An increase in cyber insurance and liability enquiries from health and care organisations is being reported by independent insurance broking and risk management specialist TL Dallas, as attacks continue to demonstrate the potential operational, financial and regulatory consequences of a cyber incident.
The health and care division of TL Dallas is reporting an influx of Cyber Liability enquiries from organisations operating across the health and care sector, as providers face growing awareness of the potential impact of ransomware, phishing, data breaches and attacks affecting third-party technology suppliers.
The insurance broker’s health and care team says the increased interest reflects a wider recognition that cyber risk is no longer solely an IT concern. For organisations responsible for delivering healthcare and social care services, the consequences of a cyber incident can extend to operational continuity, access to information, regulatory obligations and the delivery of care.
The warning comes as the latest UK Government Cyber Security Breaches Survey, published in April 2026, found that 33% of health and social care businesses surveyed had identified a cyber breach or attack during the previous 12 months.
The National Cyber Security Centre (NCSC) has also identified health among the sectors reporting the highest levels of ransomware activity to the organisation during 2024-2025, reinforcing the continuing threat posed to organisations delivering essential services.
Health and care organisations can be particularly exposed because they frequently depend on digital systems to support day to day operations. These can include electronic care records, medication management, rostering, payroll, finance, communications and access-control systems. An interruption to one or more of these systems can create additional administrative demands at a time when staff are already managing complex care requirements.
The sensitivity of the information held by health and care organisations is another important consideration. The Department of Health and Social Care states that the UK health and social care sector is considered an attractive target to a range of threat actors because of the quantity and sensitivity of health data available.
For care providers, cyber resilience therefore needs to form part of wider business continuity and risk management planning rather than being treated solely as a technical issue.
Rico Young, from TL Dallas’s specialist health and care team, said: “The increase in enquiries reflects a growing understanding among providers that cyber incidents can create costs and disruption extending well beyond the initial technical problem.
“Cyber insurance does not replace effective cyber security controls, but depending on the policy, it can provide access to specialist incident-response expertise and financial protection for specified losses arising from covered cyber events.
“Potential areas of cover can include incident response, forensic investigation, legal expenses, data-breach response, business interruption and cyber extortion, subject to the terms, conditions, exclusions and limits of the individual policy.
“For smaller and medium-sized care providers in particular, access to specialist expertise following an incident can be an important consideration when assessing the value of cyber insurance. We would encourage providers considering their cyber risk to review both their technical controls and their insurance arrangements.”
TL Dallas recommends several key areas to consider:
- Multi-factor authentication: Organisations need to make sure their systems are properly protected, including using two or more different types of authentication when logging into their networks or systems.
- Backups and recovery: Organisations should maintain appropriate backups and test their ability to restore systems following an incident.
- Staff awareness: Phishing and social engineering remain significant routes into organisations, making regular staff awareness training important.
- Supplier risk: Providers should understand how critical third-party technology and service providers are protected.
- Incident planning: Organisations should know who will lead their responses, how incidents will be escalated, and which specialist support may be required.
- Insurance review: Existing policies should be reviewed to understand the scope of cover, exclusions, conditions and applicable limits.
The NCSC continues to emphasise the importance of measures including keeping systems updates, using strong authentication and maintaining resilient backups as part of protection against ransomware and other cyber threats.
Rico added: “For health and care providers, the message is increasingly clear – cyber resilience is closely connected to operational resilience. As organisations become more dependent on digital systems and third-party technology, preparing for the financial and operational consequences of a cyber incident is a vitally important part of wider risk management.”
Visit: www.tldallas.com/health-and-care-insurance or email rico.young@tldallas.com or call Rico on 01274 465577 to book a complimentary review.