The workshop
How can cyber insurance cover optometry practices when using AI apps and software?
Emily Tyler, commercial business development manager at Lloyd & Whyte, an AOP affinity partner, explains the implications of a data breach for an optometry practice
19 August 2026
The scenario
“As an optometrist and practice owner, I have started using a third-party app to record my calls with patients and provide a summary afterwards. This has been working well, but recently my business partner flagged that there might be a risk in terms of insurance. I'm now confused – would I be liable if something went wrong with patient data whilst I was using the app? Also, could using the app have any impact on my existing cyber insurance policy?”
Joe, AOP member
The advice
Emily Tyler, commercial development manager at AOP insurance affinity partner, Lloyd & Whyte
Using an artificial intelligence (AI)-powered app to record and summarise patient calls can save time and improve record keeping, but your business partner is right to raise a red flag. Bringing a third party into your patient data workflow changes your risk picture in two distinct ways:
- Your legal liability for the data
- Your standing under your cyber insurance policy.
Here’s how to think through both aspects.
You are responsible for the data – even when a third-party handles it
Under UK GDPR, when you decide why and how patient data is processed, you are the ‘data controller.’ The app provider, processing that data on your instructions, is your ‘data processor.’ Taking recordings with a third-party app does not transfer your legal responsibility to them – it adds them to your chain of accountability.
If the app suffers a breach, loses data, or uses it in ways it shouldn’t, you as controller can still face regulatory action, complaints, and reputational fallout, alongside the app provider. Similarly, if your AI recordings are lost or fall into the wrong hands, this will be considered a data breach, and you will need to take active measures to address the incident.
Your business partner is right to raise a flag. Bringing a third party into your patient data workflow changes your risk picture in two distinct ways
What steps can you take?
Before relying on any third-party tool for patient data, you should confirm:
- There’s a written data processing agreement (DPA) in place, setting out what the app can and cannot do with the data
- That the app only processes data on your documented instructions
- Data is encrypted, access-controlled, and stored appropriately (ideally within the UK/EEA, or with adequate safeguards if not)
- The provider has a clear breach-notification process, so you can meet your own 72-hour reporting obligation to the ICO if something goes wrong.
- Patients have been informed (via your privacy notice) that calls may be recorded, and you have a lawful basis for this.
If any of this is missing, that’s a genuine gap. It’s worth asking the app provider directly for their DPA and security documentation if you haven’t already.
Your cyber insurance policy
In response to technological developments within AI, we have enhanced our cyber liability and data insurance offering to address evolving risks linked to sensitive data stored in optometry practices, vulnerabilities within digital systems used, and AI scribing tools, such as call recording or note taking apps. The cyber insurance we provide includes cover for data breach-specific incidents, including:
- Costs relating to reinstating or restoring data or programmes following a cyber attack
- Notification costs around third-party data breach
- Legal costs in the event of a third-party breach
- Legal costs should a government entity investigate you following a data breach.
Cyber insurance: be transparent with your insurance broker
If you use AI tools at your optometry business, and you have a cyber insurance policy with Lloyd & Whyte, please let us know so that we can adjust or extend your insurance coverage to fully protect you from a cyber incident.
Practical next steps
- Ask your app provider for their DPA, security certifications, and details of where data is stored
- Call your cyber insurer or broker and describe exactly what the app does. Ask explicitly whether it needs to be disclosed or named on the policy
- Update your practice's privacy notice and staff procedures to reflect the new tool
- Keep a simple record of this due diligence – it’s useful evidence of accountability if anything is ever questioned.
None of this means you should stop using the app. Many practices use AI tools safely, but closing these gaps now is strongly advised rather than discovering them after an incident.
Lloyd & Whyte® Limited is authorised and regulated by the Financial Conduct Authority (FRN 306077). Registered in England No. 03686765. Registered office: Affinity House, Bindon Road, Taunton, Somerset, TA2 6AA. VAT Registration No. 477 7248 00. Calls may be recorded for use in quality management, training and customer support.
About the author
- Explore more topics
- Business and practice management
- Business
- Artificial intelligence
- Communication
- Feature
Advertisement
More The workshop
-
Understanding equipment in transit insurance for optometrists -
Understanding public and employers’ liability insurance for optometry practices -
Future optometry business owner? The three aspects of practice insurance you need to know about -
Business owners: why it’s vital to update your insurance as your practice grows
Comments (0)
You must be logged in to join the discussion. Log in