Updated in May 2026
Cyber insurance for pharmacies delivering online: what to insist on now
Direct answer: buy a cyber policy that names patient-data breaches and ransomware.
It must include contingent business interruption for online ordering and delivery.
It must cover PCI/DPO liabilities and e-prescription errors.
It must cover third-party courier liabilities and refrigerated stock loss.
Ask for sublimits for regulatory fines and notification costs and sample clause wording.
Expect premiums roughly £400–£5,000+, depending on turnover and risk.
Action now: send the underwriting checklist in this guide to the broker, name delivery partners, and insist on explicit wording for EPS/e-prescription incidents.
A single breach can cost tens of thousands and stop online orders.
Owners who scale online orders or who faced a near miss need clarity fast.
Pharmacy with modest online orders using third-party couriers
This profile fits a branch that takes online orders but outsources delivery to national couriers. The main risks come from courier app breaches, misdelivery and address exposure.
The manager should check if the courier accepts cyber liability for misdelivered prescriptions.
Insurers will ask for named courier partners and copies of courier insurance.
If the courier carries the risk, the insurer still wants evidence.
A missing contract or no DPA often triggers declination or a specific exclusion.
Pause here to check progress.
Prioritised cover here includes third-party liability for data leakage and contingent business interruption. The latter applies if a courier platform fails.
Notification costs for exposed patient data must be covered. Forensic costs must be large enough for a courier breach investigation.
1. Incident: courier app compromise
2. Containment: stop deliveries, isolate systems
3. Forensics: log capture, courier logs, chain-of-custody
4. Notify: inform the ICO or other relevant data-protection authority within the timeframe required by applicable data-protection law (for example, GDPR generally requires prompt notification and, where applicable, within 72 hours)
5. BI & restitution: re-deliver medicines, cold-chain checks
6. Lessons & insurer negotiation
Real claim examples and cost breakdowns
Example A: a courier app compromise exposed patient addresses. Forensic response cost c. £12,000.
Mandatory ICO assessment and legal advice cost c. £8,000. Re-delivery and patient contact cost c. £3,500.
Total immediate outlay about £23,500. This excludes regulatory sanction or long-tail liability.
Example B: ransomware locked the PMS for 48 hours and caused BI losses of £18,000. Forensic and restoration cost £22,000.
Refrigerated stock spoilage cost £7,500. Aggregated bill about £47,500 plus PI overlap disputes.
Presenting anonymised examples helps brokers size forensic, notification and spoilage sublimits. This beats relying on a single overall limit.
Pharmacy running in-house drivers and cold-chain deliveries
This profile suits pharmacies that run their own drivers and vans. The risk set includes device theft, driver account compromise and route-planning SaaS outages.
Temperature-monitoring failures and cold-chain breaks are major concerns.
The insurer will probe the cold-chain controls. Expect requests for temperature logs and tamper-evident packaging.
If controlled drugs are delivered, insurers will ask for tight SOPs and driver vetting proof.
Insurance must include explicit cover for refrigerated stock loss caused by a cyber event. Contingent BI for dispatch system lockdowns must also be present.
Stand-alone product or clinical error exclusions may block cover for misdispensed medicines. Brokers should be asked to remove or limit such exclusions.
Warning: clinical or product error exclusions often stop pay-out where an e-prescription error leads to wrong dispensing. Insist on explicit wording covering EPS-caused dispensing errors.
Quick check: have SOPs and logs ready to show underwriters.

Practical mitigation checklist for delivery, EPS and payments
Operational controls reduce premium and claim friction.
For couriers: require DPAs, insurance certificates, MFA on courier admin portals and tamper-evident packaging.
For in-house drivers: enforce locked phones for delivery apps, hardware encryption and remote wipe.
Also require driver vetting, ID-check SOPs and temperature log reconciliation at handover.
For EPS security: enable MFA on admin accounts and keep immutable audit logs.
Retain a time-stamped transaction log for 90 days and validate e-prescription hashes before dispensing.
For payments/PCI DSS: use a PCI-compliant gateway and avoid storing card PANs locally.
Enforce network segmentation between POS and PMS and provide PCI evidence at underwriting.
Include tabletop exercises that simulate courier app breaches and EPS corruption. Insurers increasingly request dated exercise records.
Common buying mistakes and warnings for pharmacies delivering online
Many pharmacies assume a standard SME cyber policy will cover e-prescriptions, controlled drug deliveries and courier faults. That is unsafe.
Insurers frequently exclude clinical or product errors and courier liabilities.
Another mistake is accepting a high overall limit without checking sublimits. A £1m policy with a £10k forensic sublimit leaves a large gap.
The Information Commissioner's Office can trigger large costs. The ICO can fine up to £17.5m or 4% of global turnover (UK GDPR, 2018).
Failing to show documented cyber hygiene and supplier contracts at underwriting time costs money. Insurers ask for Cyber Essentials and NHS DSPT evidence.
Lack of MFA, backups or DPAs often increases premium or causes exclusions.
When this guidance does not apply: if a pharmacy has no online ordering, holds no local patient records and uses NHS-managed EPS only, specialist online delivery cover may be unnecessary.
If a larger corporate or NHS policy already names courier liabilities, buying duplicate cover can waste money.
Always confirm by sending policy wordings to the broker.
Typical clauses to request
-
"This policy covers loss or unauthorised alteration of electronic prescriptions (EPS) resulting in financial loss, clinical harm or regulatory notification obligations to third parties arising directly from a cyber event affecting the insured's IT systems."
-
"Contingent business interruption cover extends to interruptions caused by failure of named third-party delivery partners, couriers and app providers where such failure results from a cyber event."
-
"Cover includes refrigerated stock loss where the preservation of temperature-sensitive medicines fails due to a cyber-related disruption to monitoring or logistics systems."
Highlight the exact phrases above when emailing the broker. Those phrases reduce the chance of a claim being denied on wording grounds.
Frequently asked questions
What is not covered under cyber insurance?
Direct answer: intentional criminal acts by the insured, bodily injury and pure clinical negligence are typically excluded.
Many policies also exclude pre-existing incidents, war, and state action.
Policies often exclude losses where basic security controls were missing at the time of loss.
Insurers often exclude clinical or product error broadly. For pharmacies, human dispensing mistakes sit with PI.
If corrupted EPS data caused the mistake, cyber cover must explicitly include EPS-caused dispensing incidents to respond.
What is professional indemnity insurance for pharmacists?
Direct answer: PI covers professional negligence claims such as dispensing mistakes and clinical advice that harms a patient.
Cyber insurance covers data breaches, extortion, IT outages and related business interruption.
Both policies can overlap if a cyber event causes a clinical error.
The broker must clarify which incidents are allocated to PI or cyber cover and remove gaps.
What are the exclusions in cyber insurance?
Direct answer: common exclusions include known prior incidents, failure to patch, and unencrypted sensitive data when encryption was promised.
Some policies exclude criminal acts by employees. Clinical and product exclusions are common and must be negotiated.
Read exclusion text closely. If a policy excludes "loss arising from clinical negligence", ask for an endorsement to retain EPS-related cover.
How much should cyber insurance cost?
Direct answer: expect typical premiums between £400 and £5,000+ per year as seen in 2026.
Cost depends on turnover, online sales share, controls and claims history.
A small branch with low online volume might pay under £1,000. Larger operations with cold-chain deliveries may pay several thousand.
Premiums fall with strong controls such as Cyber Essentials or NHS DSPT evidence, MFA and backups.
Higher excesses reduce premium but raise operational risk at claim time.
Can cyber insurance cover misdispensed medicines caused by an EPS error?
Direct answer: yes, only if the policy explicitly includes EPS alteration cover and lacks a blanket clinical exclusion.
The wording must link the cause to a cyber event. If absent, the claim may be treated as clinical negligence.
Provide system logs, timestamps and forensic reports to link the misdispense to an IT incident.
Will insurer pay for refrigerated medicine spoilage if the courier system is hacked?
Direct answer: possibly, if the policy includes refrigerated stock cover and contingent BI for courier outages.
The courier should be named or the policy must provide broad contingent cover for contracted couriers.
Ask for the refrigerated stock clause and check spoilage sublimits.
Typical forensic costs for these incidents range between £5,000 and £30,000 in market cases.
Do couriers need to be named on the policy?
Direct answer: not always. Insurers vary on naming couriers.
Naming gives clarity. Some policies accept broader contingent BI clauses for contracted delivery partners.
If a courier is named, supply their insurance certificate and a DPA. If not named, expect tighter underwriting and possible exclusions.
Can the policy be bought online?
Direct answer: standard SME cyber products can be bought online but they may lack pharmacy-specific clauses.
For pharmacy delivery risks, a specialist broker placement is usually better.
Online products often miss EPS, cold-chain and controlled-drugs wording.
Managers search for terms such as "Buy cyber insurance online" and may consider brokers such as PolicyBee. For complex delivery risk, ask for a broker who knows health sector risks.
Worked premium examples to help estimate likely cost
Direct answer: use these examples only to shortlist market approaches; they are illustrative.
Small community pharmacy: turnover £300k, 8% online sales, outsourced national couriers, no cold-chain. Typical premium ~£450–£900.
Forensic and notification sublimits £25k–£50k.
Medium multi-site independent: turnover £1.8m, 25% online, in-house drivers with cold-chain. Indicative premium £1,800–£3,500.
Refrigerated spoilage sublimit £50k and forensic/notification £75k.
Larger regional operator: turnover £6m, 40% online, high controlled-drug delivery. Indicative premium £4,000+ with bespoke wording.
Forensic/notification sublimits may be £100k+ for larger operators.
Pause briefly to review these numbers.
Next steps to buy cyber cover for online pharmacy deliveries
-
Gather the documents the broker will need. Prepare turnover, percentage online revenue, average daily orders and delivery partner details.
-
Evidence controls. Get screenshots or certificates for Cyber Essentials, NHS DSPT entries, MFA on admin and EPS accounts, backup schedules and PCI DSS evidence for payments.
-
Send the underwriting checklist below to the broker. Ask for explicit wording on EPS incidents, contingent BI naming options, refrigerated stock cover and controlled drugs cover.
-
Ask the insurer for sublimit amounts in writing. Request forensic and notification sublimits of at least £50,000 when exposure justifies it.
-
Run a 90-minute tabletop simulating an EPS outage and courier app compromise. Log the exercise and keep the record for underwriting proof.
-
Compare at least three market options. Focus on wording, not price. A cheap policy with clinical exclusions or tiny forensic sublimits often costs more at claim time.
-
If the broker returns standard SME wording, insist on endorsement language before binding. Copy the sample clauses earlier in this guide.
Underwriting checklist, copy and paste to broker
- Business name, trading address, turnover and % online sales.
- Average daily online orders and peak season multiplier.
- Use of EPS and whether local dispensing records are stored onsite.
- Names of delivery partners and copies of their cyber/GL insurance and DPAs.
- Whether controlled drugs are delivered and cold-chain requirements.
- Evidence: Cyber Essentials/Cyber Essentials Plus, NHS DSPT status, PCI DSS evidence for payment processor.
- Technical controls: MFA, EDR, patching cadence, offline immutable backups and encryption of PHI.
- Operational: delivery SOPs, ID-check procedures, driver vetting, staff cyber training records, DPIAs for online services.
- Claims history and any prior incidents with dates and outcomes.
Comparative policy features
| Insurer / Product |
EPS wording |
Contingent BI (couriers) |
Forensic sublimit |
Refrigerated stock |
Typical premium band |
| Hiscox (example) |
Often available with endorsement |
May require named couriers |
£25k–£100k |
Optional; case-by-case |
£400–£2,000 |
| Aviva / mainstream |
Generic cyber; pharmacy wording limited |
Contingent BI sometimes excluded |
£10k–£50k |
Rarely included by default |
£600–£3,000 |
| Beazley / specialist cyber |
Specialist wording often available |
Contingent BI endorsement possible |
£50k–£250k |
Can include cold-chain cover |
£1,200–£5,000+ |
Notes: table rows show typical market behaviour. Exact features and premiums vary by control evidence, turnover and claims history.
Pause briefly before the legal points.
How GDPR and NHS rules affect an online pharmacy purchase
GDPR and the Data Protection Act require breach reporting and safeguards.
The ICO expects notification within 72 hours of becoming aware of a personal data breach (UK GDPR, 2018).
Insurers will ask for DPIAs and evidence of lawful processing.
NHS Digital and NHS DSPT expectations matter when using EPS and spine services.
Evidence of NHS DSPT compliance reduces underwriting friction.
If the pharmacy integrates with NHS systems, share compliance evidence during underwriting.