It is 8.15am. The booking system is unavailable, and clinicians cannot access patient records. Appointments are being cancelled or moved.
By lunchtime, you may be paying for IT recovery and answering patient queries. You may also be estimating lost fee income. One cyber claim could consume most of the policy.
For a small private clinic, aggregate and sub-limit choices should reflect restoration, downtime income, patient notice, and a serious privacy claim. Turnover alone is not enough.
Is your annual aggregate enough for a clinic?
An annual aggregate limit is the most an insurer will pay for all covered claims in one policy year. It should withstand more than one clinic incident.
Use a cautious calculation instead of a turnover percentage. Add lost income for the likely outage period. Then add extra working costs, recovery, breach response, and privacy liability.
Test whether two incidents could occur within twelve months. Think of the aggregate as a yearly household budget. Each covered claim takes money from the same pot.
- Lost income: income from cancelled appointments, rather than appointments merely delayed.
- Extra working costs: overtime, secure temporary booking, manual administration, and patient contact.
- Technical response: forensic IT costs to find the entry point and restore safe access.
- Privacy response: legal advice, notification costs, and support during an ICO enquiry.
Test a second incident in the same year
The aggregate is used across claims. It does not reset after the first claim.
A ransomware event costing £180,000 in April may be followed by a billing supplier incident costing £140,000 in November. That can leave far less cover than the schedule first suggests.
The most frequent error at renewal is testing only one large event. Small clinics can face a second, unrelated incident before the policy year ends.
A useful renewal test: add one severe system outage to one smaller patient-data incident. Compare the total with the annual aggregate after each excess and sub-limit.
Aggregate, per-claim limit and excess explained
An annual aggregate caps all claims in a year. A per-claim limit caps one event. A sub-limit caps one cost type. An excess is what the clinic pays itself.
| Policy term | What it limits | Clinic question |
|---|
| Annual aggregate | All covered claims in one policy year | Could two incidents exhaust it? |
| Per-claim limit | One cyber event | Would one serious breach fit below it? |
| Sub-limit | A named cover section | Is restoration or interruption capped too low? |
| Excess or retention | Clinic contribution per claim or section | Can cash flow absorb it quickly? |
A high headline limit can still leave a weak claim payment. The sub-limits and excess decide how much of each cost the insurer may pay.
The six sub-limits private clinics must test
The six sub-limits most likely to shape a clinic claim are forensic IT, restoration, business interruption, notification, regulatory defence, and privacy liability.
Forensics and clinical data restoration
Forensic IT costs pay for an investigation. The work identifies how access was gained, what was accessed, and whether systems are safe to reconnect.
Ask whether this includes Microsoft 365 accounts, remote access, outsourced IT, and cloud-held electronic patient records. Those systems can all hold or expose patient data.
Even clean backups do not remove recovery costs.
Interruption and patient notification
Business interruption pays defined financial loss after a covered system outage. Check the indemnity period, which is usually stated in months.
Also check the waiting period, saved expenses, extra working costs, and lost-income rules. Ask whether postponed appointments count as lost income.
An insurer may treat delayed income differently from cancelled income. This detail can change the final claim value.
Regulatory defence and privacy liability
Regulatory investigation costs pay for legal support during contact with the Information Commissioner's Office. This work relates to the UK GDPR and Data Protection Act 2018.
Defence costs differ from GDPR regulatory fines. Fines may be excluded, capped, or affected by legal questions about insurability.
Privacy liability covers claims alleging that patient data was mishandled or disclosed. Check whether defence, settlements, and damages share one cap.
Check whether professional indemnity excludes privacy claims caused by cyber events. The two policies may not respond to the same costs.
How a clinic claim can consume cover
1. Phishing
Mailbox accessed
2. Forensics
Scope the breach
3. Recovery
Restore systems
4. Response
Notify and defend
Each stage may have its own sub-limit. Each stage may also reduce the annual aggregate.
Professional indemnity and cyber insurance should be read together. Do not assume they cover the same loss.
Professional indemnity often responds to claims about clinical advice, treatment, or another professional service. Cyber insurance often pays for forensics, notification, privacy liability, and business interruption.
One incident can involve both policies. A compromised EHR may make records unavailable. A clinician may then make a treatment decision without key information.
In that case, cyber cover may fund recovery and restoration. The professional indemnity insurer may assess the clinical allegation.
Check professional-services exclusions in the cyber wording. Also check cyber, data, or technology exclusions in professional indemnity wording.
Ransomware recovery is not limited to a payment demand. A clinic may face forensics, legal support, negotiation fees, restoration charges, replacement hardware, extra working costs, and lost fee income.
Extortion cover can have its own sub-limit. It may require insurer consent before negotiators are engaged or payments are made.
Sanctions rules can prevent payment to a threat actor. That exclusion can apply even when the clinic faces a genuine threat.
Ask whether restoration is funded when no ransom is paid. Also ask when interruption cover starts after the waiting period.
Ask whether every response expense reduces the annual aggregate. Clean backups may exist, but safe clinical rebuilding can still take several days.
A sub-limit review matters more than the headline figure alone. The next question is whether a supplier outage triggers the cover you expect.
Will supplier outages trigger interruption cover?
Business interruption may not pay for an EHR, booking, billing, or diagnostic supplier outage. Contingent business interruption must be expressly included.
This cover concerns a dependent third party. Think of it as cover for a key service outside your clinic's walls.
Check the supplier definition
Ask whether named and unnamed technology suppliers are covered. Ask whether a cloud platform counts as the clinic's computer system.
Also ask whether the supplier must suffer a cyber event. Ordinary service failure, planned maintenance, and contract disputes are often treated differently.
A case that often causes confusion involves planned supplier maintenance. It may stop appointments, but it may not meet the policy's cyber-event definition.
Check the time and income calculation
A twelve-hour waiting period may be manageable for an afternoon outage. It may not be manageable for a two-day diagnostic-platform failure.
An indemnity period of between three and twelve months can matter. A clinic backlog may take weeks to clear.
Check how the insurer calculates lost income. It may deduct income from appointments later rearranged.
Supplier cover only works when the wording names the right trigger. Next, check whether early response costs reduce funds for later losses.
Do response costs reduce the money left to claim?
Response costs reduce money for later losses when they sit inside the aggregate limit. This can matter before downtime and liability costs are known.
Costs inside or outside the limit
Compare whether response costs sit within the sum insured. They may sit in addition to it or under a separate sub-limit.
Neither structure is always better. The right choice depends on the clinic's likely technical and legal response.
The part most guides miss is this: a low excess does not fix a low restoration sub-limit. Each limit needs separate testing.
Claims-made dates and exclusions
Most cyber liability policies are claims-made. They respond to claims first made and reported during the policy period.
This cover is subject to a retroactive date. Check continuity when changing insurer or broker.
Also check when compromised access began. It may have started before the renewal date.
A suitable annual aggregate should cover one serious outage and a second patient-data incident. Test three to seven days of downtime, restoration, response, and privacy costs against each sub-limit. This approach does not suit NHS bodies or major hospital groups with bespoke risk financing. For most small private clinics, written answers on limits, excesses, supplier cover, and claims dates give a firmer basis than turnover alone.
Questions & answers
How much cyber insurance do I need in the UK?
The suitable amount covers realistic outage, recovery, notification, and liability costs, plus a second incident within twelve months. Start with three to seven days of downtime. Add the relevant sub-limits instead of using turnover alone.
Is a £1 million aggregate enough for a clinic?
A £1 million annual aggregate can suit some clinics if sub-limits and excesses do not restrict likely claims. Test restoration, interruption, and privacy liability against your systems and patient numbers.
What does cyber insurance cover for clinics?
Cyber insurance can cover forensics, data restoration, interruption, extortion, breach response, and privacy liability, subject to wording. Check cover for electronic patient records, outsourced billing, and supplier outages.
Does cyber insurance pay GDPR fines?
Cyber insurance may pay regulatory defence costs, but GDPR fines can be excluded, capped, or legally uncertain. Ask the insurer to separate investigation costs from fines under UK GDPR and the Data Protection Act 2018.
This framework is less relevant for an NHS body or a large hospital group with bespoke risk financing. It is also less relevant where a clinic holds no identifiable patient data and relies little on digital systems. It is educational only. It cannot determine suitable cover or replace advice from a regulated insurance professional.
Renewal questions that expose weak wording
Use a written question list before accepting a renewal. Written answers are easier to compare and keep on file.
Ask these questions in writing
- Is the stated limit annual aggregate, per claim, or both?
- Do forensic IT, legal defence, and notification costs reduce the aggregate?
- What are the separate caps for restoration, interruption, extortion, regulatory defence, and privacy liability?
- Does interruption cover an outage at our EHR, booking, billing, and diagnostic suppliers?
- What waiting period and indemnity period apply, and how is lost income calculated?
- Which excess applies to each section, and does it apply more than once?
- Do professional-services, prior-acts, or supplier exclusions affect our clinic?
Before quoting, UK insurers often ask for evidence of basic controls. They do not only ask whether antivirus software is installed.
Typical questions cover multi-factor authentication for email, remote access, and administrator accounts. They also cover tested backups, patching, endpoint protection, user rights, staff phishing training, and an incident contact.
These controls can matter after a loss. The wording may contain a condition, warranty, or minimum-security requirement.
Keep a short record for the booking platform, EHR, billing system, and outsourced IT provider. State which party is responsible for each control.
If a control cannot yet be put in place, tell the broker. Obtain the insurer's position in writing.
Do not rely on an informal answer.
What matters most:- The annual aggregate should survive more than one covered incident within a policy year.
- A sub-limit can make a large headline limit unusable for restoration or downtime.
- Supplier dependency needs express interruption cover for EHR, billing, and diagnostic platforms.
- Response costs inside the limit can reduce funds for liability and lost income.
- Written answers to wording questions are more useful than premium comparison alone.
Further reading
If you want to learn more about this topic, these sources may interest you: