDPL over personal and health data, and the emirate's ADGM/FSRA and UAE IA regimes where relevant. Providers serving US healthcare may separately face HIPAA.
For a healthcare entity, the finding that matters most is a broken access control that lets one patient's record be reached by another - a mass health-data breach with no exotic exploit. ADHICS testing has to hunt that, and we do.
CyberFortify ADHICS-facing reporting// 04 Why health-data access control is the focus
Health information is among the most sensitive data any organisation holds, and the highest-impact finding in a healthcare test is rarely a textbook technical bug - it is a broken access control that lets one patient (or an attacker) read another patient's record. Healthcare applications are full of authorisation boundaries between patients, clinicians and staff, and when those are enforced only in the UI, a manipulated ID or API call exposes protected health information at scale. So an ADHICS-aligned engagement weights access-control and business-logic testing heavily across the patient portals, clinical systems and their APIs - the same discipline in our healthcare work. Book ahead of any assessment so findings can be retested to closure; map the cadence with the GCC compliance calendar.
// 05 Frequently asked questions
Does ADHICS require penetration testing?
ADHICS sets information-security controls that Abu Dhabi healthcare entities must implement, including vulnerability management and security testing of systems handling health information. In practice providers conduct VAPT, track findings to closure, and report against the ADHICS controls. It's framed as security testing within a broader controls set, but penetration testing is the recognised way to satisfy that control.
Who must comply?
Healthcare entities in the Emirate of Abu Dhabi under the Department of Health - Abu Dhabi: hospitals, clinics, insurers and other providers and their relevant service providers handling health information. Any organisation creating, processing or storing health information in the Abu Dhabi healthcare ecosystem is expected to implement the standard.
How does ADHICS relate to HIPAA and the UAE PDPL?
ADHICS is the Abu Dhabi emirate standard for healthcare. HIPAA is a US law and doesn't apply in Abu Dhabi, though organisations serving US healthcare may need both. The UAE PDPL governs personal data federally and applies alongside ADHICS to the health data entities hold. A provider serving multiple markets may map evidence to ADHICS, the PDPL and, where relevant, HIPAA together.
How does CyberFortify produce ADHICS-aligned evidence?
We scope to the systems handling health information and deliver a report mapping findings and coverage to the ADHICS controls, so an assessor or the entity's compliance team sees the security testing control satisfied. Findings are remediated and retested, and the testing weights the access-control and data-exposure risks that matter most for health information.