DuoKey
Compliance

ADHICS v2

Abu Dhabi Healthcare Information and Cyber Security Standard. CS 1.2 says the cloud provider must not store or control the entity's keys.

Requirements

What the regulation expects

ADHICS v2 is mandatory for healthcare entities and their service providers in the Emirate of Abu Dhabi. CS 1.2 is unusually explicit: the cloud service provider must not store or control the entity's cryptographic keys, and the entity must be able to generate or configure its own keys. No provider-managed KMS meets that by design. Federal Law No. 2 of 2019 (ICT in health) is the federal counterpart when health data leaves an on-premise system.
What the regulation expects

Mandatory for Abu Dhabi healthcare entities and providers

SA 3 Cryptographic Controls and CS 1 Cloud Security decide the key management architecture.

Encryption for stored and transmitted health data

SA 3.1 expects encryption within and outside the entity, with the same keys reaching clinical systems that hold the data.

Key lifecycle as platform behaviour

Activation, deactivation, revoke, backup, recover and replace are Pre-Active / Active / Deactivated / Compromised states, not procedure alone.

UAE hosting for cloud environments

CS 1.2 expects physical hosting in the UAE including backup and DR. That is a deployment commitment in the contract, not an automatic SaaS property.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

On-premise or in-UAE vault (including air-gapped) with inventory showing the entity as key owner.

Learn more

Microsoft 365 DKE

Double Key Encryption so the hosting provider does not hold the only usable key.

Learn more

SQL / TDE / EKM

External keys for Oracle TDE, SQL Server EKM and KMIP-capable stores.

Learn more

Cloud BYOK / external key store

Keys generated in the entity vault and referenced by the cloud service rather than held by it.

Learn more

Key themes

Where independent key control fits

Cryptographic and cloud demands below carry Transitional and Service Provider markings in the published standard. Confirm current grading with DoH for each engagement.

SA 3.1 Encryption and key lifecycle

Encrypt stored and transmitted information. Generate, share, protect, activate/deactivate, revoke, backup, recover, replace and monitor keys under enforced platform states.

CS 1.2 (4)(5) Encryption and key not from CSP

Data at rest and in transit encrypted. The key must not be provided by the CSP that hosts application, infrastructure and data. Provider-managed KMS cannot satisfy this.

CS 1.2 (7)(8) Entity-generated keys, CSP does not store or control

Keys generated in the entity vault and referenced by the cloud service. Vault can run on-premise inside the Emirates.

Relevant products

CS 1.2 (2) UAE hosting including backup and DR

On-premise or in-country deployment so the key management plane and its backups sit inside the Emirates. State this explicitly in the contract.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.