ADHICS Penetration Testing & Compliance Consulting - Abu Dhabi

ADHICS gap analysis, readiness review, an ADHICS-scoped penetration test, and a DoH auditor evidence package - for hospitals, clinics, HIS and EMR vendors, and healthtech platforms regulated by the Department of Health Abu Dhabi.

Duration: 3-5 weeks scope-dependent Team: Senior Security Researchers with UAE healthcare and ADHICS mapping experience

You might be experiencing...

A DoH Abu Dhabi audit is coming and you need documented penetration testing evidence mapped to ADHICS V2 control domains - not a generic scan exported to PDF.
You know ADHICS V2 mandates bi-annual security assessments, but you are not sure what scope auditors will actually accept as the approved boundary.
Your HIS, EMR, patient portal, and connected medical devices have never been tested together as one PHI data-flow scope, and exclusions have never been justified in writing.
You need an ADHICS consultant in the UAE who can run the gap analysis and the pentest, then hand your auditor a single evidence package they can trace line by line.

ADHICS penetration testing is no longer a one-time project for Abu Dhabi healthcare entities - it is a recurring legal obligation. With ADHICS V2, the Department of Health Abu Dhabi (DoH Abu Dhabi) standard now mandates regular technical security assessments with explicit penetration-testing scope. For every hospital, clinic, HIS vendor, and healthtech platform that touches patient data in the emirate, that converts pentesting from a once-a-year event into a continuous compliance requirement.

We run this as one engagement, not two invoices: an ADHICS gap analysis and readiness review, an ADHICS-scoped penetration test, and a DoH auditor evidence package that hands your assessor everything they ask for in a single bundle. Dubai-based firm, Abu Dhabi healthcare-serving, with every finding mapped to the ADHICS control domain it belongs to.

What ADHICS Compliance Consulting Actually Covers

A generic pentest vendor hands you a technically competent report structured for nobody in particular. ADHICS compliance consulting is different - it starts from the standard and works backward to the evidence a DoH auditor will trace line by line. Our engagement has four moving parts:

ADHICS gap analysis - a controls and documentation review that maps your current security program against ADHICS V2. Where does your vulnerability management SLA fall short? Are third-party integrations covered by policy? Is audit logging on PHI systems actually validated? The gap analysis answers these before any active testing, so you fix the cheap things early and scope the expensive things correctly.

Readiness review - a practical assessment of whether your team, your documentation, and your evidence trail would survive a DoH audit today. This is where most entities discover their previous “pentest” was a scan with no scope sign-off and no re-test evidence.

ADHICS-scoped penetration test - the active technical work. Manual, senior-led, external and internal, authenticated and unauthenticated, across the approved PHI scope.

DoH auditor evidence package - the deliverable that matters. Approved scope, methodology statement, risk-rated findings mapped to ADHICS control domains, remediation evidence, and a re-test confirmation letter.

For the item-by-item breakdown of what auditors check, see our ADHICS penetration testing checklist.

Is ADHICS Penetration Testing Mandatory?

Yes. ADHICS V2 requires regular technical security assessments, including penetration testing, for all DoH-regulated healthcare entities and the vendors connected to them. The requirement is not buried in one obscure clause - it is reinforced across several control domains:

  • Technical security assessment - systems handling health information must undergo regular vulnerability assessment and penetration testing.
  • Vulnerability management - identification, risk-rating, and remediation on a defined cadence.
  • Third-party and cloud security - testing obligations extend to integrated vendors and cloud-hosted health data platforms.

ADHICS is the successor to the legacy HAAD information security guidance and is the healthcare-specific counterpart to NESA at the national level. Where NESA governs critical national infrastructure broadly, ADHICS applies the same security philosophy to the healthcare sector under DoH Abu Dhabi authority.

How Often Do You Have to Test? Bi-Annual Under ADHICS V2

ADHICS V2 establishes a bi-annual cadence for security assessments. In practice, most DoH auditors treat an annual external penetration test as the minimum acceptable floor, with internal and targeted assessments filling the gaps between full engagements.

Cadence alone is not enough. ADHICS treats testing as change-driven as well as calendar-driven - re-testing is triggered whenever your risk surface shifts:

Assessment typeFrequencyTrigger
External penetration testAnnual (minimum)Calendar - regulatory baseline
Internal / segmentation testBi-annualCalendar - ADHICS assessment cadence
Vulnerability assessmentQuarterlyCalendar - vulnerability management domain
Change-driven re-testAs neededMajor system change, new integration, new cloud workload
Post-incident assessmentAs neededAny security incident affecting PHI systems

This is why a growing number of Abu Dhabi healthcare entities move from one-off tests to a continuous testing retainer. When you ship releases, onboard a new lab integration, or stand up a new cloud workload monthly, a single January pentest does not reflect your posture by June. Our Guardian retainer assesses every material change before it reaches production and keeps your evidence package continuously audit-ready.

What Is In ADHICS Pentest Scope?

ADHICS scope follows the flow of protected health information (PHI). Before testing begins, you map every system, interface, and device that touches PHI - that data-flow map becomes the basis for your approved scope document. The categories a DoH auditor expects to see covered:

  • Public web apps and patient portals - booking portals, patient dashboards, forms
  • HIS and EMR core - clinical information systems and electronic medical records
  • Telemedicine platforms - virtual consultation and remote monitoring channels
  • APIs and integration layers - FHIR and HL7 interfaces, REST APIs, integration engines
  • Third-party integrations - lab, pharmacy, insurance claim gateways, telehealth
  • Connected medical and IoMT devices - diagnostic, monitoring, and imaging equipment
  • Cloud environments - AWS, Azure, OCI hosting PHI workloads
  • Network and segmentation - clinical versus corporate and guest separation
  • Identity and access - Active Directory, IAM, privileged access

Connected medical devices and third-party integrations are the two most-missed scope items in failed ADHICS audits. Both get silently excluded for the same reason - teams assume the device manufacturer or the integration vendor owns the security. ADHICS does not see it that way. If a connected infusion pump or a lab interface processes PHI on your network, it is in your scope, and an auditor will expect evidence it was tested. For the full attack-surface picture, see our healthcare penetration testing guide covering DHA and ADHICS.

The DoH Auditor Evidence Package

The report is the product. A DoH-ready package contains the five artifacts an ADHICS auditor asks for, plus the control mapping that ties it all to the standard:

ADHICS control domainPentest activityEvidence produced
Technical security assessmentFull external + internal penetration testMethodology statement, risk-rated report
Vulnerability managementAuthenticated assessment + re-testFindings with CVSS, remediation evidence
Asset management (devices)Medical / IoMT device and network testingDevice-level findings in scope report
Third-party securityIntegration-boundary testing of vendor interfacesThird-party findings, scope sign-off
Cloud securityCloud configuration review + workload testingCloud findings, config baseline gaps
Access controlPrivilege escalation, role and IDOR testingAccess-control findings, evidence pairs
Network securitySegmentation and firewall rule validationSegmentation test results
Audit and accountabilityLogging and monitoring validationLogging gap findings

The difference between an evidence package that passes and one that triggers follow-up questions is local regulatory fluency. A UAE-based provider that maps every finding to ADHICS control domains hands your auditor a report they can trace directly - saving weeks of internal translation and removing the risk that a finding is dismissed because it was not framed against the standard.

Who Needs This

If your organisation creates, stores, transmits, or processes patient data in Abu Dhabi, you are almost certainly in ADHICS scope:

  • Hospitals and clinics operating under a DoH licence
  • HIS and EMR vendors supplying or hosting clinical systems
  • Healthtech SaaS platforms - telemedicine, scheduling, patient engagement
  • Medical device integrators connecting IoMT equipment to clinical networks
  • Cloud-hosted health data platforms on AWS, Azure, or OCI

For vendors specifically, an ADHICS gap does more than risk a finding - it can disqualify you from selling into Abu Dhabi providers entirely, because your customers fail their own audits if your platform is not tested. Our healthtech industry practice is built around exactly this buyer.

Engagement Phases

Week 1

ADHICS Gap Analysis & Readiness Review

Map your current controls against ADHICS V2 - technical security assessment, vulnerability management, third-party and cloud security, asset management, and access control domains. Identify where your program falls short of what a DoH auditor expects before any active testing starts.

Week 1-2

PHI Scoping & Scope Sign-Off

Build the PHI data-flow map that justifies the testing boundary, then finalise the approved scope document covering all in-scope categories - HIS, EMR, patient portals, telemedicine, APIs, third-party integrations, connected medical devices, cloud, network, and identity. Exclusions justified in writing.

Weeks 2-4

ADHICS-Scoped Penetration Test

Manual external and internal, authenticated and unauthenticated testing across the approved scope. Critical findings reported in real time, not held for the report. Senior researchers, not junior staff running an automated scanner.

Week 4-5

Reporting & ADHICS Control Mapping

Risk-rated findings with CVSS v3.1 scoring, business impact, and every finding mapped to the ADHICS control domain it relates to - so your auditor traces each result straight back to the standard.

Post-remediation

Remediation Re-Test & Evidence Package

Your team fixes the findings, we verify the fixes, and you receive a re-test confirmation letter that closes out high and critical findings for the DoH-ready evidence bundle.

Deliverables

ADHICS V2 gap analysis and readiness report
PHI data-flow map and signed-off approved scope document
Full technical findings report with CVSS v3.1 scoring and business impact
Findings mapped explicitly to ADHICS control domains
Methodology statement referencing OWASP, PTES, and NIST for the auditor
Remediation evidence and re-test confirmation letter for high and critical findings
DoH auditor evidence package - every artifact an ADHICS audit asks for, in one bundle

Frequently Asked Questions

Is penetration testing mandatory under ADHICS?

<strong>Yes.</strong> ADHICS V2, the Department of Health Abu Dhabi healthcare information and cyber security standard, requires regular technical security assessments that include penetration testing for all DoH-regulated healthcare entities and their connected vendors. The requirement is reinforced across several control domains - technical security assessment, vulnerability management, and third-party and cloud security. Hospitals, clinics, HIS and EMR vendors, healthtech SaaS platforms, and medical device integrators are all in scope. A missing or inadequate testing program surfaces as a DoH audit finding that can put your accreditation and operating licence at risk.

How often does ADHICS require penetration testing?

ADHICS V2 mandates <strong>bi-annual security assessments</strong>, and most DoH auditors treat an <strong>annual external penetration test</strong> as the practical floor. Cadence alone is not enough - ADHICS treats testing as change-driven as well as calendar-driven. Re-testing is triggered by major system changes, new third-party integrations, new cloud workloads, and any security incident affecting PHI systems. Because Abu Dhabi healthcare entities deploy continuously, many move to a continuous testing retainer so every material change is assessed before it goes live.

What evidence do DoH auditors ask for from an ADHICS pentest?

A DoH-ready package contains five artifacts: an <strong>approved scope and rules-of-engagement document</strong>, a <strong>methodology statement</strong> referencing recognised standards (OWASP, PTES, NIST), <strong>risk-rated findings</strong> with CVSS scores and business impact, <strong>remediation evidence</strong> showing fixes were applied, and a <strong>re-test confirmation letter</strong> verifying closure. Auditors also expect every finding mapped to its ADHICS control domain so results trace directly to the standard. A scan exported to PDF without scope sign-off or re-test evidence will not satisfy an ADHICS audit.

What is the difference between an ADHICS gap analysis and an ADHICS penetration test?

A <strong>gap analysis</strong> is a documentation and controls review - it maps your current security program against ADHICS V2 control domains and tells you where you fall short before anyone touches a system. A <strong>penetration test</strong> is active technical testing that proves whether those controls actually hold up against a real attacker. You need both: the gap analysis defines what to fix and shapes the approved scope, and the pentest produces the technical evidence a DoH auditor requires. We run them as one engagement so the gap analysis feeds the scope directly.

How long does an ADHICS penetration test take?

For a mid-sized Abu Dhabi healthcare entity, a scoped ADHICS engagement runs roughly <strong>3 to 5 weeks</strong> end-to-end - gap analysis, scope sign-off, testing, reporting with control mapping, and remediation re-test. The exact timeline depends on the number of in-scope systems and third-party integrations. Larger hospital networks with many connected medical devices and integration endpoints run longer; a single healthtech platform runs shorter.

Who needs ADHICS penetration testing?

Any organisation that creates, stores, transmits, or processes patient data in Abu Dhabi is almost certainly in ADHICS scope: <strong>hospitals and clinics</strong> operating under a DoH licence, <strong>HIS and EMR vendors</strong> supplying or hosting clinical systems, <strong>healthtech SaaS platforms</strong> (telemedicine, scheduling, patient engagement), <strong>medical device integrators</strong> connecting IoMT equipment, and cloud-hosted health data platforms on AWS, Azure, or OCI. For vendors, an ADHICS gap can also disqualify you from selling into Abu Dhabi providers - your customers fail their own audits if your platform is not tested.

  • OSCP-certified researchers
  • CREST-aligned methodology
  • Senior-led, never juniors
  • First findings in 48 hours
  • Professional indemnity insured

Find It Before They Do

Book a free 30-minute security discovery call with our AI Security experts in Dubai, UAE. We identify your highest-risk AI attack vectors - actionable findings in days.

Talk to an Expert