Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
A physiotherapy practice runs on a single software package in which records, diary and billing come together, and there is nobody in-house to take over if that package fails.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
The treatment record contains the referral, the diagnosis, the examination findings and the progress. That is health data and therefore a special category under the GDPR, alongside the professional duty of secrecy that stands apart from that law. In the event of a breach, the report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours applies and, because the risk to those concerned is generally high where medical data is involved, so does the duty to inform the patients themselves. The number of patients is smaller than at a hospital; the weight of each record is not.
What makes a practice vulnerable is not the volume of data but the absence of spare capacity. There is no IT department, no lawyer and no communications adviser, while the diary is simply full. The incident response cover is therefore the component on which you choose this policy: a number you call, people who establish which records have been affected and who draft the notification and the patient letter while you carry on treating.
Also consider everyone who can get into the system. Locums, students on placement and self-employed professionals (zzp'ers) working with you have their own login details, and those are not always withdrawn when the arrangement ends. Insurers ask about this and attach conditions to it; answers that are not correct affect the duty of disclosure under Article 7:928 of the Dutch Civil Code and the consequences of this in Article 7:930 of the Dutch Civil Code. The same applies to the question of whether you can reach records from private devices.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
If the package fails, you do not know who is coming or what for. You can still treat on paper, but rescheduling appointments, reaching patients and billing afterwards becomes manual work. The interruption cover works with lost turnover; a practice's real loss often lies in the weeks afterwards, when cancelled treatments are not made up. So ask about the indemnity period and not only about the limit.
Claims to the health insurer run through links with external parties. If that chain stops, your income shifts back, even if your own computer is working. Check whether the policy also pays out where the cause lies with a supplier or an intermediary party and not in your own network. That is not a given, and at a practice the distinction often decides whether anything is paid out at all.
A practice works with changing therapists, and old accounts are often left open. That is exactly the point at which insurers include a warranty clause: multi-factor authentication, personal accounts and withdrawal of access on departure. If the investigation shows that an incident came in through an account that had not been withdrawn, the payout may be reduced. Keep a list of who has access and when it was ended.
Not covered are administrative fines of a punitive nature, the costs of improving your systems afterwards, and damage to equipment itself, which belongs under the business contents cover. A complaint or claim about the treatment is also excluded; that belongs with your professional indemnity insurance (BAV). Intent and wilful recklessness remain excluded under Article 7:952 of the Dutch Civil Code.
This is what people ask us most.
Yes. The GDPR draws no distinction by practice size. If you process health data you are the controller, with all the duties that go with it: a record of processing activities, agreements with parties that process data for you, and in the event of a data breach the report within 72 hours. Precisely because you do it alone, access to specialists is the most important part of the policy.
You remain the controller for the records and report to the Autoriteit Persoonsgegevens yourself. The supplier reports the incident to you. Whether your own policy then pays out depends on whether loss caused by an incident at a service provider is included. Check that point in advance, because it is not included as standard.
No. Complaints about the care itself belong with your professional indemnity insurance (BAV). The cyber policy covers the consequences of a digital incident: recovery, investigation, the costs of the duty to report, your interruption and claims arising from a data breach. If a case involves both, report it on both policies.
You may, but the insurer normally attaches conditions: disk encryption, a screen lock, no local copies and multi-factor authentication on access. If you state in the application that work is done only on practice equipment when that is not the case, that can count against you after an incident.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.