The mandatory healthcare information security standard for entities operating under the Abu Dhabi health authority.
Healthcare providers, payers and health technology suppliers operating in the Emirate of Abu Dhabi. It is mandatory within its scope rather than voluntary.
The entity classification determines the depth of control expected, so confirming classification is the first task rather than a formality. Healthcare data carries sensitivity that changes the risk calculation: the same technical control protecting ordinary business data is judged more strictly when the record is clinical.
Compliance assessed by the health authority, with obligations that continue after the initial assessment.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.