August 19, 2026
Insurance

How can cyber insurance cover optometry practices when using AI apps and software?


The scenario

“As an optometrist and practice owner, I have started using a third-party app to record my calls with patients and provide a summary afterwards. This has been working well, but recently my business partner flagged that there might be a risk in terms of insurance. I’m now confused – would I be liable if something went wrong with patient data whilst I was using the app? Also, could using the app have any impact on my existing cyber insurance policy?”

Joe, AOP member

The advice

Emily Tyler, commercial development manager at AOP insurance affinity partner, Lloyd & Whyte

Using an artificial intelligence (AI)-powered app to record and summarise patient calls can save time and improve record keeping, but your business partner is right to raise a red flag. Bringing a third party into your patient data workflow changes your risk picture in two distinct ways:

  • Your legal liability for the data
  • Your standing under your cyber insurance policy.

Here’s how to think through both aspects.

You are responsible for the data – even when a third-party handles it

Under UK GDPR, when you decide why and how patient data is processed, you are the ‘data controller.’ The app provider, processing that data on your instructions, is your ‘data processor.’ Taking recordings with a third-party app does not transfer your legal responsibility to them – it adds them to your chain of accountability.

If the app suffers a breach, loses data, or uses it in ways it shouldn’t, you as controller can still face regulatory action, complaints, and reputational fallout, alongside the app provider. Similarly, if your AI recordings are lost or fall into the wrong hands, this will be considered a data breach, and you will need to take active measures to address the incident.

Your business partner is right to raise a flag. Bringing a third party into your patient data workflow changes your risk picture in two distinct ways

 

What steps can you take?

Before relying on any third-party tool for patient data, you should confirm:

If any of this is missing, that’s a genuine gap. It’s worth asking the app provider directly for their DPA and security documentation if you haven’t already.

Your cyber insurance policy

In response to technological developments within AI, we have enhanced our cyber liability and data insurance offering to address evolving risks linked to sensitive data stored in optometry practices, vulnerabilities within digital systems used, and AI scribing tools, such as call recording or note taking apps. The cyber insurance we provide includes cover for data breach-specific incidents, including:

  • Costs relating to reinstating or restoring data or programmes following a cyber attack
  • Notification costs around third-party data breach
  • Legal costs in the event of a third-party breach
  • Legal costs should a government entity investigate you following a data breach.

Cyber insurance: be transparent with your insurance broker

If you use AI tools at your optometry business, and you have a cyber insurance policy with Lloyd & Whyte, please let us know so that we can adjust or extend your insurance coverage to fully protect you from a cyber incident.

Practical next steps

  1. Ask your app provider for their DPA, security certifications, and details of where data is stored
  2. Call your cyber insurer or broker and describe exactly what the app does. Ask explicitly whether it needs to be disclosed or named on the policy
  3. Update your practice’s privacy notice and staff procedures to reflect the new tool
  4. Keep a simple record of this due diligence – it’s useful evidence of accountability if anything is ever questioned.

None of this means you should stop using the app. Many practices use AI tools safely, but closing these gaps now is strongly advised rather than discovering them after an incident.

For specialist advice and/or a new insurance quote tailored to your requirements, get in touch with a member of our team.

Or request a quote.

Lloyd & Whyte® Limited is authorised and regulated by the Financial Conduct Authority (FRN 306077). Registered in England No. 03686765. Registered office: Affinity House, Bindon Road, Taunton, Somerset, TA2 6AA. VAT Registration No. 477 7248 00. Calls may be recorded for use in quality management, training and customer support.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *