UAE · Department of Health, Abu Dhabi

Abu Dhabi Healthcare Information and Cyber Security Standard

The mandatory healthcare information security standard for entities operating under the Abu Dhabi health authority.

Who it applies to

Healthcare providers, payers and health technology suppliers operating in the Emirate of Abu Dhabi. It is mandatory within its scope rather than voluntary.

What it requires

  • Controls sized to the entity classification assigned to the organisation
  • Protection of patient health information across its lifecycle
  • Incident response and reporting aligned to health authority expectations
  • Governance of third parties handling health information

What preparing for it involves

The entity classification determines the depth of control expected, so confirming classification is the first task rather than a formality. Healthcare data carries sensitivity that changes the risk calculation: the same technical control protecting ordinary business data is judged more strictly when the record is clinical.

How it concludes

Compliance assessed by the health authority, with obligations that continue after the initial assessment.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.