Care homes and domiciliary care providers increasingly rely on digital records, remote-monitoring devices and mobile staff devices. A cyber event can cause care disruption, regulatory fines and reputational damage, but the right cyber insurance can reduce financial consequences and support incident response. This content focuses on practical, sector-specific information for England-based small and medium-sized care providers (1–50 staff), comparing care homes and domiciliary care needs, explaining policy terms, indicative costs and clear next steps.
Key takeaways
- Care homes and domiciliary care have different cyber exposure: residential settings often face concentrated IT and networked medical devices; domiciliary care faces greater staff mobility and third-party data flows.
- Policies vary by cover and limits: typical covers include data breach response, regulatory fines (GDPR limits), business interruption, ransomware, and cyber extortion, limits and sublimits determine actual pay-outs.
- Size, payroll and number of records shape premiums: microbusinesses often pay lower premiums but may have higher relative excesses and stricter security requirements.
- Practical controls reduce premium and claims friction: basic measures (patching, MFA, backups, staff training) are commonly required and often influence acceptance and premium.
- Incident readiness matters more than perfect security: insurance combined with an incident plan and breach-notification procedures reduces downtime and regulatory exposure.
Why care homes need cyber insurance tailored to size and services
Care homes (residential) typically hold larger, consolidated datasets, run on-site networks supporting CCTV, medication records, rostering systems and sometimes IoT devices (room sensors, remote monitors). A successful ransomware attack can encrypt care plans, block medication records and halt payroll or access control systems.
Insurers commonly treat care homes differently from domiciliary providers because of: concentration risk (many records stored centrally), greater regulatory scrutiny from the Care Quality Commission (CQC) and potential for immediate patient safety impacts. Policies for care homes therefore often include higher limits for business interruption and access to external incident response firms.
Smaller care homes (under 25 beds) may qualify for SME policy terms but still face requirements such as patch management, multi-factor authentication (MFA) and secure backups. Larger care homes may face tailored underwriting questions about IoT devices, third‑party suppliers and disaster recovery plans.
How domiciliary care microbusinesses assess cyber risk differently
Domiciliary care providers typically have small teams, workers who visit multiple clients and reliance on mobile devices or apps to record care notes. Key exposures include lost or stolen staff smartphones or tablets, insecure public Wi‑Fi used during visits, and data transfers with local authorities or the NHS via portals.
Risk assessment checklist (indicative):
- Inventory of devices and apps used by carers.
- How client records are stored (cloud, local app, paper backup).
- Frequency and method of backups.
- Contracts and data-sharing agreements with local authorities/NHS.
- Training frequency on phishing and device handling.
Insurers will ask about device management, password policies, encryption and whether the business uses approved social-care software. Microbusinesses often benefit from simpler, lower-cost policies but may face narrower cover for ransomware and lower limits for regulatory defence costs.

Choosing policy limits for SMEs handling patient data
Choosing limits depends on the value of loss, potential regulatory fines and the cost to restore operations. Consider these components when selecting limits:
- Data breach response costs: forensic investigation, legal, PR and customer notification. Typical SME events cost several thousand to tens of thousands of pounds, choose a sum that covers external specialists and communications.
- Regulatory defence and fines: ICO can issue monetary penalties for GDPR breaches. While insurers may cover defence costs and fines where lawful, cover for fines is limited and varies by insurer. Indicative at time of writing: many UK SME policies show sublimits for regulatory fines, so check wording.
- Business interruption: time taken to restore care records and systems can directly affect operations and staffing; higher limits matter for residential homes with centralised systems.
- Ransomware & cyber extortion: ensure the policy includes negotiated ransomware response and, if permitted by policy, funds for ransom payments (many policies differ on insurability of ransom payments).
Indicative limits commonly purchased by SMEs (2026 guidance):
- Small domiciliary microbusiness (1–10 staff): £50,000–£250,000 total cyber limit.
- Small care home (up to 25 beds): £250,000–£1,000,000 total cyber limit, with business interruption sublimits.
- Medium care provider (25–50 staff or beds): £500,000–£2,000,000, depending on contract obligations and NHS supply chains.
These ranges are indicative and depend on payroll, revenue and number of records held.
Comparison: care homes vs domiciliary care (HTML table)
| Feature |
Care homes (residential) |
Domiciliary care (visiting staff) |
| Typical data concentration |
High, centralised electronic records, CCTV |
Distributed, mobile devices, cloud apps |
| Main cyber threats |
Ransomware, IoT vulnerabilities, insider error |
Device theft, insecure Wi‑Fi, phishing |
| Business interruption impact |
Immediate, on-site care disruption |
Operational delays, scheduling and payroll issues |
| Insurer focus |
Backup integrity, network segmentation, IoT security |
Mobile device management, encryption, data minimisation |
| Typical limits |
Higher BI and data breach response limits |
Lower overall limits but specific theft/PD coverage |
Table indicative and summarises common underwriting differences; individual policies vary.
Covering business interruption and ransomware for care providers
Business interruption (BI) cover responds to lost income and extra costs while systems are down. For care providers, BI may be triggered by a cyber event that prevents access to electronic care records, rostering systems or billing platforms. Policies will often require proof of loss: restored logs, forensic reports and evidence of mitigation steps.
Ransomware response typically includes: forensic investigation, restoration support, negotiation assistance and sometimes ransom payment facilitation. Many insurers provide access to specialist incident response firms that liaise with law enforcement and the ICO.
Common limitations and practical notes:
- Waiting periods and indemnity periods: some policies apply a waiting period (hours or days) before BI cover starts; indemnity periods vary (30, 90 days or longer). Longer indemnity periods increase premiums.
- Sublimits for ransomware: certain policies cap ransomware payments or related costs separately from total limit.
- Contingent business interruption: cover may be available where a key supplier (e.g., an outsourced care-records provider) suffers a breach causing loss of service.
Operational recommendation (general considerations): maintaining isolated, recent backups and tested recovery procedures reduces downtime and increases the likelihood of insurer support without payment of ransom.
ICO reporting, regulatory fines and compliance expectations
GDPR obligations require timely breach notification in many incidents. The Information Commissioner's Office (ICO) expects organisations to assess breaches, notify when required and demonstrate appropriate technical and organisational measures.
Key points:
- Notification timescales: where a breach is likely to result in a risk to people’s rights and freedoms, a report to the ICO is usually required within 72 hours. Affected individuals may also require notification.
- ICO engagement and enforcement: the ICO can investigate and issue fines; insurers may cover defence and regulatory response costs, but cover for fines is often restricted or subject to jurisdictional exclusions.
- CQC expectations: the Care Quality Commission expects providers to manage incidents affecting safety and service continuity. Evidence of incident logging and mitigations helps when responding to inspections.
Links to guidance: ICO guidance for organisations, CQC, National Cyber Security Centre (NCSC).
How company size affects premiums and excesses
Underwriting commonly considers: payroll, turnover, number of records, sector and security controls. For SMEs in care:
- Microbusinesses (1–10 staff) often see lower base premiums but proportionally higher excesses and tighter eligibility criteria for ransomware cover.
- Small businesses (10–50 staff) commonly pay higher premiums but can access broader limits and additional covers like dependent BI and extended legal defence costs.
- Larger SMEs may face bespoke underwriting questions about IoT devices, supplier contracts and continuity plans; pricing becomes more sensitive to previous claims history and third‑party dependencies.
Premium drivers specific to the care sector include: number of clients and medical records, use of connected medical devices, dependence on council/NHS portals and frequency of staff turnover (training needs). Many insurers offer discounts or more favourable terms where recognised controls (e.g., Cyber Essentials, penetration testing, EDR) are in place.
What typical policies include, neutral comparison
Typical cover sections in many SME cyber policies:
- First-party costs: forensic investigation, data restoration, notification costs, PR.
- Business interruption: lost income and additional costs to restore service.
- Cyber extortion: negotiation and potential payment (varies by insurer).
- Third-party liability: legal defence and compensation to third parties for data breaches.
- Regulatory defence & fines: legal defence costs and, where insurable, fines (check policy wording carefully).
Important exclusions often found across policies:
- Deliberate criminal acts by insured personnel (fraud exclusion).
- Failure to maintain agreed security controls (e.g., no MFA where required).
- Known prior incidents not disclosed at inception.
Practical steps for buying and managing cover (step-by-step)
- Prepare a simple asset register (devices, software, data types and third‑party suppliers).
- Document security controls: patching, MFA, backup frequency and staff training.
- Obtain quotes from at least three brokers or insurers and compare policy wordings, not just price.
- Check incident response support included (forensics, PR, legal) and whether ransom payments are covered.
- Keep polices and contact details accessible to managers and ensure the incident response plan references the insurer's 24/7 hotline.
Common mistakes and how to avoid them
- Relying on price alone; narrow limits or exclusions can leave significant gaps.
- Not reading policy definitions for “personal data” or “system”, these determine scope.
- Failing to disclose third‑party suppliers that host records, which can void cover.
- Overlooking mobile device controls for domiciliary care staff.
Incident claims: what happens if a breach occurs
Typical insurer-assisted process (general description):
- Notify insurer immediately through the policy’s incident hotline.
- Insurer appoints or approves forensic and legal specialists.
- Forensic report produced; containment and recovery actions executed.
- Claim assessment against policy terms; eligible costs are reimbursed or managed by insurer.
Documentation to prepare: incident logs, affected records list, evidence of controls (backup screenshots, MFA logs) and all correspondence with third parties and regulators.
Infographic (responsive HTML/CSS)
Care sector cyber risk at a glance ➡️
Indicative • 2026
Care homes
Central records • IoT devices • Higher BI exposure
Domiciliary care
Mobile staff • Device theft • Data sync risks
Quick mitigation ➡️ MFA • Encrypted backups • Staff phishing training
Strategic analysis: pros and cons of common cover choices
- Wider limits (pro): greater financial protection for BI and legal costs; (con): higher premiums.
- Ransomware cover (pro): access to negotiators and restoration; (con): some insurers exclude ransom payments or set strict conditions.
- Contingent BI (pro): covers supplier outages; (con): requires detailed supplier lists and may carry sublimits.
Decisions depend on service model: a small domiciliary provider may prioritise device encryption and staff training over high BI limits, while a residential home may prioritise higher BI and incident response budgets.
FAQs
What cyber controls do insurers commonly require for care providers?
Insurers often expect up-to-date patching, multi-factor authentication (MFA) for remote access, regular backups (off-site and tested), and basic staff phishing training. Requirements vary by insurer and size.
Will cyber insurance cover ICO fines after a data breach?
Coverage for fines varies; some policies cover regulatory defence costs but exclude fines or apply sublimits. Policy wordings should be checked and legal advice sought for specific cases.
How much does cyber insurance cost for a small care home in 2026?
Indicative premiums vary widely; small care homes may see annual premiums from a few hundred to several thousand pounds depending on limits, controls and claims history. Exact pricing depends on underwriting information.
Are ransom payments always covered?
Not always. Some insurers permit ransom payments under strict conditions and government guidance, while others exclude them. Confirm policy wording before assuming cover.
Does Cyber Essentials reduce premium?
Holding Cyber Essentials may help with underwriting and sometimes reduces premiums or satisfies insurer minimum requirements, but it is not a guarantee of lower cost.
What is the insurer’s role in incident response?
Many insurers provide 24/7 incident hotlines and appoint forensic, legal and PR specialists; however, insurer-appointed vendors and steps must follow the policy’s procedures.
How soon must the ICO be notified after a breach?
If a breach risks individuals’ rights and freedoms, notification to the ICO is typically expected within 72 hours. Provider should keep records and evidence supporting any decision.
Plan of action (three quick steps <10 minutes)
- Create a short device inventory: list laptops, tablets, clinical IoT and key software used.
- Check backup status: confirm last successful backup and where it is stored (offsite/cloud).
- Locate current policy documents and insurer hotline number; add them to an incident folder.
Conclusion
Cyber insurance is a risk-transfer tool that helps manage costs and access specialist response during incidents. Care homes and domiciliary care providers face distinct exposures, centralised systems and IoT risks in residential settings versus staff mobility and device loss in domiciliary care. Choosing appropriate limits, ensuring basic controls and documenting systems and suppliers improves the likelihood of a smooth claim and reduces business interruption. For regulatory or contractual obligations, documented evidence of reasonable technical and organisational measures is essential.
Sources and further reading